Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
fMDYks4W2a.exe

Overview

General Information

Sample name:fMDYks4W2a.exe
renamed because original name is a hash value
Original sample name:b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb.exe
Analysis ID:1589529
MD5:54e383ca658ebd3caaf586f032f1c401
SHA1:bc013aace5491c65a869e944123a4344cea6c1f0
SHA256:b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb
Tags:exefunklockerfunksecransomwareuser-TheRavenFile
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
AI detected suspicious sample
Creates files in the recycle bin to hide itself
Creates a process in suspended mode (likely to inject code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
JA3 SSL client fingerprint seen in connection with other malware
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • fMDYks4W2a.exe (PID: 2656 cmdline: "C:\Users\user\Desktop\fMDYks4W2a.exe" MD5: 54E383CA658EBD3CAAF586F032F1C401)
    • conhost.exe (PID: 3320 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • net.exe (PID: 6112 cmdline: "net" session MD5: 0BD94A338EEA5A4E1F2830AE326E6D19)
      • net1.exe (PID: 5840 cmdline: C:\Windows\system32\net1 session MD5: 55693DF2BB3CBE2899DFDDF18B4EB8C9)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: fMDYks4W2a.exeReversingLabs: Detection: 50%
Source: fMDYks4W2a.exeVirustotal: Detection: 49%Perma Link
Source: Submited SampleIntegrated Neural Analysis Model: Matched 97.8% probability
Source: unknownHTTPS traffic detected: 199.232.192.193:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: fMDYks4W2a.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: darkfunk.pdbf source: fMDYks4W2a.exe
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: darkfunk.pdb source: fMDYks4W2a.exe
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\Config\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\Jump to behavior
Source: global trafficHTTP traffic detected: GET /mlUvWYT.jpeg HTTP/1.1accept: */*host: i.imgur.com
Source: Joe Sandbox ViewIP Address: 199.232.192.193 199.232.192.193
Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /mlUvWYT.jpeg HTTP/1.1accept: */*host: i.imgur.com
Source: global trafficDNS traffic detected: DNS query: i.imgur.com
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://127.0.0.1:13556/InsiderSlabBehaviorReportedBuildInsiderSlabBehaviorInsiderSlabBehaviorReporte
Source: fMDYks4W2a.exe, 00000000.00000003.2248432687.000001E65D0F8000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D06F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D159000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2248432687.000001E65D0D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome/acocfkfsx7alydpzevdxln7drwdq_117.0.5938.134/117.0.5
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D06F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome/acosgr5ufcefr7w7nv4v6k4ebdda_117.0.5938.132/117.0.5
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D06F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D06F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/
Source: fMDYks4W2a.exe, 00000000.00000003.2248432687.000001E65D0F8000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D06F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567
Source: fMDYks4W2a.exe, 00000000.00000003.2248432687.000001E65D0F8000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D06F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg
Source: fMDYks4W2a.exe, 00000000.00000003.2248432687.000001E65D12C000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2248432687.000001E65D130000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D0A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe
Source: fMDYks4W2a.exe, 00000000.00000003.2236045591.000001E65D059000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20
Source: fMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://g.live.com/0CR%1/30
Source: fMDYks4W2a.exeString found in binary or memory: http://ns.adobe.queue
Source: fMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://oe.msn.msnmail.hotmail.com/cgi-bin/hmdata
Source: fMDYks4W2a.exe, 00000000.00000003.2264908029.000001E65CF51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://account.live.cB
Source: fMDYks4W2a.exe, 00000000.00000003.2264908029.000001E65CF51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://account.live.cBV2
Source: fMDYks4W2a.exe, 00000000.00000003.2232861986.000001E65CF98000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://arc.msn.com/v4
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF59000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.147.37?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.177.11?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B
Source: fMDYks4W2a.exeString found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D0C9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/odclientsettings/Prod.C:
Source: fMDYks4W2a.exe, 00000000.00000003.2236045591.000001E65D0B8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/odclientsettings/Prod1C:
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/odclientsettings/ProdV2
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D0FA000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D13F000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D14B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/odclientsettings/ProdV2.C:
Source: fMDYks4W2a.exe, 00000000.00000003.2236045591.000001E65D059000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/odclientsettings/ProdV21C:
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96
Source: fMDYks4W2a.exeString found in binary or memory: https://getsession.org/
Source: fMDYks4W2a.exe, 00000000.00000003.2130986596.000001E65B2A2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://i.imgur.com/mlUvWYT.jpeg
Source: fMDYks4W2a.exe, 00000000.00000002.2279784638.00007FF652978000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://i.imgur.com/mlUvWYT.jpegd&
Source: fMDYks4W2a.exeString found in binary or memory: https://i.imgur.com/mlUvWYT.jpegd&8
Source: fMDYks4W2a.exe, 00000000.00000003.2232861986.000001E65CF98000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.microsoftonline.com/common
Source: fMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://m-vnext.sqlazurelabs.com/
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nexus.officeapps.live.comhttps://nexusrules.officeapps.live.com
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://oneclient.sfx.ms/Win/Installers/23.194.0917.0001/amd64/OneDriveSetup.exe
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D0C9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe.C:
Source: fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D159000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe1C:
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://otelrules.azureedge.net/rules/.bundlesdxhelper.exeFailed
Source: fMDYks4W2a.exeString found in binary or memory: https://www.blockchain.com/)
Source: fMDYks4W2a.exeString found in binary or memory: https://www.coinbase.com/)
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownHTTPS traffic detected: 199.232.192.193:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: RegisterRawInputDevicesmemstr_256688d0-b
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D633000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIntegrator.exeB vs fMDYks4W2a.exe
Source: fMDYks4W2a.exeBinary string: Failed to open \Device\Afd\Mio:
Source: fMDYks4W2a.exeBinary string: 0\Device\Afd\Mio
Source: fMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Microsoft.Vbe.Interop.VBProjectClass
Source: fMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Microsoft.Vbe.Interop.VBProjectsClass
Source: classification engineClassification label: mal56.evad.winEXE@6/135@1/1
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile created: C:\Users\user\Desktop\README-QgmBS5YRoI.mdJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3320:120:WilError_03
Source: fMDYks4W2a.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile read: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8B8000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE SchemaVersions(schema_id INTEGER PRIMARY KEY NOT NULL, SchemaVersion INTEGER NOT NULL, GitSHA1 TEXT NOT NULL , UNIQUE (SchemaVersion, GitSHA1));
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: fMDYks4W2a.exeReversingLabs: Detection: 50%
Source: fMDYks4W2a.exeVirustotal: Detection: 49%
Source: fMDYks4W2a.exeString found in binary or memory: /load_hpack; header malformed -- pseudo not at head of block
Source: unknownProcess created: C:\Users\user\Desktop\fMDYks4W2a.exe "C:\Users\user\Desktop\fMDYks4W2a.exe"
Source: C:\Users\user\Desktop\fMDYks4W2a.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\fMDYks4W2a.exeProcess created: C:\Windows\System32\net.exe "net" session
Source: C:\Windows\System32\net.exeProcess created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 session
Source: C:\Users\user\Desktop\fMDYks4W2a.exeProcess created: C:\Windows\System32\net.exe "net" sessionJump to behavior
Source: C:\Windows\System32\net.exeProcess created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 sessionJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\net.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\net.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\net.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\net.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\System32\net.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\net.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: dsrole.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\net1.exeSection loaded: cryptbase.dllJump to behavior
Source: fMDYks4W2a.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: fMDYks4W2a.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: fMDYks4W2a.exeStatic file information: File size 5447168 > 1048576
Source: fMDYks4W2a.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x376200
Source: fMDYks4W2a.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x189a00
Source: fMDYks4W2a.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: fMDYks4W2a.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: darkfunk.pdbf source: fMDYks4W2a.exe
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: fMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: darkfunk.pdb source: fMDYks4W2a.exe

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.LockJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\Config\Jump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeFile opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\Jump to behavior
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: elwKk1x5+9NJD0oC1Sm0PchOiV+3spsDahFOwVMcIA7E=/
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: lwKk1x5+9NJD0oC1Sm0PchOiV+3spsDahFOwVMcIA7E=!
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 13:11:26.031][MicrosoftEdgeUpdate:msedgeupdate][6164:6168][Send][url=https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.177.11?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A&appBrandCode_edgeupdate=INBX&appBrandCode_webview=GGLS&appChannel_edgeupdate=6&appChannel_webview=5&appCohort_edgeupdate=rrf@0.24&appCohort_webview=rrf@0.75&appConsentState_edgeupdate=0&appConsentState_webview=0&appDayOfInstall_edgeupdate=0&appDayOfInstall_webview=6118&appInactivityBadgeApplied_edgeupdate=0&appInactivityBadgeApplied_webview=0&appInactivityBadgeCleared_edgeupdate=0&appInactivityBadgeCleared_webview=0&appInactivityBadgeDuration_edgeupdate=0&appInactivityBadgeDuration_webview=0&appInstallTimeDiffSec_edgeupdate=0&appInstallTimeDiffSec_webview=0&appIsPinnedSystem_edgeupdate=false&appIsPinnedSystem_webview=false&appLastLaunchCount_edgeupdate=0&appLastLaunchCount_webview=0&appLastLaunchTime_edgeupdate=0&appLastLaunchTimeJson_edgeupdate=0&appLastLaunchTimeDaysAgo_edgeupdate=0&appLastLaunchTime_webview=0&appLastLaunchTimeJson_webview=0&appLastLaunchTimeDaysAgo_webview=0&appUpdateCheckIsUpdateDisabled_edgeupdate=false&appUpdateCheckIsUpdateDisabled_webview=false&appUpdatesAllowedForMeteredNetworks_edgeupdate=false&appUpdatesAllowedForMeteredNetworks_webview=false&appVersion_edgeupdate=1.3.177.11&appVersion_webview=117.0.2045.47&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=2&hwPhysmemory=4&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=VMware,%20Inc.&oemProductName=VMware20,1&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.2006&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=scheduler&requestIsMachine=true&requestOmahaShellVersion=1.3.147.37&requestOmahaVersion=1.3.177.11][request=][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF59000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 08:56:22.600][MicrosoftEdgeUpdate:msedgeupdate][3356:4472][Send][url=https://msedge.api.cdp.microsoft.com/api/v1.1/contents/Browser/namespaces/Default/names/msedgeupdate-stable-win-x86/versions/latest?action=select][request={"targetingAttributes":{"AppAp":"","AppBrandCode":"INBX","AppCohort":"","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"1","AppRollout":0.96,"AppTargetVersionPrefix":"","AppVersion":"1.3.147.37","ExpETag":"\"VPQoP1F+fq15wRzh1kPL4PMpWh8ORMB5izvrOC/chjQ=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"core","IsInternalUser":false,"IsMachine":true,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.147.37"}}][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: PXA5AScIvMCImrQWnUlK4F/6o1LRBi5HHuZNpAnWxvI=+
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 13:06:04.175][MicrosoftEdgeUpdate:msedgeupdate][8536:732][Send][url=https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.177.11?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A&appChannel_webview=5&appConsentState_webview=0&appDayOfInstall_webview=-1&appInactivityBadgeApplied_webview=0&appInactivityBadgeCleared_webview=0&appInactivityBadgeDuration_webview=0&appInstallTimeDiffSec_webview=-86400&appIsPinnedSystem_webview=false&appLastLaunchCount_webview=0&appLastLaunchTime_webview=0&appLastLaunchTimeJson_webview=0&appLastLaunchTimeDaysAgo_webview=0&appVersion_webview=117.0.2045.47&appUpdateCheckIsUpdateDisabled_webview=false&appUpdatesAllowedForMeteredNetworks_webview=false&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=2&hwPhysmemory=4&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=VMware,%20Inc.&oemProductName=VMware20,1&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.2006&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=otherinstallcmd&requestIsMachine=true&requestOmahaShellVersion=1.3.147.37&requestOmahaVersion=1.3.177.11][request=][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: eeKcxqaYUpQemuF/g4XeY+/GN/5r9nu6fcwnr/bvuY4c=/
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: nHfHDfN6bsbeT8o/5kyYSl66SsuWvyQeMuXDlHbQfqo=9
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 13:05:09.866][MicrosoftEdgeUpdate:msedgeupdate][1336:8952][Send][url=https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.177.11?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A&appChannel_edgeupdate=6&appConsentState_edgeupdate=0&appDayOfInstall_edgeupdate=0&appInactivityBadgeApplied_edgeupdate=0&appInactivityBadgeCleared_edgeupdate=0&appInactivityBadgeDuration_edgeupdate=0&appInstallTimeDiffSec_edgeupdate=0&appIsPinnedSystem_edgeupdate=false&appLastLaunchCount_edgeupdate=0&appLastLaunchTime_edgeupdate=0&appLastLaunchTimeJson_edgeupdate=0&appLastLaunchTimeDaysAgo_edgeupdate=0&appVersion_edgeupdate=1.3.177.11&appUpdateCheckIsUpdateDisabled_edgeupdate=false&appUpdatesAllowedForMeteredNetworks_edgeupdate=false&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=2&hwPhysmemory=4&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=VMware,%20Inc.&oemProductName=VMware20,1&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.2006&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=otherinstallcmd&requestIsMachine=true&requestOmahaShellVersion=1.3.147.37&requestOmahaVersion=1.3.177.11][request=][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/05/23 08:22:44.675][MicrosoftEdgeUpdate:msedgeupdate][9612:9436][Send][url=https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.177.11?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A&appBrandCode_edgeupdate=INBX&appBrandCode_stable=INBX&appBrandCode_webview=GGLS&appChannel_edgeupdate=6&appChannel_stable=4&appChannel_webview=5&appCohort_edgeupdate=rrf@0.24&appCohort_webview=rrf@0.75&appConsentState_edgeupdate=0&appConsentState_stable=0&appConsentState_webview=0&appDayOfInstall_edgeupdate=0&appDayOfInstall_stable=0&appDayOfInstall_webview=6118&appInactivityBadgeApplied_edgeupdate=0&appInactivityBadgeApplied_stable=0&appInactivityBadgeApplied_webview=0&appInactivityBadgeCleared_edgeupdate=0&appInactivityBadgeCleared_stable=0&appInactivityBadgeCleared_webview=0&appInactivityBadgeDuration_edgeupdate=0&appInactivityBadgeDuration_stable=0&appInactivityBadgeDuration_webview=0&appInstallTimeDiffSec_edgeupdate=86400&appInstallTimeDiffSec_stable=0&appInstallTimeDiffSec_webview=86400&appIsPinnedSystem_edgeupdate=false&appIsPinnedSystem_stable=false&appIsPinnedSystem_webview=false&appLastLaunchCount_edgeupdate=0&appLastLaunchCount_stable=1&appLastLaunchCount_webview=0&appLastLaunchTime_edgeupdate=0&appLastLaunchTimeJson_edgeupdate=0&appLastLaunchTimeDaysAgo_edgeupdate=0&appLastLaunchTime_stable=13340960379323595&appLastLaunchTimeJson_stable=2023-10-05t06:19:39.323z&appLastLaunchTimeDaysAgo_stable=0&appLastLaunchTime_webview=0&appLastLaunchTimeJson_webview=0&appLastLaunchTimeDaysAgo_webview=0&appVersion_stable=117.0.2045.55&appUpdateCheckIsUpdateDisabled_edgeupdate=false&appUpdateCheckIsUpdateDisabled_stable=false&appUpdateCheckIsUpdateDisabled_webview=false&appUpdatesAllowedForMeteredNetworks_edgeupdate=false&appUpdatesAllowedForMeteredNetworks_stable=false&appUpdatesAllowedForMeteredNetworks_webview=false&appVersion_edgeupdate=1.3.177.11&appVersion_webview=117.0.2045.47&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=2&hwPhysmemory=4&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=VMware,%20Inc.&oemProductName=VMware20,1&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.2006&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=scheduler&requestIsMachine=true&requestOmahaShellVersion=1.3.147.37&requestOmahaVersion=1.3.177.11][request=][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF59000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 08:56:35.318][MicrosoftEdgeUpdate:msedgeupdate][4092:4100][Send][url=https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.147.37?clientId=s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A&appBrandCode_stable=INBX&appChannel_stable=4&appConsentState_stable=0&appDayOfInstall_stable=0&appInstallTimeDiffSec_stable=0&appLastLaunchTime_stable=0&appUpdateCheckIsUpdateDisabled_stable=false&appVersion_stable=92.0.902.67&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=2&hwPhysmemory=4&isMsftDomainJoined=false&oemProductManufacturer=VMware,%20Inc.&oemProductName=VMware20,1&osArch=x64&osPlatform=win&osVersion=10.0.19045.2006&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=core&requestIsMachine=true&requestOmahaShellVersion=1.3.147.37&requestOmahaVersion=1.3.147.37][request=][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: enHfHDfN6bsbeT8o/5kyYSl66SsuWvyQeMuXDlHbQfqo=/
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 13:05:10.568][MicrosoftEdgeUpdate:msedgeupdate][4796:8636][Send][url=https://msedge.api.cdp.microsoft.com/api/v2/contents/Browser/namespaces/Default/names?action=batchupdates][request=[{"Product":"msedgewebview-stable-win-x64","targetingAttributes":{"AppAp":"","AppBrandCode":"","AppCohort":"","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"","AppRollout":0.63,"AppTargetVersionPrefix":"","AppVersion":"","ExpETag":"\"VPQoP1F+fq15wRzh1kPL4PMpWh8ORMB5izvrOC/chjQ=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"otherinstallcmd","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":10,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}}]][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ePXA5AScIvMCImrQWnUlK4F/6o1LRBi5HHuZNpAnWxvI=/
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/05/23 08:21:22.527][MicrosoftEdgeUpdate:msedgeupdate][10084:4916][Send][url=https://msedge.api.cdp.microsoft.com/api/v2/contents/Browser/namespaces/Default/names?action=batchupdates][request=[{"Product":"msedgeupdate-stable-win-x86","targetingAttributes":{"AppAp":"","AppBrandCode":"INBX","AppCohort":"rrf@0.24","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"1","AppRollout":0.24,"AppTargetVersionPrefix":"","AppVersion":"1.3.177.11","ExpETag":"\"VPQoP1F+fq15wRzh1kPL4PMpWh8ORMB5izvrOC/chjQ=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"scheduler","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}},{"Product":"msedge-stable-win-x64","targetingAttributes":{"AppAp":"","AppBrandCode":"INBX","AppCohort":"","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"117","AppRollout":0.04,"AppTargetVersionPrefix":"","AppVersion":"117.0.2045.47","ExpETag":"\"VPQoP1F+fq15wRzh1kPL4PMpWh8ORMB5izvrOC/chjQ=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"scheduler","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}},{"Product":"msedgewebview-stable-win-x64","targetingAttributes":{"AppAp":"","AppBrandCode":"GGLS","AppCohort":"rrf@0.75","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"117","AppRollout":0.75,"AppTargetVersionPrefix":"","AppVersion":"117.0.2045.47","ExpETag":"\"VPQoP1F+fq15wRzh1kPL4PMpWh8ORMB5izvrOC/chjQ=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"scheduler","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}}]][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: A8eXZTvg7YGvCcJUzyxbHGFSKXp/UmDdgVxDyBqqswI=e*1
Source: fMDYks4W2a.exe, 00000000.00000003.2234057339.000001E65CF66000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: [10/03/23 13:10:48.035][MicrosoftEdgeUpdate:msedgeupdate][4220:5516][Send][url=https://msedge.api.cdp.microsoft.com/api/v2/contents/Browser/namespaces/Default/names?action=batchupdates][request=[{"Product":"msedgeupdate-stable-win-x86","targetingAttributes":{"AppAp":"","AppBrandCode":"INBX","AppCohort":"","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"1","AppRollout":0.72,"AppTargetVersionPrefix":"","AppVersion":"1.3.177.11","ExpETag":"\"qWJSzWwPfdcLR+XGIv6xrZfiYOxhPU2s1NWmjWcaFPg=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"scheduler","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}},{"Product":"msedge-stable-win-x64","targetingAttributes":{"AppAp":"","AppBrandCode":"INBX","AppCohort":"","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"92","AppRollout":0.65,"AppTargetVersionPrefix":"","AppVersion":"92.0.902.67","ExpETag":"\"qWJSzWwPfdcLR+XGIv6xrZfiYOxhPU2s1NWmjWcaFPg=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"scheduler","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}},{"Product":"msedgewebview-stable-win-x64","targetingAttributes":{"AppAp":"","AppBrandCode":"GGLS","AppCohort":"","AppCohortHint":"","AppCohortName":"","AppLang":"","AppMajorVersion":"117","AppRollout":0.6,"AppTargetVersionPrefix":"","AppVersion":"117.0.2045.47","ExpETag":"\"qWJSzWwPfdcLR+XGIv6xrZfiYOxhPU2s1NWmjWcaFPg=\"","HW_AVX":true,"HW_DiskType":2,"HW_LogicalCpus":2,"HW_PhysicalRamGB":4,"HW_SSE":true,"HW_SSE2":true,"HW_SSE3":true,"HW_SSE41":true,"HW_SSE42":true,"HW_SSSE3":true,"InstallSource":"scheduler","IsInternalUser":false,"IsMachine":true,"IsWIP":false,"OemProductManufacturer":"VMware, Inc.","OemProductName":"VMware20,1","OsArch":"x64","OsPlatform":"win","OsRegionDMA":false,"OsRegionName":"CH","OsRegionNation":"223","OsVersion":"10.0.19045.2006","Priority":0,"Updater":"MicrosoftEdgeUpdate","UpdaterVersion":"1.3.177.11","WIPBranch":""}}]][filename=]
Source: fMDYks4W2a.exe, 00000000.00000003.2174318452.000001E65D8E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: eKcxqaYUpQemuF/g4XeY+/GN/5r9nu6fcwnr/bvuY4c=A
Source: fMDYks4W2a.exe, 00000000.00000003.2275879881.000001E65B252000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000002.2278083906.000001E65B252000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\fMDYks4W2a.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeProcess created: C:\Windows\System32\net.exe "net" sessionJump to behavior
Source: C:\Windows\System32\net.exeProcess created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 sessionJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$WinREAgent VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\$WinREAgent\Scratch VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\.curlrc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\Acrobat_23.006.20320 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.0.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\DeploymentConfiguration.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\DeploymentConfiguration.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\DeploymentConfiguration.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\Manifest.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\Manifest.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\Manifest.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserDeploymentConfiguration.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserDeploymentConfiguration.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserDeploymentConfiguration.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserManifest.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserManifest.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserManifest.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Integration VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\MasterDescriptor.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\MasterDescriptor.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\MasterDescriptor.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\s321033.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\s321033.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.dat.cat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.dat.cat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.man.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.man.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.man.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\operations.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\operations.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\operations.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\VirtualRegistry.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\VirtualRegistry.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\MasterDescriptor.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\s320.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.hash VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.man.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\UserData VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA} VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\AirSpace.Etw.man VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\AirSpace.Etw.man VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64ww.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.onenotemui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.onenotemui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.powerpointmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerView.PowerView.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerView.PowerView.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.wordmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.wordmui.msi.16.en-us.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates Logon.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates Logon.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\wordEtw.man VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Crypto VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Crypto\DSS VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Crypto\DSS\MachineKeys VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Crypto\SystemKeys\4fbf593b24f129e7d8c9fc84ba6a1ac3_9e146be9-c76a-4720-bcdb-53011b87bd06 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\pictures.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\settings.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-GB\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-GB\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-GB\resource.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DeviceSync VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\CustomTraceProfiles VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-194626ba46434f9ab441dd7ebda2aa64-5f64bebb-ac28-4cc7-bd52-570c8fe077c9-7717.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-194626ba46434f9ab441dd7ebda2aa64-5f64bebb-ac28-4cc7-bd52-570c8fe077c9-7717.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-194626ba46434f9ab441dd7ebda2aa64-5f64bebb-ac28-4cc7-bd52-570c8fe077c9-7717.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-4bb4d6f7cafc4e9292f972dca2dcde42-bd019ee8-e59c-4b0f-a02c-84e72157a3ef-7485.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-4bb4d6f7cafc4e9292f972dca2dcde42-bd019ee8-e59c-4b0f-a02c-84e72157a3ef-7485.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-4bb4d6f7cafc4e9292f972dca2dcde42-bd019ee8-e59c-4b0f-a02c-84e72157a3ef-7485.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-5476d0c4a7a347909c4b8a13078d4390-f8bdcecf-243f-40f8-b7c3-b9c44a57dead-7230.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-5476d0c4a7a347909c4b8a13078d4390-f8bdcecf-243f-40f8-b7c3-b9c44a57dead-7230.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-5476d0c4a7a347909c4b8a13078d4390-f8bdcecf-243f-40f8-b7c3-b9c44a57dead-7230.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-7005b72804a64fa4b2138faab88f877b-14cf798a-05a4-4b7b-9d02-4d99259ebd4a-7553.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-7005b72804a64fa4b2138faab88f877b-14cf798a-05a4-4b7b-9d02-4d99259ebd4a-7553.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-af397ef28e484961ba48646a5d38cf54-77418283-d6f6-4a90-b0c8-37e0f5e7b087-7425.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-af397ef28e484961ba48646a5d38cf54-77418283-d6f6-4a90-b0c8-37e0f5e7b087-7425.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-af397ef28e484961ba48646a5d38cf54-77418283-d6f6-4a90-b0c8-37e0f5e7b087-7425.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-d5a8f02229be41efb047bd8f883ba799-59258264-451c-4459-8c09-75d7d721219a-7112.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-d5a8f02229be41efb047bd8f883ba799-59258264-451c-4459-8c09-75d7d721219a-7112.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-d5a8f02229be41efb047bd8f883ba799-59258264-451c-4459-8c09-75d7d721219a-7112.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-Eco3PTelDefault.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-Eco3PTelDefault.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.allow.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.allow.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.allow.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.privacy.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\Diagtrack-Listener.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\Diagtrack-Listener.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\Diagtrack-Listener.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\EventTranscript VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\FeedbackHub VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\LocalTraceStore VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\osver.txt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\osver.txt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\osver.txt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\parse.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\parse.dat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\Siufloc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\SoftLandingStage VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\Temp\DiagTrackTraceSlot_aot VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_Autopilot_2023_10_3_9_57_25.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_Autopilot_2023_10_3_9_57_25.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_Autopilot_2023_10_3_9_57_25.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_Autopilot_2023_10_3_9_59_39.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_Autopilot_2023_10_3_9_59_39.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_DeviceProvisioning_2023_10_3_8_56_48.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_DeviceProvisioning_2023_10_3_8_56_48.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_DeviceProvisioning_2023_10_4_9_46_43.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_DeviceProvisioning_2023_10_4_9_46_43.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_DeviceProvisioning_2023_10_4_9_46_43.etl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\IdentityCRL\production\wlidsvcconfig.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\IdentityCRL\production\wlidsvcconfig.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\IdentityCRL\production\wlidsvcconfig.xml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\MF\Active.GRL VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb00001.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb00001.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edbres00001.jrs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edbtmp.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edbtmp.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edbtmp.log VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Office VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Provisioning\AssetCache VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Config VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00011.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00011.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00012.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00013.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.Crwl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.Crwl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.Crwl VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeQueries volume information: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\fMDYks4W2a.exeCode function: 0_2_00007FF652965058 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF652965058
Source: C:\Users\user\Desktop\fMDYks4W2a.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
11
Process Injection
1
Masquerading
11
Input Capture
1
System Time Discovery
Remote Services11
Input Capture
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Disable or Modify Tools
LSASS Memory1
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
Process Injection
Security Account Manager2
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Hidden Files and Directories
NTDS13
System Information Discovery
Distributed Component Object ModelInput Capture3
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1589529 Sample: fMDYks4W2a.exe Startdate: 12/01/2025 Architecture: WINDOWS Score: 56 21 ipv4.imgur.map.fastly.net 2->21 23 i.imgur.com 2->23 27 Multi AV Scanner detection for submitted file 2->27 29 AI detected suspicious sample 2->29 8 fMDYks4W2a.exe 136 2->8         started        signatures3 process4 dnsIp5 25 ipv4.imgur.map.fastly.net 199.232.192.193, 443, 49709 FASTLYUS United States 8->25 19 C:\$Recycle.Bin\...\desktop.ini.Lock, OpenPGP 8->19 dropped 31 Creates files in the recycle bin to hide itself 8->31 13 net.exe 1 8->13         started        15 conhost.exe 8->15         started        file6 signatures7 process8 process9 17 net1.exe 1 13->17         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
fMDYks4W2a.exe50%ReversingLabsWin64.Ransomware.Funksec
fMDYks4W2a.exe49%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ns.adobe.queue0%Avira URL Cloudsafe
http://127.0.0.1:13556/InsiderSlabBehaviorReportedBuildInsiderSlabBehaviorInsiderSlabBehaviorReporte0%Avira URL Cloudsafe
https://account.live.cBV20%Avira URL Cloudsafe
https://account.live.cB0%Avira URL Cloudsafe
https://getsession.org/0%Avira URL Cloudsafe
http://oe.msn.msnmail.hotmail.com/cgi-bin/hmdata0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
ipv4.imgur.map.fastly.net
199.232.192.193
truefalse
    high
    i.imgur.com
    unknown
    unknownfalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      http://ns.adobe.queuefMDYks4W2a.exefalse
      • Avira URL Cloud: safe
      unknown
      https://g.live.com/odclientsettings/Prod.C:fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D0C9000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://g.live.com/odclientsettings/Prod1C:fMDYks4W2a.exe, 00000000.00000003.2236045591.000001E65D0B8000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          https://g.live.com/odclientsettings/ProdV2fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            https://www.coinbase.com/)fMDYks4W2a.exefalse
              high
              https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                https://i.imgur.com/mlUvWYT.jpegd&fMDYks4W2a.exe, 00000000.00000002.2279784638.00007FF652978000.00000002.00000001.01000000.00000003.sdmpfalse
                  high
                  http://g.live.com/0CR%1/30fMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://docs.rs/getrandom#nodejs-es-module-supportfMDYks4W2a.exefalse
                      high
                      https://g.live.com/odclientsettings/ProdV21C:fMDYks4W2a.exe, 00000000.00000003.2236045591.000001E65D059000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        https://g.live.com/odclientsettings/ProdV2.C:fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D0FA000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D13F000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmp, fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D14B000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://i.imgur.com/mlUvWYT.jpegfMDYks4W2a.exe, 00000000.00000003.2130986596.000001E65B2A2000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://127.0.0.1:13556/InsiderSlabBehaviorReportedBuildInsiderSlabBehaviorInsiderSlabBehaviorReportefMDYks4W2a.exe, 00000000.00000003.2212378863.000001E65D23F000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://account.live.cBV2fMDYks4W2a.exe, 00000000.00000003.2264908029.000001E65CF51000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://i.imgur.com/mlUvWYT.jpegd&8fMDYks4W2a.exefalse
                              high
                              http://oe.msn.msnmail.hotmail.com/cgi-bin/hmdatafMDYks4W2a.exe, 00000000.00000003.2181415237.000001E65D8BE000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6fMDYks4W2a.exe, 00000000.00000003.2238098280.000001E65D119000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://account.live.cBfMDYks4W2a.exe, 00000000.00000003.2264908029.000001E65CF51000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://www.blockchain.com/)fMDYks4W2a.exefalse
                                  high
                                  https://login.microsoftonline.com/commonfMDYks4W2a.exe, 00000000.00000003.2232861986.000001E65CF98000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    https://getsession.org/fMDYks4W2a.exefalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    199.232.192.193
                                    ipv4.imgur.map.fastly.netUnited States
                                    54113FASTLYUSfalse
                                    Joe Sandbox version:42.0.0 Malachite
                                    Analysis ID:1589529
                                    Start date and time:2025-01-12 18:48:07 +01:00
                                    Joe Sandbox product:CloudBasic
                                    Overall analysis duration:0h 7m 31s
                                    Hypervisor based Inspection enabled:false
                                    Report type:full
                                    Cookbook file name:default.jbs
                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                    Number of analysed new started processes analysed:9
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Sample name:fMDYks4W2a.exe
                                    renamed because original name is a hash value
                                    Original Sample Name:b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb.exe
                                    Detection:MAL
                                    Classification:mal56.evad.winEXE@6/135@1/1
                                    EGA Information:Failed
                                    HCA Information:Failed
                                    Cookbook Comments:
                                    • Found application associated with file extension: .exe
                                    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                    • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.12.23.50
                                    • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                    • Execution Graph export aborted for target fMDYks4W2a.exe, PID 2656 because there are no executed function
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size getting too big, too many NtQueryValueKey calls found.
                                    • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                    No simulations
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    199.232.192.193http://steam.usercommunityart.com/filedetails/sharedfiles/id=319248110/Get hashmaliciousUnknownBrowse
                                      https://heuristic-knuth-588d37.netlify.app/?naps/Get hashmaliciousHTMLPhisherBrowse
                                        https://theleadking2435063.emlnk.com/lt.php?x=3DZy~GDHJaLL5a37-gxLhhGf13JRv_MkkPo2jHPMKXOh5XR.-Uy.xuO-2I2imNfGet hashmaliciousUnknownBrowse
                                          https://media.maxfs.de/Get hashmaliciousUnknownBrowse
                                            setup-avast-premium-x64.exeGet hashmaliciousUnknownBrowse
                                              setup-avast-premium-x64.exeGet hashmaliciousUnknownBrowse
                                                https://report-scam.malwarebouncer.com/XcUR2TnV2VTlXT0s0Z0NYa01KSGt3dUtWMWNiblBrc29mMlpZUU1WdThBSjdDdTlRQTVDV1ZZd0pDeWRmUU5rQ1QvVDNiSlBNYWd2bTd0eTRkZW5jT0hrYTBKWHFiVUc4TVZBOGpiNkh4VG9OTm9zNTVUWHNmNWVydHpqbzhIc1llSzdzTHZ0dENVNWRLZy9BbCsyVDRMSGRHOThUWnV5QUxPU0RZL1dPalNYTmUzMTVoRzl5bmk1ZVZRPT0tLUdVYnJkMC9GazI3MWlxYmotLUpFOURyOWkzK1l6Vy9BYTVOVDBVNkE9PQ==?cid=2346401253Get hashmaliciousKnowBe4Browse
                                                  https://pwv95gp5r-xn--r3h9jdud-xn----c1a2cj-xn----p1ai.translate.goog/sIQKSvTC/b8KvU/uoTt6?ZFhObGNpNXBiblp2YkhabGJXVnVkRUJ6YjNWMGFHVnliblJ5ZFhOMExtaHpZMjVwTG01bGRBPT06c1JsOUE+&_x_tr_sch=http&_x_tr_sl=hrLWHGLm&_x_tr_tl=bTtllyqlGet hashmaliciousHTMLPhisherBrowse
                                                    https://covid19.protected-forms.com/XQTNkY0hwMkttOEdiZmZ0V2RRTHpDdDNqUTROanhES0NBYmdFOG1KTGRSTUtrK3VMMzlEN1JKVVFXNUxaNGJOQmd1YzQ3ajJMeVdZUDU3TytRbGtIaFhWRkxnT0lkeTZhdy9xWEhjeFBoRXRTb2hxdjlVbi9iSk1qZytLQ0JxRjd4UmpOS3VUQ2lpOEZneTRoVmpzY2dyekR1WlhYOWVteVcrUXg0a2Y2aEU2ZEZwMVNId3R0U01RK3N3PT0tLVR0bDl1WEFUelg3K2VzTystLUxaMkFrZnU0UmJXRkR3aE5NRE9BOEE9PQ==?cid=2351432832Get hashmaliciousKnowBe4Browse
                                                      https://employeeportal.net-login.com/XL0pFWEloTnBYUmM5TnBUSmVpbWxiSUpWb3BBL1lPY1hwYU5uYktNWkd5ME82bWJMcUhoRklFUWJiVmFOUi9uUS81dGZ4dnJZYkltK2NMZG5BV1pmbFhqMXNZcm1QeXBXTXI4R090NHo5NWhuL2l4TXdxNlY4VlZxWHVPNTdnc1M3aU4xWjhFTmJiTEJWVUYydWVqZjNPbnFkM3M5T0FNQ2lRL3EySjhvdVVDNzZ2UHJQb0xQdlhZbTZRPT0tLTJaT0Z2TlJ3S0NMTTZjc2ktLTZGNUIwRnVkbFRTTHR2dUFITkcxVFE9PQ==?cid=2341891188Get hashmaliciousKnowBe4Browse
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        ipv4.imgur.map.fastly.netCF537GfmKa.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.196.193
                                                        siy9g3WGCc.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.196.193
                                                        SjDqoVVmzX.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.196.193
                                                        http://steam.usercommunityart.com/filedetails/sharedfiles/id=319248110/Get hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        https://heuristic-knuth-588d37.netlify.app/?naps/Get hashmaliciousHTMLPhisherBrowse
                                                        • 199.232.196.193
                                                        https://freesourcecodes70738.emlnk.com/lt.php?x=3DZy~GDLVnab5KCs-Nu4WOae1qEoiN9xvxk1XaPMVXahD5B9-Uy.xuW-242imNXGet hashmaliciousUnknownBrowse
                                                        • 199.232.196.193
                                                        https://theleadking2435063.emlnk.com/lt.php?x=3DZy~GDHJaLL5a37-gxLhhGf13JRv_MkkPo2jHPMKXOh5XR.-Uy.xuO-2I2imNfGet hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        https://media.maxfs.de/Get hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        http://synthex.cheating.store/Get hashmaliciousUnknownBrowse
                                                        • 199.232.196.193
                                                        setup-avast-premium-x64.exeGet hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        FASTLYUSCF537GfmKa.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.196.193
                                                        siy9g3WGCc.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.196.193
                                                        SjDqoVVmzX.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.196.193
                                                        sZSXKXOnBw.exeGet hashmaliciousUnknownBrowse
                                                        • 185.199.111.133
                                                        sZSXKXOnBw.exeGet hashmaliciousUnknownBrowse
                                                        • 185.199.110.133
                                                        PDF-523.msiGet hashmaliciousAteraAgentBrowse
                                                        • 199.232.210.172
                                                        http://steam.usercommunityart.com/filedetails/sharedfiles/id=319248110/Get hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        https://heuristic-knuth-588d37.netlify.app/?naps/Get hashmaliciousHTMLPhisherBrowse
                                                        • 199.232.192.193
                                                        https://terrific-metal-countess.glitch.me/Get hashmaliciousHTMLPhisherBrowse
                                                        • 151.101.129.44
                                                        http://procustodiavalueslive.github.io/mediantime1db1d62ef90e6fec5644546bc086f16336d68481479f56e29285a338fc23/Get hashmaliciousHTMLPhisher, Mamba2FABrowse
                                                        • 185.199.110.153
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        3b5074b1b5d032e5620f69f9f700ff0eCF537GfmKa.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.192.193
                                                        siy9g3WGCc.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.192.193
                                                        SjDqoVVmzX.exeGet hashmaliciousFunkLockerBrowse
                                                        • 199.232.192.193
                                                        rii2.mp3.htaGet hashmaliciousLummaCBrowse
                                                        • 199.232.192.193
                                                        sZSXKXOnBw.exeGet hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        sZSXKXOnBw.exeGet hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        v2.exeGet hashmaliciousAdes Stealer, BlackGuard, NitroStealer, VEGA StealerBrowse
                                                        • 199.232.192.193
                                                        c2.htaGet hashmaliciousUnknownBrowse
                                                        • 199.232.192.193
                                                        E6wUHnV51P.exeGet hashmaliciousDCRatBrowse
                                                        • 199.232.192.193
                                                        resembleC2.exeGet hashmaliciousBlank Grabber, Umbral StealerBrowse
                                                        • 199.232.192.193
                                                        No context
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:OpenPGP Secret Key
                                                        Category:dropped
                                                        Size (bytes):249
                                                        Entropy (8bit):7.134347413839395
                                                        Encrypted:false
                                                        SSDEEP:6:+iGphV5DviV8GxhdDp8/q6GUI8WvQIL/eA8I+zM+usy:dGvDK3xi/q6RfGDL/fbUusy
                                                        MD5:3ED96E7485CFEF60EF0C600CDB775A68
                                                        SHA1:30276468129F53EA0A119DE458DA259C29508E9B
                                                        SHA-256:92E9C709B361E24E74459D5C554396E693BAE4D9365D27078F50CB0066F6A857
                                                        SHA-512:183008D90DDB42B1181E1E63D5363AE93301C3CFEF3D3BEC0748992A4894F8A45B2CA99A1717517B103EE68C4AA27285960D4F2F2C061C27AB70122D25DB82A8
                                                        Malicious:true
                                                        Reputation:low
                                                        Preview:....>.{.>.uV.(!...@`...C...-...~.uT.4/.t.r.EV#.3...._..Sa4..~\..T....;...{......,....M.Z.U.;..d2..3..n..?..RA.`["...H.m.hN. ..=y.c...}:...........=...3........{,.r.f.....p.Y.}.w...o.H.j(.\....n:.![..|.&.........m. [..n.....z.h.Y.5 .
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):249
                                                        Entropy (8bit):7.136978024409892
                                                        Encrypted:false
                                                        SSDEEP:6:oEV6ttSuUNSDm2/tkLtXLaeawCUxrSrlE5yIVn:oEuKSVUacYrlEMGn
                                                        MD5:10AAB1C7DED681A7197D162EE6E747EE
                                                        SHA1:3FD62522CF854A6315ECE28DF733A11382E15754
                                                        SHA-256:11C03D3E08B06F7C2260F7CCA7B3EAD9ED7B2E3183E8EA01C35EB76BB6B804F8
                                                        SHA-512:46E883B44BC3E8D9A5CB06CB0F27DBB2420A3DEB3DA2A971B96A942DF412802095034DDEDAEA01600FF629C8D5E651B3BF0C17FEEC7323B0B3D81CC5DCDC55BE
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:n...J.)'..5J...k [.B{...X.E.*.F:...bR.YvJ..n.pb..b.C...........H..sq..m;..]...+.ps.?...b.e9.,[.....n.1.TUHH9.v`.#o.....b!Z3..M(..........u.![.2.A...1..Q.VQ..Z..pS.M...g?.,....S'f.....B|!....r.a+R....1...,..C.*.5.......D.J.$..[^.k..e(Vm..$
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):249
                                                        Entropy (8bit):7.021833307690788
                                                        Encrypted:false
                                                        SSDEEP:6:8HiPkrBB9CPIf7lD7tBcUYONiuosnNs0s:8HWSrHxfp4zsC
                                                        MD5:988BEDF075967C7FE2596EA92C6B36B7
                                                        SHA1:3D63FB13B9CB9BEF1B6D6296D81C4007D15B00EC
                                                        SHA-256:15ED5F99DA41914F90DCF67191D42F4E557CA0993FDFE9D87DCAFE19B396542A
                                                        SHA-512:907746B02BA6D3BAAE43EC915877690327729EE5E140C6C9DB5D1DCD81777A17188387C6D5D94F91142C31E63F76CFA350F2BEE4C95B6EAECACF5B4E37992F45
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:C.......A..M.17....)..O..4{.I%.."m.f...R;....*3.Q...Z.b'N.q]RR..U.;.XW..7..K.~.@.....$W...N.|f..g..,t...^.K....H....W.....C[...AR.. .R~....=.......]e{.D/......r.,....E.GU...m......b .....y...Ck.<.x..{@..'.......2..}.....}?.........QQ....ibvD
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):249
                                                        Entropy (8bit):7.165673795605582
                                                        Encrypted:false
                                                        SSDEEP:6:LgtIIRdQfK2gZguuN2punNFIP+TXRVr8OUU8zx9n:L3IDMKFguW2pqqG3onx9n
                                                        MD5:EFC072E6C73B99423637A33B16F10F31
                                                        SHA1:91098AC82455382CA69F875E2A8128FB7F1CDD54
                                                        SHA-256:5400A95F959BE3AAA55CD5414DA74DFFCC6396D6072EB8AC51BA071A769B16FA
                                                        SHA-512:764F352E84F06BEFB11924CA4F6BCCF70205B2CC9387C07939A6C8051FD78EB138DFAB96E95B11EDBEFE8584399A6B8C3552313DB758864E593E6E78838A17E2
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:o.N...Z.eK(v...^.z3-...8r<{.>8A..e......>....E...".V..4.J.).%.f.3g.....*..u..E/......+re.....-..m.P.=6...M/.H0..Q..FZ...l..}......U.iq..&.......~...@.....WU.d.>m.J......hS....@Z.Mar[.<.w.e...9..V.....O...m.,s...o-..pW$.....dB...<.w....h..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2766
                                                        Entropy (8bit):7.6571770126129355
                                                        Encrypted:false
                                                        SSDEEP:48:P2cIF/zp0H4MBXFUU57eF5TsRem+doTJ2Io1q3gQ6S71Y+nzrpWee6CyczCUneQT:+FZ2rtFUUFYmR0CAZ1kg3MY2we7wCUeA
                                                        MD5:CC02218824BBB1A23E6395E2BF900F6E
                                                        SHA1:FFE8D44BF0F38B3E03DFA1B0D45F2740EB7FC2A1
                                                        SHA-256:3C7860260D2D4651AAA2D5DEC9E164C63BE26D62DAEE2768A66577787F01A200
                                                        SHA-512:9335F7976FB72A8B47ACA638A201A7AB60AEFA9907AEFA1D2117BAB22EE7E9D2FAC4717DBF8770997F33603EAB75A7C7DF714C8E075E8A54940D01C694232F76
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:.0.................%*..`[.. F|.'h.z..]P.G...`....a...[..G9;k........nw..+2.fM..3pu........4%&ct...?8.....9'...2..9.q.a.C......?.@.....>.Ms......!EJ..kQ.g.}...m. .....Z.+`%.r.T#.....Iq..*(..........E.X7V[........B...p.v....Gr;z........n...62.f...3=u........~%rce...f8U.L..9*...j..9.q.a..M......?.@.%..>.M`.f....!AJ..wQ.gX}..mU [....Q.=` .z.X#Y..r..:..........<.......-.p.o.*..S.<. 8........Gh;g........n{..-2.fC..3$u......F%gcr...=8.....9-.X.-..9.q.a..........?.@..s..>.M7.>....!.J..0Q.gF}..mQ \......`}.'..#.\..8..\..`.>.b...#J-.......S..=.Fhc.o..e))...G$;3........n~..!2.fC..3(u.......f%vc<...|8>....9(...c..9.q.a...........?.@..y..>.Mf.{...!NJ..nQ.g.}...m. .......m`l.5..#p.c.r.......~.u<'.......k......-....9.kip}...Gv;c........np..!2.fV..3 u.......6%&c1...`8.....9?._.\..9.q.a.C......?.@."..>.Mf.m....!FJ..kQ.g.}..mZ K.....m`l.).@#...Y..T...?..(.......MGF.........k..1.......t7R...Gp;)........nF..(2.fc..3>u....b%oc~.../8Z.&..9(...c..9.q
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1934
                                                        Entropy (8bit):7.6199179301318445
                                                        Encrypted:false
                                                        SSDEEP:48:L9ewCkq6zrOC//wUejr7Q1kklgwjMixF7hpLN66gyfIDUz4:xVzKC3bir7Q1kklgwjRxLpFgyfIr
                                                        MD5:3D00831F78BD56E70137807E54BC0ED8
                                                        SHA1:F827E2C73BC38C6C9A6A6AAA164981EE50EB9A96
                                                        SHA-256:BD8CDE82597880EE7610C1CE0476845224AC80A15491935068F4C95DE969EED1
                                                        SHA-512:9CCE5A6D5AE4EBB32A89E914E9185D3D00F681F5FACADD28F931CBC7AAD9C48CBB920594BAF1EA3DE24C703D339172BC87D0B2777A7F72FC253B72FBE5F250CE
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:.{.dC.N..I......_dk..H.k..cA..$........:>.pIM......&&._...L..e...:y....TN.B.d....K.cV3..}.^*..A.y...L.,....W<....n~~......h"..3n.......J.0.oou.zL8(.B..8...j..._}..~....O.%.zN.....2....P.5..v.kX.{M....7...o..?D.%H.J....L..g...:y....TS.X.1......$V ..}.^~.._..y\..L.,....Ws....n9~......."....bn.....J.0Go.u.zL84.[...g.J.5.a_v..h....O..u.h.i)^...}b...>..A&.....i.%B.....D...o....U....L..k...ty....TH.Y.j......<V?..}.^k..D.y...L.,....W'....n'~.....4"..>n.....J.0Oo.u@z.8s.....x.N.1.y_P..^.I.O.....aG..J.`..*...>.'..A..).B...B....Y...}...!}....L.L...iy....TD.e.j....T.pV5..}.^z...y..y7..L.,....Wj....n)~.....l"....{n.......J.0ioDu.zZ8-.J..'...p..!_|..8.X.O..,.....C..QM0O.E#AM..;%.K9...+. Qo...z.9....=/.......L..~...Iy.....TD.X........lV=..}.^*......y...L.,.....Wq....n`~......N"...hn......J.0DoJu.zP8!.I...w...v...+_0..8.X.O............H_.o27ma}.._]x%@...\_.0(..#\SYS.c6..-N.....L.4...jy....T~.G.b.......Vr..}.^c...Z.y...L.,...W[...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1934
                                                        Entropy (8bit):7.608685234363996
                                                        Encrypted:false
                                                        SSDEEP:48:L9Z1iBN1qWcpnC3zMExmBf9sX/YAq8eFbms2XEv0/h:xZMBN1qWcpnCDMExmRgwzt/oKQh
                                                        MD5:92DC0DB12E582D75D77A7783BD573252
                                                        SHA1:974834674B58FF48B786EBACA4A4CE7D836A87AB
                                                        SHA-256:9B3DBF3AD8B6B21739C5B602898A76D8DA4E516870E71D008547DC6AD86DF3C9
                                                        SHA-512:2200183105503A1C28E9E6962243EC36CB433317B94FF92CA94ACC30C3FBC08621C1E62A5080F000217EED3BD2858AB1832A0D4717D68E345AD38E8F758F7878
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:.g.S/.Q..*F5!..v.}x .<..`.<.......... <!r1.@[.?X.....-.....E...K!...^..`..S....l.B3..W.D..l...F.2..IQb]...Y`..W.bm-S.....G...WP.Z..#S.7.\..X..qU.N|..:..]..v...d4.`.`}S.,j...y7B..c.2...Y.3.C.......w.,......I.W.rK.."...%z.A..LM.E...K#...P..`..N....lGBa..D.V.Cl...F.2...Q)]...Yo..W.by-N....G...W.....#.."....A..q>.J|..&..]..).L.;4.`i`vS.,|...q7N.U.tx..[..r.....'.=...._O.R..C.?..5..4.#.A#...LI.E...K"...N..`..U....l^B~..[.T.{l...F.2..AQc]...Y:..W.bY-~....GD.WW_.W..#_........q)..|..a..]..6.H.?4.`q`PSV,J..,7.....w.M...........L....k....U.w....M\g..Q.[.Gdp.Lm..E...K$...X..`..Y....lRB,..Q.5.[l..UF.2..bQc]...Yr..W.b1-.....GA..W.....#U..._..\..q~.E|..?..]..i...~4.`)`|S_,,..>7..l\.....[..?/.X......._%....0#...8.Px..r..Z....LM.E...Kw...]..`..Y....lZBb..Y.T..l..XF.2..GQv]...Y=..W.b~-I......G..-W.....#.."._.k..qp.I|..3..]..9...x4.`#`0S_,,..>7.....%.:. .L%B....+L.KC..0}l....O_..k....G{.C.L...E..K,...X..`..c....lYBe.......Ml...F.2..GQr]...Yi..W.bu-
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):878
                                                        Entropy (8bit):7.783033494606959
                                                        Encrypted:false
                                                        SSDEEP:24:irLJAktDDndJltkv8sF5GjnxEQWOjor8dBUxMUn:irLOkpztOv8QGbx6OOn
                                                        MD5:5982BB3FEB0A58D0F6C3D70CCC046A34
                                                        SHA1:D2FCDBC50AC1EA26428CEBB8D115F9220945C0F9
                                                        SHA-256:6472640A4E889D447E37DB312019069894E5D135888CCEC064DADEABABADA88B
                                                        SHA-512:96C1D933D71E667932AE67DF04A550B7B1FF201F2EFADF144F0DBFFD33C5E46A7FDED60B189A7893530FC83F6ADB28681E1D18F38A4BE71B24456A828745E220
                                                        Malicious:false
                                                        Preview:...5.v.;..-..JJ....5m#Q5.~!3Jc5...ZD...6..+t.'.#{d.J...,..P.[.lFNaE.._D,..m.0."".....,.j3..T.c?M.:ScPW.z..]..[r..)+.{.O|&9ufju;Vi/.A......C....&.............^..=....h2._)..$H7.d......_._d..%6...#....i2.1l\.?B...\r..I....T.:.R.J..,.. .....<..[.3.+/...h".|,@..~'yF.jomJQ.s..V...T....{O8.Bp1g$#L"x.7z....V...9..[5.................$......`2._8..&D....F"..A..J....ff.8..$./..+....$d,6H.T....6..K.1..L.R...wk.-.....s..G...,2....%/.hgM.T:rt..5@nZY.i..W..F....}Nh.S..r5&n?s,2t........H..V"..............@..9......j.+~..vY.......~..4'...zP...7.=.n.B..|..(&SwE$..S..Gaq^[. ..P.K.SZ. ...8.s..M.b.?.....)..c9..U.y7@..g?.H.h....+]....sT3.?.)U5%}$t.*x.R..|...9..S#..........]....o...!k0.@c..WE.*........n....K.f.......-B.F..B....>C..6..Z[.-....M...V[.17....u..]./.sg.....-.O5..O(b$C.sll...P..Q...p....uU$..%.z.m .s.2r....K...c..L4...D...A..a!sx...?...,
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):6924272
                                                        Entropy (8bit):7.964122831035671
                                                        Encrypted:false
                                                        SSDEEP:49152:7QNx2x9vC/whtsfa1NPkIbkjapPbK1zOTsxwnKT2K3NkzX0KevHEkt2h/AX+ZF/q:7+LwNPGwPb6QCOziE/N/zgjnVlwpuL/
                                                        MD5:3698EAD73CB114D26BEF2045ED4AB033
                                                        SHA1:B3CDE0EDB90129CC8405037F7739603F5CB41295
                                                        SHA-256:8901AA4A59F28D65871633BEC1D5095BCD2E1355B716A7DFE8B614BB14295CC2
                                                        SHA-512:580A5EFFFE3A56994B7AA496F43805191725FFD83E1BA016F49941C256805CDE45E374009CAA84EDE8EAB0B56D40DC72571DEBEA5D8DAE0751CF31393BA2B644
                                                        Malicious:false
                                                        Preview:>...b.d.5|.xr.1r.*.=.G@..B..Gd....a._..;..&+......p.i...b.-..I......:...q..q.P..1E....D.s.|.@..4D.^...U..f..U..L.4.j)i.%......f..p.J../)...%./k.....+.|...j.Z.>L90....!.`E.>(!U..jb...{.jhq..J.....%..#.UQ...?.vn..U...E..C".._./.nV..~^N..:...c.".\..1B......w.w.^...!_E...W}.c..F.Q.y...~.r.....-..s.Y..b$...u.m?....C0.*..V5...(B0&S...'.}L..-:...x..$.....{.>.20s2Jw......C....fK,D.d....I...B.8.,...a....=...0..n.BP.2....B..w.w.^...!_E...W}.c..F.Q.y...~.r.....-..s.Y...A...q.i O....5.c...i...(Ksu-...;.wX.s..F.c.EY....P.......a..A...Io.$..4>h.Og.aJ..m..Y.N.c.A.<.{J.......4...&..,..R.uV..C....s.;.!...%UA9....N. .......f."S?.x....q..B.=..;..u.m?.....1.0..D8.4.~.i.J...yB&..ac.J...D............D.l......e.BKS..5.. .1...<..S.y~...z.X...._F.Ly......p.A..6....}8...G.>.....%_AN...F`.......X.5./V=.o........e.v...t...x.n!^....(.?...w.K.(\4'......pF."&0..i.)..LE.e......T.]cX)..V..~..Z..+A..<.}...L...A.".g`..+Qs.}R....s..r.X..|*....D...,.(.....0[K....=..\..].[.3
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):878
                                                        Entropy (8bit):7.791091008704674
                                                        Encrypted:false
                                                        SSDEEP:24:BJLibX3A5ZCtYisyk4JfktWsZhapZP66cEn:TiTs0YimeyVVQ
                                                        MD5:B37D7758301B6AAD332E51C37F0C7E52
                                                        SHA1:56888D8A4759EF1A92EC3B975050A7C9CC311916
                                                        SHA-256:069CACEDF21064554763F01A776372804F1C6593C0D39C2B827640A6478CE220
                                                        SHA-512:7AFD91DF17DCAEDDA515971FE7FAC429CBD67832A3F7F01D9905B3F5344DC035730A19FE101B981CDEC72E764F4367493314558EE6CEB49D2CD0272CFF98FC86
                                                        Malicious:false
                                                        Preview:r...5.{.}K.S.>}..VF.{..W.Hdz.n.....~.....{PD$.r...Z.i.e..*..8._n.QF..#U....u.i.M...,.J3.K...p.>....N....R..._...1Y.g.....Q..1..`2Wn.[*.d.c..a.......Z...?...6+..>.|.E.~....W....J...)....uS.:..7@.2/7>....0.ts.D...cL..D..1.T6..{..).\=...PNh.@....._.N..o.K*.Ea..8.|.N..E..q.T...T...6...V......H..YP?l.*...t.H..gU7).......K......yl..'.?..!.v.......... ..XYq..v........#..J.5.=P.L.?...P........K/..x..1.Ii.|.]@d.T.....CHx...-&J&.Ht..5.>...[...r.\....U...$...K....c..Y.5D[.i.:...#.e.h.m:>.....O......@55..:.6..u.|-9......O..BzW.=..T.3..I...4..B.e.ygK....e..h...3.j./[/..5..(.ca.M.PC~.d.....IU...$A...tc..r.?....L..#.M........?...P......=Y.&_\,q.,..A^.k..{B??......K......je..l.m..c.}....B...~....T....`..Bx.. @2eA..g..5By.......TF..N\.....[)..2D....(.L.Aeb.G.....Y.R.....G/.Jt..y.%....T..p.....S.......K....Y....{r[)i.&...i.I.C]G (.....I'}.`]+Q$o".=.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):4352478
                                                        Entropy (8bit):7.976690475932868
                                                        Encrypted:false
                                                        SSDEEP:98304:sN77tU56yZkKEGcdTrP3lmdM3RnXNta3ai:UQ/UHhMai
                                                        MD5:40B2FAC46DE33EAB16783C8E4E4274C7
                                                        SHA1:988C4D00EAC4FB1AB66A237BAB1F1E1DAAD17026
                                                        SHA-256:0906AF4CFB532150D94B294D3D40D3EEAA5AA81E8293BB7A7495A10C8DB4D220
                                                        SHA-512:DD73368396F5267AF3F63584676BD7F8B40B458D9801D3EAF3C2349687F987182DEF4BA9C9E4C0B5C23F27378EAD1EB1E4DDA7F1C87C497CFD8FC297A1ABED57
                                                        Malicious:false
                                                        Preview:oi..H..._.w....N.'..6s...K.Q$..h...%...Z....,w.nc.A.Tw.6.!T^(.`..8.....m.....9.....B..)..N~BIa..wnz..R.".I...pb..v..x.g..H..&7..pH.m.h.......)".y..E.].b....@W..@..0 ..xC...`..u...f^5.7X.B..8.?..1...V7./.^.|.f...S...k.?.>.b[[..d..+.'..!......9.l.Z..[&..iyJ_f..(Bm..G.&.K...#3..u..3.k.....U<'..o.....Y......Ihm.3..\...p........I. 0....+.....i..$..8.'...._...S3.....j?I.. wOHM.u.o..e.$. .|Nx,.h..L.s.........h...t.R..Cy..4*..P..%9=...Q3...../+..t..*.F...C..fd.*..s..&.N...?.|..`.sPD.......I..(a...e..Pa.D9.y.S.f.h..c=P.ec....n...L.I...`.'.<.KJ5\;.i.:.=N.b.a..d.`.. ......5...3.E..E...aqFJw..655..W.<......Nc..c..,.|.....I95..|D.}..h........+.?...PG.}x...MX.D..,<..b....E........f..ce.#W....{.$P..........:'.9W.9.'.=.I4.d..W.=..7.......+......]..2..mz..V..wy`..Z.<.9...ht.F):.6.}.....Wkh..zF...n......]/*.y..R.L..L...@Z.B..ws..........v5.=..v....i..ydu..B?t)X[.mV.....Y..b..F.~.Zk.#.#..o.}..*.=..?.......+...m..@..;../-..&..ue`..@.p.%...mr
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):10672664
                                                        Entropy (8bit):7.827926751541465
                                                        Encrypted:false
                                                        SSDEEP:196608:axh9alVAJu+H+H8PUNGfWJnIgm9kmIAoeuvW:av9alyIsmGfWJnIgmt/ue
                                                        MD5:CCAA7A5309AB91A81ADA5A4E8B419321
                                                        SHA1:DAFC9EE99B87F6730680AD7E8C7A3FEBD13CA134
                                                        SHA-256:D4F8ABA10F8F8BE8AA31DA6FFBE49EA8D09D9F0F187C1F8C6801F33AAA320610
                                                        SHA-512:D882EF0A86C2BEA69A66B0757489C23CD57CE8EE38F8BADAC20F073B1A3167B4F0A63B326C51A6BD01255E1006275E23E2F5A2C78824CA3C948CC6384A231AB6
                                                        Malicious:false
                                                        Preview:k....*...r....@....b.'4).I.).4....Q.r..iH..[Ot.......<.W....V$.......7.........m..IB0.v..!..KOt/..T...a+..X.C.h<m.R7...*..'...z..kt8.X...6..~.p}..Z}K .8......d.{Qzz.F(%...<!.\.".ND.....THk ........@."[.....=x........."...[xV....V$.......7.........m..IC0.v..!..=Ou/...2...a+..X.C.h<m.R7...*..'...z..kt8.X...6..~.p}..Z}K .8......d.{Qzz.F(%...<...^..t..w.4@s1.q..y.....3N.8....W[.I`.......[xV....V$.......7.........m..IC0.v..!..=Ou/..T...a+..X.C.h<m.R7...*..'...z..kt8.X...6..~.p}..Z}K .8......d.{Qzz.F(%...<i...LM....w.=.[....s............ }OZ.\/....+.0..[xV....V$.......7.........m..IC0.v..!..=Ou/..T...a+..X.C.h<m.R7...*..'...z..kt8.X...6..~.p}..Z}K .8......d.{Qzz.F(%..= .oqMZZ..L.~..r.y.-.'a...m.P]K.{....N.aN...a.[.....]...V$.......7.........m..IC0.v..!..=Ou/..T...a+..X.C.h<m.R7...*..'...z..kt8.X...6..~.p}..Z}K .8......d.{Qzz.F(%...<...5..PGq.d..4...C.h..O.........7.5...9....u..[xV....V$.......7.........m..IC0.v..!..=Ou/..T...a+..X.C.h<
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):49408
                                                        Entropy (8bit):7.926717590295821
                                                        Encrypted:false
                                                        SSDEEP:1536:O8MXybTe0Z5eX5hceFWoq2PGxCXKC2m7M:O8MCXeaeX5qeFWD2dXKX
                                                        MD5:EF91CFDD208D633EA3537B09A52F02CA
                                                        SHA1:071B972B5B31985D02AC616B00F2A137583353B7
                                                        SHA-256:609497034BA08D31CDBDC34A6E0C28BEA0ADD9A3086985F4F751B1D2C87E57B6
                                                        SHA-512:D46F70130D00700CD30DE80D76DEB4BDD9833EEDC0A36D09F3413D4EA2EA0293231C2A50245FD1430C6B2D7FE15B17641500E81575B63086ECB97420ACA53FF9
                                                        Malicious:false
                                                        Preview:..vq....@...g.='<?...~A<.II.%..._.I..}\..0@......._B.....n.C...J........3b.aW:.8..u.gk..|e...1U..~./fT..B.2....RY.f.H.d..S.....j...e|..n.E....... 5.-d...&.J..D.F8....H.&.a.......Sa......hs.0Y..;.Oz....0T)w.8......g..x...>......M........+5F,.n.e..w.-...c{....$C..n.5hK... ....8.)....1...Z.....,.......D+....G...tl..U..a.K.._.N.....H...t......{t...m......s.B-...#.#q..V{......gA.W.<.+?...=.K....T....7...<W.mH;."..$......+....^.T.7..yV..C.c......h....9B._I.....2......R..j.R......"+.....c....I.J:....!Jg.$..-..9(qMbv$.b.v.@#..aS.E.i..?.~?...L.tL...V=.....M..........^D.[=.I4.;.{..y.%/..NQ...t.H.G.8bG..T.L....PT....G.V..].....=...s,.i..........c~.vQ..I.......}..@. .$.hH.@da.....#.P...5TH.f. .|.:..k...0*.......?Y.........]..........-.{".~.v..x.rn...&(..t.T.8.+y.....a....H.,.<.?S._...... ....AR..m.R...t...ey.tL..N.......a....J.".:....[[.~...:T.t.^.F..NC.c.j2^-...{X=.....q..Cw^P....q......Y....te..V..gTp.n..2.>x..uy....^.T.7.{5...D. ....}
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):608801
                                                        Entropy (8bit):7.9996377332714115
                                                        Encrypted:true
                                                        SSDEEP:12288:VJZCXVaEX3jICIC8/91dwQogDM8LJ7YstMiQZusbikU0663S1M6nZ:7ZCkEjIC8/9Hw4LJYsvQUNkU0+PnZ
                                                        MD5:DE88B48A94C63D8CBCB9FE3DDBD34540
                                                        SHA1:C9DAD2BF3FDC1FE26B2B2357702007D79E805D76
                                                        SHA-256:070B10E6032B04BC860ABF4C56C10C0F309179FCF1F067952702D667EC615172
                                                        SHA-512:CE7CB5D2F246F4B503C0E02CFC43E420A62E00FE0D72CDCEC1DF523756438FF028CF40BAA3F7392AA180A8E71D9B7103DA17BFDFA0F2D00FF5173BDF383A4E0B
                                                        Malicious:false
                                                        Preview:.......~...?......1.s...0...L.OQ...`.=..sp.p.A...>.x!-..c..^U .I..+~V&....#B.......eg....H...xv.....|\J..<@......[.vR..^.c.\<..8.X`.........y.RC..M.x.B.]....9}ha...e1..(.X..\...M6Z|.~#.+..8T.4..z...]..Dp._...-7.D..vH...bE...V...L&.?\.G....uqI.x....+.f..:`..Q]'...,.nE|-=..T.......I._..H.:.^f..".?...T.5rrP.f.X.o.K.g......@....-."zL..W...R.4...{..Tn.h....Jy.oQ..Nf...).Ia.S6...CMV....29K..Y......2O..~..H..b.7.Q/..S..k......X:}1|x^e..pu..6.^....="!bD.J.:KKD..4Q.X..]<..n~.......7_.~.....5...r.,..B.wY./......zZ....;..+..........Q..c..g..6!.).].9...;E.>....w.....e.,aS......Fh.w3..C.r9.&f ..GH......Ln.l.....'N.:%.X>.x|....!.N&h(V.(.L..0S>y.N..0.nZ...T.9l.3.>.oi........f..S............Y.6.i..&..PrH-.v...b...N..]...V-...c..o.4.h...\...Q.{.b#J...fkd.....?r.x....5..UCX{.4._..t...........HXFn+...\.8.m:.X.Z;s........U.....\...../....~3...2t.6ue..u...]....)..<...<....rV.S...g.Y..)W....wB._T.Y.wH.J.......M.........1..u...C#\iD....^VUdJ*4eWrEM{.#..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:OpenPGP Secret Key
                                                        Category:dropped
                                                        Size (bytes):1288045
                                                        Entropy (8bit):7.8010739972078325
                                                        Encrypted:false
                                                        SSDEEP:24576:/VifAyLLW3bO1u8Xz+jsnnDIK5oolrfSeduj4KyfCHgnMMKL7m:/EAyfgiKjsnnDIK5oolztuELqHgnMMl
                                                        MD5:12D0643F2F53CEFAC7FC3532D046DBB3
                                                        SHA1:041EE2CE1F035A8C9666E4FA1189EBF4E53E8A87
                                                        SHA-256:7BDE8C466CAA41D65EAA3FC1CA72E5D8B044718F1FC946D2AB91B2A2ABE6D38B
                                                        SHA-512:77ADCD05CD5FDB6915312D1565CB45C45BAA35AFA0A040A88073D39415F3B7A9FFF81240C766BBBC612A3D52DE5E2DDDAF1062A18E05A6C06B94BF844B9D96B2
                                                        Malicious:false
                                                        Preview:.O~.iN.Uf....[.i..;........U......0.~n. .U.'.L52......k.....@?fhc`.!.....y..{.}..n.t......F......_.%*.-...j..(.^.s.{h..e.)ZKg...:..Qe;.a...j.^!jn....T..........u../...;..G.]f....G}....$..o..[!&..P.=|...s......Q.N...U.....X.f.4..U.........b..l.F.....F..}.....jE.B...6..M.o...#.>y....3...'.yB.>.N......t1}._.9....z.l......1...*#.J..Z....a.H..0*.$~.B.p....A>........j.....l..:.'.pE.........F].....*ah4u.!.....F..G.=..lzF.....#...c.i_.%*.$..._..(.^.a.ehW...lZ.g...:t..e+.{...p.B!/n................u#.]...9.Qf]H..d".Tlmd4q..:S..*.5..k;..|I.d|...W.8.[C..........*?.h[u.!O.........e.].p...W..F..{.....fE.B...6..F.*...N.Xy......0.P.|B<>7N.......1w.=.Z....z.7.......u#.J..d..G.]<.+iN....Z.*[b.+..gD..ao..\T.R ...c,`.o.............XVf.4.......]...}....l;F.....2...y.n_.%t.r......(.^.A.^h<.].OZ:g...:..we..[...H.p!On....(.3.........u{.J.L..G.KO..d..2...Y.......3.x..c.....DL8.... :A.....!..Qm)|....X?.h[u.!g.........e...1..5..F..N...,.HE.B.6.E.-...Q.Yy
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:modified
                                                        Size (bytes):15471128
                                                        Entropy (8bit):7.9898454243369965
                                                        Encrypted:false
                                                        SSDEEP:393216:bE6RMJ6myYr7w2sYYyV3IObhsedSNtie72H+c8+xYgaHc:Q6RMJryibYyV39V/dO3m1hic
                                                        MD5:9A4D18A26B3532CE4BFC78B7660904B8
                                                        SHA1:06CD717A3059DECEAD50A585A9287F520156545E
                                                        SHA-256:CD7C8F2E85D1C78B1A2AD3EA49379FE7E5FC779690FD2B843458874A7AA7A034
                                                        SHA-512:95BC6D026C6DBED3D128C7D4BDCDB206D391F22C262B0A2EBE44A1AFC7544809F5D12727685F7DEAA0857650E2178E928F8354D7538057E6AE4039B2CB152480
                                                        Malicious:false
                                                        Preview:.-.Q@y5.&k.Qa[.LG.%.).Dl^....y.y...5..o..A.T..4.p.R.tx.._....pY.[l.V.].....l......Qd5S..a_F9.....A....H..f-.WO.u.[..$.M.g.m..U..[)Vh.1.....>.UO...`u.b].!.*)...h .<&..E!..>..._....XV.\qm).3G..?.xW.Hce....^............N...}......r.<..z.(".........z..R.;Y..chG...."......H..f-.WO.t.[..$.L.g.m..U..[)Vh.1.....>.UO...`[8.X.!.+&%...R/w3..~K$.M3...S...\`.s0u.....7.....2A.$.=e."@.NK..y....0.b(.t.X....y.4..7}} ....m.......Qd?...`.F9.........H..f-.WO.t.[..$.L.g.m..U..[)Vh.1.....>.UO...`[8.X.!.+&%...R/w3..~K$.M3...S.f_M..+!.&%.d.......H.......G.r../(..h..!...P.X...<Y.##.6}.N............>.Q.nq?N/U......k.8-..q:..f....>~.P.?......_..^.lv<.s..X.J.&g.d...Q.x.o.na`...b6a.-5.}..|.4...i..~v.......G..-.p....y...*;.W.../..k....M..G|@t..g..@q.N".D....(......1s.+[%N.k.....j..<....^.w......k.p.l.(.M..P..\.e.).t...K.m.yo.d..{q...f.y.a....{W..!^.j..f.4.7..]W..K...".:5.%.v......D....g..{p......]Rs.k[~=...g..]z..3.M............ls>.bg.m>J......l..&..9}.#'.+..:Z
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):49214
                                                        Entropy (8bit):7.9514749367145345
                                                        Encrypted:false
                                                        SSDEEP:1536:r8c3G62/ODXufgVWlbKn+uDvIOI80o5XrqhMdV6z:r8c3dwlbI+POmmehMdVa
                                                        MD5:E15D30F64113FB426F2F071F4C848D21
                                                        SHA1:2EC06D950088B7DAD58EAB11F66A242661B78C27
                                                        SHA-256:B9D7E241E3F9927CB39FE35B079282306F94B49B799443A2FA517BF3E9656CDF
                                                        SHA-512:90E5DBB1F694AB3B008054A8E7D9A68E2DA54A9EC97503CF27C56A05A22215278A73645E3B76AC7A9D1CBC5437A2287DB360C74EE0908F19FA54B406F6D7C708
                                                        Malicious:false
                                                        Preview:#....f.&.8.."....eTZ.#.`qy.E ..2SB....f.Iy...u.5.h8...O....y,..[^e.'....B4:"...Ek.@...v...t.:.T.h.UU........J:.jQt..4u.6...[:..E....o..,..R.h.^...K.&.v..W..o.....1.$..)..d......R..... .~..`.L.dd..CQ.C}/..z.....gXN../$.?...2b,|...Il.1...N5:#..S.&...O.i.....".K.Y..^.........q.HC~..s..y.J..o.......o......-.8.......6.t./.f..".3...*.,3.d3.d...."..v..v...s...y......sz.....~g[.V;c..F..T.?..X.`g$..Ynu.8...m.42..1Yg.A....M...".*...W<d..V[..J%.%.\..e7.8.M..g.....c"..o...|.k.R...#.c.h..'Q.?.P..<.(..xi......g+.`e@.........1..Y6..q.uP...D.L_J"U..54o.V..`1yC....OeY.....fqa...>.\...%[..$.".U.o.I.N..JT.....+.k....6d.7.\.S....W..O=...1..f.&.....M.f.V.5..`..!.z.....iC.7..d....g..*h.V....t.yji..Y.i]bD.\.....u...Q!.k.....D.....,gW....6W,....+%$..N.....\.k..B.a.....W<d..V[....r...=..W4.8.H.OG......^?..1...O.D.^...p.c.5..)..z.N.....iC.7..d....40.;.^.z.o.K.R.G..{..<GN.L>%.-Z.0..!A.....wq...M.e3..[. E......`4[.Cnp.A.R.s...?.m...T.K.A..|[...FJp.HC~..s
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2377177
                                                        Entropy (8bit):7.999867785548213
                                                        Encrypted:true
                                                        SSDEEP:49152:Eh+hpKzWkl3nmadtGNOKV3i/dipDhwtx4nWNkZf:lhpKzTl3madtfKc/ohqyWNmf
                                                        MD5:0BE1EE7148A2336DC0DC0B4E39A549CE
                                                        SHA1:C927DBDAD1A940F1F31A0A7B85C493F3C32C2D4A
                                                        SHA-256:109E494A616096EBCC1C37F346124DB5F84908AD3549F4B921B0922D15BC8127
                                                        SHA-512:87E94ED8E93300EB42DAD6438D92B65C6E9BAB4ADC2837E74309D7AF02844F91862508AE285B90D695834357AE752F7085B0E7BBAE5BEB09454509E89595CF2C
                                                        Malicious:false
                                                        Preview:w........3....$..U..@...o]|..F.............Dj&...y....a..5.....dd. .'.........}..NJ....X.Oe.+..K;L.f..|f....(......JA...!.T...n x5HI&.?Ahw?.&.S..x.]Dpl .CZ......O4..m.:...7.....Lci. ...z\?&.8..>#.........rR{..)|.k.-p......".M.gez.C....H...|...8;,..4_.C.Fh....D.._.=.....5....|.B....O.....h...=..p-....&..j._...o.*..Y..+y.d..\;.c..{.?.*.@..u...t.....P9P.....V...-$...Pf.;DE.qIO.......'...*s..\..T..i......c1..3T^.3.64.`.....u#....8Z...,...7y=v6..u.nrK...S...3....IE.....L..`..@.`....{...,.1~.P...3o.....#.`.+....."p...A4..<b].;....?.y...._...lO....K...#{....T\......^....;..,B...g|z..kz'UA..t....1.V;_.=...........g..|..p.....|.....4a.{W.`.s.G......."...n.0.Y}tG.;...<fG.+.<..X..s........R...4.F.c...R..'..{@.fVd]../.4..y...2f.v...iC..r(..,A..1-g.C.$#..b...;!.].6......:..!...w.&.Q....m3H+.X8....H..&.E...KL)!..S.<r8.F.bf......P....c.....H}V9.a.U.A.B.C...n...5.'..5p~.. ..../.w#... ..J|Y..1L....t.....z'......-n....9...y..q....E.Yf.*9Nt......D.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:OpenPGP Public Key
                                                        Category:dropped
                                                        Size (bytes):6080932
                                                        Entropy (8bit):7.778694577410336
                                                        Encrypted:false
                                                        SSDEEP:98304:kntxAwr8AQSivVq7ef1sx3rBtYedvUNGdsxAAtNcd:03QSaVNdsjtxvUwix3K
                                                        MD5:C7A6FE58CB2C2F64EE59A2BCB0CD0588
                                                        SHA1:873DFC69F3B83739A1B2DA6EF3366D9A85629288
                                                        SHA-256:FDC049EB2602B76E2A6179250862A9F4D4860A8729260A6FCCE2D67F509937FF
                                                        SHA-512:84FBC964187FDAD7ECC813F472C70BC9361B9128216B55A0DE87E70F7867B32AB3249579BF8DE9C10B317501A935F0C985767D041C10DDCE47AEA6C3AFA60794
                                                        Malicious:false
                                                        Preview:.[.Q%.#-...\y]N...t...$..)(..s.]vS._r.c...\..U..I.*u.%......_3o......q..5-.">.....s!+R....`..'c..H.EP..q.deh.]8B`d.{8.W%...l7K...uu..a...<.........6y.....1S2..O@..kL.r<'.....DD. b.q.5.^F..>......f.$..f....C..I.#.]..N{.....9.+-.E.V..$......."M..X.`w!lR....`..'..mH...........3]1-...V..aC.|...?>..)=....{rZl..k...N.K.e.......0.g.&v.5.|.BS.. ...e.J.......^....4............i.?GA$..Z.Zz...%......D.ouqf..\.q.....>..h..s.+b....`..a.Zmy...........381...... z;...l.K>..uO..c...0.....'.(..y...1C2..^@..CL.r.'........$..o...@.:'&.(..\.... ...gd....D..../....^.......$.t-WEEV..:........"V..X..!wR..f....'h.CH.Et....../..i8.{...8..a%.....$>...=....mrql..k...N.K.e.....X0^g.&3.F.#..SJ.b..}.Z..B..&6<..\...*.`..G.p.. ...!6'.ih.w.B.b@*.!.%....D`o,q5..\.q...V>.....s@+ ....`..h.zm..,......S..3Y1.......aV.4...">..X=....yrgl..k...N.K.eT......0.g.&p.+.(..SK...t........@.G..#.p.~.Z....*...........bq..z;A.........D-oEqV..\......."b..X..!NR..`....'=.[H.E_...y.iei.R8C
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):93204
                                                        Entropy (8bit):7.676243152395476
                                                        Encrypted:false
                                                        SSDEEP:1536:TaQr1cFinHK/sSbzS7X6uk32Wg2BaDDU5hnrys5jvOIe001iq:WGy4nHK/zbE6ukGb24mhnOsBze0C
                                                        MD5:BCC7F326EFBD30A5F03B3CA13E0471AB
                                                        SHA1:21D4DB01C843691E4F01223CBDD8D0CC891C3B5F
                                                        SHA-256:D1BE77E6C46233F1048E2BA240ADC28127F28E131B6866A346DD22E546605A7A
                                                        SHA-512:141493AD171053210E05ADCD1CC07ACE1CBBDCA4137C069B9C147559A092F94C5BA7A041790F1921742CAEE55E108DDB66DEBCAF76C8D21F43723B5FDC98CD15
                                                        Malicious:false
                                                        Preview:t.F....R...f....]..`..96}.....|...=..j.tL.E.S....@..,...VA-#D..d+]/....p.....b{N@..'..g..X.$...N. ..Y5|Q>..B./XVLuC".|..i..'..Z.D....[R.N.J!.<.|.2\.Y....[-..+U\$.*.F.'...+.E...A~.......N....Ww.l..VgZ@.......^S\......,G.V.-3D..1+./..L./.....bzN^..'..g...X.$..N. ...5qQ,.KB./DV>u0".|..w..'j...`....WR.N.Jy.T.8..\.Y...&-...UM$.*.F.'n...7....m.+.g.~..}I......Z.)......^....e.......,...V]-lD..d+A/..0.v..^..bGNd.-'..g..X.$...N. ..}5.Qq..B../.V.u.".|."..'j...g.....WR.N.Jo...`.)\.Y.....-..qU.$.*.F.'../..u2#...3_e....f..Q.. ....@.F .ePk.....F......,[.V.-ED..,+./..J.(...h..b.N/..'...g..X.$...N. ...5vQ_..B.../$V.u.".|.1..'c...).....[R.N.Jd...}.s\.Y.....-...UW$.*.F.'.qD.Px2.r..w.U'....d...RJ.Ieg.4.\.B?.8...8..>....,...VI->D..z+j/..H.^.....b~NC..'..g...X.$...N. ..|5.Q_.MB.../CVHu@".|.a..'>.T.'.......R.N.Jq.(.o.)\.Y....-...U]$.*.F.'.<.>......A...t.e....R.I..j.=U.Y...ao../.c.......,T..Vn-@D..R+|/....s..Y..bjN%.A'...g..X.$..N. ..m5.QX.7B
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):23356
                                                        Entropy (8bit):7.677856196288753
                                                        Encrypted:false
                                                        SSDEEP:384:4qMjUEen4nBCR9F8cVUUeiNTShzCwqzRktS0s3G5aZH/rtyi4gz17wWKE5ows1v0:sUpJUUyhGl+Tctz4UteA6U+/5Q
                                                        MD5:48479A3B53B910D89AA1E1A28B765260
                                                        SHA1:9589CC858CA4EEEDBDBF577A0FF6C1296003F77C
                                                        SHA-256:445C75E54F3C2BD8C511ABCDE7405B9372F3F89364E605550E0FD5D00B6982EC
                                                        SHA-512:9EAADC992124756EA45CD5A456138417DAE430EAE0AB8C0C8F70B64F31D33886AB732C9657069036373DE3DE372B641653D6146C8B69A1B4BC92F69A557C5627
                                                        Malicious:false
                                                        Preview:...}[.....F.{.X...#..1...H.^..#Z.1...)..3..1.;].Rw0.JrSY=..:.mn.....T.}.5..+. .E..d....q...QH...C....1.h.B9..U.C.n9Wo).y_.W..F.s:..JVJ.dY...b.........&.R...[D......|..\yx..3.w...%.b.[.M.b.i..n..>u.......%5./..f.$.pc.5....5.$nV.\..T.}.5..h.y..E..d....o...QX.M......e.1..9B.X.Cen+Wo).y-.$..F.m:...J.J.d^...b....X....&.R..~[-...m..m..\0x....G...Q....S.y....((....X.JN!.........n4C..........}.an...._T.}.5.... .E..d..7.V...Q+...^....8.D.T9.....C&n.WF)SyN./..F..(:.J'J.d....b.....E....&.R..C[....3..}..\0x..z.....Wc..c.,4....?$.. N..d...[q4.....{BG5..K.g<...g.gn....UT.}.5..=.0.E...d...}...Q;.4.i......S.c95.:..C.n2Wo)ty".$..F...:...J'J.dv....b.....R...&.R...[....9..j..\ x..H.M.....}./.A.;b.h...ml..`..I...2.3_R"r....c.|n.....T.}.5.......E...d.......Q....~....0.`.A9O.J..C'n.WL).yN.,..F..5:...J.J.dY...b........&.R..[@...0...}..\fx.......:&.xV.....K....*......Kv;.$.].@f....t.K@....d.an....^T.}.5.. .q..E..d..7.V...QT./.H....&.u.^9..H..C:n
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):238848
                                                        Entropy (8bit):7.70445821592422
                                                        Encrypted:false
                                                        SSDEEP:3072:rHZuRUKdiN7EVcFMKtKpCrn8knObakJTu+EL56kfE+ZYiTDAZKi93MjtDP0usY40:zCUTN76IK7sy2L5yi09cSuG/Yl
                                                        MD5:41003234958461FDD6B10110769B103A
                                                        SHA1:D83A742EC245BFB3FEE724AA5FF4BCA4E4033405
                                                        SHA-256:5906C04B5DB51FD9111EFC39C19BA58CDECE2A7EA58DD01AAD6B0AB43F52E8CE
                                                        SHA-512:D9D79B3D711A9B44A67F5AC4EE741D6B8DF2A740D704CD1152729AEFE9390681D89626A7438987ABB93E09214A852423B8422F98FEDC113682F2AE8053776F63
                                                        Malicious:false
                                                        Preview::.......gqp.Pg.S3.....&..1...|.I.-....a..O........v.I .....r.].cP...u.c..".Ujopj9m.`......:\...>.+i................e.\.6&.@........U.Zoba...Y.s..o.;*...;....2.K.......+.....h.7.Y..|...t...d..].la{</.j{nM........j....9k..:....;...?P..u.c..a..j0pB9}.r......:S...`.xi......G.....e..e.\.6T.3.........U.ZKbf..@....oJ;r....;D...d2.K.q....,....../.?..>..i..s;...#.>h,>....$....&.#8Q....}b..:T...e.]..P...u.c..%.pjipw9$.|......:w...%.*i.......4.E.N.%..e.\.6y...........U.ZLbh...]....o.;d..;....2.K.6...................e..Y.8.Q.-.|.v..Iz.#z{r..2.i.{.'.L$....8.:....'...<P..u.c..e..j7p)9........:N.....|i........D...`.(..e.\.6b..........U.Z.b"..J.q..o.;$..;....I2.K.. .... .....n...`wR....5.T..NJ.Mn.M....S....D.p.Z..A....h.:u...7...tP..u.c.....j2p<9}........:S...b..i......E.....d..e.\.6!.5.........U.Z.b ..B.b..o.;~....;D...I2.K..,....<.....)n.n.F<.1.....f:..9..DgU'.h.#..pFZ..~..g.R.:y...I.u.CP...u.c.."..j pO95.;.....:....u..i.......(.z.q...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):129894
                                                        Entropy (8bit):7.675878288709037
                                                        Encrypted:false
                                                        SSDEEP:3072:J/c0c+CoFpCwshe98SlpsRWO64HZu2TVc3cSPc:Jk0Fp5B98Sb4WO6CZu2TVc3ccc
                                                        MD5:EA9134E1422D1FE48AC1521293498CDD
                                                        SHA1:E3AF91C0C756934B018AC131C4353157D52289FB
                                                        SHA-256:772DF852EE377FC9D621703C4B38ED6C4E1492546C4230787D4CFB08733864CA
                                                        SHA-512:052E20F4BC9EB4811DE5264D4FE563DB36864E7A836B35C357577E5174C41F0B697817DD7667FC7BCE45B8E612A1401C5AE7A02812B7114A94F7A8CF3A80145F
                                                        Malicious:false
                                                        Preview:D.+.mly.C...kf..7...-i~....y.+>/.%.T.WM....%KB/..+.......T..W.q]...:S).w...X.#...@Z.....2...T-...L..}J......r.Df....r.4....L^...k.,V5.]7F..).<.E.......<.....S.E.......x.e.1M..a...qz.._.0~..1.=......Y..LO].5.)|......6..U...........a]...:.).w...X.#...@[.....=....-..,L..)J........r.Dt....r.4....Q^...k.,.5.]0F..)..f.....F...q.Q.{.:.8.q.7.....4.zM$.r....H=.jK<....T.8..A.#.n.(.e.P2x.RPY.O...]..}.C..K.>]...:O).w...X.#...@f.........a-.~L..pJ.....Ar.D]....r.4....#^..k.,.5.]>F/.)..+.O......'.&.......6.R...,.j.PM...N..9..Zx,s.T..3.<%.8.o..1...pDa~.g..^.;M................]...:.).w...X.#...@-..... .|..-.(L..XJ.......or.D.....r.4.....^..k.,.5.]tF-.)...H......=...5.X.C.".....U.7.|M.|..EY..m.T...+.......F.N.lz....T..l./a.y....E...F.......5]...:.).w...X.#...@.....d.t.U-..>L...J........r.D.....r.4....^^...k.,]5.].F...)..v.....I....W.3.......!...`.z.3M...K3.:-".....5...6G/..7.........C..C.j.`*j....o...N.h..O.0]...:.).w...X.#...@......2.q.H-...L..ZJ......Er.D
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1512
                                                        Entropy (8bit):7.5838268381143505
                                                        Encrypted:false
                                                        SSDEEP:24:8ITbY+wlcZ4RqnzGpvq+2+VdlNyiUwquUXAWkPMJplzN09UxX6NI0XYjQe/0gxVu:dTsdlId8j2+blo9huUJgopr09UE6XjLg
                                                        MD5:5D4CF782AE8AA5E5683C4C24C139178F
                                                        SHA1:3AE2042A4DFB401F60242BA91F481555A0BB3FC7
                                                        SHA-256:1CBF8623AA0A5AFE9713B9FA3DC3DBD422CB2B2DDF9CEC732AA72B09F2A9527E
                                                        SHA-512:0B3D53A33E5E04D595FCADE64612525F2337163B8E5BD941C9D29932C6F2B09FE0D6969E98CA9562BAD1273D03B161971156A592FF3020F8CA22F9440B49C937
                                                        Malicious:false
                                                        Preview:.....VY~#....i.O.......H.....)8&..205....C..R;.y.x=\..EyVUg|.l$];f..n0mY...!.UY......(.....elF....^*.E.}k.....5..xOym........+....n>..y.......+....K..aE.Jf?.,.....Tt=.e>r.O.n,#..7.|89...kX.$+b>..cTA..n.xd.p.. .Vv(.. .Oo....Jy.U<|.l4]}f....-04Y...!.UK......(...B.;l....^s...*k.....5..xSy.........v....n...y......U+...#..a...fG.E....Tu=.evr..~.R.fX.N8..w..4U.wd....8......~".O.. ....'.$..,.....yJUN|.lp],f.....0.Y...!.U.......(...>.blV....^N.!..k8....5..x.y(........`....n...y.......+....T..aG.}f......].T~=.e#r..6.........i..h...0..&......6x...F.x&e.;fk..H.....y@U~|.l&]of.....0.Y...!.UG......(......nlK....^..D.wkA....57.x.y........P......nX..y .,...E+...._..a...fz........T(=.e2r..YA.&|..U..........j.@,.6....=1..f^*n'e.s_~#.._....My.U=|.l6]xf...._0=Y...!.UG......(.....el@....^}.&..k8....5n..x$y9......Y.C....nd..yj.T...+...o..aX.Kf..&...H..T.=.e.r..e...wM.X....Zp.}.....y.R....3..T.DG%.ED....".R.....yCUz|.lj](f...Q0mY...!.Uv......(...1.dlH....^-.N.tkE....5
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2196
                                                        Entropy (8bit):7.628673043399256
                                                        Encrypted:false
                                                        SSDEEP:48:vApIPfhPsk9EW6+pZys4V3la07vKUWgmcoUWptQE:vWshuW6+pU1a07v7GcFEeE
                                                        MD5:07E3A3551AFFD39532D839495A94C9C2
                                                        SHA1:627D30B26ABE385FC1BF553942C5A79AFF9D557D
                                                        SHA-256:6B21BF33D73408F982D4017578AD7BD802B36DC7B0B2E814FE0A67CEFC8398F1
                                                        SHA-512:BC8801C9BD58B35A9BD1B385DA9277BC271C96417BEB50E128DB43810BA4F2632D5DDB6AB5D570CACCE7B159419EB8543D08CB440D9A62C852EAA639F959F580
                                                        Malicious:false
                                                        Preview:*i..(.H.`.nd. .s..8z.J.U....\...JD..WA.^......V......D..p'tu..T.v..Q.b./..H.v@..Q.m..a...5d"........R....Y$..x../....vT.S....*..?../..F...]u.&...\.1m.o...........}.2K.........9..f9..M...T...v...:.....+.....}.{AJ..)..@..-O/{..."tz..T.v..A.$.z..../@..y.}..a...5d"....J....Z..Y}../../..f.dT.S....Y..?..1..Fw.U]Q.!...E.=m.o......K.....}.26.........R9.\z.-.9K\...RL;}...U..I....*6.G.....b[..>....'...xt/..T.v....u.t...1..@.......aB..5!".S.6...B....Y@...../..j.dT.S]...i..?.1..F~.U]Q.2...R..m.o...........}.2Z........9..%....s...]...W.ta.p-......6...e....[T.......zt8..T.v..L.6.h..6..@..6.Y..a...5;"..F.....T....Ym..p../..9.LT.SR...U..?..3..F"..]..q.....`m.o.....M.....}.2............9V,..Zj.O"_..,v..G<L.........._J.*-...so\..Y.>.x."t...T.v..E.U......'@..B.r..a...5.".[....._....Y9...../.._.+T.S....s..?.~..F~.Z]Q.g...X.=m.o...........}.2..........95..gt3V...,.R.q.%.THf{{..n......=.p>.qsZ......,t...T.v..3.R.g....[@.......a...5y".s.8....1..Yt..'../..+.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):139890
                                                        Entropy (8bit):7.693319621206833
                                                        Encrypted:false
                                                        SSDEEP:3072:gzof/EJ4x9dydxNagrPRrbhwJYdf3WQ0R0Hh+6FoA0IDfrvUbhDqU9n:DwwdMNaafhw2f3OxI/sDV9n
                                                        MD5:84A6E233634FDC3AD901E91F1AE9C5FD
                                                        SHA1:FEADADAE98A8AAC42B50A446483E82C755C8A60A
                                                        SHA-256:D61E9733060C5B0303F625C03F83C9CCA55E03B8BDBF8A7570EE79E65ADD1E0E
                                                        SHA-512:62C3FA23129B6ADC8F43538F252E999D3B5AFB8F5E4F5EC3648D3A86020052F28B2FF7B05B2C4478A168DC151A33BBAD7F13A27AF49D553546BFF50F18EAF0BD
                                                        Malicious:false
                                                        Preview:]-..Y.f.fL...B._Ytg..............Gt.Z..J.vO............@....nE..k..(.S..u.-52K..E..c..>B........tX...P.3.i...Sr{/A8d..C).\..........KyN...7...f.._(gv(G.d..kk..k..Q8..U:4..N....si....@M..89... ......d........~W.O............'E..7..(.S..*.n5kK..m..q..>\........t.......3.i....^ri/$8v..C5............K.NG..7...f..S(=voG...d..&k.......QG.?U+4...N..n.@?..PX...h0.R+l`.<....+...e.......A....*.PT.....yE..w.(.S..i.*5.K..X.....&>f...4....tC..S.3.i....r4/d8_.8Ca...........K.NO..7..:f..S(pv"G...d..pk..z...Q..ZUf4..N.....z..H.)...... .k.W..O...mp...n1...a#......#3......;E..4.(.S..3.j5mK........m>-.......tp.....3.i....Yr./i8..vCU...........K.NT..7...f..[(nv"G...d..ak..{...Q8..U34...N....k.RO>.T..6D..h.H......|..-..+.jV\/>Iy.0.6JBCE....._E..:..(.S..F.f5.K......v..>.........t.......3.i...^rk/98..`C7.+..........K@Nd..7..[f...(pv=G...d..ek..<...Q=..U?4...N..5.5^"....o...S.Y)j...y.Jy...~..v..#.......5.%.......YE..b.(.S..b..52K..N...c..>'...D...tZ.....3.i...'r./X8
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):150322
                                                        Entropy (8bit):7.706302256984574
                                                        Encrypted:false
                                                        SSDEEP:3072:SFlsrxa4D8piE8QjqJmW+sf5I+qcrRKgIfwxDSuQaUWKeNOywNf3mzLmaZ3Um:S3qSiE84bWTxzIfw4uXVvvx3Um
                                                        MD5:FF869BABF816A5843D7E4D5FD313C8C5
                                                        SHA1:1FE2843E1371AD73D8C4D18C65E17B7329BB492C
                                                        SHA-256:A975458B59622DBCB9F8B2BE374FCF443DF31BBF891B669E468C40EF238DDF1F
                                                        SHA-512:A4A848A831CC02D5714DAAEE1398EBAAEFDF7981DE152795B2F7BE9688242E9547CB081D02D401C29C6CC9221C5A86C410CB3368712491725F937FA47C5192E2
                                                        Malicious:false
                                                        Preview:I.6LYnv`......(.E.J.zFp.....8.L..I..5.O.X.....9Wv.?y.VYo.......q..X1..K2.T,@E7.'...r3....`i.]......F.2....Q.....4Y..rsA......$.5.h..R.6`H.F..']r.....a.........9D.....K....h..Q.....%..:(=).."..O...@e.zu.-.p.0.3..n.z..v....\o........a..Xd.Kq..,.E..7...r-....`y...........2.^.\.....&Y..ns3.]. ..$.5.hh...6gH.F..+](.i......O.....99....Z....h..}...`..T....b^;M.n.^)|kf>..N.|d...Y.......I.J...on......>..X1..K5.q,FE*.n...r....`u.h......K.2..-........Y-.:s..l.}..$.5.hh...6iH#F..+]e.$..T..........9..........h...GSs'..!t.V..q..0eP.c....V}.iT~[....Z..g....$*.Ro...........Xy.Ku..,.Et.X...r\..`.........c..2..].[.....BYc..s..y.1..$.5.ha....6#H.F..2]y.$..Z.........9......B....h....SLW.S.......Hr..7.N..aNY..XI..(.'..~.7.aH-...oY.......s..Xf..Kw.~,.Eh.+...r)....`{.........a..2.[.(.....PYv..sD.,.m..$.5.h6.(..6|HBF...]e.;...P.........9......N....h...B.Y....j.t.3..?....`..i..ZSI...+"...5...m\4x..Xo..........X...K..T,CE<.i...rV...`..Q..........2..=.%.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):6172
                                                        Entropy (8bit):7.68643257878463
                                                        Encrypted:false
                                                        SSDEEP:96:l8JM+4svkkZWfBuPytTNzoalPB7gtBn1u/RIfptkdWpJA9a1NigQspm:S1bofcylNzLJB7IBnM/OfpKKUa6gQspm
                                                        MD5:E83C88E95A765F406B2A985C4697AA26
                                                        SHA1:36361D92320E18F6BD2EA502106910FD7433E677
                                                        SHA-256:A5061C95C653AF071DF14B76BFFDB804765B5D8FA46A05E089C4355081B620B5
                                                        SHA-512:921F4B7685889740B0E1B2A25BD30B6670BA5C59549CF960CE6AAFCB1C087F992055426253B593977B2F2CE5F32F64D2DF25A4FCFD74B31307ECA5B4BAE583C1
                                                        Malicious:false
                                                        Preview:e......(@.lz%.D.{..|G.(.`VKrf.-.....]...ISf.:.l.?.q..........A.i]....q.8...T{..5...!.G.n..[..O/.f.).y...w.7......78......I^..9...E...[b6...}..j.sX.......7..N..{...#...:%..:..E}.P.._...A... ../...B..e.Pb.Z.8.........YM".......A.iM...qN8.....{..%... .G.n..K.YOq.5.k.-....w.7.......78........IC..9...EQ..[e6...q..j.s..........O..N......"...r%......g.G......w.l+...y....!.....l.l.3....L..E..X"B.....A.i....qn8....2{.N.G.q..G.n....%O(.v.2.#....w.7>......7..J......I...9...EQ..[v6...U..j.sZ..........N..\..)...h%..........4..D...Xa..C%......wQ.Hv.....Ga.q:.S"S...A.i.....q.8....{.X.C.b..G.n..F.KO..}.%.x...w.7S....7..G.....I_..9...E9..[.6...s..j.s........b..N..U..(...b%......W....@.7..In/...h.$..?K.u..x..8;......`..B"h....A.i?....q!8...~{.%... .G.n..O.\Ox.G.k.%...w.7.......7K.m....IQ..9...EM..[=6...._..j.s........6..N..2.N....%..r...0...M....vE...'/..eF.{...zHr.yZ4AW....-.R.Pu"N....A.i.....qC8...V{..g.L.u..G.n....TOc.~.p.)...w.7r....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):165054
                                                        Entropy (8bit):7.674220656279657
                                                        Encrypted:false
                                                        SSDEEP:3072:wFXdEqf/9S0yIYfuEQJVYbIn1JE6p5+QzDPNYq802cok0KCkAfv44UiN:0aqY0yNf9aLrp5+Q/lYX02Vzk+g4UiN
                                                        MD5:D87E48CAC5961D4AABA49185A1FCF395
                                                        SHA1:40B7D8DE440C080AD20C0E377830C83D765F6EF0
                                                        SHA-256:3133D8C27987A2818AE6AF6CDFA06429EA064E7772BF49863672B82A06B0E7DF
                                                        SHA-512:45AEBA774850C7A7B197878115782CC23535007528F47FB6D32EEFABFA7D41F2D5B2BD4E95CB4B188C7A6A1E3447D40A7C730E7BEF4F1DFB446DE009021E653F
                                                        Malicious:false
                                                        Preview:.'#.8....V8..I-.PJ..YrH..x..s.9...D>a..jE....5.......v....g.n...b.o../...2#fD..... .q.`.'..9....%.A.[Q..%-2)......f*....E...THe..Ie[>. ....Y.<`.2.9......&.}.gy.q.".&wm9h..v.Z].=X....0...s..g....N''7..Wl....\.+0...."7.....@gXn...b.o.../J....2.fT.....>.q.o.7.W9..R..%.A.[..% 2;.....f6...ES..TVe...I8[..'....U.f`...2.9M.W.t.^....y.q.".&pmhh..S.....o9R.>r;w.6\.....#....[W.t&..(GtQ7N..G. ?....g.n..b.o../...2>f........H.K.;.79....%.A.[W..%.2f......fb...E..T.e...I0[..)....U.+`..2.9......7.#.1y.q.".&#m6h..r.5......,..'.9....# ...._..P..7.p.V..6... ...y.....\g[n..b.o.../N....2`f;.....O.l.r.F.S9..V..%.A.[..%'2H....fV...EB.T.e...I+[S.c....O.>`...2.9..[./.+.{.1y.q.".&.mth........DB......cS.7>-$jc6.D.....q.....q..B.@,;m"....g'n...b.o../?....2.f<.....#.s.{.C.W9..V.%.A.[..%V2I.....fF...E...TNe...I`[X.q..T....`...2.9....+.n.<.1y.q.".&smph..].y....lX.\......<C^x.}....[>....pJ!./..08>....Sg>n..b.o../....2mf2.....H.(...b.Z9..G.%.A.[{..%O2[...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):15828
                                                        Entropy (8bit):7.692945835129517
                                                        Encrypted:false
                                                        SSDEEP:384:4YEVVyiAagSCMkZA/3OX3bqqEx2Uaf//sZSLd:4YWnAagNcON/U2/uq
                                                        MD5:D46C8B5F2052B40CF36F719665A2DFA3
                                                        SHA1:925D812F7DC436B858D523EC1C41253689E03EFF
                                                        SHA-256:49B8CF117F8E5CE74F083EECE6AC853329B27C8FC07491F29492D9816ACAA29F
                                                        SHA-512:A6F53FF4E7E3F60998AB071874F8694B82D7F11C7436567271E2934413418D84997F8F1EED9CA80FDA92CEFFDF177CD38F67D7D86FCF8CD94B50582CE714A49F
                                                        Malicious:false
                                                        Preview:0..l?y.E...B..2f$....h.@5.b..`p.G....&..S..-/._.....Uh7.FW.......i.b...n....p.k.1=*0.`....K...u.....c..._.|^.....yl.....in..4...tN...M..qB.....0........^.<.....,'I.<;<<..Y..... 5..p..H..O.........4.)t.....o...?J@..0y%p..4S%.R..@...Vi.bF..n..V.Up..C.!=80.`....D... .......7...U_H|S.....kl.....i...4...t.......qE.....<...I....q.....E'4.C;.<..M...I.t....T...8u...........\..<..Y.n.|\m.}G......$0.........i.b...n..l.lp..9.J=m0.`.......\.....9...o_q|j.....kl..I..i-..4...t.......qV............T.0......'Y..;.<..l...[....U^q..{6~....)]D.M."8.p.j..L.qGz.......(q...u;.........i.b...n...Gp..U.m=z0.`...T...U.....k...._.|......Dl..M..iz..4.."tJ...x.q......<...._...B.'..... 'P..;<<..Y...X.s2@.J<.]..J.<d.....~.1#e^.-...y..<.8...&h\H......S..Ti.bB..n..#.Wp..(.H=M0.`....]...U......A...T_U|%......l.....ii..4...tw...S.q......>...^...I.=.....B'7.v;Z<`.5..o..Z.sHdI..}....-?~...;...IP...-.._......,..n..1.........i.b...n....p.j.b=m0.`.......2.......3..V_;|&.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):39876
                                                        Entropy (8bit):7.70718203611252
                                                        Encrypted:false
                                                        SSDEEP:768:/YwKgsZz+w6BjX7H6v/FNnl2pG0s3fOyahewhc9d+AIaoglZH92:/KgsZx69LHa7nlaGlffahrhPAIDgU
                                                        MD5:71BDB39852C4B89038C07BAD8B4AB888
                                                        SHA1:CBF8C0E4DE31227EC2654767DA508B2F0AB90873
                                                        SHA-256:D35FE0DF24AE07969BBFA465974FD1A64EF2D63CE6CC609EAD42F20186C1ECEA
                                                        SHA-512:FF0ABDA4876A1EB734FC011BC9F0A3F31A95602973B74F1F136EEAA1FD38812FF8D5EF0B8D88F945677F99F3536DDD0D49C483C8FF454988EAFC71344D2EFB50
                                                        Malicious:false
                                                        Preview:.a..[.'.. B..d0p..'@+6-.P....A: .6:?..i.V.)LR......|R=....H..6.........q"..*:...@..jH..ER. |...?.Sh...7l...Y..q..".n.W.7y...y.U.[.B..&S..Tr.Ln.../...@.~.g4..AM.Ga$...-..8.....u..q...$`..........:..B..^.....~<..........._H..j.........q{..*....R..jV..JR.u|....}..h..7;...K..q..".n.W.7&...g..U.[.B..!S..Mr.L4...w.....3.=4...A0.8a....9..8..#....4.2..U.X....;...B.....P.<..MI...h@.....W.......H..;........qB..*h.....j....R...|...$..h..7.. .r..q..".n.W.7)..g..U.[.B..2S..Zr.Lm...-...[...g4..AU.Sa$..,..8..`.\Gg..NY.x....ib...Q.;Y..qV.....jM.a.^X..B........(H..6.........qx..*v...2..j....R..x|....n.:h..7.. .r..q..".n.W.75..)..U.[.B..*S..Pr.Ll...{...V.,.!4..A..Ear......8.. 4..bDn..2..d.9......!...XGz6a..Y.]...:..Gm...q.....]H..w.........q...*b..O..j_..!R..|....qh..7v...E..q...".n.W.74.."..U.[.B.MS..6r.L5...I...S.e.v4..A...aA...A..8....&.?...b.>o...b..;qJ=JR..M5......Z.s.x41.@#........H..(......q?..*&..+..j[.. R..(|.....xh...7n.D....q
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):33598
                                                        Entropy (8bit):7.67991183161477
                                                        Encrypted:false
                                                        SSDEEP:768:eGQk5S4qcfT7b5+Jpwlwce3SXr8ZdjUKEzC6qWexA8Z1L/P7KxrvZp9A:hSYnb5YpcwJ3C8PNovetPLQ9A
                                                        MD5:5C9E9048C8202929528213F1535AA147
                                                        SHA1:A27CCA5E2578B201DF23758EB8BC80F65AC21729
                                                        SHA-256:E8F3BFF9B0BD57E85BDF2283E2011052BDD8DA85F465368098E855EE35F3DA91
                                                        SHA-512:C1D56679FF425E5EA147AF834CEDC4941DC2714908CC740B91C47AECC5607B310AEFA0775B5635B4B8B2C95F66F6CB98E23C706CD6CE255D2D5F1784D02594DF
                                                        Malicious:false
                                                        Preview:b..h'..B(.H..c.Z..p._.v|..?....i[.B.=......t.^...1Q.3.*$..pDw.;U..h..o.*..TDw..PKaq.\.".....-.}.'....C.6..q..sfBd..L/...a.h...p..a.)].....).U.O.&#...<......}....Z..W..........Z.w...".s.83......\...3x+.{..*_......f.B..6RP.v.!..p.w.;...h..0.i....Tlw..BK.q.\.".....-.}.'.....h.q..af'd..L/...anh...n..a.)......%.L.C.|#P.<..Q...'....Z..(............v....._....|*3v/..aO.....Z.......CH..E.Q....Uc.{.pXw.;X...h....S....T.w...K1q.\.".Z..-.}.'...'.R.q..Xf+d..o/S..a^h....n..a.)......8.[.g.%#O..<......}....Z..C..............;....x..`.....4D..../..../=.Dr..%o+.b.iC...u.pzw.;U...h....i....T.w.."K1q.\.".K..-.}.'.. .Q.q..Xf+d..e/_..aDh.... ..a.)".....:.Q.@.$#..<.....;....Z..".....8......[.<..s..}.aR.:..Q.6b+.IL....c,.[..7[.=..k..P . .p}w.;...h../.t....T.w.._K`q.\.".....-.}.'....i..q..of+d..I/]..a[h....+..a.)_....C.7.'.}#].<......l....Z........u.....Qn(..?..&o.|...=.V=G.J...J....}k)..W.q...ID...K.}.pHw.;K...h..x.8..TXw.;K4q.\."..V..-.}.'....D....q..0fyd
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:PGP Secret Sub-key -
                                                        Category:dropped
                                                        Size (bytes):33598
                                                        Entropy (8bit):7.678098360663871
                                                        Encrypted:false
                                                        SSDEEP:768:vxokpW3LImkk6fyK5SxTfxsZRnmt2Mru1nxDIojPlcP+khUNBDfO:v9ut4esvr9r+hafO
                                                        MD5:D10F71F1222C60DD639E0974ED936D66
                                                        SHA1:C72254BE5B3244E74CAD63B3BE4401446843A9A6
                                                        SHA-256:27A5689AD1F7E7ECCCB6191724D0DF2637C6D078B515159B6241CB5F3E36CB4B
                                                        SHA-512:0B2BF3BA65F824714DCC0FF181A632F78D408802C7D5DD82850A9636DDA4927D9F35EECA17451F1F97368932077E6A199BE8AF59B73382837C40EDA41E357B22
                                                        Malicious:false
                                                        Preview:..Y...@e*....A.....+..R.)....9..R............f"...U.$...\AH6.L..e.K..e..X.:..4.......~7;~..D.._r..A#:.6e_0.aV..T}N.Q-j.Aq...K..s!Jc.R1........9...^.:..m.l..N\.-Wi{.?....q.........$}..9Og.../.]Ho3`....(g.+E.UM......I..5b3?I.G...\NH....Ce.K..0..X.:..j.3....{7%~..K.._'..Ap:.61_i.?VZ.Y}\.4-x.Aq...K...s<J}..1....... .....}.Sm.l...\H-/i..B.r.(q......G..%=y....;..El..G....>.Y.]..v...._.......@....2...\.H*.e..e.K..>..X.:..R.I......7a~....._[..A3:.6?_T..Vc.`}e.8-x.bq.K...s{J}..1.......7...].b..m.l..O\.-cit.'....q......M.6.t.<.....P...#.k.......|.d-/.IE....W...Z.S\....\.H..H..e.K.._..X.:..m.W......7g~....._*..Ab:.6._S..Vc.`}e.8-}.hq.K...s{J3.+1........=...\.1._m.l...\T-Yi-.y.x.HqN.3...a...th....-......^k.X..j..8.@.b.W...V.R ,]........\?H..c.^e.K..D..X.:..k.E......7%~..V.._Q..A.:.63_i.>V..K}R.8-..Dq.K...spJ8.11........[.....p.mm.l..U\.-Pi}.u.C.qqu.~.....&.,..X.:....F_.2.<]..#..@n....Y.=..G..b#.E.....\.H:.T..e.K..F..X.:..........+7(~..!.._z..A%:.6N_7.KV...}..j-
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):114128
                                                        Entropy (8bit):7.717214232794886
                                                        Encrypted:false
                                                        SSDEEP:3072:CyEODrrakf0zPeDRLQInR7K7h0/vbVa0QBK0cB5huIc:CyBXOksqDpIqcBA4
                                                        MD5:46BA0A359DE48DA78B744DDF63F1D122
                                                        SHA1:E92A42C7361C394BED34ACA990C5D40E9A7CDAB7
                                                        SHA-256:48B30D20560DA94E0830D2580E0BE3E15480B4EE9D5C903C6B7C9E4A6DB2AEAE
                                                        SHA-512:545A7FA6416052D3CCC5AB7397D7D2E2EAD171920377FF39E8D7FE1E626E9E256E33706FCEAC841B6DF95BDCFE19613B59D1D3ACC0F54F40B9EB4F2881691C94
                                                        Malicious:false
                                                        Preview:.S...0..#.j.kDQPu....7.}.....'."...X..... ..2.:h..e...O@..p3IPb....Kr..1*.r...#.z,Z.#.G.L\{.L.00......O.Z.n...u....).....<..TzP....Z.`g./..Rh.....M....go.F.W.J....%.V.5..."k..,....q...>..$..6L,..h&'.sn!...k...c......E]..$W...2]u3FP+.V..Kb.1..-..z.%,r.3.U.LB{.L.0 ......O.Z.n...u....;...... .rT.P...D.=g./M.vh.....M.... o.F.W.J....%.V..J.1.3k..}....Z@U...y."`.X..+1^5.Q.-...yO/....o.Y^1..j....F.:]$35Pu....K=..1*.n.....|,G.j.[.Lx{.L;0,.....O.Z.n...u...f...$.t._T8P.......g./E.qh..:..M....mo.F.W.J....%.V....T.~kJ.#..............5..Z;..... ZE..I8..>...*...t.....C|]{3GP7.U..K..1b.4..|.",..\. ..L3{.L.0Q.....O.Z.n..u....H....j.@.DT-P......g./^.?h....M....`o.F.W.J....%.V.....)k..t...`...=.G!...U..W4..*..@.qj.B..a}...)wy.....,I.W=].3.P'.B..Kj.1..D..|.P,w.3.P..LC{.L.0$.....O.Z.n..u....2...... ..TxP... .Yg./Q. h..8..M....co.F.W.J....%.V.....3k..t...m...o.Xq.....B5.-E...|...>...0.....sGl.....vw.k].3.Px.0..K;..1..r...h.5,..{....L.{.LW0-......O.Z.n...u...Y..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):143572
                                                        Entropy (8bit):7.6808187306490865
                                                        Encrypted:false
                                                        SSDEEP:3072:BSVp3KRnEThbA0QW8sx2dfMF2ATmum98nAHB57lSJH0z68hPrI:83K+9kBWcVMA1inAHT7cJUzzPrI
                                                        MD5:C469CA0D860AE174428D4D6F73BE1020
                                                        SHA1:77AC1F9B092FA3416EDAA2A3C909D032B23E92DE
                                                        SHA-256:CE0498A58FADFE1D4B2BB4CB30D376F16F7E47816565D883C7C0FCA5F35FECA0
                                                        SHA-512:7E9AF25A94862F57B309C905244F98BF446AF414F9111D13A334425FAA8EF03DA3A4E6DF0237E173A19B9D9FD666DC783FE0531CE0DD9D4A23830E1E851E94FC
                                                        Malicious:false
                                                        Preview:...o.o...d!..s...9Z..Bk..bul.B...tJ.(z.u.....W.:.f..8b.{.0..w..f.....7..kF..g&1#"$...eC$.J.|..Gs...#T,..C...E.P........Z...n....f....*p......5.X.M.0...5{e./.2...,.8.......a;E.....8c..`.1V:....Z.L..v...^...:......0..#..0..>..:....7.....k...w&###$...eL$.J.|...s....zTr.yC... .B.......i.....n...;....&p......r...%.t...o{..F.O.....)......9=g.$...b... 8.3dL...\s-kn?M../....]4r-./..+.I0.`..z......7....k@...&-#.$$..eh$.J.|..Fs...9T*..C...`.k.......X.X....n...3.....p......?...x.,....{t.q.d..v.d.........2..b.1..{.VU..EQ.6...$..y..X;..p.g...t.....8m..0.."..9.....7.....k.....&V#U$o..eQ$.J.|...s...sTv.zC...m.&......M......n...(.....>p......&...n.+...%{d.*.d.....3.......].b...&2p....F0.c....U+.4....S.Q....{.W...A2.6.D0..{...n.....7....k....&*#$$...e$$.J.|...s...sTo..C...T.).........H....n.........4p..... ...Y.#...0{-.n.d.....9........)..........\.:.0..o..R.......v..4.1B......*.D0..-..E......7....kL...&z#.$K..eC$.J.|..]s...&T'.tC...S.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):81236
                                                        Entropy (8bit):7.684699614414446
                                                        Encrypted:false
                                                        SSDEEP:1536:qvY9jGM0+pMsAsx0KQuw/yGQyQ3ZIcThcsWUU:COBpPsKQu2QZIehcsWUU
                                                        MD5:0F9B27BD2028C2D0DD102ABEFE15C82F
                                                        SHA1:71DA78172111479C4790250F63C1C1E244A40050
                                                        SHA-256:F307D7F839B0BFA04031B99A6823E59B40045044960482197A6C498B27C081A2
                                                        SHA-512:2B1B451AC8828CF012626EDF5F516A7FCD45C314412E5F0AFBF52C315A99DD470360C0AD2F2FF7B650226A678A5D0A9190EC9CDD97BF8145029BAA7CFE08013B
                                                        Malicious:false
                                                        Preview:.E.e..S~y/..X....}i>...........Q.r..O#xJfp.fd*..~..un.....i.Eq?@.....K.Me.5......}.....2F..h....lBC..h.Dpv.T.lz....TV....CR.j..Fb||g{B..c3.1NW.`..lD...q"./...q.....R..Tf.{...Is.,p.%.*.2.i.'=.%..X.L....b`.em.v...2b.....i.E*?....E......e.5V.....o.....=F..=.@.Ml.C..1..D'v.T.l.....HVp..R.j...F.|!g_B..c*.=N..'.Ll,...qx.W......q.....R..0f..c.t~..R.j.l..2..$......,!.)B.*...8...V......i.Eu?_...K...3.7e.5[...D.3.....].|F..-.>..l@C..<..DZv.T.ll....*V`..)R.jl.FH|.gJB..ce.rN..F.gl]...q........q.....R..0f+...5a....ioF..f.s/c.oq..).:4.....3..{.._.#.~g....i.E9?p......K.Qe.5....U.......R.yF..h.,.2lKC..h.Drv.T.ls.h..JV..CR.jq..F.|%gXB..c;.5N~.d.Ylq...q........q.....R..%f.A.....X...tB..0m.c......m|.c.........n../.....i.E2?....F......e.5....D.,.....W.uF..I.M._l`C..@.DTv.T.l|.{..5VP..R.j..FX|sg.B...cd..Nx.`.Xld...q*.?......q.....R...f..v..7. ..eD.....F`.O..=Lcj.....N..1%..f..F....i.Ep?I......M..e.5m...........D.^F..`....l]C..b.D[v.T.l[.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):13534
                                                        Entropy (8bit):7.677249756367035
                                                        Encrypted:false
                                                        SSDEEP:384:0aVYoDZrS/2ChWX3UBVewT2Ip32jBjrooZ28x:021rS/2CQX3UBVew3SBfog
                                                        MD5:06566B31CB4C76578BA6731D151D082D
                                                        SHA1:F8EA38FDF300993129D382330FB326B83FDBAF41
                                                        SHA-256:8CC30C0FB20DE7C296694BB0B18832062F2FDBB9FBE25447D9F45A1683715A7E
                                                        SHA-512:8B4A99669CFC1E03DE05D620EBE21661ABA40A177B3C50FB451C62D4CA2AC319558A96EE17C9BE15EC0C8C3A5E0BF52A8C32D2033CDD116D864F70159CFE4D14
                                                        Malicious:false
                                                        Preview::.....{Y.......R.&..].6.t=>.<..h[Qx.2%.s'..|..}.-a...;..!......7.`/.(..q......I...8|| ....#.].\.[Y......7'..{.5..99.f.l,\-.HGd.3........I.0k.o#.!f,..|.Q.jn...<?...G."...Z..."35..{n.......U.^.IP.....+G..qI..zn..uJW...F.-.k.......l..`?..(......I...8n|%....#.].\.[..L....i'..v.5l.+9.f.l^\^..Gy.-.........N.<k.o/.{fk.B|.QEj#....<V...8."...Z.."...l...|..p.....sc.F.3..&.;`..-....6Dt...;.s.0.......3.`{..(.......I...82|a...#.].\.[y.......{'..'..5=..9.fNlx\X..G6.}........`.+k.o`.ff..[|.Q.j<....<....M."...Z..".B.os.6X....o.x.FV&CsPz...F.pL..C.~..5S....G..........`I.(..F......I...8=|c...#.].\.[..3....:'.....5:..9.f^lx\*.\G..I.........F..k.ob..f(.W|.Q.jq...<9...e."...Z..."L?SK)h.P...p7f.j...l..4.....^...I.h.....\..e........`M.(..F......I...8.|T....#.].\.[..O.......'..+..5/..9.f^lx\R..Gf./.........j..k.o...f..w|.Q2jS....<|...g."...Z..."../...R.I..a.r.;&TZ..Qj.O....k....Q..s'...G.......d..` .(..o......I...8`|.....#.].\.[R......5'..f..5=.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):52250
                                                        Entropy (8bit):7.705560613331684
                                                        Encrypted:false
                                                        SSDEEP:1536:csY+bDSbyQ5xHVSZLWKdU2xINj7dvVp68fy:csYKDSuCDSZyMUoINXdvVpJfy
                                                        MD5:2FDFD439F9DC3F1E8366F60A3730E973
                                                        SHA1:E00F0A5536AE06FAF0A1FF2A907738A75EC8C97B
                                                        SHA-256:EFD332143CCF2A079161974555E2535C18ED3BCD8788F3ED655E568D405DDD46
                                                        SHA-512:EB6CB3DF83A75B808C18B5CCF235E0987B40D2A01B6B3B8B98E649F2F8618D9C19C0E2527533485D69B8DE08765E25CBC9C3C74BEB4D0E16B7BC63B08A950154
                                                        Malicious:false
                                                        Preview:...j....w<...%...V..N.-.#6d/......6...n!).1Sf...v.....)...&Pr..XQ...[.~~:....6.'.!..[...N......q...XP.F.=v..fx.*u.WOG.D.p.v...m.\.G..hQ.m7.Q. ..JY.`.........e..K.J...-..w.tN..q............J.H<.i........K..?.Z._...=.I.....k...&.r...Q..[.~!:..h...1..^...G.....q..X...FQ=(..fu.8u.W]G.D.p.vu.m.\.G...Q.m..V.,..JU.:.....m...e..3.#...R..w.tG...........g.2..1a..[U3[{.2..v.1a.....4.>..`e..<. @y...&dr..GQ..[.~.:...e...y.........F....q...XR.F\=:..f..Ku.WWG~Dmp.vc..m.\.G...Q.mZ...f..Jk.N........e..y.{...#..w.tb.....R..SS....s.+Z8......^..Ah.....~........n...mj.-C...&er..WQ...[.~c:....y...z........v....q...X\.FP=...ft.8u.W(G.D.p.v~.m.\.G...Q.m..U....JU.b..........e..f.j...".w.t...b.....V0..;....y.v.H...D.W3.)j....4V3.7.Y..>y<B. ...&.r..zQ...[.~.:....:.,.U..W...;.r....q...X..F.=q..fx.*u.W+GcD.p.v...m.\.G...Q.m!.Y./..J........i..e..R.Y......w.tg... ..y....>.F..d..:........X.7DRI.n_.aY........4d...&"r...Q...[.~|:....4.,.o........f....q...X2..Fh=...f..mu.W
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):30386
                                                        Entropy (8bit):7.708547105670298
                                                        Encrypted:false
                                                        SSDEEP:768:t5778AkuD3Vppi5+NM37qwFBE8zvyr4BZqYfnUc:t5778Aku/pjNomMBHvyEBZqYp
                                                        MD5:61FA24FCEE22CA1CF1E311B57AA84A3C
                                                        SHA1:D98E42E335A08B46C88BBDC8FDD5E29224702C7F
                                                        SHA-256:ECF9CC79DB794FBBA44FFFA5F7661DA87D4FC5FA6715B87C0F55E01194DDEE21
                                                        SHA-512:0710AF597A881EBF310173DC254DA96B61946EAA5F77A0350026E682A504EEDC644322FA96D6740DA61DB89B520235450EE0A73485BF20B6983258D05A9E08F5
                                                        Malicious:false
                                                        Preview:);....^.m.].F..{..$.....u......I.(.fE./.P...T.L`gV\..d...z.x`v..:j...%B.q....8.!i.x..T.g.."(S...6..B.......}^m....rT.Y..Ww.L3O.....b.......4...N....m..f.[.J3fW'...h..&..2lr...w...A.-K../.Q.r..e..L..}...).."/.d..Km.8>...d...z.x<v..|j.%..)....8.!{.}..T.g..2(...e....B....O..}Lm....nT.Y...w.L-O....N.F.......4...N_...)..f.[|JZf*'`.>h../..2.r<"R..0....?..X...3..H..qU..qM7...R.z...n..C.......d]..z.x.v..rj..%8......8.!'.9.}T.g..g(....4..B....3.}2m....T.Y..Uw.LlO...............4...Nx...M..f.[#J.fn'..0h.....2.r.$...+-[.).Y)...._?...d.{.`....yG..Z.......`....du..z.x~v..?j...%E.8....8.!".*.^T.g..d(P...6..B....N..}Om.......T.Y...w.L~O....L.W.......4...Nj...1..f.[?J.f.'m.@h..r..2}rE.........m....L2K...r...)_<.1...U..PL,m.P...:...d...z.xav..?j...%R.}....8.!i...bT.g.. (....6..B....N..}Om......cT.Y...w.L}O....C.W.......4..No...s..f.[.J<fF'|.8h.....2sr..3....H[..(:.....L......v7.9..Q./U.u.....l...da..z.xSv...j...%r.6....8.!i.i.kT.g..j(...p..B...3.},m..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):15762
                                                        Entropy (8bit):7.704153218969028
                                                        Encrypted:false
                                                        SSDEEP:384:/PGKn+IohXa3tJZ3C5ZllQPZYnenPG3rweu8bK4k+wX:/PGKn+69GEVPG3rwNF+wX
                                                        MD5:133FDE1C58193E0768E3D2E288B1BFB0
                                                        SHA1:BF0DBFDEE4C96BBFC4B03A13B4318F8AA5B82AE3
                                                        SHA-256:95954EDA57F0B8B19FB5135FE813FDAE8443F056DD9D923476F1B3D492E690F2
                                                        SHA-512:00418FA5AC2F70697B75C0F05B0FD929F578E29D27129BA55F080AAE73AC9E7A9C5F2C17152072292A723D65763D3F8B6D30A5AB69C2BA45B839623D73726DE0
                                                        Malicious:false
                                                        Preview:....i..V12w.+e}.J..v.VB^.>.....O..1x.s83..A.W?.0..)..2..B.h.._.T.+5D<Q.......".~...3K!.O.[B..y....g..8'..........r....45.C....c..ASv.^...+:.....6..,.Q..q.....n.D...<=.;D...|.1.G:.t...p.2.@[.!.....cl.................GG..Pm...B.hU.....;5.<.....L...Q...!K$.Q.RB..h...Lg.z'...........`....4G.0....c...S......,:.....6..k....q........-..C=.;E...4.v..H.I.Q.I.......^>~a.Qvzw..d.'.MxiU.p..?.:..zE...B.h..v.Y..5S<......u.D.,...tKq....B..<....g..#'............`.9..4p....._c...S......?:.....6..t.S..q.....~.x....=.;E... .}.....i/.V...lV.!.n..:.\.%.m.*[...._.x....O.2X.....B.h..S...+5b<U.......9.-...3K..l.aB..P..ug..'............R.|..4k.....Uc..)S.......:.....6..y.@..q......+....O=.;a..q.'...TBq....|.....=)v..^.#.....P.Z=SR.3z..{.x........B.hU.....;5.<......N...)...'KU.T.^B..$..Bg.x'...........H.(..4......3c..pSS.$...+:.....6..w.|..q......'.a....=.;U...$.3.HU......1|.Kv.K.D.`..*'.....8.5.W......pP..M...B.h..G.J.n5{<P....;.?.....gKu.'..B..<...Jg..'...........
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):390694
                                                        Entropy (8bit):7.6807301459058674
                                                        Encrypted:false
                                                        SSDEEP:6144:LyC8aywdas0qmDk5Mym2GK7bg6khsx5qu7WScESdT65M/i1xdlb0cLvIIhvMZNTg:LyC8nRs0qmDk5ZGYbg6khsx5qu7WXESm
                                                        MD5:DA009F8CB00366C40D6B21CC0D794C88
                                                        SHA1:CF83AF0731A0B51C3D5C8715D3E6E6D1539020E2
                                                        SHA-256:9C252CB629D22F538007E3F120F75BF3120144782D32D9C6E38782DCF7C2A4AE
                                                        SHA-512:AC99FDCC36DD8B41CEF3DBD8D593727A5FD3D4DEB1F3A5A69820BC04ADD3D7BD09F8ACBDF808605BA469FC6C6E834DC824766D556115200AC016AAC570636DAB
                                                        Malicious:false
                                                        Preview:........I.4..C<.7 .(....]...N..*..._KH.[..U.q..h......47.....m..p/.{:%..,t.tSZu....T.Z..e5...|..,%.......Q:...!4%.aa9?...!.`hm.I..'..~..N.k<.u..e.B....q..j].?..{Mi..Ex..Q...L..P`..*.[..M@kT.M...~DwF.;..e........-5.CX1.f.........m..,/.{|%V.st.t.Z(....F.[..e5...m..,{.....W..Qd...34@.sa9?..n!.`7m.I..z..~C.j.l<.l..e.B....q..'].?...M...EG..Q..L..../.....r...3.<.R.....D.......S...l...*IR.........m..l/.{"%..0t.tvZs....H.f..e....`..,>.......Q<...n4..Za.?..C!.`jm.IS.H..~K.m.b<.q..e.B.....q..q].?..%M?..E".QW..L..>jm..)o,in..\. C..Z@.&~1.j.......9.......".{.........m..//.{|%K.jt.t.Z-....3.-.e(......,......&..Q`...@4...a_?.X!.`&m.I@.C..~P.#.(<.m..e.B...q..}].?..:M=..Ex..Q..L..5^+:7/.J.%..MP'n.?..L...cP2:.at6)i;.S.R.w..{......m..!/.{7% .kt.txZ*....N.F..eD......,.....Q..Qm.....04].waL?...!.`{m.I.....~..).w<..>..e.B...q..d].?..:M=..Er..Q..L..G~..*.1.....H.<T.M[...&......l:...|.o_.`[.W"~<......m.s/.{9%..*t.tSZv....@._..e%...9..,........Qv....E4$.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):184244
                                                        Entropy (8bit):7.7244017711149295
                                                        Encrypted:false
                                                        SSDEEP:3072:CmNcoVORh6DHXzyZ2CaVN3yVAc4VYChD3pznvMKJ:uo20DOmliiYEDFUKJ
                                                        MD5:5079F8E7EC330E214BC17A92C06B44DB
                                                        SHA1:89248EC462B45B8B4784839FF56A6D80B77F2A13
                                                        SHA-256:25A8206733004310CC349EF77462F070C101A66A6801FAABD62437F6987BBC33
                                                        SHA-512:5BE3F0EA07D5EE530F2F681B95ADFD782844B97D7997EB78341796049494C5993BF77E0775AF0F4E45CD4B441C387DF3489374E3A338D4931EDF33FD76E7A364
                                                        Malicious:false
                                                        Preview:..xR 3.......@C[.0|).3...V.>...].X.lhH.N>.9.|K..kJ.qI.Beha..a...kM....h...\[..fApiVT..2p .....r.+..e.r...!wb.0.>mr..Vs......Ad.=f...T.E&..#.m..'..W0.FCdMZ"...i.D.]nwkT.....7,..}@..Sv..41=.u).....^2.......dG.....p.V.c..d..a...7M.....hP..\...fQp{VQ..2y ....,.x..eCr...! b.0.>.r..Vs..r....d.=x...2..&..#.m..+.Ww..C.M."..F...-. n.ks....7.&.:...ze.|....a.m;^.5..yjf..].O......&.j.....2.1..a...tM.....hw..\;..f.p'V..2) .....R.)..e.r...!Wb.0.>hr..>sm.i...Ad.=....*..&...#.m.....W..*CkMx".7.[.u.hnykd....7.d.....FK.&..o"B..T..5Z.L....%..............x..a...dM....h...\F..f.p-V..2% ...z.!..e.r...!Lb.0.>.r.Ls.......d.==......&..#.m..+..Wh.DCyM{"..?.N.f.yn|k.........7Ow-.?....[...q.....L.@.%.{._.j....m.V...c.....n..a....IM....h...\S..f5p.VX..2. ...T.j..e?r...!tb.0.>.r.#s....w._d.=....2..&..#.m..x.W_.oC=M."...p.W.on]kW.....7...}.Y`...@b.a&...Skb..@.L.)u.f...D.5..'.N...B..8..a...BM....h3..\....f/piVE.2! .....>.m..e r...!\b.0.>jr
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):25346
                                                        Entropy (8bit):7.71613522514604
                                                        Encrypted:false
                                                        SSDEEP:384:tqj4PsMtY2xdDxA3mI0Vplb3xH0QLIji1wvVBqoC3uGpFrvcdk0pXElQR9g:MjasMG0Dy3m5lj1X2aoRC70pXEQS
                                                        MD5:D6A640DEC896E8C534CAF79E472196A7
                                                        SHA1:84782B71E0727A174C61949CECA41A329BB59265
                                                        SHA-256:C380656C9D5606F85F70158315DE0F83A33A14E29365CA9941E690895A6D24DC
                                                        SHA-512:8111AB9D2A83F56BC76D3A03AA7AEF1B8FDF0E646E71CFF9DD2D81DEA2060267946DB862519D4D0CDBA06263EA299D58E1DD4AC37CBF414ED1A76317517B88DB
                                                        Malicious:false
                                                        Preview:W.......P#l.G.qP..7B.u....\\...Sj.K...4..^.............Bo.7.f.[.a}...p..sv......,Ney$zZ.......F+.g.q{5..e.........*..=lA$.5.1...IH. ..i.u.m*....,]3S./.......N....P.0..cB..Q?.ah.2~.....+.O......!.......}.. >[bK>.#....%C..Mo.7Uf.[.a;.../..s/......,\e|$dZ..!.....+.g.q/5..;.L.......8..=pAV.F.n...WH. ....M.r.a*....v]tS./.....V.6.......w.1..c...QjY^...{.....6d......wa.8.{&@a.JC.D,.......b_.7C...o.7.f.[.a5.....s.......,.e8$.Z..`....f+.g.qz5..).3......1..=.A;.K.K.{.UH. ....M.|.3*S...].S./.....8.i.....~....c9..Q\..ypM.:*w.(./..=...R.<.<.~_....v"w.=...[.s.&.3.C...o.7?f.[.ah...m..sp......,#e.$2Z..o....g+.g.qv5..n.M......N..=rAI.!.3.f..H. ....I.u.m*....*];S./......;......q....c:..Qi.b_M3.........[..D....K..-..k...Z....QJ......oC..So.7Sf.[.a)...L..sr......,.e+$1Z..H....g+.g.qQ5._.9..........=%A(.!."...DH. .....;.F*....;].S./.....e.1.......w.1..c...Q.E.i...b.hT.VB...T..b...-./...`...<....Y,....{7C...o.7.f.[.a5.....s#......,.e.$5Z..i.....I+.g.qS5..x.........
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2834
                                                        Entropy (8bit):7.642136683658803
                                                        Encrypted:false
                                                        SSDEEP:48:XmPHME4R6/qYGJXEHxtIZPZv9ZRVo+ElOzTXUqua1+Vo75NFvhof15ghVNCHklf:X0X+uq3hv9HCrUcqP1i+N/3NOef
                                                        MD5:DAA3DADDDBD4CE44F850CC67922134A6
                                                        SHA1:EC75AB657C891A792CD33C1F6264D2AE0204E47C
                                                        SHA-256:BD251F515C28E0E02B3C513BF699C9991AB16E2C31594EC1AAFCD256FCDD5CBC
                                                        SHA-512:3E845F8A1C58C07E7E8F3835ADA44B870394FD46314135AD4110E8C41B570E3CDDB86759ABB2C5C8D4573553F16640D27FFB06FDF2DDD6970F19B4CDA09FF081
                                                        Malicious:false
                                                        Preview:e.)yz..M.5..8..Z./.~....J"...9...l.h.d..@..M=.......'c]W...q.Q.T.*.....pI#R.r..@.i#nM3!cx.....&.....h..l........S.4.....P...T..).....$.pDU....Z.... .$Zj..|2..|....|1............Z...._|...<..........:....7....E.."..XW...q.Q.T.*..Z...3IzR.r^.P.{#kM-!jx......u.S...1.l........S.(.....M......)....$.p]U.........d.iZ0.x|[..|.....|y.N..Ze.La'u..5..Z.`!.gdOa.f".@.IS...m..XE.{K...G^G....W...q.Q.T.*..T....ICR.rS.;..#>Mi!&x.......6.......l........p.x...........)....$.pJU.........;.&Zc..|...|.....|m.E.spg..}..2...`.*...>K.....(s..g..?..l?m..?..*G..%W...q.Q.T.*.....fI$R.rR._.i#aM.!Yx......y.=...l..l.........5.Z........A.<..)...$.p.U.........b.{Z>.E||..|......|<...^.},>..re.J..T.....o..%Dw..W.2.b.+..g..L.B.D.^G..XW...q.Q.T.*..Z..0IxR.rV.;.}#.M(!fx.......y.Q...n..l........a.'.....f.&.e..)....$.pZU..........[.BZ..I|...|....|i...{.....\..g......1......\Y.E.R.w..le.z....P.....W...q.Q.T.*......!I.R.r..4.%#,Mi!2x............j..l.......
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):6708
                                                        Entropy (8bit):7.659180281977384
                                                        Encrypted:false
                                                        SSDEEP:192:0QrcxT3i3PVqmOYc2rie8onyfzezti1EjoQ:vwZ3CVqDX2Ge8GyfyhF
                                                        MD5:5B97BB079828C16B3EC8D4A668E60CBE
                                                        SHA1:F361223D140E77A2A091C429E5A282219584F109
                                                        SHA-256:3FA09261818E1A353442649409BD043BAF65F4D81C748CE8DC1F29B37712A606
                                                        SHA-512:01C538AC2B6132A5D50A28A0FA8A8D5A86DADF1BBCDCED30189D2E5DB47CCBB403E5E3F360CFB5150A16959EC176A32ED0797BACC47937FFC0C8E393E9DB566D
                                                        Malicious:false
                                                        Preview:..."".... ... ..p..^....;.e^.....YEl|P.i}*rg....E.R<^`~.xN....U./.G{.9..Fr...++..S..dV..[gzl..ST;.3S...KR.y..pk...I\/J.....U...c.*S.g8.w9.....2N.|.t.`.,..W=...U..`K..$......}kImxV........3..E..G....p....):!.6...ED..Q..........GU./.Gk......r...+..S.vV..[nzc..S.;.3..J..R.y...pf...,\=J.....U....~.4SGg^.*9.....2W.p...'.t.xWy........`6..$!.....5k.m....q.A..@.<.@..^Z!.+%j`H.X...M.P8C.WQ.H........U./.G/.....9r...+M.S..#V...["z<.ES};.3C....R.y...p_... \=J....U....9.4SQgW.*9.....2@.T.w.8....W&...\....`p..$6.....!k.m<..*..C...^p..q..;..LA."u.3....4.....N#u;..Nr.......U./.G{....Fr...+0.S.dV..[]zG.)S8;.3..$.@R.y..p8..r\.J....U....3.zSrg\.?9....O2..f.*.5.=.vW.........`...$7..E.pk_m.h.o.=>Tn....5..c......>%.).....H.....o..U.....FU./.Gk.b...qr...+..S..pV...[bzv.]S.;.3..H.lR.y..p9..y\.J.....U...U..S+g...9.....2P.o.v.;...JWF...8....`Z..$......%kKm@{......ea.s....eb...x|{z>......g.=....Z.O.r..........U./.G>.....r...+7..S..(V...[6z".LST;.3`...LR.y..p3..O\
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):155542
                                                        Entropy (8bit):7.722147497421163
                                                        Encrypted:false
                                                        SSDEEP:3072:jL9uAZHTlltaqqeihYhI/Fp0vNTninUSfkdXOi5AB:o4r/i6CdRMdXL5AB
                                                        MD5:EAEDD07533B0994CE97E7CC93559ECA1
                                                        SHA1:1060E82107BAAAF664C544E497846B78E6F6F6FB
                                                        SHA-256:DE02E053BB0B223D3D9C7F99C15A50230B8B40234157D1856AEB9714F5B22BE6
                                                        SHA-512:B3C48285F7C631B1B7196EFDC21CC151A34121EC42652D8E00A6593EA8BAE17E3E6147DBF35D2F2BFB27DBFE84B80054D8D104B79DDEDFAC393EB4085B9EF11E
                                                        Malicious:false
                                                        Preview:ps.....o[GRT.........+.E.8....+....cy...[...w....=...H).z.....fZ.....=.d..#.&.\^...0.....c.q`.vmd.c..y...;./(..&.....6d....4.......x...`.ws..6.n.5#....d..OD9g.H..........@B......u\..`....7..0.....l.N..$.7.4VR.UJ/..2.D........=ZH....=.d..`....^...".....c.qp.#m:.0..y..e.x(..4.....6x....k.........M.D.ps../.b.o#.......O.9=.0............B...y....`Y.t.....x.(GJJhy.o..>*...b..*d...S..SM.>........fZ..I..=.d..$...Z^....,....c>q|.Cm..b..y....=..(.i.....6,....6.........E.C.~s..2.b."#....Q..O_9J.Y........0...LB....Q]B......)G`..I2...[...+C].tw80>.*.r..Fm@.y...w....3Z:....=.d.d....^....#.....crqy.#m<.D..y.....x(.=......6.....z........^...4s..m.<.a#......O.9@.R...........B....\.baLH..^4q.B.Ruc.a.d.<.-..#/.?..M.cp./..k...{.....IZ;....=.d......^... .....c.qs.Wm'.9..y..x.y(.E......6x..../......P...q.fs....n.&#......O.9E.X.........._B....O.B..V./c..z..t.{..3n=./..d)......".....;.*..2....dZ..k..=.d..b...]^....M.....c.qb.3mA.e..y...9.-(..&...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):38668
                                                        Entropy (8bit):7.697936985571279
                                                        Encrypted:false
                                                        SSDEEP:768:kynka8dj17q+SECB1GpfNENx/yjqPo6u59/T0LP125hiY:Lnkj5CbGBNEN4jR6u597g125h
                                                        MD5:29F947E51FC4CE4B75A8F6DC724F3D9F
                                                        SHA1:35D068ABF9D09C2CF2F247006426C5D600DE76B8
                                                        SHA-256:967F9BEC9774D415D0EFEC8BBE433C9D1C4E8914723C0C2C4060D73AEF9A6BCA
                                                        SHA-512:5FF26172AA6461D1A076589907325AB591CDF8BA96D0C67153F98C4C07CA84025E75505003E8659D53BA0C01FC5F5BE5ACE759C284BE9CF80DD9B7ADE5AE0034
                                                        Malicious:false
                                                        Preview:...U..;0.......*..,..6...M].......k........@ek.....SMtcU.2..cU.~?.03..2.H...,.T^........ oF/...t..G..2.g...4......UP..vl..7z..&.l.....s.5%|..]..?..Z.P....m`..n.X...S{n.7.5..D+K..g.S5...........D~.9..Im7......k.....rVM{c..i..cE.8?.0l..2.H..V,.F^......... :Fq....t...G.e.j...Q.....'P...vq..7'..&.l5....j.9%&.@].W........m...n1X....{...w.._|.....:i.X..|.]@.D..l.'@e..ymY..........r.M.ca.6..c..6?.0K..2.H..&,...^E.... *F....t..G......$.....0P.v...7U..&.l ....%.v%>.!]..&..y.k....m[..n+X...1{....x|..p.....H3. \P..@p..........-...Y..y.U..!r#M.c~.z..c8.a?.03..2.H...,..V^z.... oF....t..G..0.k...=......WP...vs..7...&.l2....{.1%U..].......y...mD..n.X...>{..Z...~A....)..aQ..(....f...r......E.@...k..<.<rAMzc..q..cE.;?.0c..2.H...,...^E.... NF|....t..G........5........P...vn..7F..&.lr._..$.{%S..].....\.X...m...npX....&{)...QI%.r(...Y..5.......]0..^...o..Jr.. .....M{..\.r.M.cD.3..c9.a?.05..2.H..g,.>^P.... gF$...t..G....3.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):18398
                                                        Entropy (8bit):7.6990010106243325
                                                        Encrypted:false
                                                        SSDEEP:384:07D7hIwPGEYIaDyASfPkFf3IUYQ8aTiIAbUJ+ZpVN/1qVNXzg6/x1DRVPpP9m:0n7hIwOoayASfPkFf3RB8aTDAbUgZpV5
                                                        MD5:3E5CE7A66A9A9BB17F8E2E398A24C3E0
                                                        SHA1:82C5F7EF4EDD57EE563816AAEFB01E21DC80F039
                                                        SHA-256:F827C5AA9687692430044A11E8610ED4F08A467E5EC9548620BC321615A71E43
                                                        SHA-512:DC5E0717C53A4A73C5D080F3FC1B83F1E495D4DFB9A4273E102C19124D452EDEB353EA5D30F41302D94BD29509CDDDE3121F3824F039ACFDBBA60A7BC0400C3A
                                                        Malicious:false
                                                        Preview:.w..l%>.<..@}.8DE..sC9"Y.T.%.... {F}..:&.$.;/..~.........IQ.......=k.NL.j....P.G...gz....Rwy<.......{..eB.p..........,...7UN.S.<..@W..&D....(N...KS.!Z..o..;...\.3[s...S1.......l.rH"...[..\...`H...Ca.&.....O.w......$...N.. =..K@.dLQ...T..={..L.j........wz....Lwp<......{..'B.p..J.......I...7UR.!.O..@J..&....^(j...GS.!V..o..c....~[)...:1c......l.r,"......Q...{.......r%..j...j...."a.....Wf....d.QL......=?..L.j..0.....?z..:w <..Q....{..gB.p..X......,..._U+.:.Y..@H..&(...W(#....S.!h..o..W...~..[X...b1+.q....l.r/"`5;.D..l....^..Q.7..`.....!wi<uI.TM....?....o.?dPQu......=9.WL.j....M.....<z...w,<..{....{..iB.p..L.......J.o.-UA.B.D..@...&:...^(}...fS.!V..o..9...}.r[Z...`1?.~.....l.r["..W<GLHx.......J.k..V/T.^|kx.......\t........\dFQ...B..=*.UL.j....X.K....z..^w.<..d....{..*B.p..........H.l.BUP.@.4..@G..&,...O(X...DS.!...o........[r...@1,.U....l.r."....1\y.....6.C...cS......Z.M.q..j....b.n@.P)..dKQ$..k..=..]L.j....X.E...)z...w,<..]....{...B.p..s........
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:OpenPGP Secret Key
                                                        Category:dropped
                                                        Size (bytes):1128512
                                                        Entropy (8bit):7.694467406848154
                                                        Encrypted:false
                                                        SSDEEP:24576:No5XnVmF95esIv5w7gW0mtP+AdGy5bQN8hnE3b+sqgXyqgfQXG+gaTpA5jxiETc:N4VoisIvm7NtP+0Gy5bQyhnEL+rgXyqJ
                                                        MD5:5D7C8BD6AA8FF7EA6B4D89FD3606BF85
                                                        SHA1:54FCB7FA58E6003EC81BE8DDB8E32F1F080F4EB8
                                                        SHA-256:D4A8041871A2286832269372FB118BA8069CE72A85EFC72B07412D13A29E313F
                                                        SHA-512:71D741DC6A6BC2025A306C4AC7EC7E534F273040938E0592937DA3D82C2F0DFCBC6442975E8B808459297CA73422E4943E6D38F5E1E8BA1B8EB88DA837F1E1C7
                                                        Malicious:false
                                                        Preview:.anW0@. }..ht2"W.hq....,A.E.[W.......N...V.. ..i....gA..coH..."3mr...o..z.|\...>...V.D..r.D.U.~.....^....^.&..W+...].9.f&8.o.2UN#.......E_.\.{.......^_&Z..#3...-...Sl$.,......?c...R..~../..P...Y........\...~. .b......yfoG...."omb...o...z.|....>...V.D..}.T... ......^.....+..WN...]~9qfy8.o.2.NE.......\_.\.{H.[.h..^.&...#Z...-$..Sk$.,...+..4N.CZ+[.D........0e!....t..R..dC....."..:.y7o4..."/m=...o..z.|Z....>...V.D..Y.X.`.e......^....z.t..W.....]S9@f$8ioT2:NE.......A_.\.{..M.5..^D&w..#m...-A..S8$.,..*.h ..V.E^.!W............z..Q....Z....`.i.x..yhoF...."lm....o...z.|.....>..V.D..`.%...V......^.....,..W.......]H9Ufh8PoG21NL........M_.\.{J.`.?..^@&Q..#5...-=..S4$.,.........PH.@.G.J'....L...ZT..eW....y.N,....yoo@...."om.....o...z.|r...>...V.D..i.".r.T......^...z.*..W=....].9If&8.o`2(NY........_.\.{J.e.5..^D&K..#5...-5..Sl$.,....e...7..o.J.....,?J.:rk.E......<SQ.6.(%9n..N.y:o.....".m7...o..z.|....>..V.D....;.`.B....^....f.]..W2.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):112724
                                                        Entropy (8bit):7.7066855146073285
                                                        Encrypted:false
                                                        SSDEEP:3072:eCO4KyB90qddfSYIRBUZGqvC83mPSlpFoH7el0filRYyhUNRI:eiKyB9rdfSYwBkGqK83mPE6ql0fibYfY
                                                        MD5:385F42DFBD29842900A634968A0F7A43
                                                        SHA1:E5822685B3DEE224DBED0F52C277F6EF081B21FD
                                                        SHA-256:9EEA1DD64F1DA4135A085ADA77930346CB3660947DCD4EB33BD1DA9FBD23A657
                                                        SHA-512:415E1498822F768A040F4D6EF9E190C3D5101064DA14635CD34C13796D95BE97FD364D8EE6A403BA118CBE9CA55173C9211715016839BBF7EA968AAB587B92E6
                                                        Malicious:false
                                                        Preview:..:U\.....F..]..5.ag.h"..]...=.c...M.k.....Z........$8 ...M........I.kz_.]...=.i.7.1 4.........../...S6.....o.;.f.k.....{,..K.....\)....pX.kg..*.<.S_...;..2.5,]!SXn.c.....zM..&+.....3pG.....(....z.mS.(...R4W.;.|....$...m8{...].B.J.D..I.k$_.]...=.i.7.1/4........./P..Sa.......).f.w....$,..U.....)(...|X.gg..m.d.;_C..;...2.5Q]^S.n.c......[%..2../......@:}.?o.(.U...M..ga..t..j....$.....8$.....L.w.c..I.k)_.]..F=Bi.7.1n4........../]..S.....m. .r........,.W......)(....X../g....U.G_9..;.2.5.]0Svn.c......J..>...J{z/.?..(.....N..F...S..k.4C..De.7w.5.<.$....y8.............I.ks_.]..e=Ti.7.1a4........../...S`......._...u....y,.......),...pX.Dg..".y.>_W..;..2.5.],S`n.c.........0.D>..]`.?..E.Qz.v5.UF.sW..........;.(.A;.$...m8}...^.P.Z.'..I.kp_.]..K=Qi.7.1F4...........//..S......v...I.".....h,..F.....^)`...[X.fg....u.o_...;...2.5d]MS.n.c.........7....]M?..L....r.L..WE__......lO.U.g..23...$.....8$.....L.w.c..I.k]_.]..Z=|i.7.1g4........../...S%.....0.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):5568
                                                        Entropy (8bit):7.667268262882377
                                                        Encrypted:false
                                                        SSDEEP:96:xu2fti99Hc+io0UAGBLF2n9bpdieFI7aMKEPBPKO8/uJwGNX3zk:Y9OnjEuLo74EpP1ASw8g
                                                        MD5:65C89133F368BD56B2BA231669FDAD98
                                                        SHA1:15F7FF68D192970D2DB42BC8A661620D12E44AF5
                                                        SHA-256:A801DC238959FF925A70FBF4BF655514B8E2C811FFB38846C605B9C2337BFF8A
                                                        SHA-512:151CEF552E6E8947F5B008C721BA489C6EF8B2E27E16EC6BBD42E2F890BE1D7C5BD29432F3DA4AD470E3D81AB5B3B61EE3A94D29F3EE380580466EB67CEB5403
                                                        Malicious:false
                                                        Preview:jN7.s7W..?4r.Q.z.g..Z....=..\..`../umVJ:.....a4.G.R4Q... Ph@%.....4.. S;B.2.?N..4.m.B?....a....Z.3.,'....bp6.J.e..l.E~n...RJ.`..-qhA...4+...K_P......&.8..i...Z].:6.A.d......;.}.l..0.....F.V.b.....L.....[.{....b..$B..o...... .h.%.....4..5SsB.2.?R..a.*..?....m....Z.3.,'....bx6.J..$..U.,~4.Y..J.`..J-.hd...P+..K.P......9."..iD..Z..k6.A.d.... .J.,.2V3.c :.#.......".p...A|...b.e.s&..Qp.......8... .hQ%.....4..1S B.2.?h..o. .M?....J...CZ.3.,<...b,6.J.p.....2~n...UJ.`...-Fh{...Z+..K.P..... ....if.bZi..6.A.d....B.,.b.~..C0.g..)N..2.f.R..&......[M..=...\....I%7..... .h[%.....4..#S=B.2.?G..`.,..?.........Z.3.,:...b.6.J.{..].q~0.Y..J.`..-Jhe...N+..K.P.....'."..i..VZm..6.A.d....O.0.s....zd..Z..y.......1......!1X|g..+..t.5..E..E... .hL%.....4...S!B.2.?...h.<..?....-....Z.3.,;....bv6.J..g..W.v~1...)J.`..O-.h8.P..+..K{P.....7....i...Z..l6.A.d....^.*...D.{Xp.03z.F..Ws0.3.@.Y..A,.....~g%..}.MR..}..z.. .hY%..Q..4.. S*B.2.?G..{.o..?...7....Z.3.,=....b.6.J..4...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):9264
                                                        Entropy (8bit):7.684079770039302
                                                        Encrypted:false
                                                        SSDEEP:192:vfr7CkTDI10GlbfAdbn8CWIX4q1Z5xsiPhIyWw/Y2:vThIdlbfAdjGS15lmyvH
                                                        MD5:C4FC48B1236A53B1FC0A4A5070A2155C
                                                        SHA1:AE7CA2BC31BFE87D6CA403B89772056A1BA7F669
                                                        SHA-256:0E0D30F1AFCF6A5373304CDC306FCFBCB72AB29B48FD6A9DDE4AADC75F57FFD5
                                                        SHA-512:161DBEA6C2883ABCBC844D7E6C3FC496FD4CD7A990BBBEDDAAF66CB1C6ED7386BB9B5BB1EEBA0EE99C2FD56480BD5F75E342C224DEDBB56213295E6F5C50AA46
                                                        Malicious:false
                                                        Preview:o/...@.k...r...L..0.;...".....Y.m...4...X.Q{..J...I..N.p.......&...>X=J...j.....GK5w....m6...;.&[5t.T}..W.A.X...=N.......JUU.smv8.....'[.(z|....>.rT...+.0/:1..G`.._.5c.._e..@.@.{.:....-ekc=...}.?..........z.@_6...A..^....".D...."...<X(J...j....G.50.S..mu...v.*[8t.T}..W.A.X...=........U..5m&8....Z.)[.(+|.....6T..+.02:q...`..Q_.8c..ueu....G..m.a.;..+...R...]N.$Iq ....8........pk5.."...).P.....>...)X,J...j....G.5:....m.......[.t.Tf..W.A.XP..=[.......KUR..my8...E.+[.(+|...1.@T...+.0x:S...s`.._..sc...e.._...."9.....x.SUlF.j.t.._..]c..Q.../.9...[w$.L....^.....%...'X>J...j.....G.56.[..m)...n.7[3t.T`..W.A.Xi..=P.......U..?mw8...[.+[.(+|...H.aT...+.0):0...w`.3_.:c...e..N.....Nc..A...K......L}VauZ.F...=1....*....`......%.G.....%...vX.J...j...G.5&.U..mc...h.6[)t.Ta..W.A.X...=L.......[U..8m*8......t[.(o|....x.bT...+.0f:7...`..[_..jc...e..B.>.x..L..'UW.."...i..M%-96.....p.p.d....ua..... ..l.T.....j... X=J...j.....G.5u.X..mg...n.1[>t.Tg..W.A.X...=....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):6094176
                                                        Entropy (8bit):7.961426920726547
                                                        Encrypted:false
                                                        SSDEEP:98304:fmKmu6bMinL52bUxga8FJqOci9ClUKDo4RY4qiTFwSz5Ilr5wdKp0/zZ/a9FZ458:su6QicFJqr1uWYkhwSFIlr5wApgzZ/a9
                                                        MD5:8550DC33AC27A79DF28B11922CF289B8
                                                        SHA1:E045047AB8E02AB3C5DCB5A037F2A02617E3186E
                                                        SHA-256:A24E3B11AA9729A882BFCC897713F8D682154B800A0968EAC70CD3383EF080C2
                                                        SHA-512:A8DDAFFF818E12A8CF0C54E71D3BA1D8982D38821A0A10CE9CA15E826F76DC64C956BBB272678D265A4C59994BD12459FAAC80C882E666F1949F4A5FE17AEB30
                                                        Malicious:false
                                                        Preview:0(..pf..........b........" ..w..,.=...........a.]%g.m.Dg.FWi...m.....#+.O..;...iD;..Mc.^=n..h.....8...+..}Bw..1.YL.....c...#...WZA.R..,.Q.._V..S......m..".R..#.F...X..>....;=.-...S..r.]B..C+.c.Q....p..B..).E..)...$.}.m)$.......d..2!..6..Ng.0.(t.P`..TV,.<^..b/..{N......=>...`&zd.4d.......~.....D...;.)..2. D>LS."<...bU6..../0.p.......I..0...4>Q...[.7......k`.z......:.....Tc...e.pY...u. j%L0.'.J.f.U.2!.hL..Og.0.h,.I`...iD;..Mc.^=n..h....=.2.?..}Bw..1..M...M.L..7...`.:..).#k|-7..0........=R.<..L.....3.[.......-....><Y._}...^...d.0`...r...M>..<...|.jq7../.h..)D..qFWiY6.m...,.#.._..+....iD+..Mc.^=n..hN\....8.....ZwBw..1.qM.....mG......_..:.71..{|-7z.0........=P.<..w......>.[.....=.-.......[.............#..,v.+....V......RfRVH....L.-.F.l..y...&>.#..O..;....iD;..MM.;E...hp(...8..S...yBw..1.qM....m.......z...:....#kW-7.0.c.....=P.<..M.B....../.......-.u...t.#..%....C...I....W+(..."..2....35B...$m<....3FT.$..m...<.#..O..;.Z...6X..M..^=n..h.........+..}Bw..1.1M..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):4041
                                                        Entropy (8bit):7.918608316624965
                                                        Encrypted:false
                                                        SSDEEP:96:Q8YATBe8LwJqks0hd5tf37yQj/xb5rt6U9Y1CXUFniL/Y:dRB52qkVFt/G4/xj6/UUFSY
                                                        MD5:433085CB52A26B54B5F69D9674C34B47
                                                        SHA1:0E10926D50AEC93A18B7BAA5AE7CC71DE7ED92A3
                                                        SHA-256:7A881C638186B18794082772A19BA2CEBB9DF7B8E782238EF7A621FDD5D7901E
                                                        SHA-512:57CE9292115BD64D57E9EF4959DAC7A583B2226AFB3908C853BCC0DE626E188D745A147E4107E991D353C8FA7B70300075E33CEB9446331A2FA62D2B9D0446F9
                                                        Malicious:false
                                                        Preview:......t..2..l:*.Kz...!\...R.Y.`.U.. a.h..!.....7.._xO..6...d.S.0..o}..z..l...v.8/QeTE.j..J1.Zp4(.Y.UW.2....~Z......p.b.,.f.O.........F..@oe......^....E.i}...]wi.u't....dZ,.Xr..~pf./.W3.m...zP......`...:`Q...!C?.K..'0}x....w.H.<..Acq..k...4...%.~n.7.K.xZ.v:..1ex.}.....m......L..G..aN(...o.G...........Jg`.*....B.F.....bt...;I_.A.W....uW5.rr.RH....u..J..G..PS.t...6E...ml..........c....f.....T....o...~1..1..v...|.}?.!...>_./x.[(-%.9..UU./....[Y...F.vO?.>. .L.M...........mg.m.%..F.]...../|...}!i.`l1....bZ(.eu{..5VSNx.-4q.....[J..C............QY...$i(.ZD......~.../..G?!.4..,...1.:z.#Y].9W./~..8PA.;.....8....,9f..[..aZ=.>.o.A.O.......R...FN.8.\...P....}l...wcv.:l2....9.u..=W16.H...*...P..FD9...O.....t.%..&DW..KW......|?Uf.....~.S..|...nc.....j...~..(fl...h...K..6m..9..F@.8....`.N.=..6.{.}@l.A..........O...#N.N.*..o....w.-8....y{l.N:t...uS9.BM.D..o_s..m:...:...x.j*.\.u......4....F.CH..Q.x...f...0.v' ..7...j...e.n/V-<..:J.4l.Juf..h..Y../....fU...U
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2439
                                                        Entropy (8bit):7.902821547034773
                                                        Encrypted:false
                                                        SSDEEP:48:k7Gv85qKPdbI7B1OZUaOEqzI2J1f2NtotvfZgxP+ax0ErqXYWsCpA/wIyIP:kw85XPdbI7B88vb9vxkxmqqEC+FZ
                                                        MD5:3E6A0AB45A13F6D977C78059E2206E11
                                                        SHA1:97D9C5B72AE37B1F1A6772DA1DC2606950571541
                                                        SHA-256:1651762C0F90620CFE261E4E54D2355CC29371A5D6A41182FF483F8EBD5F2DD6
                                                        SHA-512:E4CF64F9DA8E74AF488643D73BC8FA7E4A18D8F9B7EDB416BC865B2CEE18DD950CB2812F3926A83AE8F8D2CCE3A4A446EA3432E350B0B55E499ED8E507C57FE5
                                                        Malicious:false
                                                        Preview:....o.)@.'.=.d.!.~..\6b).:..}7._CQ..........&(mA...?..z{.f..<.b...<rh...._....x..$.@Ou0.s._.......{w.U...`_s..`[.P...]...&....%.9}.mU...}...%...CA..?>nU......>.............t.../..-v?..w.F2....va.n.Q.lN...=.b-.dp..Qn....db.v..F{..(.q...0y...XE..../W.g...di.h.I......i-.U...6.(N.b..6.......3..Mm2..}.l....h...1.C.X...73a].]....)........7....e....]^....'.\..{.J.L>ED..MF..Q..t......~.\.)q\Fo..Fd..`.$..F.c>u..H.T...s/.+..P"&.=..K....cy.....d[w..+j.]..]...3.[~-C,~.<E.j./...&.@.^.;.vp6[.M....{.............W...X.I..Q...tk....3...}:./.r%...+:..........o.P.i2...=..3.}...=_:..._...Q'^.r._Mf6.3.>V.....KX.....7.:..#H.N.......9.../.+.V.X=.B. ...c...XMB.%.~_................S....+...:...Fd.Ms[B..x.F....uY.O..#....'1Jb!.....@..s.e..p<..3.g....0y8...._...zH./...e7....M.....hm.c...dD4:.6J.Y.......2.V`5V.i.j..N.j...&...I[f.5$.H.......u.......3....c...;...b.FE.#...H.s}.n|..5..m.-Q.[........yL.....0s..U+..>./...6q{..J.C..:c..+..+r!....Z...cj.c...dD4:.6J.Y..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1901
                                                        Entropy (8bit):7.883834147676109
                                                        Encrypted:false
                                                        SSDEEP:48:lJHZ+xkTV0tbuu7mLXHhaO6swVz7GTOdxFbITKCbGc:lJ5+EVMbuu7mjH8O6sGhxFbITL
                                                        MD5:2DB164BCAA4E83795A73C75AB179A848
                                                        SHA1:A5EAB06C2D52CAEF00B2B686BFC03B2D3598C37C
                                                        SHA-256:B31AF88927F1F15ADCB48CD3304CBA70666A6689196B59BBCB9F6BF407320683
                                                        SHA-512:57440E590064634B8798F923823B8B49DC951D5C7274E5129B37DE0D4CAB501AFBEEEF82247FA921067F9DF0B2B4386313FACBCBE620451F240142756550C96E
                                                        Malicious:false
                                                        Preview:.0...]......c.j..l..'...w.....F..d...j.^.%........|......E$%7D...y...E..N.D......>c.W..h.?.i.s.H.......<....Q?..fF-....P...............F_.....9.....z.k...sp..5..=R5....[.....vw..+...S.`..?..e1.,....c....&.!..j.g....e..B....f...7ii+A...~..............1w.*5.C.%......O...l.#_....'..!A*...J...j.R.........[..[.J.$....;...X.ut..$..#.y....M.._..vf....k.OQ.P.:..B.6.....q...H..D..&..?68.k5vK.O......('s....u..............&m..[.A.~.#.^..V....j..$.....\..d.*........E..N........A..7.N.r....!.<.R.su..#..$Y ..[.......r2...2..%1.....N> H.D....zX.4..b..uM..mV.+Y....J!.[..o 'pF...O..............>&.4....b.?.^.......l...9....S4.."A+.....................F......Z.....!.<.T.+$..>..(h.....a.....t...x.~.E'W8..d_.{.0T\.t....(.nk......*;33u.....|!=.\'(pW...t...............3a.Z..\.i.h.t......v...4B.9.S0...c<.....B...#..C.........0...L.p......h...T.:&..3..?R4..........)=..M..h...AwE0...]xP..h..^`...O.fj..g.Z.Z.....? ....S.w.8.F.c........Y.......e..$.O.b.h....N....v...?....I8..x.*..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:OpenPGP Secret Key
                                                        Category:dropped
                                                        Size (bytes):1886
                                                        Entropy (8bit):7.870610934259844
                                                        Encrypted:false
                                                        SSDEEP:48:70MP86lxzlTT/5NS2J1Dfu2v6CTR8NlODLeNQlameFBB:gMP8udRT/5ECu2v6SqODLenmkB
                                                        MD5:0CA465A19F9DD6E6ED847732C3957DE1
                                                        SHA1:7A874D6F5BD76F18465630190B984391735A44B8
                                                        SHA-256:57A754BC6140D21A00502A25692AF6FCFCD07471516624799397E589A847BB84
                                                        SHA-512:A86FEC9E02C2040670024C1FB6A20E6F5CE670E1080E2B315EDC13535EBCECE06B0B99579215B0798A8FCD3389032A2B7241B1D4CDEB3A90AA80DDA314500320
                                                        Malicious:false
                                                        Preview:.......|DS.......-."W.~..~.?......q....)...,..(\.......=u'..),1...7.;j.DY...*..M.5C...F...Jn.....w...6.j4Y..qI...8..q-...p.......d....T..4..-A....j..dq..'1z...J...H..C`'...j.-..yqg.3.......pK..d.~.........W.t.F... ..ck....qi"...$....W.x{.US...>M.V......;.[..l.......2...z.pm...9...."..*M...!.......y......b/...f.....bu..6.m0..w...^..B/"...l..7.....m7..[.........x^T|.!"ZvN.zH............?1q..%,,...j.b`.U....$E.8..N]..k.F.Ni.......`...d..)[_.qK...k..)b..Zz.....2.c......4d......&..dtT.1.p7...}.....D};...p.K.1.B.. t`To.0.$.........w/t.",....XB.Qd)u....o...?2%....>....b.x}.WB...o..|._NA..g.F........{...5.|z[..w....9.{"..Q=.....Z.c.......P.RfA..5..e:J.#.c9..n...L..Q|9.;.t..R.1.....4E2....tU."..#.......N.....z././.c..J....?46...%'6....'.tz..R....C.7...M...F....o.....v.D.;.xn.<!`]..........G~.......2...[.dz..7]..'..b+H.+.v+..P\..C..Ff6...%..QC.@.~..IC...l.lJ.e.P..>..S.@;...y_.p.K.._p,....?2o..`.,....`.rkX.e....r.k., E...u.L..i......=...3.~7viL%.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):15159
                                                        Entropy (8bit):7.905882010530551
                                                        Encrypted:false
                                                        SSDEEP:384:1zu4PWJO5NoOEiVWuQtDt9l/qPuSS2t/lKG+KVAYchi:QF1iVWuQtLqPuSnJlABhi
                                                        MD5:F23B2B706CBD2138D136BAB15B6537AA
                                                        SHA1:55B4B9D661B8958C8B19DD504032A20815D2E8C2
                                                        SHA-256:BED214D1EE2AA6DB12A90A42788FE7B826313C8FB40E602B4C17DCC7B36672E4
                                                        SHA-512:E55365C83C3DC222189159D5AA3C4C69495A159144634E091BD8A1B3F5F42143323304EBAAF79BE43689412D66604BC772C263D43F8340B7E0BB1AA08A67056C
                                                        Malicious:false
                                                        Preview:s+....x.wVB>.F@..<..D|.]...`l....}....C.....\..4.Z.O.[H.p...o3.Ys.....k......>./.H u..1b.......(.3..DU$...jf..=........cE(....t.E.......oM.......V....wA.V...?YF...L..i].j.\p.i...._9.M.....hlX..:.F[......$r.N....V...%.-...[...m.._y....-......3Sw..2q..+<..X.Y.. .y....4..}]Im.iL..$......@"aX..2.W........r_..M@S..........V..H%[P....,C]{f_..6..e.wi1zW9.PV.;4...;+.?pd8`.Y.d=..w.G.a0%.-G...>...~y.Rx.....}.......3.s.Ymr.. e...U..N.a..D.i..P%%..tN..]......m.aX....w........-.X...t.......h.{9.Tq......Q.a.@....k....=m..@K...m.......4...BU...(....O..a..5'.d....y...n+.x|..i.....WpEv.N7a..g4..H.1..7.3....^"...$'..9...>.....m.aX....}.V.....s...V.-.........VP...6_B...^.g7.R.hI.b.k.q.v...{.b..5.....'.(..."..I.....9..^u.0E0.C...i5.Sn....i.....W5.g.K5...g........../....k.. ?+............#L-.....a........ .A..SE.[....FJH>.Tq........,C]1.q&...EX.b.$W..Q+...|.l......0y...z~OD.-..!..%.1.......l5.Dx....i......I]o2..t3..3}..U.AH.c.a....B9.......<
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2112
                                                        Entropy (8bit):7.87702554146037
                                                        Encrypted:false
                                                        SSDEEP:48:Qnvg3jA5Z0BnFwqTS3G6oY7NgktwqC+QVSK:Qn43yEFk3/oYBt4VSK
                                                        MD5:20E27081C4CFB14C6F7B01D214984878
                                                        SHA1:29B4138F598E3F20FE9C2E5BE6253D2DD4CA3A0B
                                                        SHA-256:31CCEB5F17F792E38C6B7349B18A9A666F2270D0BF5FD25890C7119E7B81CA4F
                                                        SHA-512:02E6EAF7246BEDE372D8CFD5625981AFE876E95395B11C00C8976BCD3CE422A3C1768F6C68B2AE95D40DFA8E7063BA3047CB85D96DCC667C30B9487636B77106
                                                        Malicious:false
                                                        Preview: .l9......Y<|....u.;..^e+l.M/...g.c...!..m..[.!.~n..`.KD........h....K.S..ey2:...O4._.^c.aC.....0..kh..."...4.b.+.....Aqbu=.C.|;.._......T..'.......l....z..@.<M*...&..6.%...5.N...wN@..(HSJcw#Q.#.*.,~n..q....q.Jt...oC4...$vIvq.W.]R..s..@...^..").0...@h.-.8>.*..l...1..eR...J..N_z.,.1......?#/z.t.7!NO].....EF.i....D..6...<...C.;{n...=..2.z.,.`......N..b....E.....}uo.O.F..Oa.`y..=q...!..%./.......@L..?..BMV..Z.srq:...Ig.o.87.6..u....b..nOE..3....d.U.c..@V..kozx.F.pb@Qn......D..q.......-....z...@.>6r..o.Si...e.'.D...K.9...-...^...Y.0_...>.D.j.b..........y3.2.....BYE......u...T.....sr2 ...Q).o.l'.$..j...*..,L.."....).p.7...B.c.!=x...&$..JG......X.`....D..&..0U..L.,z;...<..!...../.....{..x..$c........V..k..^..yyb=.EX...*{.H]....c...[.......h.......R.g)\_R.C.5.~.q .c..8......yO...5..._5.+.,..@...phs?...XvBO.[.....PF.l...Z.."....6..\.u(>...:.S:.W.m.%.....p..n]..M[^.wY.zO.^d...~...b...p.d....^..neo........R...h...7p.C..<d%'....`.7.!l....k....-..yNU..&....z.-.3...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:PGP Secret Sub-key -
                                                        Category:dropped
                                                        Size (bytes):15660
                                                        Entropy (8bit):7.892284467777724
                                                        Encrypted:false
                                                        SSDEEP:384:+nja3MyKlvGzF3b+l1hsa1XLv/ualpWrlsVSgj/7Ual9lcJfQlebzOl20yll4FE9:i8KG+eaGa+reVSgj/JfyhQ0e+/4FMye
                                                        MD5:4A15D43A8201F112155D9F978F01C5B8
                                                        SHA1:15A98B692EC985A2440B71014C3C889D70774A96
                                                        SHA-256:6FF38FE220181BB7A590FE251BEBE5B73878A329737B7DE43A370A767646E96A
                                                        SHA-512:E1F40231018DFC94CA8AD36F5B71305EB45A068752F65F5747BA283B6A59D7190CF487DE6DA3737DDC0D53E4BF88A084FEADB314BE3060953B74AB0B11B7A185
                                                        Malicious:false
                                                        Preview:........h.o....{...A.3...........%.....V..?x.(.x..<+...CN.n..WK.....'.<BA..Dp1d.nqo...\..yJ...l....@...K.....+h"L.W.... Z.....Z.z%.0..wY....HI..L.Y.W....g......d%m..LS....0w.2...........,|d.&.Z-.u..jU...u.. M.mv.7sB.?Dv[..AS.m..MAC..].|.nHZ..Up;>..)" .i....r...@O]...UC.@.....&&9........m.P....OCYL.}.>.....W6....m.[.......K...d>.....Z..nXb...!...........=-...G.N.R.3..*..r.6.W...:v/n5T.IL[.:...A...../.y.NW.A4oa...y/s.k.P..eL....F.......@.......!w5.......~.].F..f_t4.,..lR..........._.....l...V..dz........<0`.Z..(.;.\D.WW...p...)....`Ob.....V...V0m.y..M.N.d..JM.....7..HA].Pk6m..or7.s....{3..T.D.@S.M.......t*hQ.L.....m.L.\...]tf.}.zR.........Q.P.....?...U..d>.LNS.Z..s................@.[..|..2.iW.a.[P_.,.;........7.._.N.+..KJ...S.E.mRF..M|1w...~*`...o.e...T.D.@S.M........1{dQ.Z......V.....Q.:2.}..#.....ZY..C......."...K...d>.LNS.[....+..1.R.g`.1....yx.T*P.........8..'....;..V.T\j. k..b..wJ...Z.t.CdC..S^*j...$.H.}.B.e...T.D.@S.M........-7
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):125
                                                        Entropy (8bit):6.595666984610175
                                                        Encrypted:false
                                                        SSDEEP:3:w8j/JKrocvqffuGGFej9RaFIe7RnbngyXiWzEPHCo5K58S5P2T:wy/I/RFeTaJ7NgE/EPHCoPS5PE
                                                        MD5:60612C3E30BE813F33B29D298107BE49
                                                        SHA1:F77DCB950A77990B451A6B311E981C9756653A2B
                                                        SHA-256:3B9D8F1061A90CFE2C7905BB96F5CD8B71A662CF21DF096578778BB7C72FEE6A
                                                        SHA-512:EA889E1036E0B36C7FA79B70030C787B123FBE8BD53496B6F7F4FC7D8A0741D01C127DA31CE528ED419AC6FDB8334CE9563A5DC26DA5E546278D7404402938E1
                                                        Malicious:false
                                                        Preview:..@e.(.Q.1......,.......Ev....ax...h....v#Y.i.\.Q.|.x.#.t:.`......@~...WrG......T.H..@V.bc.....u....aI}.7\z...My-...A.-2T.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):207785
                                                        Entropy (8bit):7.9691566739576745
                                                        Encrypted:false
                                                        SSDEEP:6144:o+t5oUupbaUHcCQRJQUaiFE+qOaO/bDqNcE6bqm2OZrlQjE9:jt5oZGUHcCQRJOuE+qWbDqCZbp7Zrijw
                                                        MD5:3325579E17B31B1EE8DCA52462E615CC
                                                        SHA1:D7D9C8709E52EE81946281B7686D9ADD58C926D3
                                                        SHA-256:F956E91260D16E55E59CD464CC45E5E1CACD99C23AD3420E431C39F61C7F35A4
                                                        SHA-512:329BEA88C716F277DACBF6AD80096A826318A4DC7AA946F477E6208206585F64528F6D9166C04589537E1C6400FE0E6E131CA969ECE509A29A2852189FF61171
                                                        Malicious:false
                                                        Preview:.n.*.v.J.{......@.........@2Y".0..'........%.... zl>......Cj.T2.....'kDTE....&......Lx.1N.{..#....V+.....!!{..Yf[n.F.....8..._....A.\...|.'..H.=X..X.!s...t#.#l.m.C.*2..S.....J_.jB.F..l....P....n...cD.b..cE.n.1!..*.W..m...]o......^.G-...#.1~]MG..1.p......X.&N..U=. ....V+.v..=+f..|Qt.....s.1..Y....YCX...~.l3.U.>d..M.+'....b..lI.m.v..-.u......z..J&.E...Q......e.,L.W..SU..$...j.H*.C.....&_...C|.I8..9.&pGN...$.s..O...Gf..L..U).4....O9.4..<(k..qju.\...T.7..OO...@]n....f.e2.].>.L\..b?....h...O.I.k..*..i.....OB?.w?....CV9<.'...o.U....S[....`<...._.=...........fc.e1....#lDuB..?.l..O..lm.&I..x<.o....Jr.=...&(|...xNv.}.....a....,...F@m...e.f ...3T....!o....I,.#V.0.`..0.U.M...BS(.8].......I.6W.l.bQ.....r:9E..:hd.,7...WN!.....1..r...3.-l_[_..9.q..]...Ly.k...N:.o....X0.b..z.j..pJh.....@.&..YC......F....x.o#.k.5U.._..i....bN.mT...`....Q.M....OBw.r.Nh../0...O.....^...9ZQ.B....j....&..h...........^.G-...#.1~]MG..1.p......X.&N..U=. ....V+.v..=cK../}u.A
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):193
                                                        Entropy (8bit):6.882308591537697
                                                        Encrypted:false
                                                        SSDEEP:3:7mA5siXYfrImUNm6VHUUGvST9wZXlxEuu3rA8ORM4um7BaQz5svDZKJ4vHVDE:B5saYfrIHNm68a9K1oL6umNqvDQJixE
                                                        MD5:EF303B1714D021C82E6CA43F8F8CED1D
                                                        SHA1:671B8104AF0D2626BDD3968EDF55FAC6C0D5914A
                                                        SHA-256:9E51F466CFB26998B57BD2EBCBFF0F87504DD0D790F8B4A36CA67BB12370470C
                                                        SHA-512:08EA9743BBC0A47F3DBE454328DE28CDC8E2E9432A8119E9332599855E56570A19B7C815F667F71827452230B5E8FA4B06AC035E9B7468D755BD1C8235E72A46
                                                        Malicious:false
                                                        Preview:V.f.7OH...T..=Q..a....Y^.0k.z..].(..d.J7...rt.T....w.J...V...1X.f..Q..,..OQQ...>..n.sGT..h.N^AM.@..N..y~8kk......5......?.M@.S.+.Ku.*@p..EI.HHz)h....R&..J...?,.ZR..f..Zuy].....xD.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):193
                                                        Entropy (8bit):7.004120897259597
                                                        Encrypted:false
                                                        SSDEEP:3:YsXm2Z7+NIfHQSXBhxWBdCe2Nrm6jwFC1MLjJ1hv4rw/nAShbOWps/CGR/osWvVA:Y2vVBhYd0Nr/WJ/TbzyZHWvVFcnuwbd
                                                        MD5:402522D2B841A77AA5C584A536E542B6
                                                        SHA1:05D335461B356010017827C6203CBA703B0D78DD
                                                        SHA-256:665267771C35BDFC0EC49345F2CC1C287D7EB9CE935D43FEBFF62B746703B740
                                                        SHA-512:ABE40880F9F129A98FD89946662747FD8AA6364FBD62C56EA6CD2164E4FEA91A9EC99425F2176AF3AC2768885CBEC830C9123165276D328DFA40703F61A45207
                                                        Malicious:false
                                                        Preview:...a..w_2.....Cq.|....+........%.....=...rd,.|....^SY.L..Pfm_....;..........uU..N..n.l.*.......g]N.5...../.%.!.....G..J6...lkI.......v..Z.sxH..s.pqVL...u/...:u.'%....x_...,.B".?/{8
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):193
                                                        Entropy (8bit):6.912879236770291
                                                        Encrypted:false
                                                        SSDEEP:6:izV0AH5oUG3mNL/rqLfyV8txM3W5Xef8Mn:k5VG3m9VeM38xMn
                                                        MD5:A9D59844645BA6B1D97FF45B1659AB50
                                                        SHA1:9FE0D2076CF5EECB67F09EFAFCFF57C31FA5CB2A
                                                        SHA-256:0AEF2E1C9ECD7271A2F5FC36FD9BD7D957F3439A858953C332F2E80A52BC09BC
                                                        SHA-512:EF2FD07416A745057072E19D5C3D8D1B872FFFAAAD224E11D657E2F2C96A787C41095FA6825F17A7AAAF3D5939BB6064CBB7161F46B1ABFD63D7252CA1EC41D2
                                                        Malicious:false
                                                        Preview:T..J.C.B..T..2..Ac.*..N.z.........O\......~X...\ ..4=..Ar....1H.n|.q..W.w.,...B..4.h.O}.%.i.&f.n{..[...7.4........4.].?Y.....ML\V....q.Fb...N.&{......]M.[.......T......:}F4.#.5..K.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):193
                                                        Entropy (8bit):6.953678734080791
                                                        Encrypted:false
                                                        SSDEEP:6:BuUrEgyE1vVP0LW1iinohvK7i+tA0yth2JtgwjVP7:BuUzRZX1fnohSm+tAp2Jt1hz
                                                        MD5:48B454D98EE469696E28300E2F7E7FD5
                                                        SHA1:1DFA8DD48A100A03FB697E99943919CFF2DB4BA7
                                                        SHA-256:B07F5C67FC64D8EBB9D9BC7C4EEE22503924712C0A67226E637ACF8F839744FA
                                                        SHA-512:AF9B564B14BF3037FFFBE12362C2AB33A76C4BC1BBDC6D3898B5994F53DE5FD4D4A376D8D0489BBD6DD2FD2264FAA45F0A1E2E6549106EDD816304F4699C6A88
                                                        Malicious:false
                                                        Preview:.\J.P......b%......."...B..7....h..F..w............e..S...'6..<........l...l..~q3.D.z.....H....dD...|.P..G}..<6"*. .JLecM?.hE..2..%..X(....nt....L.....b.A.M.....US..h...........@.. V
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):193
                                                        Entropy (8bit):7.004974767914417
                                                        Encrypted:false
                                                        SSDEEP:6:b8ccs70wwsx7RnTf7pRiAwOUf3MvQCjJTCDf:Q20jsNRTTSnOm8IC10f
                                                        MD5:CE0C4ACDA1B2F4CF96542A8CE44CB29F
                                                        SHA1:322EA40E6FECEF4BD1C5BAAABDAAD5773251BDF7
                                                        SHA-256:3E9B0E94E40DE1577181CE51A43BD035810CD256E11A76BBD5009BD1E4C82B3B
                                                        SHA-512:593B2E0CD982D3D23D8BF6BAB6D54CB5DD7E3F7D94C14638B9B1583AEF06EE4A3F8519A42264BB1A83971CFA1A0064114495225B1FFCEADC7D2B904AE2194459
                                                        Malicious:false
                                                        Preview:.2>.;E...Y....\.L;....hq.g/.8...+._>fU..J.6..,TXY...`.C..m....K.&Om..c..j..}.:...L....k:.v ..lyFY..w.. ....x..........3._U.,O.i......ZufuMl.A............H.j.uiT.b.~......d..O.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):193
                                                        Entropy (8bit):6.962670120057523
                                                        Encrypted:false
                                                        SSDEEP:6:3E8REtfOT0MYj6Jk6T8nNYjhfYl8tQlysUem+lQS:bEfOwdWBT8nYxYl8twyeDz
                                                        MD5:B784BA4154BC8F847B551A4425F9B867
                                                        SHA1:47E9C0941EC5DCAC7F6A922753923656886D9DFA
                                                        SHA-256:F7F12AA331148F4858AEDF77DB09D06778C47EC92F39C192D41D471375800562
                                                        SHA-512:485E732E5BF6B01EF3C9A0E8E7ACAF6C0E79C2116064982B3BC0B6728511829A655F956233BE1C371CFED875A8A1F138F48B5A1003CF7E8715959F7CA5DE8500
                                                        Malicious:false
                                                        Preview:Q..a.._...............!2.:kpD.{2...k.e........#......;3GZ.}..p.`\N...y...,...Y]..}..{.... ..B.......Hi...i......D%....\G.........5....$o...5WdmM/s.8.....}......m...gO....2.5~...Y.xG
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):129
                                                        Entropy (8bit):6.668090336768278
                                                        Encrypted:false
                                                        SSDEEP:3:oJxaB0Zxg6FkFHG783Sw5QIQYshosHbyevw1xgISNpkNoQc:os0jg6FkFI8iwEYshxHba4soQc
                                                        MD5:E2FAE6B93EC00FF91F67322E7A82C24E
                                                        SHA1:EB3BF500834F2D28475D6870F10A2D954D569DE6
                                                        SHA-256:BA4C0D9E2B66CDAF1D69640BA3E664D4944190C410AFA06674D2A8F6956C9B02
                                                        SHA-512:135A72953649A997DD571EDF434FD0ADFD7E99A763167740A29FB5E10215BC093FDC75A76C210CB3CA0A6F1B4CD2B60B0EE15DF28847D026FE3A19798FFCB0B9
                                                        Malicious:false
                                                        Preview:.f"..Do..~....7h......S%. "pIb.6..7.5...!.[...:....U.n..Q.M...?......H.W)D.......ac.yE.......=#.......@..{p.|c....hU...h....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2667534
                                                        Entropy (8bit):7.9747871510122454
                                                        Encrypted:false
                                                        SSDEEP:24576:r0yPgnPYKICwqQcQmWI3vZSjLbbfGLZne+olq7DCYChKhMw:enPYgw5cQhKZSjLbLGLm/Kh/
                                                        MD5:3BF5A2BAB86483CD8A0AEA0AEB220B99
                                                        SHA1:548D0203F697C481D26EDA865796A870CB331AE9
                                                        SHA-256:B976D268A7E6B38282FD4BCA8E51625795ED69EC33FE0E94C3DC0CCE21922A5A
                                                        SHA-512:8B41E5992BAF26801230A6F7C25AF20226F67A2B24AA73179C77D096E2FAF509E5A6CF31640835F9098CBA743A41BB85A38BE8108C2298755C0E614626EA51B9
                                                        Malicious:false
                                                        Preview:..odWM.n..%2J...MGC........m.4.dI.s.#....9.ZI..X......../1...0.6|?.<..]O.F...X..?.Fx.:...,..3_7.=_.T........P].0.+.....N..;|7..b.....v..,...(.m..8w.....#.q.Y..].Ca..%3....cY..;;..O2..X..ra....{L*iv\.....fce.......p!.Bi6(..%v.....71..OU.co4.'...@.G.K.....2..k./...y..tX&.'Q......@4..)/.Z.$.....WS..mr9L.o.......*...:.l..I.Q[.J.d.H.E...MQl..+=....<Y..&..P..".......;L.t`..-...URH.~3.......}Y0...^`..Z...-k..>$.61r.)...~..C].....Q..-.w...7..3.c.eM.\....M<..?7.k.8.....AN..!9h..W...Q....b.Z.~.u..Ot"].N.-...\..M..2W.+d....$...O~...$.l...Sk.!..g..$..8..|........w.ML.[....L.....@..6f..R...*l.t.|o.i...Y.. ../....l..(...k..E....b..?n.e.r.......J..*s..!...I.0..+.?........ZQ.K.!.q..F.~V.>".%3....cY...~.D6.89D.....fE..j.)..>.*:_s.....|x.....?...'.b..|~....v|u.g....[...G...?.fX.7...a..!.b..p.........19.|.<...Y... .9..b....)..0.P.`.'...X.....Zc_.E...U.8T.5].....?:..+p.D4.U'2...C..P..-!..l.&....`.q.+....R..n...21..GT.v%'.c...I.X...K..`.Fs.a..>..xB5.fc.p...[b.#%.H.`...
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):154121
                                                        Entropy (8bit):7.983780172678479
                                                        Encrypted:false
                                                        SSDEEP:3072:s9aSD8AIMhwIzzlIzflGnB2zEMzmi6/HDrvZQ:sHI5jWczEMzmfjzq
                                                        MD5:1BD6ABDD3F5E2C165F27F57817FBF745
                                                        SHA1:9CDE15581F3B9F04048125F2546F6F6113CECBF1
                                                        SHA-256:6A866D16C536DAA2E214F98D99EA066B69F1CE8E65E61E369EADCC131FC05EC7
                                                        SHA-512:61ADEF09F09C8B969CFEBEBA4BBBA84134866EB26C66410CB16CD17467E0AC8AF6FAF724BE6F40735400C03B2490E2119DDA271FBBAEC9F5CE6B7EAF1AC665FD
                                                        Malicious:false
                                                        Preview:.a..s.E,.iXm..t....S....'d.._m.....* ./1.......K'no.j..0B.<xc....#B.[.....c.Nc..!.{..m.F.........,x.D.k H....o.&.6l.P..6......STo..x.z...D..>%......X..{...Y..j.l.K..2_.......5Ov.?..b.....,.%w..h..:?I#.6...J.[.....9..........c..}/.X...U......:.^o.j..k.m...(......H.L.C.l!.T..Z........J^F4;.@...r.&1...U......w:.zd.......g.O.uj...E..SP....}..D......R..>......B..\.....i.{.x.T=...H.-.y......|..#..{,....gU.....A. ].b.>.#...(.].....\A.B.7t.U.]VF..N...U..ef.....u.q*.....\..,.s:.x4........... ....l.>.3P.......5K....b..3.L.j%...:.A..-.........B....Sr1-...X... ..(2.....g_.....Y.!..}..=Nl...{.V..DHP..@.j ._..V....I.\.J]E0:.....'.*f..T....~.q5.~4...N.]*...j.bg.b.&..(E.......1Sq...Q...}..(<..7e.rJ.'.xu.~.?.......Xt;.:...v.t#.B...e.....E.%..a..7Kn...$.P....B\....={....PB...N...L[.49.F...p.+*...P....g.v>.1e......../...=.}b.e.g..M't......J'..}....T..c.2C..{S......).`... ...|..\.K..1+.....y.`Er?...gX.......%.^i..=M9.....I....OQ..@.7!.D..6&.....'.6l
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):3803
                                                        Entropy (8bit):7.94396051076102
                                                        Encrypted:false
                                                        SSDEEP:96:pm08hyPCkWSE+9hyNrYQirKVlcVJBuiatzrApY0lujeo:pmJUPdVE+7QirK4jBD4spYpH
                                                        MD5:097E8105CD92A645F1AC5B8208E86AF6
                                                        SHA1:DF00F6DDF0A20A773250CD597B7519706B90F5BC
                                                        SHA-256:3DA8B1C1170A86871E15EEA33F2C17D90594849DA8E5B98466A2B69D94701C69
                                                        SHA-512:9D27FE3BD02E12B99ED33CB05CEC31ADCC0787FAC193FE44C852DEF010503572EFD901422C02BA4DED0E49ED9BBDB62E9F671BC81F0BEB7E91924772D06A71C8
                                                        Malicious:false
                                                        Preview:Cx....)...)........kb...J..S......C...b...a.....&..M...".'qj.Z...b.8.K....8..|b..s{...{.IE.T.J......A.N"..Kv^%.....%C...j.B...3u......(.'..J.q.Br...W...IU.m..k.5....\{)...na .1A.............._...B.nM4.6m..".......s/'...cw.%..7-S[.!...@...h....F.C.V.".[.....LPC...F...?yb.cZ..eu<.....-|...m.r."..y......-.i.H.{{..$o...[U../.o.n......4..{W..L..Q...4.uIov...+_.i'.U.x.G.=s..T..8.V.~>..yg1{.-...n]U.9...X..-g....F.m+Y.6%Z.....mnk.f.E....~.Jt..fbx+.....|."._.J...(_......q..X.3.P...q...I$....z.<....Y.....[$.......}P..h.......F.o....8....(G..)...O3.#..r.&. ..oY.1...U.%.M....X.[.$. -).....TSR.c.....(oq.e/..|.D......>.5.[...U..7r.........p.h.yO..+z..|PD..7.k.&....i....Tv*.\gC..%..E..g..(2..k..K._.].[.O....~+...*...e}...7<mV3.....v..ZS....;.y.V..oP....>pWm.B.c....6ud.Hw..QC~4......m...B...^...f......qB.5..U.k.^j...q..?Kp.n...|.2...r.g..^_...;*.M..?..!.^!O\.......;4.fP4.I.3......8...HT.P.&.q.B.1..i...n....{.v.B..2{.....Th..........ng.f,..biE....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2954840
                                                        Entropy (8bit):7.96879663415948
                                                        Encrypted:false
                                                        SSDEEP:49152:RHn+hUmO5nHZ97ZN1GHP/DXxjUx0dxDV5s+amUl4GjnYrbTDTEfhF7JnQgdwF/cW:KxMA
                                                        MD5:3A3E1212619C5CC1B250D75FA4426020
                                                        SHA1:820CBD84E6FD61E2A115F282394604419AFBE64A
                                                        SHA-256:5C74E03EDC627C1FE3D8FACF3ADD1CD6C387A464020101FFBE24C5DF09566631
                                                        SHA-512:473D70C73B7F334E896ADC10636D71BD6AB0857F203C2762B94512866A9C8FDB25990993AB804367049D63CB9ACADFC8AA8A93087793033B29506DF4ACAC84FD
                                                        Malicious:false
                                                        Preview:M..'I.......kS0E.....P...6.....%.!...@?.,.%W.m"".'..p.$.E...w..n4....m,.1....F.TF..B."A.rUx..&:4a.>....nT...N....\..7.N.T..M...K...W...RZ.Z.....<...Z.q.........Q.._N.Z.%........3.C?...u.8..Bh.S.].O.$.og,.Z.k.S/3.ka.\.tmGV^......,}.lr....5#.0.....KQ....8..1.r...-)3'..+...:e.3.<."....a...U....Z .Y..W..SK....F.B......;........o..S..X..N_.l..y.Uyr^..O....?..`.@.b.0.P.C[z..c.zP."<j~._....2...g\.ao....v<.<........P.C_r..eWm...a.$o.{...#t.p.g..r.\..a.N......{.Q.X. ...TG.U...../...Y.*.L.......+...J...T...`....S....d]...7f.%C..`.....i?.N54.N..@.@jZK$iIb.n......~.. w.....i9.7G........C.|.CDh...ytzX.6.....e./.c....P..9...\..C.-1V.L.....I^....D..S...X...i.Z.......0..!Y....C..8....:.......|...Zr....%=....)..?.(k..#.}[...).lz......oG.,s..../z.}......^K....3M.n.z....yl!l.{D...8l.p.)..$....f.9.s....n.FQ..%..SM.z..E.N...(....{........%....Y....Nn.e.]..!....n..].c.Oh.T.pL..z....#...Ym...^?...zGZc.K....,..cr....x,.}_........B9.k.a_w....yt.~.7....b4.z.E..h.R
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):113
                                                        Entropy (8bit):6.466196661530247
                                                        Encrypted:false
                                                        SSDEEP:3:g/fTg7Z6T+g+0q2eWRs1vSYqL+Uvzj/MNWZsThPQn:g/k7EJ1q2edvS5L+UrjUEZcQ
                                                        MD5:FC6BA2A4E350562E044A97F78AF2CC92
                                                        SHA1:F27201502DE805F5B615A2ECFA96418F041A3A11
                                                        SHA-256:599350E3FE8FEDB08CD3F645F1F0AC2D291D5DDC0A2518006FB966498AE3D24B
                                                        SHA-512:0E2A1C61FBD178D0D7B1A6D89CC566D33DD53D794BD3A24D5EC60375663E35CE7A0E651B5EF7119384469F6E633E437E565AFE7A9603005776999E3D71F7D711
                                                        Malicious:false
                                                        Preview: ..as.?6.p7<..._S...-.~......a~<......O...nO3t.k.6..7U..Q..q}.K.^|..81e$......:..t...s.5..v:...).Q_...1.,..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):180248
                                                        Entropy (8bit):7.802772381919405
                                                        Encrypted:false
                                                        SSDEEP:1536:YtzaWJ7h3yD9de8lsdljhwl2ycrtp835Vnrq1D8dK/aukX2HMVLU3uxPvWy1ry5l:YFaWTEkT6TG1DyKyuQ2mjwEBcQHxc
                                                        MD5:9076072ADD2A4CBC98CBA08AF6EEF92C
                                                        SHA1:C3D31F218BA26C9307E13E0246A28F325F9E85DA
                                                        SHA-256:BA115C662EB4BA42AB4194215C939093508A7746689254168BA66B7C76CD521B
                                                        SHA-512:E638B865EBED7CD62E1AEA3F6B6025DA683E06890C7F322D86008B80B6F7B7BB84671EA3744C986597D619784EDB9F8BB9723F26C7654B45B706FEDEB3669309
                                                        Malicious:false
                                                        Preview:.[...F...*<..,.*...J..h:l.....U5...;..K......Q..}.*..&X.....5..5.Gu.U".3.{..mY1.8.=.%_g....6._.SuBP.....L...)......x2.V.%.i..<-...9.....&...f...}..>.........v..->OP...sH,C..M..N.)...g..'%.-.S..N.._a.......b.Nbt7y....{...*.C|:..t..5j.5.Gu.T".3.{..mY1..=. _g....6._.SvBP...k-..S.k.....xV.:.I.G.............&d~.f...}..>.........v..HtOP...sl.3GH.M...ra......"..v..V..2..W..C..@3.'...'. ]'.=k...&X..T..5:.A..G..0".3.{...Y]......_U....6._.SvBP.f;..m...)......x2.V.%.k...-.........&.........m.....9...v..ar..\P.rm.6GK.M..w......S0(1..(..H.Z...~Z~4....^.....+H@.e.c..bX..5..5..G..G..>".3.{...YE.].S.@_.....6%_.S&B"..;~....D.]......xn...L.....B........& ~.f..y...x>....i.W..v...t.Pf.ts..jG..%.....l.Vv. a....g....;..g.>...GW.p.mC).....t.`..SX.0..5..[..G..2".3.{..1Yu.Q.\.B_..\..6|_.S[B...;j....G.|......xF.:.%.i..<}...9.....&...f...}..>.........v..HtOP...sl.6GK.M...........1.[..X..Rpv.%....Bw.r.jT..W.Q.p.1Pf..&X..T..5z.5.Gu.U".3.{..oY R..~.F.-....6._.S..wO.b.....+.$.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):146456
                                                        Entropy (8bit):7.963544982215482
                                                        Encrypted:false
                                                        SSDEEP:3072:N6Tfh6dIIH8mX/CcuDu72T5t2XVsAyjReidWrYu006Ug/cXI:N6l698697dqpONRZI
                                                        MD5:9386F973368507A7E45D7410187CBEDF
                                                        SHA1:F48C8DE70D8CA36C6D9258CD1FC6EFE485C331F1
                                                        SHA-256:C6CC0D66452C572622FBF477F37CF29EDAD0382973326A41251E5B5A9F770BC9
                                                        SHA-512:0AEA1A8C62BC46778E1B0BBA59A549EB7AC58AAC9408965503D77ACBC11C682B1F0A0BD1265F31FE6500BF3D4E9BE7028816AFF702D21FE06E80138EF72C8084
                                                        Malicious:false
                                                        Preview:..O?..v..=e.L.C.........20 ..........3..f..._.)...e./..N.u..|.a..F&wu.`oZ..O.A....Td...]..:.g.t..)..P....p..l3^&..#.......y....q....,Q.7H....}._.j-\.*Tt..U..e.t,./{.Wq.Y.+..9_.I...P.$.8&.8p$V......\.WJ..:.5..{...).|..:.U........F6ww.`/z3.O.T....Td...]..:.c.t..)..P....p..n3^&..#.......y....q....,Q.7H....h.q.b \.*P}..^..Ko.}b./{.Wq.Y.+.;.....Q...rk[..N4..kLd.....U.....d.i".Pn,.[|..:.U........F6ww.`/z3.O.T....Td...]..:.c.t..)..P....p..n3^&..#.......y....q....,Q.7H....h.q.b \.*P}..^..Ko.}b./{.Wq.Y.+.....iC?}.......{.A.n.5. .:.6+Y..j.f.,.......C.|..:.U........F6ww.`/z3.O.T....Td...]..:.c.t..)..P....p..n3^&..#.......y....q....,Q.7H....h.q.b \.*P}..^..Ko.}b./{.Wq.Y.+...L..{._.kw...X.(.g2...6.x.>%.1.B..*UXC..GA.|..:.U........F6ww.`/z3.O.T....Td...]..:.c.t..)..P....p..n3^&..#.......y....q....,Q.7H....h.q.b \.*P}..^..Ko.}b./{.Wq.Y.+..T]!.,....+..tis........y...I......W..X.4:......|..:.U........F6ww.`/z3.O.T....Td...]..:.c.t..)..P....p..n3^&.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):45080
                                                        Entropy (8bit):7.442832403511304
                                                        Encrypted:false
                                                        SSDEEP:384:piy3W3AbnHs4zprsOcyO9DoxJXlrVaDjkw/kQQDhv5mC6iU2fVbV+bESkZKNtzAf:FHr45n/WpHJi5BFrW
                                                        MD5:4032164E0EA94AD73E2FDBDBB3FBA81C
                                                        SHA1:1256653EFCC7CA67972E5E3BF08ABB19A34CE37A
                                                        SHA-256:F5CEC5436D5FF1DDADFE583AA43FB0E2AA963D7789601CF2C2FB7523460380F1
                                                        SHA-512:70C08C9A873C671AC146D24A0AF727881ECBFBC8B7162129E1B2F78BF5B64F67AE2E19089F997F85CBC00EE13AB0A719BC32B874B09001941EF6CE79C5566688
                                                        Malicious:false
                                                        Preview:..>.*k3X....a.{..T?.!...h.....Wes.?..d.s.vi..".R\......T...X....u..6....t>..(.....r.'[".C.w.jM0.z....p.=.K...5{JV....R~d..A6W;>B.\.d..y...I../........#~...%.'N~.PI..Y......F.c...GZ...~...4rf....c..D...7^G.J,._@..U.....;...,...u..6.....t<..(.....r.'[".C.w.nM0.z....p.?.K...5{JV....R~d..A6W;>B.\.d..y...I. '....7.....Bv..!...N~.PI...>.....).qa...R.s3"t....X-.(!......X7W..bR.u.U.....;...,...u..6.....t<..(.....r.'[".C.w.nM0.z....p.?.K...5{JV....R~d..A6W;>B.\.d..y...I. '....7.....Bv..!...N~.PI.....,.M.)..;.......(...f.g..#.-d..*9.q.&=.U.....;...,...u..6.....t<..(.....r.'[".C.w.nM0.z....p.?.K...5{JV....R~d..A6W;>B.\.d..y...I. '....7.....Bv..!...N~.PI.C..t..w~. .v...c.3\.(....u.... =.?.*.,..T>......U.....;...,...u..6.....t<..(.....r.'[".C.w.nM0.z....p.?.K...5{JV....R~d..A6W;>B.\.d..y...I. '....7.....Bv..!...N~.PI.0.V.^|C...`... >:.wb..^..f_...:.P...ml...N...-.U.....;...,...u..6.....t<..(.....r.'[".C.w.nM0.z...Q.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):39448
                                                        Entropy (8bit):7.7235643016087145
                                                        Encrypted:false
                                                        SSDEEP:384:RJAUecJp31XC4Zqh6QTNAr/uCj/GP0+bpA70iigKQLXyH10O8sD1p43RqRXp03qh:RJC71vm0bgtXEQynjyG04Blhd2u++3
                                                        MD5:F20E488E1A66EC2738977804CDA34A5F
                                                        SHA1:687464DE6698CD822F4AAFD424CDFF67817C6A91
                                                        SHA-256:5F0DA78646C9947C9A813BE32B88B527B8821ED02B49EC606560D566F6D6D0D8
                                                        SHA-512:F45FCFB6B9DE9EBF8D124D40518FDB784E23651668A1D9FE9FAA01FD1B0BDB9C8D9514A60F424A039D8D80C6BE45D0738BAF3B54A90A2E097950EF94CE524585
                                                        Malicious:false
                                                        Preview:+.z.y..........K...M...1m...8.n....-..B.Q.HrI_...v.~E...(.h...%-.(.5.k..a!...n?.^.....S(nz.z........0.2V.._......4.2...6_u..:8.p3..0..w.L..1...O6..q.........@>U...ud]p..........~....8......1..G.......@.+].A..R.f=._.;F.....-.Uh.M7.r..DY...%.i..!.-..n8.^.....U(nz.z........0.2V.._......5.2...6_u..:8.p3..0..w.L..1...O1..I...........J._...ud]p........G_.B.%.Z....k~.Sx...nD.k5.@r4...&.!9.8.....[..-.Uh.M7.r..DY...%.i..!.-..n8.^.....U(nz.z........0.2V.._......5.2...6_u..:8.p3..0..w.L..1...O1..I...........J._...ud]p............<.I....4M.P0......|......9.3.... Cc.#....-.Uh.M7.r..DY...%.i..!.-..n8.^.....U(nz.z........0.2V.._......5.2...6_u..:8.p3..0..w.L..1...O1..I...........J._...ud]p........,..M...&....Y.......-L.s.l..]U..=Z..6~<A8U...-.Uh.M7.r..DY...%.i..!.-..n8.^.....U(nz.z........0.2V.._......5.2...6_u..:8.p3..0..w.L..1...O1..I...........J._...ud]p........x.9(%..e.a...S.Cn.,.q.....e.....ZA.V.%WD...e-.Uh.M7.r..DY...%.i..!.-..n8.^.....U(nz.z........0.2V.._......5
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):82
                                                        Entropy (8bit):6.104443620445361
                                                        Encrypted:false
                                                        SSDEEP:3:dAKweaaww7ljWqeoiJODwaLi7Die:Caww7ljWqeFJPao
                                                        MD5:A6DDCE1AE4E2C90FC2E8BDB5CCDD0D08
                                                        SHA1:75C9FA09A78DFBB3F1DD82ACAB9C1AEC9EC8D08B
                                                        SHA-256:77CFC1BDB034CDC5CCEE0263943349BC3C77146D5FE7BC42B53486A9E60E6480
                                                        SHA-512:9BD2487271F206F550ACC3A9B7683F446E0BC8F8ED5138DF0C99948B142CF4C233B5243DA35A74AC0A87F76AAF9DB3D5CE7B64CC030DE31D42E192DD01A7A7E3
                                                        Malicious:false
                                                        Preview:..J.2......u.[^...."...7.5.PaI.....}sag.....~s........N..+.....G,.3..I......
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):24
                                                        Entropy (8bit):4.584962500721156
                                                        Encrypted:false
                                                        SSDEEP:3:ysa+GXxBg:y6QPg
                                                        MD5:48FF165F215A8A772F493CC80A81A18A
                                                        SHA1:A9567183F97BEFFEFE70E271AA3140F91D871084
                                                        SHA-256:64672781820D772B5AE49D2884F9C2FF1797CE6D7D142012E83B087543CCEF96
                                                        SHA-512:0E389FD1BA46CEB78A433792E126836853F94F75E42586A4D0E074CE42BD96DBF3204CE6EF9258606C3A9D7D7A3A2C7E3CC890B4A59BA17DE643B9912EF32386
                                                        Malicious:false
                                                        Preview:......[...mc.l0..*JId.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1081368
                                                        Entropy (8bit):7.9108402661491075
                                                        Encrypted:false
                                                        SSDEEP:12288:/dIm/pR0bBceBUmzIYyiXvCcv/TFSlCYd0Bw2O3gf15scC7Yu9f:17BXWvGIYdsA3Cy7L1
                                                        MD5:A44817DF12254D56C7825988F5C1B621
                                                        SHA1:BE4A0E1F68E934FA4F595AE98CE983DFEF885DE2
                                                        SHA-256:E3B4D663C4B5DF1107A1DB4F1D8E72EE1781B806B12AA4F1B2EBE291F87E9222
                                                        SHA-512:BAB338227AA80D9CBE9AD540EF975EEEB0E3DAA1A00514702D4089FC6671B825B0DB93A548E5168CA21960F5CA9FD49807DD2D9396E34C12140E1C17DAE2990F
                                                        Malicious:false
                                                        Preview:...w<.....#..s.X:..Y....V..B...x?...kt...y<p..;..:........"e@.O...d..b.a&..{u3|...`U.C........]m%.{R..[..Z.....D&.d._."....Gp....k....0..I....V|EC..i{..#.e....(@.....>.....v."L...."..P../e.m...i......U......|.....+.......2."e..O...d..b.a...{u3....`U.C........]m..{RO.+.nZl...D....3.N.5....3.~..<.0.T.5.~o.}AC..h{..#.d....M......>.....v.".? G...&........6..{2.........&..3..b?`..N..s*...6."e..;......b.a.....{.3P...VU.C........]m..{R.._..Z.....D&.d._."....>...~..<.0..E..~o.}..]...i.<...........?.....v.".@..+^t..8^k..R...[.T...N...=.Fp$...x.P....-]T....o.W.Ee.. .....b.aj....{63/.....!U.Ce.d..x.1m...R.....ZB./.DI...-.C.t..._.q..~.q.Y.7.G..o.}.Cp..{..g....#.....`>...v."............l....!.\A..H...U..L..9.M.-.).........E.e.re........b.aE....{.3.......U.Cv.e..b.)m...RC.0.sZ].,.Dy.'.0.N.u...].q..~..c.q.!.A..o.}(Cz..{..|.V...~.....$>....v."..<.C7hjJ./........&5...uC0..DY..`BO....v..o...3...}e..z......b.a&..{w.,...l.`UNT...>..N.l..{R.._..Z.....D
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):991256
                                                        Entropy (8bit):7.894147212040519
                                                        Encrypted:false
                                                        SSDEEP:12288:sMv7fP02qQnHKJPjSGukmwr5XeK3TmQag70s2IdUnDkJs9j3BUDNuYKigdLq19h7:sO7fMPtEjwVXG3OWu/pm6
                                                        MD5:350AF824CCCB2BB0C46E22F78923A488
                                                        SHA1:E0989C965ACE5235FB418C72FBCC87D7335978B1
                                                        SHA-256:7232F4001750068D104E170A7A66CA610D4BCA7F34584A7541C99D7B4CAD639D
                                                        SHA-512:F66A6EDF775EDA9FAC9C8660CFE5EB5FC74618BFC789CF1F723798C1E93E211D81F6672D1C78F6128EAF9C3E7B84E495F307DE0A050EE6F23805BBED7335A147
                                                        Malicious:false
                                                        Preview:.2.{m.f...|.hE.k.+...A.k.X..@.8.Q*=.#S..^..>......o..7I#T....D7..x....]r.>5...;....n....5T.........W...!.i...q`se..:hn..e.^.....k..]...e.N...F...V.q.o....&..$.`Q..Q/.h...}......>3.t.r...^.G......z.EBo..*w....W.p...l..AW.m...5..s....]r.65...;..R..n....5T.........WK..!.......q.s...:.n....p..A...k..].O.e..@.h....U.q.m....'..$.e4\.Q..b....._0E...w.C_N.p.~{_V.F.HW'm...+.......;Gt.9.2..$Q].#.I#U.i....5.......]...5..;....n....T.........WK..!.m...q`se..:hn..e.\..A...k..].O.e...b........[.Q...I...$.e....F......]0E..~+u.um-..VGL..}.....H_...n:.V.......{I%;.k..#<......5.......]..r5..;.....n....@T..n...W$.`!.....q0s...:.n....1..A...k.........@.h..].:.....H...N..$.eZ\.Q]...d.z..0*..W.4"..i0...o....v............E.E...n.W`7........#..:....5.......]..]5..;.....n....TT..q...W".w!.......q3s5..:+n....0..A...k../...$..@.h..^.<.....`......$.e.\.Q..X.R.*..0|..}J<...$.q/.R.yv..!C..r.i.p..:........%.....[K...#`.P...5..V....]..>5...;.%...n....m@..o..8..(VH..!.m...q`se.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):360472
                                                        Entropy (8bit):7.8521791420678895
                                                        Encrypted:false
                                                        SSDEEP:6144:VEckhJwZleCIC402cSIj0LcDFKvr986IvHOPMqKS+3XvlSSeQKjaJPBznab:oqO02cooJKm6fPMqMel+Rc
                                                        MD5:A44453668403D148D5D05232BD5DADE7
                                                        SHA1:1DEA1BCD5DF098C8067CF825E0BDB3CFD9DEA98D
                                                        SHA-256:BE4CBE856485C4A6565C505EDC7E6C07FE390CD1C049EE0A318D4873E1A1D32F
                                                        SHA-512:2648758A5F53E85783CDCF26D1017EAA71DBA0F2BFDAA2896A5FA8976752C062A34DF229158A4B84A692D241354F945D361C355E5768139BD6604127474C9CBF
                                                        Malicious:false
                                                        Preview:)..6....].iF.u....B-.a......9....|...h.?...L.....m....Ib..^?\...4.....U6..Yn...Q.'..in.|.J.).2i....l..\..."d)Hn.!d_+.9..P7W.5.W5..g.}.gi..N.....|X.<.-...............8..(.G.......}.X...1.....{.=9.o..:....2.".:..|..0w2j-.fS.{.I...^>\...4.....]6..Yn..5V.'..in.|.J.).2i....l..&.m.GdZH@.Ed3+.9....Y...y9....}..c"...|X.<.-.......n.....q.V...n.Le.>.2m.'.3\5A..&m.Ex.....A. 1.@,...K.....k.....I...^.\..4......{6..5n~..Q.'...i_.|.J.).2i...l..\..."d)Hn.!d_+.9..Q.k.0.J9....}.nP.T.c".X.I[..E,r7......!..$../s.S...n..EOi?...kUba*.boR..].B.........r.K.dD6...~...I...^X\..4......o6...n`..Q.'...i...|.J..H.ni.....l..3.l.MdOH..}d.+.9..5...Z.89.n......ca.K.,X.<.-..h.t.g...........V....x....u0...2.....F....9-..q>N.? ..y..x.S.. !.G.....I...^L\..4......26...nB..Q.'...i...|.J..F.@i.....l..5.|.GdyH..Nd)+.9..;...[."9.`."...c..G.MX.<.-..[. .].[.....I.}.w.....X.z..<..{......,.X0.u.Q...|./s~6.{=..2;..........I...^=\...4......5?...G.*.x&..im.|.J.).2i...l..\..."d)H
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):270360
                                                        Entropy (8bit):7.835241454857015
                                                        Encrypted:false
                                                        SSDEEP:6144:Kbm8CEnGoiCcgORp+4r5yFeKsaz3ZLYKBr4:4rnyd5X/FyFeKsaz3ZLY5
                                                        MD5:5CF6FF1F38B7EC1945CB8F63E99B87E7
                                                        SHA1:75580DF8DAF1C26F45ECD1ECCF48249982CBBC95
                                                        SHA-256:430C76AA0CB2B42DC86E9D0778DB64A38714353D1527E2B62222C2855A69FB4D
                                                        SHA-512:7E25E9CAAB46DD1828D40942B2886A4411E14C25648AFCACF51904FF67476E7EC0DEB2969FAA3F1E96231A3B3BAC1C8F6C6D483B3362847E5058DB9A8CDDDC07
                                                        Malicious:false
                                                        Preview:h....{.6Pt. .i.F..&..C|...... .<qV...'%.Ohs...<.p....=*..2.)E0..a.Z......5.....{..(g...L-.}C.?.....+4.G...v..Vz+#..ie.g...h:...Z...F.(.7.y..`.1z{RD........:..0.}.:...:d..sL.....(..B..NY"/{ .NB.. ..+..f...4\{^<.z].H.N...._).N.2.(E1..a.[......5.....|..(g...L-.}C.?.....+4.G...vy.3zX#(..e.....G....ZC..F.;.7....~.@0~{RD........;...0.|.0.f.i)];.M..n.....JR..-..qw.......h0./....e.8@:..U_.9a.&.=+.J.2.iED.....?......5.../{..g...L-.}C.?.....+4.G...v..Vz+#..ie.g...i....Zp..F.;.7DI..~.@0..w.&s..w5..;..;...p.d.l)_;.M.2...>.0^V>|O..w.|cj.8!..od..xI.|.Y.my...'...=N.&.].NEW.....Z......5...l{..Zg..Li..C..^.@.S.B4.G...vx.9zM#r.5e........Z...F.;.7.i....0-{.D.W.b....^...D...H...0).;.M..t. {..."<.|..o."d.g.....7.p_.....k.:%3\.....=L.$.].ZED...........5...\{..Gg..LH..C..P.n.A.o4.G...vh.3z{#t..e..........Z...F.;.7..6.L.s0!{cD..K.9....d.....#...U.B):;.Md...Q..^I.Q..t.;......:.(.d.u.s2WA........QL.-.=+.J.2.+E2u..1........5.<*.....,g...L-.}C.?.....+4.G...v..Vz+#
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):546050
                                                        Entropy (8bit):7.647751583887513
                                                        Encrypted:false
                                                        SSDEEP:12288:fnh58vF6U5sPiqzcP4wPSIpxmEbM+yo593AxP142xh+phMixQn:fnv8vF6UgiqzcP4guvo5dUxcphMqM
                                                        MD5:226F04420B68E28F69AB3A8010C98036
                                                        SHA1:1F236D2EEA68AE8D58CD35BA97F421B1A43B7F2A
                                                        SHA-256:378D2B1181D6429B1B96C9537D320540BD8E5779D435DBAA74F1982866F45EF1
                                                        SHA-512:D9306C0883C91C78980AEF0DA8C5B7C73C7BEEE5CED035372E489A2D8829207D23FFBA13DFEC6F4286AF5AF03A590286DD86278A9A7E21C4F7BA5DE11E087DCB
                                                        Malicious:false
                                                        Preview:BO..vI..t|mo. ...}Z@.N5....2.J...uYD,n...4r.}@y..`.\.<....k....d...........;PF>G.....4.....]........;}Y.r......v>..G..X.^RN...]Z;/.?....&.....a>.Z.)F`...Z..%..h...o..p.;F.G...8...R..TB40ez.q.........kv .m.(.1!O..W&...z....k....de...........qP.>/.......4...F].........L;IY.r......">j.[..X.^.N...UZ,/.j....%.....A>.Z.)G`...[.*%..?.i...p.;......f1..F.9.^..X.s..=.k...e..Q.@..\..c>K:....k....dd..........gP.>.......4.....].........a;.Y.r.....2>q....X.^'N.....Zz/..?...F.m....1>.Z.)o`...M.$%..5.S.+.p.;b].`.Tu.Hd...rf +.q+...W../..~.>..;..5<./.Yo./....k....dU..........gP.>.......4...i]........V;=Y.r......Y>.....X.^uN...NZ./.%..../.....$>.Z.).`....c..%..9.G.0.p.;H..6d..\........Z...wDJ...j..e..J%..Tc.....`.....k....dD..........fP >C......4.....].........;kY.r......f>#.W..X.^cN...aZ./.`....*.....$>.Z.).`....|%..i.....p.;........=...i...1.|6......$..S.^.....~hU..9..8....k....dG..........^Pq>x......4.....].......V;:Y.r....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):17895
                                                        Entropy (8bit):7.9757682828673415
                                                        Encrypted:false
                                                        SSDEEP:384:v9HqjjxS2ERhCsBuo/f8xbjFh1JdPuCds6Cq6hE2XDqg8Um8ReIb38k:dqLwwfcev1/PjCFDqgcIb39
                                                        MD5:60CB18293BC0A460CA9B6D6640768BF5
                                                        SHA1:240E27524586FB60BFE6B087D547C58C65D10F0B
                                                        SHA-256:7F50E95D777897FDB7FEDB220996B6641CABD5B76D9977B8FD49AB61C10F7FFC
                                                        SHA-512:1C4F2D7C5E310D373AB97686108999DEBBED6D37B2C17D7C00BF28E0CC15B63E2E8F1C862CC04ADD339F0EFE4340A1694067C866D47FC2FD23A635156A8287E0
                                                        Malicious:false
                                                        Preview:..u..u.{........8.F....]...Bv+k.....Z..E.~......*..c\....B..,.gSQ.r~GL..i..3.4&1.}&..~c.).2..N.y]Z...`....A(.kU.-2.:.o.v...."S..+RN.....Uw"@.MDn...A*t+......F...>W.E..($...#..'...K..b.).I.'./}2.....s..I3.m...(%..eYT'..|..W..g.}...m/.A..g..0.jv+..z!..x,.G....O.y.x..<..0....8V.qZ.ze.|.2.x...f.....6.K.....P-2....D...._=5+.....X...>....I.h.t...&I`.&5.<[..5z~y.....c..'......W...i.....;C.wM.>...e@)....&|.FJ.n..>.n>...h<..da.r....N.."...N..2.PP.v9.%..3&.`.|.a...v^....q.q-..(.6.Uv..=h.....SbV:....U..X]`.T..').....1\.{:9t..IC..A..&...g.K..Xj....9|a.Ej.G.a_.t..g..,.n.M..$;]m..o....ZW1..u-.s$.~....S.aA^...2.UQ....'..?..G.)......q......<ST......<j...QN....G7y).....A..Z3.VN.Idj..7Oz.9*..5..7.NG....i.>...v%....U.......d...:..F..Q..{Q9^C.m?.NP.i..8.}P-..s ..+".p.2..D.dEM.....>.....?.6@.?+.@.1.v....q......6VT......<j...N......SbG:......]...%..H.@m>x.1=).....~S.g.e....S.vK..d..<..{.y"...D78g^.+..._..A....}.....9.H).h..:.aa'.-a.+n.q.[..N.dF]....z.SR.x9.0
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):19641
                                                        Entropy (8bit):7.9742523062813815
                                                        Encrypted:false
                                                        SSDEEP:384:NtMtX68yi3MdMBGTQ3Y17VXnfu3Lqvmyr1NR7Me2edtDA4c7q1gzdd:bMtq8yJdMnwnLvmA7MXeHytzdd
                                                        MD5:BDEDCD36D86EFBDC0BAB1C1577310F98
                                                        SHA1:71B87F6D605B45C64A4675EF0BD5D38D0F786927
                                                        SHA-256:7EBBB604BF8ED0A68A24C9565C5F581D87A908D47D043A3533F632F6AA6DAA0A
                                                        SHA-512:D10E0E413FDA8A50BD961232AD3F9982043BB3367961551C31EEC470DB9073B691AA08731FFF2CBD445605199DE9337C9D37211653084EAD9AE57B55A67285D7
                                                        Malicious:false
                                                        Preview:...m.^....=..<..H`...S.9:.NS)n9...w.o.....4..7.....BN...`L.@...8............\}p-TX..@...@.@T`..yd.....an.p..!..hH..+...jA..Z.GX.F._....@.z...O0a....1%..6-l ..d.+'.#.}.>..Qp2.....P.........(..e..l..i..y....7V..S9.[...tO.Z....s......IW...._s.}NX..GC......@e.jdA.9..@ _?.kX.rG.|...7O..........JB...[[./.M..7&....w ..!ll!..}.5;.%.'.|...<..>[Z..gR...R.~s......E.sl+.pg?.+.Bs..\~.#.*..zD.m..U.qP@......@.V..Q|*5rN..Z...B...G..".d.I..,"]`..|...&...?...y.....JJ...[....8h)..jzy.(...x/..~.};...{.8 .r.J./..^}z.^..'hJ..v..hA.5c.!....05..%,.b7.l..{.....*.....{G.Z...8......]......vT.\TM..KSV.....Vr.6|....co],..!o..$.......,...T......MH.../@.<.\E.g4....kc..#vJ,...d..=.).5.1...7M.ybQ'o@...[+....8....g@:H.......X....>.r....wO....!.<..........J....Y"aON..g......V.u."C.....ag.v..ue.b[..:...<..........X@....L./.}XA3i....g|.Mxc{/..w.<=.).).j...n.8s..0..1..0...Q..9.:..g....RN.[.(#y,..b6f.=M....~F.-..8.?.......MQ.....qu#iHL..V...S.JX.9..*#....bw.f..#!..7
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1802264
                                                        Entropy (8bit):7.422305243148446
                                                        Encrypted:false
                                                        SSDEEP:24576:lqLESD32l40CWQEaWkI0F84xgvGDlLD0XLJFV:lsESzbRWQVNyODsV
                                                        MD5:7A81AEBAF7AA0F73D64393209B04A70D
                                                        SHA1:DBD4E197EEA7DFA2763BD140C0A3CB1F6F1CCB08
                                                        SHA-256:1852D4AA020FBF441970034C38800F06EDE33DD067CCD829F35BB9337F846B80
                                                        SHA-512:E13860E2199935AAB02724DB2171FB3F982B48593AF5251EA1E900F9B1934164440D61A0C5616AD1CB2FBA0B30BFC8192AEE6608FCCF157B4D2FF7543F1C8DD5
                                                        Malicious:false
                                                        Preview:..._.b.#.....Xu.!...j.|.E....V......l.....[#.}}....j8.)S.+.\Lj........?...7...xY}S.f.-1....l./..TmM......l.f..D.f.Q.R!......+..j..+co..).v.....p2. .J..<......;.....I..F.......v......Xu.rQC...iAfON...^*.,.;..SM..Z..Z.>.P.5.&%..+.\Lz..A...3.9..h...3pZw(?`.-1....P./...B..<......f..D.f.Q.R!.....O......J.+f..u....ss..F.n.>.N.@..gWe..x....F.......v..&`z......j..).M.t.....".N.d.S..P..{.`A{h.$.t&%..+.\Lz..A...3.9..h...3pZw(?`.-1....P./...B..<......f..D.f.Q.R!.....O...F...|D....~./>.u4...X....4.....!....zg.#c......vJ.i......Xq.3..P.+..t]....b.nkn9A...?..!.@...2H&%..+.\Lz..A...3.9..h...3pZw(?`.-1....P./...B..<......f..D.f.Q.R!.....O......J.+f..u....ss..F.n.>.N.@..gWe..x....F.......vP.@H..F.u..6.".D.r......a.Y....g'....~T../..s..&%..+.\Lz..A...3.9..h...3pZw(?`.-1....P./...B..<......f..D.f.Q.R!.....O......J.*V..u..`....i....?.N.A...fWe..x....F.......p2...A..M.#.{......).L.M.....Ls..N........c&%..+.\.z..A..UuaSt...3pYw(?a..-.....P./...B..<......f..r.g.P
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1802264
                                                        Entropy (8bit):7.481412006031582
                                                        Encrypted:false
                                                        SSDEEP:24576:zRJ90+Mx8rHV0+tj5USs9sRbHccchwAiidt5o9CSYaSq:zR/7i+tj5USs9s9HcThvii/5CCSYaSq
                                                        MD5:473A23B2EF984BC9EBFF9C1DDDFB8531
                                                        SHA1:8900AC58BCA9C807FAA12636A988882A2CEDBCEE
                                                        SHA-256:1081597FFEDCDB0FB3774307BA2FDD0C12E379BD0EF384ADDAB81573EB9FA9E2
                                                        SHA-512:658CEF6218466F9BD1CA3D4D311358CC87810AC7CC331DF339128951597EB4C7337A44D88A53F306EC3A571D4FF9C7516573054CEA3723E30F80086DAD79600F
                                                        Malicious:false
                                                        Preview:..G.{.!.[...7....=.c%/ya.v.?.{>e.e#.....=0.. }.Z!jp..>.L.*vgx...;M.?.V....AF.'......v....1....G..G..h..E.'W.i{u\F.{p1..<Z.I..'.w.5.z.'.".E........2T.^..?g.....,.M//..&#......go...g...^B....T..6N.|...Z.fi;=D..w:y?Y....u.-6...G.*vgx...:M.=3^..hL.AF.'......v.P...#1..FSh..|..b.?.E.'W.i{u\F.{p1...`....@o..q...{.Ks7......qF#.,b.{....~Hf?s/..&#......g4.>g."!q9...=..{..Q....~%..Bl[..5...A....~.M.C....G.*vgx...:M.=3^..hL.AF.'......v.P...#1..FSh..|..b.?.E.'W.i{u\F.{p1...`....z3F...|...*.V........ W.b...g....?.S.N..T.......g...e.\....R.$.B..F^X..h=..9....I..%T..;..e.9.....G.*vgx...:M.=3^..hL.AF.'......v.P...#1..FSh..|..b.?.E.'W.i{u\F.{p1...`....@o..q...{.Ks7......qF#.,b.{....~Hf?s/..&#......gIx.YwC...!...6.].I}N....)H.>..T.2.f.i..F.........G.*vgx...:M.=3^..hL.AF.'......v.P...#1..FSh..|..b.?.E.'W.i{u\F.{p1...`....@o..p.{.{;..H3)F.FZF.G#.,".{.....~Hf?s/..&#......e..0...6......d.[.r....yG75...C6.x0\..#...l..r..F.*vg....:M.=3^...o.AF.$......v.P...#1..FSh..|..b.?.E.'W.i{u
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1802264
                                                        Entropy (8bit):7.352059473503682
                                                        Encrypted:false
                                                        SSDEEP:12288:xozjWijJFfvRs1g/21WW5JOo977gNmi5HLCDyOPFQs:xavjJF3K1n19h7liZkFQs
                                                        MD5:D2DDB87D2D3F18EDDD2E7D791BF62411
                                                        SHA1:94B6A8EDACDBF5CFBB71618F53D48D966725D55E
                                                        SHA-256:88929CCA85AF65E56133628A93855DD8FA856856B3A35A4E2543AB0C2C2734A4
                                                        SHA-512:3AFF651CACF45367A284E8E93715A700A3A33D77F9281105EFD5D8FD7ACDB33B3F73EBE92B1A4B319338E26847B96A104F0A25FD83EEB6AFDDA895386F2AD937
                                                        Malicious:false
                                                        Preview:`.....&...G.....:..?.aC.......&..&.4.....B..9.n9.L&O..`..T.>.g5...&.W........E.p!..uu..|..T3Y!.=F;...).x3...s.#........N.X.s...j..T..73_`5@.]+..!O.>."....;.<N..}.Z.r.U#...I%..NT..*3 ........l$.~....u..T1..oeq.....Y...%&O..`..T.>.g5...&.W........E.p!..uu..|..T3Y!.=F;...).x3...s.#........N.X.s...j..T..73_`5@.]+..!O.>."....;.<N..}.Z.r.U#...I.^....~W.s..k......x.y..qr........<..Q.....(.&O..`..T.>.g5...&.W........E.p!..uu..|..T3Y!.=F;...).x3...s.#........N.X.s...j..T..73_`5@.]+..!O.>."....;.<N..}.Z.r.U#...I...........H.?K...mL&...<...b.m@nQ..=O.F..O...&O..`..T.>.g5...&.W........E.p!..uu..|..T3Y!.=F;...).x3...s.#........N.X.s...j..T..73_`5@.]+..!O.>."....;.<N..}.Z.r.U#...I|...4N.x..+.r.."....@.....+.8..W.g........)&O..`..T.>.g5...&.W........E.p!..uu..|..T3Y!.=F;...).x3...s.#........N.X.s...j..T..73_`5@.]+..!O.>."....;.<N..}.Z.r.U#...I..;._|)A....p..........a.....3..P.D.U..?.)~...&O..`..T.>.g5...&.W........E.p!..uu..|..T3Y!.=F;...).x3...s.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1802264
                                                        Entropy (8bit):7.447784516531568
                                                        Encrypted:false
                                                        SSDEEP:12288:f+hkakfzlKF4Gi+W+kv2ePbcWDb6P0KwebdOWTBtxsdvJFKWMgxVaolg2z:fMKKZi92ePbcWqcodOWTjEvZLln
                                                        MD5:5B0E1AFE848E04C8F2CBC0BA4B0BC2BA
                                                        SHA1:31B4518D4A03AD2AF4A34E97B662F757BD189D52
                                                        SHA-256:5A0B586FD029BA804DCAC3B94B0D71F175DC108DD7DA50508F16F4FC07A50DFA
                                                        SHA-512:DF73DC63DE13A615B579791EFD2D7BF3171EE501077CA0194401C827E1FBEA8E8B449CF59DAFAEC4CAAE3448A04E7DC1FC9E3C2CF8C45102159EF8274F99DC66
                                                        Malicious:false
                                                        Preview:..$....-h&(.hn/D.g.Asx..M...u...*..<v.%.-.-......x~-.._..|.n.?.eD._..V.....h.i.~3.58....]p...?..v....Q..3#.t-.H......n..............Y....A.E..^..d...4.{.. ....L.=Y....Y.3....(.c..t...{....d.~...h.q..VHb....;.U.D9...hcG.N#=R=f'...QEB._..V.....h.i.&o+.:"...&....?..v....Q..3#.w-.H......n........ .....[....A.]".[..[.N.Q.{..O......[...."x5....(.c..9..n..G.......fl......7..CP...c.0.k...3.do..[/R=f'...QEB._..V.....h.i.&o+.:"...&....?..v....Q..3#.w-.H......n........ .....[....A.C".[..[.+.Q.{..!.......[...."x5....(.c.9........P.?..6..1..)!...[.-.WD[.z.y.......Y.oR=f'...QEB._..V.....h.i.&o+.:"...&....?..v....Q..3#.w-.H......n........ .....[....A.W".[..[.+.Q.{..!.......[...."x5.....#.}..5:-l|.+..|..)..Y...q....'..^.fas. .x..-v....U.....QEB._..V.....h.i.&o+.9"........6..v....Q..3#.w-.H......n........ G...... ....A.W".[..[.+.Q.a.k3..z...[...."x5....(.c.`...|..h...~.U......6......J..q...$8.,D.[.@.kR=f'q..Q.a._..V.....j.i.&o+.:"...&....?..v....Q..3#.w-.H......n
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):270360
                                                        Entropy (8bit):7.408397455104494
                                                        Encrypted:false
                                                        SSDEEP:1536:x3RvgVV6Tho3oIt6nxCp7t1SOHu6B2CSzf2uBNVXn9HA9B2SL3iTDHucn:x3F8MTh8oItK87bS4dIDVB7FA9MSEHR
                                                        MD5:31DACFBE4E88661C9CBBE814EAD8CD9D
                                                        SHA1:58322E53F375600ED0C4073A881FA12E658972FA
                                                        SHA-256:B51646448C80C1EBECC6DD17DAB3320AACF6D4C7E696F6B0A1D478713B1A229D
                                                        SHA-512:5E105BB196155A646CED347444678465E81B2083A6D31E2C0A3F0A781112022399DCE0F200880AA324093B31007ADDFD206B7DCEA92D2DADF146B9C8F00D8DA7
                                                        Malicious:false
                                                        Preview:..S_I...+7G......X..?..M+}......e.Y.&&.^.l..d.*.3.."......_..\.....-.....G.0[..F8..2..:F.&....>......Dg.N......6RJ%X.x.;R,..X...E.....@..6..s"...;.y...m..C..t.Sc.8(.Hr.}J.B..\~.SX...e@3.j,..."{%.D)..V..1..e./...6..H. .d.sU..=........-.d...G.0[.n..."5..A...&....>......Dg.M..!...2RJ%s.p.1)...j.....G.....@.,...yY...I9.}......C.K..c[);".+Jr.}J.B..'4.....g..I.5.7.x..U.AC.......r.v42...._..`..U..=........-.d...G.0[.n..."5..A...&....>......Dg.M..!...2RJ%s.p.1)...j.....G.....@.2...yY...9.}...l..C.[..c[);".+Jr.}J.B....Z.e.m..!2.U.../.(.N.|.-:&.%.Ga%.o...\%.(.ICLo.U..=........-.d...G.0[.n..."5..A...&....>......Dg.M..!...2RJ%s.p.1)...j.....G.....@.&...yY...9.}...l..C.[..c[);".+Jr.}JN.<.r......$.....?.....%8.......q.6o.Qy...'l?C.d. ..8........-.d...G.0[.n..."5..x...]"...>......Dg.M..!...2RJ%s.p.1)..B.$....C.m.{.@.&...yY...9..E.@G..G. ..c[);".+Jr.}J.B...>m.p...6...R.MD....k.....U...7~.b.\.z-y...U..=@...o....-.R...C.0[.n..."5..A...&....>......Dg.M..!...2RJ%
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90136
                                                        Entropy (8bit):7.398564853272359
                                                        Encrypted:false
                                                        SSDEEP:768:Dku16qrux4wB6moWQMbbLMFLr3ah5J9QMhZENp:4usqqx5nRsLr45kMhCp
                                                        MD5:8F44E7BE6ADB10AFA6B755B791A7CF7D
                                                        SHA1:63BBD851070C409290C002458AEF767EA3404101
                                                        SHA-256:40A3D38C29681324C036143720952D64CDD656F7A768F3F2F36C53112874B382
                                                        SHA-512:737AAE318B9436CCABE9E9C7E60220400AE238887F6A4F11633B597CD032CA3A3BF5D58ABDE0A7C49306EC8B4B1EBB406A68F0AE0244F0DC9CE7D2A06AA5116D
                                                        Malicious:false
                                                        Preview:.w..".ZF.G.$%...0'...XN.-K........r'.`.="N...}.j{...\.Z o....7y..S.....rMhy7.o..T.....G.e..uhKkI.Q.p.l2.%6.E..T..S.9$z$...t....w}B..I.ZPn..t.6w........m.......j.m9.......Z(.q.-..05q..+N..._.8y...i...fw..Y..I'..!v.....w...$.H..a..7y..R.....@ElsL.m..W....G.e..uTKkI.X*..H.o8}.4.E..T..S.9$z$...7+O.w..0.....12...cY...c..ddP....nC.z..d.\..`....Z(.q.-..M.y.~b`5........>..g..-.H.-...,.O}......K%..H..a..7y..R.....@ElsL.m..W....G.e..uTKkI.X*..H.o8}.4.E..T..S.9$z$...7+O.w[ l..b.\P_.c..I......$.K..<,...k8G9......d5Z.-.-...d....N.!'.}..:..MV.HRJ.....b...rE.>z.L$.#6..H..a..7y..R.....@ElsL.m..W....G.e..uTKkI.X*..H.o8}.4.E..T..S.9$z$...7+O.w..0.....12...cY...c..ddP....nC.z..d.\..`....Z(.q.-..z@..Kh.^.......<+X.q.%...........@c.l3.......H..a..7y..R.....@ElsL.m..W....G.e..uTKkI.X*..H.o8}.4.E..T..S.9$z$...7+O.w..0....[12K.....r..o^.eP...nC..nd.\..`....Z(.q.-..T1...L!...{....U....Z..w....X.%.P..l..&:..HH..a..7y:.R......oV...0m..T....G.e..uTKkI.X*..H.o8}.4.E..T..S
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90136
                                                        Entropy (8bit):7.700409830573531
                                                        Encrypted:false
                                                        SSDEEP:1536:OVFYu0XHEUuRawkDbH5goCaRMe43sLgvGKymAYR1kkYxmMdeoQAM:GbUcaw+HHCa2L8RKpfD
                                                        MD5:489BDDB8D4A025070C82E4B52B5842C9
                                                        SHA1:E511F71A95FB5280B3E4FDDF1382048E354A238B
                                                        SHA-256:288AFD0804141A3E56DC2B8C076134D198C3EF25636147A75ED2A72C6F303E81
                                                        SHA-512:95FD3D5BB62B21316B4E06B73CA70F01F990A9A83B8B01B2BE9E6251E41BF050C0674061CDAAD6652FFDC5D82775B6FB638F518BE4E7679FD9F3194D8C66A1B9
                                                        Malicious:false
                                                        Preview:W...u...^.O...OGt...n...>!.]T/...(.%...)&........y...v..R..l....:K..|>&.bU..c..>..'..#....d`....T...RM.Mq..H...k..92r.5.....EU.....}..+.Vb.H....v.3.4"JP7B....Q...J.-...Z.I....}..^.D...<...b......+h)......|.............'..%.m....*J..|>6..eV...a..>..'..#..T!d`......./jJ.G.K..H...k..92r.5.F&..7:.|.`....Yfi5..;w..%.@Y[W>5E.....0.|.>..H..Z.I....c.z.t..5...Kb.Q...Aa.8..fh.X.D.}.o...../..L..%.m....*J..|>6..eV...a..>..'..#..T!d`......./jJ.G.K..H...k..92r.5.F&..7y. ....{.4".Aq.v....V.&-..SF.q....l...M.-..(.......A.......G$.'..z.Z.j.b.1V.J@A..4..:..\w..f.P..%.m....*J..|>6..eV...a..>..'..#..T!d`......./jJ.G.K..H...k..92r.5.F&..7:.|.`....Yfi5..;w..%.@Y[W>5E.....0.|.>..H..Z.I...ew.R....o..>..'...=.;4D......AU.....RZ...]Sbe...%.m....*J..|>6..eV...a..>..'..#..T!d`......./jJ.G.K..H...k..92r.5.F&..7:.|.`..|.Y...oY...Z.AY[W.5E..>..0.|.>..H..Z.I...#\`2.Hj.y......U.0P$.........G!x...\...2..i.-_..$.l....*J..|>6..eV.n<a..>..'..#..T!d`......./jJ.G.K..H...k
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90136
                                                        Entropy (8bit):7.358312585156663
                                                        Encrypted:false
                                                        SSDEEP:768:2pOhXQ1UZ7k410MMNgM2djSAkaYpsNoBqIlVZV3gs:NXjZHnBnRSXsNZwXV3H
                                                        MD5:A5231A76E05CBD2FB2FC6816053288E7
                                                        SHA1:41961136822367504D363CB70BED3755CB7BE73C
                                                        SHA-256:9F86302DCB9DC327E1331B36D5F354E8CB33F7F0661A5ABFE52EFFF9AC52EAB3
                                                        SHA-512:8262E64088AEC6A76F79C26ECE91BC854161948A0262D5E1F67F0730A915847CA49FD6F866CD5144CB3BC85253BC89729CAA5F68C46187FCED811083779E3867
                                                        Malicious:false
                                                        Preview:..b...W../....Z$3.~.-...`@.v*.y..e...Hq.S.j.....,....k......../L.......0.0v.l..FI.6.;.......{.gp!.VV.;vx..-T..8.xS...........V.mf.....f..u..5.0..e...K..n..N.,...rd[...0.t.-8...../.Pp...B:..=....o..z..L.*uK..n.}$..i...`...i......../L.....2).q..a.NI..9.;...X.>._w".-.;vx..-T..8.xS..-..d..h.;....CH.....i.i@].....9....y/hI....8[...0.t......\......y.oQ.8l(.\|...l.`....Z.V.b."..X`...i......../L.....2).q..a.NI..9.;...X.>._w".-.;vx..-T..8.xS..-..d.4.I.k`...w.u..s...32..V...k.....s%,...rk/..fl.t....R.DUV3.Q....o....x4`Z..5.........Zb...g...`...i......../L.....2).q..a.NI..9.;...X.>._w".-.;vx..-T..8.xS..-..d..h.;....CH.....i.i@].....9....y/hI....8[...0.t.3........O=....7......Z..8.....z..G...2C...hD`...i......../L.....2).q..a.NI..9.;...X.>._w".-.;vx..-T..8.xS..-..d..h.;.<g.C..`k8`.....".....9...../hI....8[...0.t...G...[...K.z.W.(..<....U..B.6..u...]......d.`...h........E..... .2).q..a.n..<.9.;...X.>._wJ.,.;vx..-T.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90136
                                                        Entropy (8bit):7.374333964542714
                                                        Encrypted:false
                                                        SSDEEP:768:kvquBaf3czt/ZagBIYiiOW6WI+nPIUZ7XeEuiqMvNUh:kvqfvIZBBIYEJWLKEuiZo
                                                        MD5:84B2CF01005C5CE317F47BF0FD4F2FC1
                                                        SHA1:2DCF5CF5FF00ED4876E369D4A8E4C0A6194D3A60
                                                        SHA-256:B877525567F0A5121D5122E032D8DFC008D243A89BCD77226B034200CD85DD0A
                                                        SHA-512:51BDC05A5AAC227BFC2E8E63A25969BE95D6223704E608311E54BDCCA00C6BDEDAD66524837BCE78A96441BB4C5D4BD483395B583B7062B8763559F7E11A1462
                                                        Malicious:false
                                                        Preview:..Z..7}.`z.%m...bg...Qe....xH.......;&..w$.`..f....f..p...Z..-t.....mO...>.."~<f)q.hf.+{.r....6U...eF...L..`...?hR..U.X.j........|..kK......E.d....."57.v..A.lu.\..c...c.[uJ..L.....#.88...k..P....B......HQ..........t...K...-t.....m_..4.X&N.a*{..d.+{......6].g]U~...7?.`...?hR..U.X.j.#.O...../*}..W.w7..ry..POFe....3.!../.......P[uJ..L.....b9T....fd.X..'.....4...oC.3....0T....! ....K...-t.....m_..4.X&N.a*{..d.+{......6].g]U~...7?.`...?hR..U.X.j.#.O...R..@M......V.Z....# ..P..a.Td.]..c...c./.8..L...W .....~.w..|.e..N....0....%.....\.+..z.2vY..K...-t.....m_..4.X&N.a*{..d.+{......6].g]U~...7?.`...?hR..U.X.j.#.O...../*}..W.w7..ry..POFe....3.!../.......P[uJ..L..8...\t.\9sjZ..........F33.k.z...}.b......v..W.K...-t.....m_..4.X&N.a*{..d.+{......6].g]U~...7?.`...?hR..U.X.j.#.O............Hu..p%.0Ge....3.!..X.......P[uJ..L...."..$...~.6.{B.^C&l...[...K.pG;.re.KS.H".VH..K...-t.d.......SJ.{&N.a){..e7.{t.....=].g]U~...6?.`...?hR
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90136
                                                        Entropy (8bit):7.311075021506125
                                                        Encrypted:false
                                                        SSDEEP:1536:imrDUoGVDAZt2f35EgYzd60Cp2WMRlOAUXGsv1QQB4U1qBRfkRilKmelOiHpygnj:Rz1/k
                                                        MD5:8F690A073191401538C69D14C5657BC2
                                                        SHA1:8DCF238820BE27A51FFA68EB9A97C098A0D84C5A
                                                        SHA-256:764FE6CF239BFA0C8DE3BBAC830384B6476365717AD0B0DC3C853FFB1BF2B07B
                                                        SHA-512:A2E6C594FA481D34766DC426E91B20D83E708CE52DFC7506918CF434AE4BECA19450C6CCB56A010D19CC0E239287319E15E020211541B59BA385D728225CC784
                                                        Malicious:false
                                                        Preview:b..>.|.U..6..8.?..S.b....|.....}.1j.Lz...U....>..^...c..j.....#......7........?..J.u.W.o.)kM.!..Q.&.(.$...n..T..u ..q...T; |U.g..a..p}.x.Q....../..#.....(Rt......j..aQ9...v.u.o..Y..;.}.}..{..\k.).69...+.c.c@..9..>R.=...c..j.....#......7........?..J.u.W.o.)kM.!..Q.&.(.$...n..T..u ..q...T; |U.g..a..p}.x.Q....../..#.....(Rt......j..aQ9...v.@.s%.....t..I.@.s.....l..k..V...PX..u.1....B....c..j.....#......7........?..J.u.W.o.)kM.!..Q.&.(.$...n..T..u ..q...T; |U.g..a..p}.x.Q....../..#.....(Rt......j..aQ9...v...(....~.u3 {x..V>.&....Pad...qJ.f..f`..&w...c..j.....#......7........?..J.u.W.o.)kM.!..Q.&.(.$...n..T..u ..q...T; |U.g..a..p}.x.Q....../..#.....(Rt......j..aQ9...v..N.....>&......N...]C..I........i...0."W.%.._..c..j.....#......7........?..J.u.W.o.)kM.!..Q.&.(.$...n..T..u ..q...T; |U.g..a..p}.x.Q....../..#.....(Rt......j..aQ9...v..4.c..x...B.........x...v.BeZ......*.|na.-....c..j.....#......7........?..J.u.W.o.)kM.!..Q.&.(.$...n..T..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):764157
                                                        Entropy (8bit):7.99973178620214
                                                        Encrypted:true
                                                        SSDEEP:12288:0UeJ6xv/L54nqFkljle5dpcos8b6/iBbFlyzHr6zL0tnjPT/WqUKSPaUZ:TG6xv/LWqelJeSe+/EbmCcr/WqUKBUZ
                                                        MD5:C123E751A200C2EE557A3F265CFE07DE
                                                        SHA1:CDD7DBE9B7CB3B181C37D62EE9FFA5A9C6B2A664
                                                        SHA-256:CF7D6F4051A77DCDF262F917A9C59A0EA940E330AC98D8411B55D24084042AAC
                                                        SHA-512:062336A676DFFC376F9F93AEDC8D97FD0A51609EAC35B9C1323DB00C94EF1C55DB99881E72F19E27B77BDC0CC172D6F5E8B64B6EDCF8DA7E60DBA43B389A46B9
                                                        Malicious:false
                                                        Preview:..y.M$^..y....~v.....Fh....q.K.F..0.`.iC......#v...o...P.;.J.....Z..T..zk7.r...=.s...}.....*v....io...m?.^E....mL..apc.`......._....X.....m..Z.Qv..>..h....Z+<.....$"..&...z.;.l{...!'L.;@gR}L.r.f;N.a.....p&.........y..K.....0.4u>...mZ.C.i..[/.....X..u...s5..8@'G....m........c....t.8nc].9a.W.e.'...N...RE.Ey..G.>..k..t..\$.qC.rgv.j.rY\....2...R-.'.....:j...t j..l1.~....<....,.4<.C.L.X.I....=hU..oh..I..L.J..X.j.x_e.K.....g#......R....+......a.?.7,b..}.{s.C.....eV|>..P.._..t....t...]....7...z...yFr.....<WK..*.....d._.....j!...Gx.f.!..b..2.......v..?;..1.....J...K0..>.X..J..~.E5...>...o....&c.N1...m...`.......!d.Z..M.%..o..K.lvu...~Y.WpU....tG..0....1..6...,.K.E...r...+.7..VAz...5....5....K.....a...>.nT...F... Fc.Z.:.5..].0+...4....9.)S.|......<..2B.t:..2....`..6..k.G+..,).3.+.q..&.N.8r*p.%0..0...6[]...g.n...Z%....R..Q..T...1...6...K.{....f..r.........ix.....:U.......8....{...O..#...)...5.me8....h..3.v;.."8S5...a.FVe L#.:.e....9.=....P....3PK\
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:PGP Secret Sub-key -
                                                        Category:dropped
                                                        Size (bytes):25177
                                                        Entropy (8bit):7.963517199331028
                                                        Encrypted:false
                                                        SSDEEP:768:pNf8W3UAMbzn7Ga9GYWbosKa68iQ6pr+ccmW:p3MbeawYEotu6UNJ
                                                        MD5:8EE74E43DBB9A295148ED56E0A5D4B73
                                                        SHA1:20BD8827F8DA8F3836908D7A0EF7B3DAEA184BFC
                                                        SHA-256:A4292E3C73FBBD354BCB0BD6C68A349EFEDD521958F0AF02EC6B7D2B51C1D162
                                                        SHA-512:C6D8A51499C8B9521DE25115A10FB041D134455A50E2DDA290A24DB028073418C80E6501F00913562EC1F60929EB9016CA8535E96AD42A5B749261B19BDB131B
                                                        Malicious:false
                                                        Preview:..{...+j4G?.....Au!...^S...o...!.q.q.5.....w.K'..O....C.....J*...3....G...|..-s.....T..T...`...C..1*.<.Q*.....M...s:.(Z...R0MUq&.@.2.y..Q..v..-e.(.E{..5k.......%...x^.s`..$B.k....~[.z.%..k.>MM.s.~T".R..u._h...W12....P.J.,s..U5.@.v....@.Q[rW[y~.....U....E@0..9._ub..s?Q>.....D...xn.KY...]>[G`o.W..?.f.._......kk.(.]n..9n.......0..tHD.c`.eX.12.2..E.9..a.w4Nv...R.97.9.%eF.{..-ayV..vo.N..x.... ..Z.3....F.Y^&I]c6........I.QVb^.(.Dsi...>.T-.....@...6=.$....V:.a@b....8.|......e..cp.|.Ze.Bvb........j..y]X.xi..g^.0T,IM.N ...e...ma.<..).8.<..vi5?D..h...:.f...">m...9..y.8.).....j.?.;....e0...T.XB1~.(.Dsi..#.Y8.....VR..b:.{...V:CUva.G..8.f......?>.hv.p.Py..8i.......-..nFX.8=..7..z.|...'........H....]3..E...h.wx.u.i...{.8..M..,n...!.V."....L.DS3TW*(....Tt...d.EN6]....Yhn..oFv-......S.%(..2_..m:Z@l!.]....7........am.m.{j..%4m.....%..:cX.vc..#T.2.7>v.j.m=.*.!,$*M0..rO...<..7x '.$.C..:....y..6}-i..17.A.&.3..].ZX!..Cw..b.....n.[@b~.(.H! ...0..r.....@.G.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):8229
                                                        Entropy (8bit):7.945253177455505
                                                        Encrypted:false
                                                        SSDEEP:192:PJUO3n+a/MTQmkd126qbhCaeYfJf6ApZlkB0:RUCn+akTxOfqNneYfd6Ap3
                                                        MD5:E6163B99062D123DC8AD46752D02FE97
                                                        SHA1:1603B746B1E3DE728B330909D410A51C9004097F
                                                        SHA-256:81345CB06768D7A2B194A6C57FA91EB52778761C149EA11A579E81A8C671CD62
                                                        SHA-512:3D65592AA51C75006DA675BDB517B7F137A9955DC25E9CC7592E87BA8F4B5C104C13CBD60EFAF0BD99A26DEFF607EAEBF6ADC2D1222EFC68D8720C1BEDF9DC0D
                                                        Malicious:false
                                                        Preview:)Q.mk[Q\H.c..vxG..o.u..{.x(.&.q`..Q..Z.....K...ivf..&...7...<X.&4.....&$.a&.......L..y...[X..l+<.x<M...._.....e.$..&....dL.....~Kg..b.|k..^.g5.D"..1..px.ee....y.$c..Z..x..i.."G..r.c.S;~..kb..XS...N_.k....\mS..l-zTg1[El,....(..]:..'2...B.ao.lh...........$...."W.(c_fPs.....P.......n.]..,....v]...V.sTx..l.{"...^i).Q:..5..mw.n!...-w@S..Z..9..3...}....$:....)p..q.....~uAl.J\.?.{Q.....,..x.J.=..G8X.<3...G..i.$).........2..53F..h.qP>Y....B....... .5s.._[..YP}...H.tBb..6.`(..IVr:.L=..x..pe.1j..4wMF..S..;..2..N.u..c.@.........N...jT~...ws.....O. ....>.,.$.Cd#S..9...../..)e.m.......&...53F..he`X#E....I.....t. ,..&L...dK...[.tUx..8.`&Q._]t..U7..=..aG.y1....#.Z].....k..x/.a...'9*..P...}..&A.S.'.<..7..sF..f#|0o.X.x.,.).<..K+I.:3....J.bc.:E.m...C..."...?0[.(rH%F6]....B.....f.>s..7VH..`.....;un..s._*..A]r>.l<..x..jr.b*...t #>...{..=..|R.T5..N.1....z?...../.`ym.....w....AV-_D....C.+.`.o..K/N.u....H.e:.J)..Y....R.. ...0.Q.$uBVP']...........R
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):4335
                                                        Entropy (8bit):7.930774465507318
                                                        Encrypted:false
                                                        SSDEEP:96:DxQsQXTG37fOISY5kM2Eg4RF1xQIE7l0yos/njXG:DxQsQX6SALgmFj7f
                                                        MD5:3D4AE93834A9D8B74D5E0425C961DD03
                                                        SHA1:7927545E69B803C4FB1B7A81077528FB2FE10D1C
                                                        SHA-256:5446CBA70E304123BD2209644C26B543013A2A5DA0C0B47DB04E170BA84AD260
                                                        SHA-512:2E248C828576EB67B7BC3E8000A4F66AD10CE4F0402BC685CC62DA534E29FDC1ACEADC57BFD44063B0C02C8F9B5B767ECC6B74CBB88664CACB0044DD749CA421
                                                        Malicious:false
                                                        Preview:?.[.,......04mv.p-...X....0.&....vU....Cr....TI.~k.9?....C.8I...X..L..7E...%..2..j8?..q_%....)T3.....z...|.(..E...oL|..=L7%.n8.s.A...........<....!p....M.w=....9..G... S..!..^.........Y.t..U@..K....w(.w].k.=.*.3........65D.a..'V...Z..U.Op...Dq.....q9+..p.......\.j.....RG..h.4.QK..d....;F7*.x*.:.V..`......5.RD.=p....I.r ....v..RO...I..!....W..G(m"...[sX.S....)4.9....g]..|.......b...c.....9.2........E.Yx...Bk..3..wv+..pB-....G?{....R...{.$..H]....*Km.SW5c!.-..77...v...../..L..$......~=....y...V...U..(....V.IA...1..9>..p\..R...8P....YR?V.J...6.F..yV.c..+.....A...P.%L.. ..o..?.=..mE$...P7`.....[...:.,..K.A...z.'..9Wr$.~w.s.]..t.......)..g.?5....G.@ ....:..GO.....Z.....O.L..:.g.U....G..[h.XY...3.e..].\..l(b{....3....Y.h../G....D..N.Gt......q..b;=.mH1.....a.....CG..j....J.I..o...Sz.^..@0.h.\..[.........N.=5..J.`..C...9..IU..}..Jn....^..%i..=bjv......H.4*.w0..F...>.B......8...8..s.b........C..P^.[.....q..?...kF.....``.......1..i......I..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):3523
                                                        Entropy (8bit):7.906843629917382
                                                        Encrypted:false
                                                        SSDEEP:96:E96X+bGpMKTB6jF1DZH2NlFIYVwulsqAUuY3Bi8ULNgWy:eSp0xTUIyYUB2Z0
                                                        MD5:17FDBF3FD1461EFA7C8C1B599189B888
                                                        SHA1:D22BEE9F8D708D08C31737B3AFC4E72E1958DBFA
                                                        SHA-256:B681C75CC23CD1A5406CD4AA82205B3FACF12E679B9A46C0DF5300FCD076B357
                                                        SHA-512:C2FE8D955041951604CF482666BEC5104FAE799CDCCEBEE2CCA6D17B2C5F7AA2404375117D022B3D0A78BFB043FA7C3E276539FF96F3653B69217B1A1E969CC6
                                                        Malicious:false
                                                        Preview:.B/7.\.)8U.......\..9..%D.l....|...v5.....j.\Y.7;|...c.....U..3..r...q........j5....:z.E>..Q.sG..i.*.4cCOnrx.hx..$..].nQ<H3.'..C......5......)|.!$....1k....7..._[.r.......i.G..zQ.S...+......~8`.....B.v7.|....mS$.j.t..nG.9.H.........5..+...6FT..;...k!.L...$..!..+. .....e.4wNSay1.ai^./..>.h[<G=.5?^_......7......(../8...M5g....<...NM.j......|.]..tY.=.v..V....J..wMH..d....t...k.12........m..i.....U..4..=...(@N].....$!.^..20.Gm..:.;....(.1dNCs5(.e|D.a..QX.(hL9...Sz......:......+k.4+...Cx(....c....T.g......4.[........E/...+.z`...$...l`....~.F[j...or.....+.F.....^.4>..y...x"*P.Hfk.W7.^..;$..b..2.<>....$.8%BKl{+Y'uC.1....jJyI=.h7.O......w..S..#|.8:....;m....,...[M.k....N.[.g......C.4.-f..?9GC.In...Ah[....s..1..\..p'A.K.9.H....Y.....?...$..p.VK].e?..+.?%..n..{.<.....1..}JJog=. _V.*...WGCqAb.Lz^...Z...+.....(z.2$....4g....8.....6@..._.\.L...&../..l.k..2.u.OK.U..6.KZ.n7.2...8....!...&;.N...I.....S..*......%.R.......X..Z.3:..o..Q.rJ..-.(.cFUKmz6DSxC.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):5480
                                                        Entropy (8bit):7.931289252053249
                                                        Encrypted:false
                                                        SSDEEP:96:Gb9i7oBXsj6782ddI056LIlVbB1hf3PbhK9X3CLoTMXEP9:Gk7c8GA+dI0FN1J/1K9XyLowXW
                                                        MD5:5F06FE3762956CD64BC7A0C41C50C9AA
                                                        SHA1:D4888C9EF84A94DB8110DAAE0611DDB482D6F809
                                                        SHA-256:FE20E5C6F690A375CA102C399D8C0A1081536CE2178C93BB76A768B8ADDFADD9
                                                        SHA-512:806B7FB262AB351F8B0CC683A010F3EBE7C9FC8F6F56F787899C8AE87C5ACAE9D1AF3647D7DE4EE33975F2E5FEB89BBAF2E6F9F75186B47365A8DD8D1AAEFC59
                                                        Malicious:false
                                                        Preview:~(G..3.....p......H}m...S.zL..X...{Q.u4.bI.."G..7hW.....!...A..0.3..>d.....b?....c..`...b4.Y..q.f!.....>h..l7.}'.Z}Rw...u.s....'.t..Yo..o.|J...lY.\.......[....."I^.....y..]b.`3|e..z3..|.u...{.....g).oCE?.1..?k.j....&..W.I.\.CY!z.......1.*.y1.W.L.,.....w.aM..?d."w.(."i.....>|..c<.s...aY#..s.sp...6.h.UNb..m.rN.[.m..R.......W...f._..Cg.I..Mb..!)u?.PQ.l..3C.l.p@."d..|J.uq...&..........."..% ..=E[......*.:.q4WI.VNm>....w.a...)6..l.9.$b.....;o..qp.e*..k.p..U..'{....M.K_e..`.(K.Q.nN.I.E.........U-.K.]Zg.\..Vk..#/t>W....P.Z...(..%h.A..3....\..x.';..r-?..H;...zD.QG#t....-....a..,m...2C!b.^.a.|....y..{."..i.....2...n>.4m..zG9..q.6~..>.x.T^e..-.gB.g.fY.E.T.....]...cJE..Cg.@..<...%me/.j.....'mv.h..N.M&.CE.d.......a.q..k.n..e..fl^^(n........1.}!F..5d,|....a..|...)y../.4.(,....x@..gn..o.FGs=...`. |...*.x...:..J 6"...?}.O.X..Y......kIB.~=.....Vn.3%j/O.b2........6...@{.L......W5......*....~.n..M.::o=.......0.b..<u....RJ5....i..v.../x..n.".ei.....>b..c=.7B.Z.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):3993
                                                        Entropy (8bit):7.931113001022339
                                                        Encrypted:false
                                                        SSDEEP:96:fI8jxC/xuNhdoWOVE0LDI4JXBKCx4Pyskji6mGzyckAWtvUwhPFaMRZ/X:2/xLDFLk4dBH4mjhmZckA+UGaMRF
                                                        MD5:CDD98C6EEA3CB4AC20C27EE66086D2C4
                                                        SHA1:FF9BE31826B0563A1F20BCABDF39564C282CF34A
                                                        SHA-256:83F863B2F4168FA2C7F745CCE0AEA9A3A0885FFED5D3BFA08B4589AE855B299B
                                                        SHA-512:501A3EA9870BF73432F0B74962A6B0FD48BC4F4B8F87BAD585125970641F5B8336B8F128933059F621A2FFC0FFAF27BF76962993BB501C870A22DE30F1BD8761
                                                        Malicious:false
                                                        Preview:;T10.(w2.A?..k%fde.......3.'.....(./.GR.....dr.j..s.......p.........%....9,A\B.....H..'s..q...[.w....ul.qf......f....1.5UH.e)....L".....h.f.+....."..'.-.....HB.aL.......K...,.Zd&r.rdp[x.^...V......aL...l1.gQ.Oi...0...*....fY|.Do........7"..J.~g.Q.........s@D.!...!.$....]#.qr.......w^..R.3_H.k?....[l.....f.aP"..[.."...k.!..p.....$Y.....K..6...Q..%.pu..G'...>.N.....E..h2Mo\..$.....6.^(....Je .B.....'$..O.`a..M........:{P.sB..0.?...]n.ta...^...bD...=G_,..oj..".r.....<.zZ8..S..v..e.n..b.G........B...0..9....p%*...L.8NQN..ldK|.fP9.....23..I...C.....^.Kb,J!.M......|y....0.k.........=rD.<M .8.8....Tb.} ......NkC....w.1N..k9....Pm......s.:l>..x..g...%.+..d...A.;L.........:.Z..=.....zE[...c`q*r..qf"m...Z7l}.~..n.ck...Q..D{'P........,;..Z.+0l3......K..0gX.<H5...8.....0.03......P,y...Umr.T.Nt....Mq.......U%.~..S[.>...u.D.I*...^..C......W...a.$`....bL...:?.B.gPf.w....7CF.....cMu.1./j...z.5|s=......Kk....Y|.ZI.....U..s5..:B$.0.3....[-.`e.......bZ.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):3993
                                                        Entropy (8bit):7.909553401149177
                                                        Encrypted:false
                                                        SSDEEP:96:og4E0H3T6Le5z3s8NBo0Qu3yuN09OZ2zguAFYkrXzIuYrb:1sH3+Le+83oPud0OZ2sok7zIv
                                                        MD5:E4842879C0C0E9252C3EB837B2607E25
                                                        SHA1:ABACD64E46911828AEE249D56FDFE261F0DACE40
                                                        SHA-256:29A94DBF27EAEC3AA46DD2AB59853C0F0B37F8B3E683DA57496B899C8CC84C53
                                                        SHA-512:AC52E2CE239073882BACF4AF164A926E7869B64CD1554A38055ECF294EAAC82CBB15B9D23A8C0E8DEBFCECE89878E59751F22C2EBE1F5D2A87B617D14DFEA25C
                                                        Malicious:false
                                                        Preview:.../L.5....2...e=.I...]...g.!...</..U ...&...-..j.1vL7w..*.......Q.>.Q.@...3.....tY.....p..s.O..a..B.Mk..........f.]...F..............j.pJ..4u.@.j...^...t[...MY.Q./s.1y.i..P.]%....:.....|..E.......C..~|.y........si4..5..5......W.g....[..}*....&..^... .......).pj..k........X.m.$...L........O.....b.w...f3.\.r..R...rP....X..5.ac.fl.s.....y.b...Hh...]...R..'ug.........z.^..)2U..Q.*..Qn.z........V..q..X.].Q<.....,......r.......".gj.Yn........B.#.L...?\....&..\Q........l...#;.O..u.......k.......8.2x.2$.u..c..C.U..HB}....h.q.....8..B..R..9...ka...Rsui.+..{..N...\..5.X.I?.\pY....=......=.......).cc.]g......D.E.s.....]M........N....Zh..,?..4..^..s...X2..o@...M..4..s'.t%...Q.@c.".....0RI.e...d...L.<.....X.,...Y.......?..2..Y......]..o..IR..{}G.....w6.....=..^....l.#>..*.^....Z...n.......7......R.....e..3[../;....S...7D..MP...BG.g..$e./e.$..f.N.<...^.g.H2.L...(...[H)7....i....8z.M.->h..|X.g......5..#.@. @..8.....i[.^...;...... .}l.Lz.V......\.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1365
                                                        Entropy (8bit):7.850314212604241
                                                        Encrypted:false
                                                        SSDEEP:24:TsNmi8AIhmp1ufKff688ZdGSXUDd95bgjw9Ywss4O6noFb0mHMcDNYKHEkOW:U60p1u668srXUDdfb9Yo4fxmHlDuKkFW
                                                        MD5:B5B32E8E2F8E0BF698753337B2DA8A97
                                                        SHA1:07E38F81BE93524DD61A6B0E15ECD07F27E96ED9
                                                        SHA-256:BD8439C7C64386474D2E4FECE5356569D7C39646C5760EA1267799CB98C4338C
                                                        SHA-512:0BAE00139FF740A2DE8C3B4C4282927828E0891E29229090669E5123AFC6402DE30A073137854C668D700658A7FDC07239782A28E16D1B36D8612D4E138AD265
                                                        Malicious:false
                                                        Preview:.R.s..:.0}Y.C.4.4.vU..bU.........M/..d.>..B....\.;!.C#...Kq..#AP........<..F~......*..K...!......u(8..w...%......Q~F...|....._.p$....q....Ux.~v.3.4.Hp.....6...[.].@..4..[E..../l.O..?.+N.0...PX..".&..F.h...V.d.NQ....RGL..+.X.n.. .V..........{..K0......x........Z.....F.A.R*w...*......Mu.e..z.....M.98....n....Q..ww.u.(.Pe...9.......w....[..^..u....z........U..3...9..j.t).KS'....+X$.......k<1!.K".T........e...q....G.r..V.....p...MXV...r...8......G;A....b....k.4.....x...Td.mt.}.;..Wn.....+........w....RFL\..ta.]....{.....K.\.G.|#....b...J..,....Xg........9.Z. .Dp-O........5...=..i.4.c..Q....~.....F.R...{..'....Vk.G..x.......p(....z....]$.k|.V.*..Qe.....-..X....w.......Ml../...$./.uVq>./.'.......J5V...K.^>..g...1..'..6.Q......O.......+..)0..-...)..\....k....S.FI]2...HF...7..V[...h...!.J.i*....U.....+.N|.`.5...<....6...9.].\N....GW...{s*+s+.O.m.h.....sX.8p..y.._..d.+ .F...0m......F.K...,.U........0..Ou....Y.X..o...Z.....F.C..B...Vk....M
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):100121
                                                        Entropy (8bit):7.949554832648083
                                                        Encrypted:false
                                                        SSDEEP:3072:FXomhBcJeGZ/1924LSXxWTbuunO6eWQ5m0pK7ENoKi8mzr:FNhBcJhNTR6xyCunO5udEO+mzr
                                                        MD5:9AC4F49DF70744528419EC38CCFE7488
                                                        SHA1:A974028BFA3E785EE463C5BAC58F2534BC681DA2
                                                        SHA-256:5D05D8D15037F5262C8C648A8F5B65189551C62D48BF56C2178689B55150C421
                                                        SHA-512:F914AF93B5699EC9D2F23A31224EB50833FE2DCFC2BE7D85142C3ED090ADC304C6CC418AA3D85E6B11655C878545E4B1F76886338F1774D54D84C514D75511F3
                                                        Malicious:false
                                                        Preview:..nb.%....mJX. .#Q...x....../23..G..eq.Y....s.N......9.... E]YK.+U..?.J...u<.Q...h.x....8....D.$..........p...v".j...LsE..t......2U......L".V.....rH../0..2~.g.....F.}0......=..k...!.p..\....%h-......m..s...Y.>..N..C..f\..j{.YR..?F._..*S..f....M!1.....i..<..e~..>.wNE.|......{I.'gk.a[..OuO..b.....%X......Kk.W_....gP.I+<..=x.#..T...".g~..V..4..u.0;nc......xg7.W.....<.~....Q."I...@."wL..u/.=s..mD.]K.1R..p....K;y.P...&.....s,.../.lHN.k......7P.#rq./.....<...77. R.4_....L.Pa.T.....zW.Gfs../a.h..^.../.{-......5."..).#..BI@I..[E.c.........f.4..a.n..o.v....ia[\..b.1F@..X._4.C..)_t..t..U.....Lc...'.ksE.o.....yS.d{v..A..Qw^...dL.....5_.......W.\.....aQ..%6..)e.&..K...#.;l..D...,....g..)R.Z^..~p../..<Y.{...p....l...c .>..k.S.fxPF...H.FA..Y..n.....XS..E..k....sc.....cNC.?......:B.2:>.A.....<..Q^&.....)C...'..Va..O..%.}..Ui..V..g..^..."..T..V..+9.gK.<..g{?...r.'k..Y.il.a......@.&......J.j]..j(tZ.."G]|K.,U..q.T..I0g.8Y..&.....mc.....;**.?......xN.w*>.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):100121
                                                        Entropy (8bit):7.948827939443768
                                                        Encrypted:false
                                                        SSDEEP:1536:JzNmjsoSch4dO5zfqW/UUU3a1gikI8M7szfre6TxlTbn:BwgoPRzqvUyaVkIzIzfa6tlbn
                                                        MD5:4A716026E26F89A41947CBFB8A0687D3
                                                        SHA1:08B75395571F7F5B42AAF81794629818509DB13A
                                                        SHA-256:FE424F733AE566DE3D7EC6F4DD4EDAAA72F48FD54EC855A80396BC94438BAE40
                                                        SHA-512:02B158859879742F212128E4B9B831D4E7F5FB0DF5931850AAA0D7C199323727E226D196EE3A0BF1D6869EA8F437FAA572D738BE07CC624BA7954C12FE92D75B
                                                        Malicious:false
                                                        Preview:..Aa.%8z..q.M..X....S...7FzI.,.:.\..x....H..Ge..,;c..{L<{.w..........y.r.^.ci8...hD....~l(.,.,......D..Fg}..R.>0.....|.I.4.%.C..a.:....Z...&c..c..jw..U.}.g....)Ws\..1..<....h_...I.)....4....@h.@...a.2...p.O;..PX/W>...>|.Y..y=...h........ .'...7dv*..iP...M2u.3.Y..W...-!.tgi..].w>v..(.*.2.%.M..(.-....E..."dK.b..dk..M.1.k....m.r...U..&...M}....L...SVa......w.]C.U:8....k.Q....9T%R.N4...W..._...'.....[....6."...-,7...&P....v&c...B..L..:!.Rbz..O]n(r....{.E.^.q.I...%.t...._..'.A.a...x.J.?.$....&.f...U.:....5...."..^9W......+=i.I...>..G.............@3y8......&.........r.{.W.I!{Y..UF.....2\.p.U..K...>(.Vk;..P.my5....2...0.`.M...a.&....^N...?w.i..si.L...a....hTh...U..z.W_4,...-.W...V*].....v..d......WB.6P..b....m.} ...xb.............(.7.L.N.vG..kF....j.c.u....C...nv..>;.A.P|-cH..i.E.^.%W...E.7....L...%yA.>..;N...-.M...v.).B...S..X.FM;C.........H....[3.]e.U..r..(....Q.....(%%.F..7WE.....%..........7.l...&2[m...&.....w,}.}........nd..X~..U.pz&X..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):18128
                                                        Entropy (8bit):7.937337925839501
                                                        Encrypted:false
                                                        SSDEEP:384:o3qvgTbNPGOPbW1ug4vbcXSdly3o8gtvf65DhUun1:oGg13PS10QXSHRVs/Fn1
                                                        MD5:E7B882B17BFC8458CA25FD1512378B7F
                                                        SHA1:70BF916CDBBB8F55623C0BDDF613130429EDA8C0
                                                        SHA-256:D190E2AAF5C0B7409A52242C67F770F9111F01879D9C85366067FDAE7CDDD9C1
                                                        SHA-512:9065948D6294933D4B6416AB2B58098EC15B11E0BF62518480935A6DAC3D1A5DCB3273AA64EEDA668D45D8E2C18BF7F2E6B157CFCD18226F472CB4390C80CA30
                                                        Malicious:false
                                                        Preview:u..5..'|..A`...).A.....|...zX.];...\.o...q.2K.......y...:#.7...o{z..m;...m...u.S......:%ml...v.....>{.?.?.(......>.j....p..s..S.=....`.{.."....k..[...r4..m..H..t.....SV..u..!....#(@.v.#... J..#...F.s...>.%.:].vah.... Q.<....Wm|.&..Owa..!m..Y....u.n.......<.Xr(I.D...!..?X.3.?......z.yZ4..h.;._..p...T*.{..q..D.VM8_8...2...k..^..x..P..[G..d..5...u]..~T........Fl..5w..j...I\6;t.P.i&....L..p.p....Z{m...x._!...{.Q......fW =n..@U..L...X.1.%.Jn.....+./D5..n.;..WW{...T*.{..q..D.J$@(1..0...#o&|@....A.ylA..}..e.0u;p.|...,..y.A.Y..^M.3...P9..kQ....y..(...{N...\0=.x....25..sY.B$...$.0.....Y.pb$7f..S....$Y...%./......#.$D...p..4..FUw....`.v..?....j......'...p.Q5t.=..A.yhA..g.."..'... .......&<p8.z..>.4U,qr...{..#.NM;.S2..h.A...bn.7..Lsa...e.A,...W.Y.......da;1m)..E../.. X....."......>.tw|S.#..;.L.ms...8w.|.......9e..9...)...l|@v..x..k.e...4....u. <...;.y.^...e....[........p.Y.b....1.-......j-;.s..}.p..E*...m...H.]....G.."'rr(U.w....4.nV.k.gD....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):18128
                                                        Entropy (8bit):7.94444309424123
                                                        Encrypted:false
                                                        SSDEEP:384:y6tnQyxRNkchbFy0OWnryKO7WO95MtLQPzxLNye7bUmmj7PiPbYFIWvwoqWAikuc:y6tnQyxRZhb00Lryxb9kMzxLcSbUL7iB
                                                        MD5:0E01A258E916A2B24F105CEFF6C63F38
                                                        SHA1:002EB5BF4DD06685229207F1E4AEDDAA645B5101
                                                        SHA-256:2FA608F5005DC7D511D60D5DC1FFD831F4787D3EA62EC1DED7751A81BFBD4B53
                                                        SHA-512:E89D5FE825F06FFB98C0DA81CAF3DB818CC5D0B6F0D50DB44C5B7F4BB0736E0E37A09FB0CDFE3C226BFC98EC29EF0520201210CC75DD2B07E3D43EC80D9955E7
                                                        Malicious:false
                                                        Preview:......9.L.sh.0.8..kp...s..!up...q....@....a.......gd^.4..Nn.....{.!$E..8;.~....\.^.)<.....Gh..b.?J....wo..e:.>.+\...8P.hyyp.....I..pv....I..K..~.~....w.|EOe).Z.......t...]...0..S.J..c...._.z........?....:jN.%..r.^.'.YwI.w.n....1..&.[.:>....Dv...t..(.V...)?...5.j^.j.un....{h.VE2.2.>...K.`..ea1".rRY..N.:".-.....v...X'4..7.`FIo7.V....K^.|...L<...eC.......F..p..U=b?`..Y`.A.?.........\...,Lz.....r=...G.N.6/....np..._...K.S.4"...M.,...9.A..C..ya.H.^.{.{....~~.kg+<......I.`".-.....v...1_C..5.`N.....qx..ZM.K...U...e<..Q.E..`#b..........d?....#_>....."fm...Y#^.&...Dp..Y...njX..|m...n..v...\.}f...I.$..b.'B....Gw..b&.5.!Q...~[.jy!n......I.\h.......^....b...".{IRNo.5\R..ZM.O...O......!-.......$.?....]...)...S..X.(..u.3.#`..$......#..G.X.:"F...|n...A...T...)....V./>..)..`....HI..o&.7.t`...M7Q&*dr.zDQ..J.-N.......L..p.o..,.`NN.~.^....pM.=E.].K@....1{e...7..t.._.O..h$......._`..m........w..Yv.H.i.+tu..(9...2....H...cW.....jB..b."P.......V*t.{.g
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):14604
                                                        Entropy (8bit):7.92657363323348
                                                        Encrypted:false
                                                        SSDEEP:384:Pxcr1XU2FAVTs2PijjS9S8gNPysWeazxGjSuOx3BppKKsUgog:pwU2FAV6W9S8g5y7eazxG+XlBp/sRog
                                                        MD5:04FC1C7781DB9E78BAB64B69AC55F4CC
                                                        SHA1:4BE9397E46B5307AAAD60638E94D4460F4A58DFA
                                                        SHA-256:E7A8A6A673B36B040D2F249810D371DEE7FE17F241802C6829FA2B41CB03EE6C
                                                        SHA-512:F94A869B64309AEB3CCA362813A451B73B4D2DAAD4D409D00362BB6B07B850441EB8CC5A35C5CF5C798B2962698362D0C57F993B846C0011DB17C8154115E1C3
                                                        Malicious:false
                                                        Preview:L'..S4.b.2....n...'.......+1\.Q..}....;........<M...,R.:.....Ki..wWRp.?....Hg7...7...l..fEP..B...O{. [..[eWx..DBc.......n.Rq.f.:..........)..v..%.vT.UQg:...5Hd...}{1K.s1$Dw..%[.@y..Z$....r..a.1Y.ehf.h..-....x.....[.....H...G{M..5..S.r|.%..\...c-......P".eJV..\.).}s.j...ZFKt...bk......V:..S.n.d.PW.......8A.*...#..-......)..In...Wo>G.ufB.6.."^._...ia..b.e.I.H...zA....."x..b..L..pP..NM.A.ND..'u...7..[a..{q.x...lg.~.....eV+....{.O{. [..[..U..H...@.@../O.Is.e.i.L(..'...p>.w..(.(..e@;*...^6....$M=H.b..bc..'R....sw..[]....l..|......J...W.92..5b]&>oj.'{o.....,/...%..A@Um.?.....H"y.....V+.O......e.ry.-\..ZFVr..YDb.^.....7.zn.~.i.,...L..+;.k..).p].GL&7.i.@.!...Jl?G.d&.....d.....BI4=y}.4...Dj....)_.(XU.h..... .=0`..n.oB.nJ...2...Rm..}CUn.#..v...q6......R+..T.... .g.sx.:U.0GFTh....Q......FO.Ih.g.f.....}...Ab.%..f.6u.TL:-...m1!...85.K.y'._|..N...m.q.....n...3.;.s .6..\.[.Tl.jo.q...~..M....2...vdM.,vN..&..^....p6...*..F(.e4Y..L.V.qs.:..4I]P%....-.@.@
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):14604
                                                        Entropy (8bit):7.932930971931174
                                                        Encrypted:false
                                                        SSDEEP:384:taRE5ATAZjPhe69up+7uWaBlGT3vmLkERXGUjl:OEtMpfe/mLkIGsl
                                                        MD5:09B0B8FC4FCC1B4B94A11C375795192F
                                                        SHA1:BFD26BF86C29D817F86D3783794F7EDAA528D012
                                                        SHA-256:0D4E09AC7038224837A9B3E7B04D12C57184D83094B4588CFC6B80E9E3BBE1AE
                                                        SHA-512:343B8159C958F4590FC93F751EFAF13AC0F9600B78CF3C33465D933785ABC75AA57E90143EFC087DF76A3BB8F92606F78846E6EDB007276EFDB061314E07E6C7
                                                        Malicious:false
                                                        Preview:....e8.....NR.C..<>.WSuGe.....u..#/.F(.PE.0....bO..9.f...r..m g.4B..fy-s...TU...1>..9.^..ll\w...P..T`..T...0Y(...C.m..W.j.a..].6.c.!;..W)F....h....4g._..-.....].wb..P......5..dd.a..;M....E.}..J......s .?.K...At.G.......2.%..|eC..N.*/p....^U...;s..9-Q..rAj....t..UC...T. ..U&.B..E~..].p.&...../..b.0....[-@.i......rQ.U..3....P...:.C....>.....R.......2..3........(..8=r.-vu..R..s..'...n.d..qyK.y&...x.l.....:0..v?.. -M..?.8k...P..T....M.Q.n.e.B.~0s..V.v......'... .x...S/K.U..X...u..0D.u....V.ND..L...RF..........j~.....!.$..Nn*...h%f.......Y.w6.e..*..mjQ.3_...7v.I........3u..9....3.&". .W..UC..A.....#...RHb..^.|.7._Fx..i.#...R2J....z........D.u.....@.X5...UI.D.zQ.....o...j`.9....78.Q7..7...Z;..or.f..K@..q..{..k..s.m.3\.....j ...QN...7q..m.....1$$...^.<HC....._.'I6....0$..R.w.1....I..h.I\...`..K..i...%?..D.u....T.Uy..(.I.D<.D.9w.....Q...CY..SR.....QA.3.H.B...y.c.......{..6..9><.(M.6-_....DU....e...-/..b=.$.....8FX..*.O.D.e.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):94071
                                                        Entropy (8bit):7.944792709100583
                                                        Encrypted:false
                                                        SSDEEP:1536:EymrOaNUozSCxSXfPtrPhQHNZ6Y1/h2kvDcKE8aCGqO5/5/Jhqzcnh:EyLadznmcyLKMr/JIzcnh
                                                        MD5:3CC01CA0EE59B77D9F45B98127BC77BF
                                                        SHA1:6BF30FBBA74789C68C9CE1851DFB15A764048C6D
                                                        SHA-256:53F5EF802CF2F435B52582BDA74F7A8ABDE8BE639CC22B92A67AFD1A4A684A9F
                                                        SHA-512:DEB92D1ECC4971798DAB2A686C1E1CD33BF365617E44FE5F299851B145438F10BF6877540880ECD6BDA961D0BD3B42E824E2B4B41EAE9A37540010A2DAFEDA55
                                                        Malicious:false
                                                        Preview:+ ...-....x(...xxy.&......s..L......b@\..r....m#>.0.E.7..........".....F.O.<\.Wd.~.&.%e..<....C.'..zoU.........k...........^........TN....R(.....`.o).7A....r,].(...i>.....\......u......s..Jd.7....B......R@..^..'3Y..A.4A.........$.G........:[.Vp.:...Cx5.Iew.K......z{X2.........?yk.........B.\......S....C\4.....d.j4.1J....gx9....ii..]'..v.R..8.....;..U.J.c..].q..<.G(u.n...P.W.!....P`.......%.Q.....@.<M..p.(..Wng..Rtf.M.......hX"........Dl........g.B.....H....KG'....).f).(.....=a9.....`=...\V.M..(.....E..f../.._CG.8n......'.w.a..YR.3.....S.6O.......6/......i....^2.jf.(..'CQ(..E|}.v......v)T*.........%[N........R.]........;...`K6...j.X4.,Z....rx9..T..7{....Kb\<Z....{.7.VguC5`..... 2.....UE5.C.=..g.5..c\.=U........+..O...Z....ov.Tf....2_n(...Zt.K...X.. ).t....._..*~......X.@.......N..O.........&.JcwR...?.~a?.Av..&i.......t.$7.04.....qA..2R.-j.$.P.c.G....m#.,....aP..I........".P......,.s...?..../]p(...\V./d.J..El^4.....J.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):94071
                                                        Entropy (8bit):7.951334997163676
                                                        Encrypted:false
                                                        SSDEEP:1536:fawCW9FBApHoFsfibx7ZOdEuhgA0wK2GQGkR33wvFD9yqkhQ9F2pBryoPpGCHBDu:yOTApIFCo4thJKmGkNwvFD9YhQ98pkoC
                                                        MD5:CD16A1B6E0F5D5772CFB71427C8A584B
                                                        SHA1:57E11E6FB7106B93CA14DED63C8770F8FC0DC0E7
                                                        SHA-256:A83A1A91A13683235810ADED1FC34A9542C50AD9555A5A11528E58BACA2BFD1A
                                                        SHA-512:08138F4A92D32990303929A329740D22E789C4CAA927E008D802903DE4A66D241FC82EA6F7A5FD4F497A73C08EC2F96DB2A5BC0B97581545A15858ECDEB2A981
                                                        Malicious:false
                                                        Preview:l.Ez....f[T.D(.....1.U5..X.lx1..[l_...q.....>.%..n..T.!..%:O......Pv8......A.Sxw$....0z..-......</.a....X....xZa.>%U......\;.If.~.X......p/.ZZI....S-..v...a.{....t...........t.3.G.a[..+.cc.Z^GC8/.RHj.]L/.q kt....V....U....F..%.~%P..O...Qp!..R......Vq#...t{..sC..`..e|.)g..j....s.o./lI...v...\4._t.7.OU....x!.].@...O-..c..d.t....u...gz.......5.:..)sK.d^....-9...LZ.a.j...O.F...eg...^=...e...A._jE..U...Jq1..W.....\yw5...f{..gU.J..tg.").L....?.y.:vC......?..R.:..K.....e{.F.Z...\y..h...h.f.K..a...gw.......7.;...W....L.P\1.;/z.<.X..>......#...%.....2}7..%t.;.pk\.Dv...j{j.......k..%.J..ff..sj..D..o`.)d...H.....q.(.3qR..S....:.Y).~.DT.....r4../\...Mh..c...V.`....o..g{..^....".w..a..+F1,[X..,G..T...YFxx.VA.v8....s.bxqy2..j..".jIX..N...wz:...B..l..;$....._f..oU..Q..fh./l.......L.2.|.r9......\w.cC.Z.UI....^=.@.J...Ojd..2...DQ..Q..E..az....O..h.7.(1..:.AT...k$<...n}..z8.f....q..1..3Z....@q.r.vhZ......Wv9.........0.8`....V1..mK....D0.F)........p.+.g*p
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):18128
                                                        Entropy (8bit):7.944797255212684
                                                        Encrypted:false
                                                        SSDEEP:384:3nBWIFgwWlsaqHEFG1LBC24DCJ11fDWIFP0:XBFgwWHqHUGrCd5IF8
                                                        MD5:A022688B4FE095401B2EA8C1B9C2BF6A
                                                        SHA1:1B0A07EE9241DE85C014C99482DBAFD4B63071BB
                                                        SHA-256:6D8C7D823118F53A4BADBE80762928ACB280C2C581B9B171E60C8E91A8E2D962
                                                        SHA-512:FC4903C1A41FF57153FA932ECAFF6EC4E31072D757E3ECCEFA8C2855174D35C1122D2A08C477935173482A8848015F540707CC09C8E389C2960078FBF77A4B7F
                                                        Malicious:false
                                                        Preview:ZI3...-.h..?..!.....D...W.o..'....Db..P...c....x.d.!pq....l.$A.$..s.c.+h.F.3...O....&07oN.......q.J..rF.m..,....p,hm......A.yy{........@..|......Np}..</@...y.. |.<...Ewc....}\t.......6. .[..n.@. .4.....h..q......]..$......+.=.{..a.MS.x..g>L:..7...E(..h$7lA.>.....C.[..vG.q..,.....e`;)......1%<....R..c..7.b....hR7..00.......6p.0....ck.....}Hj.....0.T....~.....q3.,Uu.E....5.......m...uXB~...w .r.^F.t..Y+P...3.H....+.*q.Tc.....G.3...)v.o..6..... |Gx......1^j.......c..7.b.....*@..0-....7...'v_.....\.....z..|...].....Yt.....'V.8V.0H.....~S...U.t`).ZLm.6.:D.<.o.W,..5.Z...8...&v..$ec53BV.....T.L...e\.e!.6....z!}p.......>]}.....4.._.."......Oua..=+....d..].[u.....X.....f_W..."...1w.?d..6.y.#.!...W..~.G...<P..qn.:S...U}H.s.i..r.^P.x.Z6Y...$...B...k#7U,VU.........xX.l..=.../.hm.......\.1-/.....E..H.. ......@`l..0#....x...x.0.....*....(h..W..t$D.._-.s..$.....{...L3..M..L....U5...Rd..'...<C.n.,a.i...y.V.v..N...v<}.i.......p.Y..gL..x.x....<
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):18128
                                                        Entropy (8bit):7.942142524447194
                                                        Encrypted:false
                                                        SSDEEP:384:cgsWwx07N8x9CqUBDjcgYgDUsoDu1bOq1Kd1gLkKrmAoFaqmo:cGtp6UBHOgOD+BYskKrmAVqb
                                                        MD5:A3AB16DAF40335C16CA46434C21DC067
                                                        SHA1:3D62D19081B097547D0E6AFCB4900C740799D287
                                                        SHA-256:BF460831D12DF3DFF9756D47DB0935700D87F0EB300DF11E89D588343717D6BC
                                                        SHA-512:34AF97733D3A379FC74FCDDD7EC0C108EABC82D6BDE38FB3AD18DF816111E84A3D0292B2451245185056BD20C27F77F7CF853134A8391DF3FBB96D7B86396976
                                                        Malicious:false
                                                        Preview:..&.l....&.....y.l.%._...lE..M[:...2..p.....Y1H.@.....7....(.....n.C......t...*.g.w....:j..K..%...C...f.8./..*k.....^..Y.j..%~.\g:IL...s.#.]P.....,.........gf&.i..A.b....Z...D`.?.n....C..Om.yHfhOH.mA.R.hX.5...l._..........L..t....b.Y.B.e.7...*.Z.}B....5l..U.......g..-z.?.f.&e..A......T."R.y<.K*|N..A.s.h.99]...f.....:...yp*.>....j....a..y.E..e..#.vN,y...$.z...jU.&.....v..e:d..M...dh......I.....n.H.|..O.8...$.e.`....r6s.....A....-d.6.x...o&..=......Z.8L..o..!{]\.A.s.h.99].....]...$....VR}..,....]....Y.....3.U...e....3.J.....$..b.....@..4|../..A......u...-...'.....].=...{...0.....G F........K..,n. .%..!o.........[.2...x..-{N`...~.}.]].....0.....(....!.I..,....Y....B....e...>...Y.).L.X%...Fe/`......"-...6.d.............d.....f.E...].5.....m..A....X4E....@Q..i..-g...(..#:.....+...w..q*.()x_....t...X\.....=..... ....0X".2....+F......OL..u..i.>..."SA.(}"......Gf..y..0...........x........*.....j...&....t....i.cF.....r..U..$...Y..|..yJf...o&.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90427
                                                        Entropy (8bit):7.955397618043892
                                                        Encrypted:false
                                                        SSDEEP:1536:x3MI7RpvsM5hOVMlv6SVDk3ajVZk9MzePI1710/ivIaJcKhHLQE9Og1f:NF9HSOl441JzfJcK0o
                                                        MD5:D2692AE4C6AA0852EBBB2CF2742E5059
                                                        SHA1:C3D62E27986D5C93EF937442911DB03EC27C9589
                                                        SHA-256:B1F31263858FDCDC5D2E9E300EE7D834B3EAE940FD0AEF261F6B096278F73E07
                                                        SHA-512:14F0DEC4774BBE085E65EAAC2030EB6BA7E09EDCFB7289E1BC709FEBB2B9A3B70920E18B1FB3B867C0A2BC401FB5E71EA26CB039D29E6B41950948D78FF3AB9D
                                                        Malicious:false
                                                        Preview:.j..k!..+s.(..:.6.!Ul.~..@..@!..6?^!.f/.q.%..(#.......;.......e...0..9.O.$.G9..j......*.P.<..KW.T.yc.....U.q../?..k..H...)...=........]V<H.?.v.7)..p..|.."o........X..l.;}.......i"l.Dwo..lN4...>..C....?..e.:..:.......OLT.Q....0...1..~.A.o]Jw..m..[.~....#..1............I.z..&....?....B...?..]!.E......YQuA.mYx.7<.;<..y...)+..Q...<.AH..y.!tQ..(.U.{...Zjo,....)cY..Y.@|k.$5k..$.....j$....C..0.p.L.*...*..v...iG.6..{...I.7....o.. ....T......Y.6..";...l....1..j<.P..[......\J.[.(Qc.c!.02.u..v`..[^..)..S..1.'uP.?P..X)......&F...O..V..H../W{g..R.......].^J._.C..........+.Y..#.z......I.0..$.`..(..-........Q.x..e2..%...S...9G..1.D.....U.I].?zo.r:.;r..K..9..N...5.S...0.-l....gk.s.....H.\JS............oi...e....h..<QS.E...1......z...8$(w..@....p.=....e........I.......;..3s...~...1...-.0;.Y......^L.K.}.!.~&Ql ..Y...lo..[...e.k...?..y.J..r...3..Zh....D`{=.#U.....V..(.X.t`|n..D..|...]..Y...e3..7..'./.kL.Z.......y.=....m.../.t.TI......O.y..vf..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):90430
                                                        Entropy (8bit):7.954940367519794
                                                        Encrypted:false
                                                        SSDEEP:1536:UwG0zzE8cFJQTa30FkMllblkkqllcjqt4cP51n24fQ2F:UwG0zI8cXiakzllbukqllMU5RQ2F
                                                        MD5:AF0FA9086CB53844CF2510CB0458DA52
                                                        SHA1:BE23CB3965599555FE98B7603A565F4755EBF86C
                                                        SHA-256:9EF716C43A42D1477988CDAD762FC63E54A975D8030786529611EBBCB4B1D058
                                                        SHA-512:8E8BA5B3213AA6A84B25100583AA8CF68FE3956E430D309E2EF17696AFD3EDC6689A8457FDED873A6F6E0D7FE0666EACDC9F527556A32984DD9E86373DDAA737
                                                        Malicious:false
                                                        Preview:...#.D1..x.m.8#...oZ...h+.].iY..cK)\.r.Y...6.c.v.l....)[.f[...A<..nX...r*b..Y..e.....3...g......Nj...-.S{O".75...b~.Y{+8..F....y.;..........8...gx..u.Y.j......Q5..Q.;.$.uk...k.S...3.s......!..u..zi......|t.y.L..E..$......8.b.dqRr....=D....:..o^...5.l.\...K.....a..T.W...43_.N.{4}".:)...lw..g l..E....w.).W.......0....q..3.E.....*..L:....:.1....4.{.....:X......Gz.P`p&.".....y?..\BBi...<T....8...S.....F..8..t_...=z8.Z...d.....k...o.A...%"D...{y['.:9..zs..mn?..u..s...Z.......-...$k..;.V.b...g..Q(..^...k....(.`.P...;Y.'...2.4ki}>.ix.......&;f.WS....>@...d'...}d|...3..I.-#..TUE..`#t.8s..8.G..z...f.~....-9C.M.ru_..61...+4..|>v..[...w.t.........:...m....G.y...$..L..... .$....h.?....".\z..$.o.9.}?.(.y...E@L!.n3.(....wr....G....V......)(....#..IT...1o)..t..&.....0...s.A.....0K.E.,$.}.fj...b.E'.-..u..*...:...........${..d.`.e.X.h...Q..Q...(....J./....;7."....i..hD.\..k...3`.,i..qr...@AZ.ZY..<.p.R....5....A...iX...l4..X.....[.KG...n._...........>4...</...('.V^
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1838
                                                        Entropy (8bit):7.869339817853291
                                                        Encrypted:false
                                                        SSDEEP:48:qp+oB1pAYbCS5KTzgW6IdnH9ohzyM1qtNkXLabNle5758i:w+4ME2zKIdd2zbnuRle3z
                                                        MD5:FF100E7015260637D5410B60813C843A
                                                        SHA1:B8E814462752F5C884D6DE8C67F0A75031735E73
                                                        SHA-256:2BFEFBE3D1C5F3CBE6D8DB5BDFE0AF64129B66327AA730AC9AD99A04EF6A57EE
                                                        SHA-512:14F9799DE4754CD41C785571535F91B8A1E3343CCB68DFF8C340734C7AC9D2B328D39B70F65A78F2EDAE2DDE3E6BA82A0811A0BB7EE76CD3B7F390E0E7FE66FA
                                                        Malicious:false
                                                        Preview:..-.....J.owQ5.. 2.eZ..6....V.9..........=.F.V`.@S....).d........."....).\.....|.>F.n}a..c...(F$..! lr...f......!..O...,N..D.:~6.o.7.f....C.O.&4..'....gx....P.PP....qt......O$..P..<zG?..[5.P......0q.P...n(..6....\....<.........*.bD.....F.,...g.Z.....8~ju.3-~k.....`%M-J. x..../......u..L...#@..U.&ix.b.(.h......S.3,..#....as.K..E.44....q#....E.+@.^.;l..8wv...7r.$...y.W/f..Go.5r...*.o..k.aI.N.h..(.`....P.x..E&.\..K..*~#N.%.2A.....kkZ-.5%k....6.....&.....(D..u..0f.e.2.2.......@..+..n...x,.D....49;..xw_...D.Q&`.8.a......."...J7.:....."K..t..!......L..H....z.{........4...Hj.>|.8..*c$G..0=O.....`&^$.1,*s...5......o..R..-@..].6by.e.3..}.....&.Q.5-.-....|c....P.45'_../00.4...O$.D#.X...g,.`.....8.5 ....KZ.....?e..b..}.#....x....&.f....R.x...hM..J....`G#C.9,1H.I...i$A#Jwy;8...5.....!..O...s...Y.|,9.k.".........B.(7.:....gy.YO..... ...",8.Y.a..v.......=F\b/Q.(.3[.2I.U..U......"...fT..ut..'PU....,.|Z...P..c...og..&....-y/S.[U~..I...j(K;.{D.+...f......;.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1838
                                                        Entropy (8bit):7.8863342593188115
                                                        Encrypted:false
                                                        SSDEEP:48:yS9JR48ZO0863cxShhpheofkBSdp8sqLiOJpFkRGPZ+:y+JR48ZOfecohDheofRhCrZlPZ+
                                                        MD5:D25F913DC6846673BF446071952C0EFA
                                                        SHA1:C344F63F9D1949A02F87059A2A43E4FF30E05A25
                                                        SHA-256:B0105406EE9AF0767193277A56DD32142703E2751DF60003E2D76C5E7BF89BE3
                                                        SHA-512:D4371CD900D2EEF21AEB39C72C29C58AABE4E8C69D03A44C557937DC2C77706F1211803C911277617482F5FA9442FA65A4D4EF856BA593808ECFFB05D72BE2D8
                                                        Malicious:false
                                                        Preview:.....x.,......N.Ar._.~..8d..G..z..8.......?.l....N|..D..>..z.1....[.b.:.........`.K.g..!wP..........)....q.vHA..P._.Y.M.....E|/Y).$`}\.....C.....V.;.Z>...~.],&[Mz....Q.......=.z...w..(R..".e.f....}.Fw..q.7.(.4.;..o..og.[..=..?.0.......%.n..........4...7.T..VX.b......5p....`OjC...S...P.O.\.....Zc-Q'.#)t]X....V.....S.4..q..j*.9.<.]z..Q.X....;.J...}..@.....E<.M.f.."d......!' .@.H..+.Q...I?..z.+......Y;.t........}...e..O..M^.,....%bA...uU`.F......[...|.*...Ly L}.8#n^....K....\_.&..U~..03.4. FFs.WS.Y.....%..j.Y(O...a.._..5.O.....h...{&..Y..0!....y]...Fm..q.......R.k..........z...*..X..Je.a.....-}....|Rq]...M...^.I.T.....Nxm[2.x.hV.....P.....a. ...=...*.8.`..$.8..Q............<....g..1>.....S.b.X8.....Y.tw..~#0Qh.d..!.1..v.,=.....Y7.$.........}...6..X]#QE.c...B..`R....y.DNA..P......P.U....Ei}5W_w|RwF...M....3B.>..c..-....!..).0t.9...Jg....w..S....".@'.1.~..x......j.C..=3..l w......;..!.~F.....B<...........q.X.O...]PtC.o......`1A..ROiH[.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1841
                                                        Entropy (8bit):7.8799358257770615
                                                        Encrypted:false
                                                        SSDEEP:48:ySl3pngl9gmCw24/6vanZDqo8Cj0OzSODL3XnN:ySlZgbJnSin9qo8C8uL3XN
                                                        MD5:BD3627EF07867BFC989D72A1739875E1
                                                        SHA1:922736EF60F44F713B41545256B86B9265FB0BD9
                                                        SHA-256:C455363A757A08587052C65FECA55AA94F32A715DDE099B4F789B77079EDC455
                                                        SHA-512:991A95F038386BAC03E12B97F3CE48EABA665E271C629998151765F14C5445AC5BAD1148A8EB1205A6C2A8290DF6909E4A6F9A8198881C3D671043D31F4812B1
                                                        Malicious:false
                                                        Preview:.Y...v..."....)..#.)..r.X......\r?L]^.o-(]..Ji\-.....{^]._,qg-W.$.~.D|..........*...8.D....y.)....,[\.8j.".......7.....Y.{....M7._.Ev.).~.C..C..x.p..b.-....b..?,..U..v.9...<./..9^^s.l\. ?`.I........&...u|F......su.....IdAB..Yisf+N.}H+..7D........n.N.f....i..*.am...%,OQ.7aE,.....xT.....K.2...R(.W.AqG .,.M..V..4.|..d.iW...6fb.6......l.c[....x.:...n....wn.c.Za........?..&...DB...]qh+T...[,#}*^.k@...1^.......|...r.F..r..1.j#....)\Q.%-\:......;H..N..m.?...D2.J.DjM:.i.V..K..:.3..}."X../fo.*..VW.j.b.......$...G..........#p;.mnpr.m..1t....Gb.F ..y?G*M...@'h] ../.w.MS:...biG...|...f....e..6.an.... .].:c_k....Zq..._....{...F3.].M*{<.~.Z..P..z.v..y.l..6fc.j..Q.8.V.9....w..wy"C..m.G.o4'.]..8.j#....>...n.....x.....I7j_..] lz.].iA...y...O_5..6...g....e..-.hl...Au....x_".......1......Z.f.....M".3..%...2.K..M..r.\..b.fE....N[.+..\.0.;.G[..p...qd...D.;rZ.=....S...\"C..)..Fw.....G.]5:x!TC..Gw1(kn.k^&..`=...S3....{...+.l.1....k`...MH7..v-.v.....
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1841
                                                        Entropy (8bit):7.878411254288752
                                                        Encrypted:false
                                                        SSDEEP:48:e3HVEaDVVnMrk01/oK7MvSd3EqdkGnSpB57W:e3HV1DbJbK7kgECkGnAB5S
                                                        MD5:341F9D035CE28C74CA45EF8E3FA541E1
                                                        SHA1:DF0F63D7112461CACE6654782D2ADFF90D626FCE
                                                        SHA-256:82E4C78CECB79329AA3338EA3316A59119B53DF998208CCDB0E86D2290EB1DD8
                                                        SHA-512:6A9403772CDFCD83D9A5280AB32D81BA6C596F732EFAC869B415C1E04580DC474F0F2583A9196BF5D3B2E7B6232D07042059D9916943778A436D9C6DC0773A1A
                                                        Malicious:false
                                                        Preview:(.....5...`.KF:(t....20p.....G_....!!-Q...zK.b..s.f^.e..S..8...eS.I....}7..X!......y.?.s...^`......@!D.f....t..1>.%p......CZ.s.q.U...!>ca.w3...[k.~....}Fd;\]..ar.z."e..=....d..:..6.]....[4(...^.....J....UZ}W.......:m.[....@..L..>...cJ.....6c..v'....E.x......+...._..hnv.r....=.. w.q.....ML.bNmh.....#6me.>:...Uw.k..B.qCy4ZV..`7...FU.Z-.....m.D^.A.....?O`..-.x.....UK.JLv.8.J.fMlc.^{.~T..J.".a.....<.E.bZ.....0y.Y!....O.x.7.8...0....T..h#P.a....$..5m.."a...~..I..BCH1.....+7`.4 ..Nd.v..L.>Od&C...t=.7.K@..6.....l..$...&.'K.X...z..Qj.y.;0..l)@zI.&..-Q.\.g.jH:+/@_.N.....'...h..B....R....C....^.e.>.....'...._..a/T. ....'.G<j.k+.....MJ.j.}c....c<xi..&..Bu.m....{qy GF..z(...G\.Hi...d..:.o*........M$..;$.;..o..C........e..?-.C...q..[@..Q..:...XY.....x)...n...O.A.:.$...'J...V..fn..1.X..'..9>.%m...T.W...n.7-Z...sR.$.k....Sf.p....QRd>\\..#c....[.Lm.....Ds....J..V*t}x.t5.|bn].X........;...e.w..^.+KT.aq..M.. .W.#j.....a....r....O...*.F...sJ...U..~=....X..t.\.w.?e
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):4019
                                                        Entropy (8bit):7.92998069223773
                                                        Encrypted:false
                                                        SSDEEP:96:TrT59/tMk7Xud96aTIt1OdwISsb593gWQxQ6m49:fcdcaEtsdQstuW7u
                                                        MD5:F9B91714E55DE94A828B5234C8AA264E
                                                        SHA1:5F6AD896A23BD08FFA732F7CA2D02A88E8DB74FE
                                                        SHA-256:108738F037A1B343EF63B7E5D379AB0C097A9553EAE14B2AFAAB72AB4D5CAC16
                                                        SHA-512:CB18549AC00B7DDDD1A886FDC2DE30ED15B64255C4FC1676B9262AF02F53FB1DA34A4396C5A496EBE25AD19B154E4C3EA5E8B2A63FE468DCDFCE4280A2B967B5
                                                        Malicious:false
                                                        Preview:.C.*w..cS.8..*...c....E'|\,._.x. .....SH......OX."....`.<...fy.a(L.B|.JL..xk...66D...-.'.......nWUw. .v#.|.lA.;..JH($G.r./..HQ.....uX0..]>2#..p>........ .$D.q..X.{.........M...ZG.}..u..!O3\.E.....#.[........CBK.....~.S-4.@..yf.4...Cz.M..v,.....0C.....&.......-.$.h....N.pN.r..[.4/....)..G_......;O=..U06$^.qlR....A$.!Y.w...>....0......B.S.<..#5..o...dU.D..Ru..1....LA....I."!h!Q,...{.`.$..l4..,L.X{.K..."2...76U...u.&.&...U.<.?.c....h.`\[k..N.>a@.~RE..L[.....%^:..Hj3?T.r)Z......OiD-D.n....4....%....N.@.R.L.#s<1.. .....&j.....H_......7<f.l....$2Z<.....&.B..u;..7G.xq..G..nb....kT*D..d.;./..[.4.8.h....l..hC.h_.G./1..4.+..I_.....:_:.._%:.b.z>q.....*..Y.j..[.!..9....p.KG.|.:..k....Oaw........n.......4'2U.l.c..M.o..).I..qw.57F.ep.T...3y....uen.....;.:...NC../.h....8..lA.h...Xjw..(@e..P.....k!_...u.i.^.m#G......,"*B.k..Y.(....a.......{.....h.|.L.._Kr....*......o=}.......j.uH.@20.2.M....Hq.27F..$..'.%2...._y.D....7.;....0C}Iv.]....k.....[;B..T.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):4019
                                                        Entropy (8bit):7.926989042613089
                                                        Encrypted:false
                                                        SSDEEP:96:sgpZRcQAozKbFValLPCh5FeRgPzyIVh41leZ5wrQ:bPcqWOlLP0F0ECvjQ
                                                        MD5:8DB08A261DB32537A174F9A26492B65E
                                                        SHA1:165F45BB7ACF005467288F845CE2D396911850F2
                                                        SHA-256:D354554B8022057663826E49E36C87A5DED7B5BEE49408A58F17CD7BCBAE6823
                                                        SHA-512:BC41D1F263F0EDC8C4A99F6404F7725856A2F7D33FD9C7B4CB263CABAA7E424A409BF1EE22D286C321F52DC7093B393C953FF720A9558CB3D4F272FA1E3D7A1D
                                                        Malicious:false
                                                        Preview:..QRpx......7.C..V.....He.F.N..t3B^L.7.u.+Y..d&..!6..D4l...'.M.).dK|g!.Z.d...&...,.].(.&.Z....hf..Z.....T6W...Q....-..P...;..L..-.W...<.I3...........x...D.H.2t6^#.;....JH}...R.C..T...vs......flI..\`.....B..#k...&..2x.... (..TV.8.R.|..fJz~&F..j..V+..+.\.zH'Gi.E.......j..^f6C...Z.....1..)e..1..B..<\K..1.V1..........m.._@.M.=r=.l.~...zR3..UG.Y....1j.kE..!s.....9..{..-..#q>......c..#..8l..5.a.02.w...f.6Q{n P..>..Lc...=...pZ'.R..W9.....$...@3P.........;.A.Q.B@.F..Qn...6.L<.........zp..Q.UA./kbQc.tM..oN`....._...:@..b..&....E.v.z.,..[..Q.._.d..g.hA.}...D.[.JT.v..EE.}qq5}.H.r..(n...B.`.aZ:.[.XX7.....i...D:....X...*...@.. Q.B..4.[..6.Mq........kk...N...)o-. .a...s.!.G..U..[..\..4.s..c..z6.0..mK.B..j......G.....?.:3C....S_.T.C.}.xlpe?N../../I.....^.+c:.N.X]"K.....$.....D...S...o...YE.*]......U..tS..c.........zJ...H3F..n+.".h....+vz..A..y.[...SW....E...i.Q}...N....f].....5.,Bt.....k%.7..$.E.z.x.$4`t..9..L}...h.c.zM6.O..6\K..[..v...C,.k........
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1413
                                                        Entropy (8bit):7.834125378365216
                                                        Encrypted:false
                                                        SSDEEP:24:6BsrVTwEjewZIfJlfQiUJfStpl3RNkbb0ywwhQkMFI/43P77XHjSwZDUget4:nJTwEfWJJZtrXGb0ywwWkuHbegG4
                                                        MD5:04EDB9EC7BFF72A26EFA63471F400E99
                                                        SHA1:D00052B99104B446DA0BE7538C407E00E1ED7F03
                                                        SHA-256:A84A7CEAB4F38B7103AA6B67329F0A76B3287CDCD8FFD9CA917C3F593D801E25
                                                        SHA-512:1C7415CE378B27B8A4098BC48E216647370094554DC737BAAC126A2B62D7922449EB4C4B0B70EE484E7AFA765BA04BE704D1A2AB759C630B48FD017C11C5F22A
                                                        Malicious:false
                                                        Preview:......!.{.....D(X.i.#|2.w.......>...=..:.....6..R..mG+.(a0...k.]..s6!r.z0.m....>d./....F.&..wG"...\&^[[.u~#...9.6.2.Ff(.>..dTy8..F-.....P.^KY.U...~...)vn....2...Y4....a....s..-w;..p...z....8D......m..L+Vgb.F...U.............7~/....i.[..4c/5..=.C.)..*6..z.....]....f...til[O.iq(...(.*.f.%e..>..rFhq...:.....^.Y.P..@..~...erb....v.....Pp...q.I...zE.gO..S.H.n>..SPZH0&..cR...:Gh..W.......?]........xk}...9.Z..<f{+.4u.l.?..*<..3...D.w..?.`...t$J^\.ycd...=. .5.J(Bsj..'`H|.I.+.......B.J.BH..*...k?-....=.....P}...j..Z..{De..}|f.*Nj.<]e..[C....RA..$.b..i,.C7.Xk.......yrr...r.P..a?7{.Px.0.@\.<-.34.....y..$.[...}(NW..q|*.PU4.1.|..{,.{..t.`8...*....K..>L.Uc..;...+|h...s.....Pq.].5.[[..b....Pi.....;RH..N57.'w.. 0h....~.:...<5.........[v>....w.Q..0sje.W_......<g.39.....l..$.k...-ftSP.".N.MN..{./.]g<.x..hGi!..Pe.......Wi.UU..0.I.jIh....,....Eil...v......KG...A..,.....et.h.....DR"..B...x].F-P[..~s.. ...Gk2...'.>...q'/~.39.`.'.........!.]....c...|,.?7.<0d.MN..*
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):2983
                                                        Entropy (8bit):7.919163034225546
                                                        Encrypted:false
                                                        SSDEEP:48:QfidpGWF60/Og0kyu5dpDtjUDyN5HJxHVAkPPDxh99Hs4aIxKCGDDX1+v:SWN/065dpBjTxHVAm9h964NGDr1+v
                                                        MD5:FC3C1CC084B6383D3BAA8F2C0D61E267
                                                        SHA1:6F086CEDA57D56CB520F4BF7ED6CBB1FE0D8F261
                                                        SHA-256:F4E100767E877657B4EC8D76D9F740A2B904A02497EC1F16A070FED151001265
                                                        SHA-512:49BB922B4D55FA6F96F44B4D171584C86BE168188B2A9786A46A823AAE3E80F30BB65AA310870DCDF0D63CD2C107045724045A2D96943B24800494D973411BDD
                                                        Malicious:false
                                                        Preview:5I..5....]........xD.@.Cn...!..C....I........0.....zyx..GT..$.TY-e...Q.k.Q...H.>.vIM.IY.w s.F@.L-Ib.2.x...K.!{Q..:..D. .>.K.N...3...[p..Ad.U...."....r...f..-.....7..{AC...@....K.3...,..../.].'..N.`.W1....k..|.(.......{o."g....R..%.M^t"..V.Sf.....I.l.w.~.....U...../Da-.2.u....(j...n...B./.,..\.Y...1....RqF.Ox.@........y..#.AIa#...7..:[J...$..b.km......:..F...1`....k;o..............6B...(....P.H>.]Xb*..H.I..P.....f.wTE..[.&N.....aSa`.7.u.....,....=......$........H...<.....Hr..Tk@]..Ea....&...).XIl6...>.O8]K..B.!.]......9?...c....D.%.......5..jD:.4.....F.,)...+K......&w...~-#...}.u.w.jSL.=..(Y...9.,Whl.>.y....nv...t..@..!.q.W.I...q....Nz..XzQF....$....i...<.AI`*D..i. taC...@.=.T.?...0..c...+A..!r_. j..@Elt.a0.5.?LI...."42..V..9.^Z`+..DT.....K.G.f.MX_....i}.....3T8".:.d..K.uW5Z.+...Q..>.+...s.C.U.....^~..ZoPz......x..<..'.P.C+...=.F>\........m.nA...T...x.)f....V......"..J...... k...c.."....I.8%.UCu5...=Fc...}...#.M\F.Q7.*L..ZJ.2.gw.e..1#/...Q..=.
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):4737
                                                        Entropy (8bit):7.93886823968107
                                                        Encrypted:false
                                                        SSDEEP:96:vQe4K4WySytsG3TIvhXm+TTCN6a9PwTjzdpCEMYzEUnohQkY9Qxy/:TMS/gUHCN642jppMnEohQ3Qxy/
                                                        MD5:7F6443500E20DB6596AE3AB118F552F3
                                                        SHA1:0F21BA4C1B76CD38D15E9F3CE0C9FC2CD74B69FF
                                                        SHA-256:95A1DD05CFE40D4CE59E69585476D8E8239DA6F31CBBB30AD9C07AAEF957775E
                                                        SHA-512:24A55621F4A681959673FE0A543B1808B5584EEC97FDD54F190E0154DB42CAAA9DBF4A267FE90D75A12B688F6B044B72163837C7BF9039D7B9541199EC5E5BAE
                                                        Malicious:false
                                                        Preview:.......T_...yK..@....1..Qi"_.X{.>.M.u.}.oN..uT..gB..OW_....".Ck../j.]*.........anA.....<B.o.kG'....p*.......H..S.........A.V0..f>B`p.r.g.6&[.r........dJ..$...A.S[.D...z.X..^...r.lQ@Xl3....FCq...A.ps.U...&s...~e?.R.`....i.......w..i..6m.........-..zoU.Y...b..p..=~.G...........C..Z....B.....O..,..q3].r.|.`.?'..|.........yE..k.F...7k..T.N.;.Q.....@9=m.[.n...a..(...8.[.'e.5n(Qs5[.(...^.c...=..%...m.C9..&k..z....E....| U.K...v..<..,o.A............^...A.....~..K.......`4Ke..&.{.%$L.g......dW..d.L...:~.O..T9.P..P.D.p(~.Z.i.6.o.I@...9....]q.2..m.?...........{......N.Hr+.}6.O#....H.^}.....Z.........,o.A.........B..H...........K..2..`4\.z.(.{...Z.a.......uu..>.O...-e..P^Ki]n.l2.|.M1.._.v.......G.....>.<.)K..yZ.D._......Ai.......a.Rp...a..w...[.jP.4!......|..7.%?~.K...........A.....lh........R6..2.]ux.h.}.<iz.g.......}F..k...%..c.I..9(.Y..N...3....-....p..b.[..U.?"....VZ.H4.d..(.. ...s.......v.H~..oM.A.....)....azC.q...bD.Z.Fm;.`...G.....J......
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):3638
                                                        Entropy (8bit):7.925391374347657
                                                        Encrypted:false
                                                        SSDEEP:96:kLlBgU8VZxJlzS8HAKBRnTsFvbSRqh3VsOh2pMg/:kL7gU0zrzS/LWRqh3+Ohgb
                                                        MD5:41C1A434F6521B3284F5A50BB616CFFD
                                                        SHA1:5DC145E23ED6F6AEE210C5F142D4B417F7D5DE41
                                                        SHA-256:37B7436F3B67D01ACCA4E9629C821DC05E2159FFA4F8589F3989FE5FFF245B0A
                                                        SHA-512:2A47D06C87C9CA1FFD3EA5E051A6AE4E73937C68EBA82034B037519B60D98250C3CC08CEE797F2391F9AD20452CDD924F023F9CE9CF7DEACF0CB4B12B37259BF
                                                        Malicious:false
                                                        Preview:+`e.3.R.\.UTY<N..~."...(*......{...".*.[.'.....G.......-.<.c..L.L.}vF..W8.....T..zyBa..j.uN!.jJ........H.n..<?...3.......)y..FhFK..1,.._X..y...|......FA..h..q.j.if..i.'_q...._=./...o..}.),.HY..N.J.......t.]L.3N.....C~,S.v.#.`^y..M.dq..Y.....R..{m.%.+Y.(.>..0....nr...\.r..u1.../..k...)v..Ty.W..<3..WV..0....r...DBM..g..50k.|2}.Y.iOq..D.Vg........k.Z..#".?@..._..j"(,...l1w....F.[.x7JWF6.bD{L.V.tw...a.....T..4m.7.bb.>Lr..!.... e..O.b..l'...%.....}}..rY.r...;%..J...:...i....J....u.X~?..&+}.L.:Tx..F.Wf.Z.....E.c..tX.>q[.>..K......wF..98...k....{rE>M,xG/.0g`G.v./*M..A1...6...",&..e.*.R..!....Tt..Z.'..p%.Q.(.......j}..Fo.I..;2..J...4...o.....JL..W..%ey.a<u.W.'.,....i,.A.X...[...........i.R..t.K....@..9.C...aW.!.,N).N7.`Hh].P.F}....|.......53Rc,ci.(Lm..4.... <......;..q..8.%..F..`{...3aE..YK...e......N.....\.Y.EJo[08.D)w.R.3^z.H.Iw.......J..v..F..X....6..w....../8..\..]N.F,}.U0`1.d.AJdL.s.qy...^m........qs.c+nx.$.y.[o....>......I..yk...!
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):1252
                                                        Entropy (8bit):7.823634451534835
                                                        Encrypted:false
                                                        SSDEEP:24:AAxt4VXJXAYTLHyRymoh0JukNpbHZQMm6Q2c1PmHwVlTjXIiPFlxFC7/:/tOXJXAYvHmNZQMmOcgHo9XIiPh4/
                                                        MD5:2BD4916EB29D599DB7D52053FFDAEEC5
                                                        SHA1:3BA827EA13ADEAEE94EAD7ED210EE8299B454519
                                                        SHA-256:DA58FC0F6F3AE12466667222F71190E0784655C09E931CEC3BA4C4D8492CE02F
                                                        SHA-512:6B06B2F300D0C3C5304196278938703B7245A99A7742239EA19C477354CC04D7E96A5E7A523604AB2664B629284C798F0CE1810FF2172C81CFAE4EE927A76003
                                                        Malicious:false
                                                        Preview:}j..}C7:...1....[..IX..pc..H.^..B..I&...d}C.7.9)c.!..U8?...J..#.X...........].;......b/&u.`.....M.n.........#r.p.W*5...>.l.N^.hk;%C..M..-...... 8..b....YYl.....e0P..A.$....8t..I......\.D<....n.h..$.Xm..i....0I71]'9............R.f...........G.;.....v/%..O..5......7V....2'.P._dT...".E.vI..w.%V..+...B.......qn..W../ER ..W.1i&V..\.8..S...[... KRP!...e...k....m4..N..z...c.e..CE/i~.y...._....E............\.1.....{`x.~..ke.N.u....Yc.z.w'.N.Y?*... ......*w;8].X\...h........(..m../D[M......n7I..\.o....!Mi..s,l-S...X..S....3...X.8...}C....;..O..........Q..!.\............P.&......~4.f.H..).X.v...tV}.P.w'.q..WS...>.!....!u&#\.F....).............Q8.....[.....m;]..A.0........*E..C.o..3.u.....9..3h..GB8T...)...%K..._&.......B.z.E.........c. ......e().....||.<.F..........N.H..y.....[.O.mh.s,.0G..o..h......*`..!\..f..>....WR;P..Z.4....$z.(..T.!l....!....U..H.|..l....ME.D......z........K...X...........R.<Z.....7{`x.~..bl...q..Q04...6h. ...z
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):24
                                                        Entropy (8bit):4.584962500721156
                                                        Encrypted:false
                                                        SSDEEP:3:n9Jv6PGkE:n9JidE
                                                        MD5:C6892D9A91B751FAB01E0EDE81C2F9C4
                                                        SHA1:055D20267D8F822777EC4AB2F28A72F27461ED81
                                                        SHA-256:9AB23CEEB90952CD28D5F56C30919486ABBED14F64ECA0C25FACA62FC7EBAAFB
                                                        SHA-512:D3BE6D38E3FD2ACD64B4145754CC5F43FB11D70B743213E5CECD6D8E741A65575DDB70EFBF3E2F78CE8FCBBDAF61EA585E8FD3405FC4814B8CE0727B083DBF80
                                                        Malicious:false
                                                        Preview:6....$n,._a.....N...+.yI
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):24
                                                        Entropy (8bit):4.501629167387823
                                                        Encrypted:false
                                                        SSDEEP:3:OVq33Dpg+u:OA331ju
                                                        MD5:C5ABC76DADA8312E55D7A2E024D5B874
                                                        SHA1:F743A774CD8CEB18BC295047F18AFC1770324680
                                                        SHA-256:9BA24264189C59AE935BD4B19FCE463C4F1165F1922A80ECA0E1D439E556F726
                                                        SHA-512:C1B9DDD52D4ED4E5F3F1BFB26A9A2EF46ED1F69A22D4F3B5993840BBCBF74CB0FAC82511FC2DFABFFE057A38C3B9B544C10F0D81C1476C01068EDF4D950DDC88
                                                        Malicious:false
                                                        Preview:%.{v.~..R...4..E%...Ut-
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):24
                                                        Entropy (8bit):4.334962500721156
                                                        Encrypted:false
                                                        SSDEEP:3:gYnoFSQ:gK4
                                                        MD5:3CE335BCDEC1924E22DCF8DEC1511F0A
                                                        SHA1:EC59B450F8E49047D9F8A8675F0D27764D47890A
                                                        SHA-256:F65E3206C7F96ACA86086BFD1FB790E6D54F7E9A85377AC20388FBB5C5083958
                                                        SHA-512:25F0A8CB212F1E3CFB2E7F92CE68905252CA8396DE69F30429BCFA0232FD69F26BC590C5AE6A68A76FD87BED310249EF32B2CD1B3B2B7460281BB492504E1E58
                                                        Malicious:false
                                                        Preview:l..<.!. ..`.k'Xz'@@.T6.u
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):24
                                                        Entropy (8bit):4.501629167387823
                                                        Encrypted:false
                                                        SSDEEP:3:Mtgb8cX9B5:Ms8cX9B5
                                                        MD5:6DB1B6FB5E4DFC1B7456D62D97BAC937
                                                        SHA1:1FAD9B307FD6A9CC0C98C96F503D3D08825405C4
                                                        SHA-256:79ABCB5555F989516C53112D45983AC62BBF70D4F7411AD81B79EE645A7172F7
                                                        SHA-512:EB3436619D51BC345D98432D557D77EBC6637117A2EA8DD696886683324CA7327E46AFA6E752375472C17C9C9ABAD5EEC8F14E36EDBADD6BCCC8B113B45E9E27
                                                        Malicious:false
                                                        Preview:Yx...V.fbZY.rme....%..
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:Unicode text, UTF-8 text
                                                        Category:dropped
                                                        Size (bytes):1435
                                                        Entropy (8bit):5.1257650238363635
                                                        Encrypted:false
                                                        SSDEEP:24:rySsCI0vCFjtp0SiKO2xU3pmcozlk7NrFA3RHeA7ZoQXPHuoiKEbWshv:zImCFpWrOU5Mze7ARj7qQXPHrN4Wg
                                                        MD5:950FFA15678127DF5213D9782CB0267D
                                                        SHA1:0956493940614DFA885E7EB3F182D5B2CA11360E
                                                        SHA-256:7AF4B13B0A82D55765E2C6F3EBDB849B397C88B4AB8A18998D57C3A668A2904C
                                                        SHA-512:5FC1E4EDCF6E6E35009D429BF89ABAC9624CF17B580F266D9F72C88F7E424944AE815D1730C0351F0EAE3FC649DD7A7E7609FB6F7F93017E7289124DDB307E16
                                                        Malicious:false
                                                        Preview:.# .. Ghost Alg.ria DETECTED ....Hello idiots , we are Ghost Alg.ria!!.You have been controlled. Your systems are not secure :)).Do you want to get everything back? .If you want to return it, you just have to pay the price here..## .. **Stop**.- Do NOT attempt to tamper with files or systems..- Do NOT contact law enforcement or seek third-party intervention..- Do NOT attempt to trace funksec's activities...## .. **What happened**.- Nothing, just you lost your data to ransomware and can't restore it without a decryptor..- We stole all your data..- No anti-virus will restore it; this is an advanced ransomware...## .. **Ransom Details**.- Decryptor file fee: **0.1 BTC**.- Bitcoin wallet address: `bc1qs4ca3m5g248hmapmm3npyt8yywf0we5tx4ds2h`.- Payment instructions:. 1. Buy 0.1 bitcoin.. 2. Install session from: https://getsession.org/. 3. Contact us with this ID to receive the decryptor: 0538d726ae3cc264c1bd8e66c6c6fa366a3dfc589567944170001e6fdbea9efb3d..## .. **How to buy
                                                        Process:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1280x1280, components 3
                                                        Category:dropped
                                                        Size (bytes):190924
                                                        Entropy (8bit):7.824460546886957
                                                        Encrypted:false
                                                        SSDEEP:3072:L8BsSiJS7n//hN7aI+j9eZCuqkNr91vbGTT6xhA2ag2mdMIiTSDN053/yfF7:83iJu/hT2QdqkjMR2aUVR02V
                                                        MD5:29ED5D8C3486D16458A5F8BCC5FF9A32
                                                        SHA1:AD83CF0C6A9DE389B987C82BE65C8360D55360C3
                                                        SHA-256:F7F82A7E4F0D77C684B4B8D5596DD8764C67B1AB319F70773907A9B4F2A51131
                                                        SHA-512:A9FDBAF4625BC0E6B7CAC6D3CEB11EF9CB39012F8EF5D66C4429818CF9B8A92B6AD81B4E676F4D5C00813D4AC69F865634DEDDC4FE806B4A02FBC7D504614240
                                                        Malicious:false
                                                        Preview:......JFIF................................C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222.....................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?.......'.p...:..z...~.(C.@.C....'<.....g.D.db.............n..By...a...Lp..(..bJ.9...\E.DC.......84....).(......0:...2!.j......(..I......Ha..Ld.(.2..9...R.....(.x.^..4..i..j.L....p0.e.w).....@.. .9..b.Bm.....Oj.........I..............A@..<#.E......v...@....4VQ.F.1.6..(...q..8.P.R.*IaLF-..f.1e..}.jl.B>I.....(.......P.@....P...P.@....P.@....P.@........r.Z....Uu...}
                                                        File type:PE32+ executable (console) x86-64, for MS Windows
                                                        Entropy (8bit):6.240421044984737
                                                        TrID:
                                                        • Win64 Executable Console (202006/5) 92.65%
                                                        • Win64 Executable (generic) (12005/4) 5.51%
                                                        • Generic Win/DOS Executable (2004/3) 0.92%
                                                        • DOS Executable Generic (2002/1) 0.92%
                                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                        File name:fMDYks4W2a.exe
                                                        File size:5'447'168 bytes
                                                        MD5:54e383ca658ebd3caaf586f032f1c401
                                                        SHA1:bc013aace5491c65a869e944123a4344cea6c1f0
                                                        SHA256:b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb
                                                        SHA512:4d10c2f888b5f56b59341e1dee5c53f56f2d81a9034eda36182bfd04246274d1fdee85b3ceccd5677ae8608626c2952ddd30fbe730dac54e405983c2a35fe51c
                                                        SSDEEP:49152:UTyQOnGEoOozdSv3U4Yn0+U0vN52S7aoRPWicuRX3EYqDqmjVNiIhnU/hHYBWZh0:KSv31WaZlah4q1W61nH/a
                                                        TLSH:E5462A22BB6A99ADC49AC0B0835687B2697134CA0B3579FF44C446743E79EF42F3C758
                                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................p......X.......X.......X.......X......(.......................lX......Rich............PE..d...;Fug.........."
                                                        Icon Hash:00928e8e8686b000
                                                        Entrypoint:0x140364dfc
                                                        Entrypoint Section:.text
                                                        Digitally signed:false
                                                        Imagebase:0x140000000
                                                        Subsystem:windows cui
                                                        Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                        DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                        Time Stamp:0x6775463B [Wed Jan 1 13:42:19 2025 UTC]
                                                        TLS Callbacks:0x4034bea0, 0x1
                                                        CLR (.Net) Version:
                                                        OS Version Major:6
                                                        OS Version Minor:0
                                                        File Version Major:6
                                                        File Version Minor:0
                                                        Subsystem Version Major:6
                                                        Subsystem Version Minor:0
                                                        Import Hash:ce5f91eb3b1ebc7df7d7ab97a153e7b7
                                                        Instruction
                                                        dec eax
                                                        sub esp, 28h
                                                        call 00007FB1F4E69B98h
                                                        dec eax
                                                        add esp, 28h
                                                        jmp 00007FB1F4E697B7h
                                                        int3
                                                        int3
                                                        jmp 00007FB1F4E69F38h
                                                        int3
                                                        int3
                                                        int3
                                                        dec eax
                                                        sub esp, 28h
                                                        call 00007FB1F4E6A200h
                                                        test eax, eax
                                                        je 00007FB1F4E69963h
                                                        dec eax
                                                        mov eax, dword ptr [00000030h]
                                                        dec eax
                                                        mov ecx, dword ptr [eax+08h]
                                                        jmp 00007FB1F4E69947h
                                                        dec eax
                                                        cmp ecx, eax
                                                        je 00007FB1F4E69956h
                                                        xor eax, eax
                                                        dec eax
                                                        cmpxchg dword ptr [001A044Ch], ecx
                                                        jne 00007FB1F4E69930h
                                                        xor al, al
                                                        dec eax
                                                        add esp, 28h
                                                        ret
                                                        mov al, 01h
                                                        jmp 00007FB1F4E69939h
                                                        int3
                                                        int3
                                                        int3
                                                        dec eax
                                                        sub esp, 28h
                                                        test ecx, ecx
                                                        jne 00007FB1F4E69949h
                                                        mov byte ptr [001A0435h], 00000001h
                                                        call 00007FB1F4E69EEDh
                                                        call 00007FB1F4E69C00h
                                                        test al, al
                                                        jne 00007FB1F4E69946h
                                                        xor al, al
                                                        jmp 00007FB1F4E69956h
                                                        call 00007FB1F4E69BF3h
                                                        test al, al
                                                        jne 00007FB1F4E6994Bh
                                                        xor ecx, ecx
                                                        call 00007FB1F4E69BE8h
                                                        jmp 00007FB1F4E6992Ch
                                                        mov al, 01h
                                                        dec eax
                                                        add esp, 28h
                                                        ret
                                                        int3
                                                        int3
                                                        inc eax
                                                        push ebx
                                                        dec eax
                                                        sub esp, 20h
                                                        cmp byte ptr [001A03FCh], 00000000h
                                                        mov ebx, ecx
                                                        jne 00007FB1F4E699A9h
                                                        cmp ecx, 01h
                                                        jnbe 00007FB1F4E699ACh
                                                        call 00007FB1F4E6A176h
                                                        test eax, eax
                                                        je 00007FB1F4E6996Ah
                                                        test ebx, ebx
                                                        jne 00007FB1F4E69966h
                                                        dec eax
                                                        lea ecx, dword ptr [001A03E6h]
                                                        call 00007FB1F4E6A248h
                                                        test eax, eax
                                                        jne 00007FB1F4E69952h
                                                        Programming Language:
                                                        • [IMP] VS2008 SP1 build 30729
                                                        NameVirtual AddressVirtual Size Is in Section
                                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x50021c0x154.rdata
                                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x5060000x289e0.pdata
                                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x52f0000x6104.reloc
                                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x470b100x54.rdata
                                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_TLS0x470b800x28.rdata
                                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x4709d00x140.rdata
                                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_IAT0x3780000x628.rdata
                                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                        .text0x10000x3760cf0x376200f7e659d6dfd9ffbc06c4a31b18b09039unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                        .rdata0x3780000x1898ce0x189a0027221bb677cf55f57a3e0fe796a93dd8False0.2634330839155287data5.391791551784191IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                        .data0x5020000x33100x3200e742c9956fec03dfccb04e1e894c44ebFalse0.16015625data2.367932203376688IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                        .pdata0x5060000x289e00x28a00796c149818f71c682c2da5b8d1173d07False0.5018149038461538data6.412273022093024IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                        .reloc0x52f0000x61040x62002dcdc2a263dcbf3d235f7dc0ca538123False0.42346938775510207data5.443102552348018IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                        DLLImport
                                                        api-ms-win-core-synch-l1-2-0.dllWakeByAddressAll, WaitOnAddress, WakeByAddressSingle
                                                        bcryptprimitives.dllProcessPrng
                                                        kernel32.dllSleep, GetModuleHandleA, GetCurrentThreadId, GetSystemTimeAsFileTime, GetOverlappedResult, FreeEnvironmentStringsW, DeleteProcThreadAttributeList, CompareStringOrdinal, GetLastError, AddVectoredExceptionHandler, SetThreadStackGuarantee, GetCurrentThread, SwitchToThread, WaitForSingleObject, ReadFile, GetSystemInfo, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, SetLastError, GetCurrentDirectoryW, GetEnvironmentStringsW, GetEnvironmentVariableW, GetCommandLineW, SetFileInformationByHandle, SetFilePointerEx, GetStdHandle, GetCurrentProcessId, WriteFileEx, SleepEx, GetExitCodeProcess, QueryPerformanceFrequency, PostQueuedCompletionStatus, HeapFree, HeapReAlloc, lstrlenW, ReleaseMutex, GetQueuedCompletionStatusEx, FindNextFileW, FindClose, CreateFileW, GetFileInformationByHandle, GetFileInformationByHandleEx, FindFirstFileW, DeleteFileW, GetFinalPathNameByHandleW, CreateEventW, CancelIo, CreateIoCompletionPort, GetConsoleMode, SetHandleInformation, FormatMessageW, GetModuleFileNameW, ExitProcess, CreateNamedPipeW, ReadFileEx, WaitForMultipleObjects, GetFullPathNameW, GetSystemDirectoryW, GetWindowsDirectoryW, CreateProcessW, GetFileAttributesW, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, MultiByteToWideChar, WriteConsoleW, WideCharToMultiByte, CreateThread, GetProcessHeap, HeapAlloc, WaitForSingleObjectEx, LoadLibraryA, CreateMutexA, DuplicateHandle, GetCurrentProcess, SetFileCompletionNotificationModes, InitializeSListHead, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, CloseHandle, GetProcAddress, GetModuleHandleW, QueryPerformanceCounter, IsProcessorFeaturePresent
                                                        user32.dllSystemParametersInfoW
                                                        advapi32.dllRegQueryValueExW, RegOpenKeyExW, SystemFunction036, RegCloseKey
                                                        ws2_32.dllsend, recv, shutdown, ioctlsocket, connect, bind, WSASocketW, getsockname, getpeername, getsockopt, setsockopt, WSAIoctl, WSAGetLastError, WSAStartup, WSACleanup, freeaddrinfo, getaddrinfo, closesocket, WSASend
                                                        secur32.dllApplyControlToken, FreeCredentialsHandle, AcceptSecurityContext, InitializeSecurityContextW, QueryContextAttributesW, FreeContextBuffer, DeleteSecurityContext, AcquireCredentialsHandleA, DecryptMessage, EncryptMessage
                                                        crypt32.dllCertDuplicateStore, CertEnumCertificatesInStore, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CertAddCertificateContextToStore, CertFreeCertificateContext, CertDuplicateCertificateContext, CertFreeCertificateChain, CertOpenStore, CertDuplicateCertificateChain, CertCloseStore
                                                        ntdll.dllNtCreateFile, NtDeviceIoControlFile, RtlNtStatusToDosError, NtReadFile, NtWriteFile, NtCancelIoFileEx
                                                        bcrypt.dllBCryptGenRandom
                                                        VCRUNTIME140.dll__current_exception_context, __C_specific_handler, __current_exception, _CxxThrowException, memcmp, memmove, memset, memcpy, __CxxFrameHandler3
                                                        api-ms-win-crt-math-l1-1-0.dllround, pow, __setusermatherr, truncf, roundf, powf, exp2f, ceil
                                                        api-ms-win-crt-runtime-l1-1-0.dll_configure_narrow_argv, _initialize_narrow_environment, _seh_filter_exe, _get_initial_narrow_environment, _initterm, _initterm_e, _crt_atexit, _set_app_type, exit, _exit, __p___argc, __p___argv, _cexit, _c_exit, _register_thread_local_exe_atexit_callback, terminate, _initialize_onexit_table, _register_onexit_function
                                                        api-ms-win-crt-stdio-l1-1-0.dll_set_fmode, __p__commode
                                                        api-ms-win-crt-locale-l1-1-0.dll_configthreadlocale
                                                        api-ms-win-crt-heap-l1-1-0.dllfree, _set_new_mode
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Jan 12, 2025 18:48:59.033802032 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.033835888 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.033894062 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.045954943 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.045968056 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.626137018 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.626265049 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.629947901 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.629959106 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.630373001 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.677300930 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.681982040 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.723340988 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788276911 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788352966 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788400888 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788422108 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788460016 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788471937 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.788491011 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788531065 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.788552046 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.788894892 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.788949013 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.789019108 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.789026976 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.789453983 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.789531946 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.789540052 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.802532911 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.802707911 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.802716017 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.849172115 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.878628969 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.878736019 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.878786087 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.878818035 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.878829002 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879086018 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879141092 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879164934 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879189968 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.879199028 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879210949 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.879425049 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879482031 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879518032 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.879525900 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879582882 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879617929 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879620075 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.879631042 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879654884 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.879682064 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879714012 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.879714012 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879725933 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.879838943 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.880382061 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.880503893 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.880542040 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.880573034 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.880593061 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.880599976 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.880611897 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.927284002 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.927293062 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.969681025 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.969702959 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.969726086 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.969793081 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.969834089 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.969834089 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.969847918 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.969858885 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.970654964 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.970674038 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.970702887 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.970725060 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.970731974 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.970753908 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.971626997 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.971647978 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.971687078 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.971694946 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.971719980 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.972528934 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.972548962 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.972593069 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:48:59.972599983 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:48:59.972609997 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.013395071 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060209036 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060225964 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060286999 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060442924 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060442924 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060442924 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060461998 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060501099 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060866117 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060884953 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060926914 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060935020 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.060964108 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.060981989 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.061613083 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.061631918 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.061669111 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.061678886 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.061707973 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.061722040 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.061872959 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.061892033 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.061923027 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.061928988 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.061958075 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.061974049 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.062799931 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.062818050 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.062861919 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.062870026 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.062895060 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.062902927 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.063622952 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.063642979 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.063687086 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.063694000 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.063719988 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.063739061 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.064464092 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.064481974 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.064533949 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.064541101 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.064845085 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.120985985 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.121062040 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.121083021 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.121098042 CET44349709199.232.192.193192.168.2.6
                                                        Jan 12, 2025 18:49:00.121146917 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.121573925 CET49709443192.168.2.6199.232.192.193
                                                        Jan 12, 2025 18:49:00.121596098 CET44349709199.232.192.193192.168.2.6
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Jan 12, 2025 18:48:59.023222923 CET5022753192.168.2.61.1.1.1
                                                        Jan 12, 2025 18:48:59.029980898 CET53502271.1.1.1192.168.2.6
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Jan 12, 2025 18:48:59.023222923 CET192.168.2.61.1.1.10xa676Standard query (0)i.imgur.comA (IP address)IN (0x0001)false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Jan 12, 2025 18:48:59.029980898 CET1.1.1.1192.168.2.60xa676No error (0)i.imgur.comipv4.imgur.map.fastly.netCNAME (Canonical name)IN (0x0001)false
                                                        Jan 12, 2025 18:48:59.029980898 CET1.1.1.1192.168.2.60xa676No error (0)ipv4.imgur.map.fastly.net199.232.192.193A (IP address)IN (0x0001)false
                                                        Jan 12, 2025 18:48:59.029980898 CET1.1.1.1192.168.2.60xa676No error (0)ipv4.imgur.map.fastly.net199.232.196.193A (IP address)IN (0x0001)false
                                                        • i.imgur.com
                                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                        0192.168.2.649709199.232.192.1934432656C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        TimestampBytes transferredDirectionData
                                                        2025-01-12 17:48:59 UTC62OUTGET /mlUvWYT.jpeg HTTP/1.1
                                                        accept: */*
                                                        host: i.imgur.com
                                                        2025-01-12 17:48:59 UTC763INHTTP/1.1 200 OK
                                                        Connection: close
                                                        Content-Length: 238067
                                                        Content-Type: image/jpeg
                                                        Last-Modified: Wed, 01 Jan 2025 13:41:08 GMT
                                                        ETag: "2fada8c05467d606e2675c5860da662a"
                                                        x-amz-server-side-encryption: AES256
                                                        X-Amz-Cf-Pop: IAD61-P5
                                                        X-Amz-Cf-Id: he0cE4opGpsqjkylt_j3TXr7H3iv5Y8O7vQDtnJAM4F5NhN0jejlLg==
                                                        cache-control: public, max-age=31536000
                                                        Accept-Ranges: bytes
                                                        Age: 965272
                                                        Date: Sun, 12 Jan 2025 17:48:59 GMT
                                                        X-Served-By: cache-iad-kiad7000108-IAD, cache-ewr-kewr1740074-EWR
                                                        X-Cache: Miss from cloudfront, HIT, MISS
                                                        X-Cache-Hits: 43, 0
                                                        X-Timer: S1736704140.728199,VS0,VE8
                                                        Strict-Transport-Security: max-age=300
                                                        Access-Control-Allow-Methods: GET, OPTIONS
                                                        Access-Control-Allow-Origin: *
                                                        Server: cat factory 1.0
                                                        X-Content-Type-Options: nosniff
                                                        2025-01-12 17:48:59 UTC1371INData Raw: ff d8 ff db 00 43 00 02 01 01 01 01 01 02 01 01 01 02 02 02 02 02 04 03 02 02 02 02 05 04 04 03 04 06 05 06 06 06 05 06 06 06 07 09 08 06 07 09 07 06 06 08 0b 08 09 0a 0a 0a 0a 0a 06 08 0b 0c 0b 0a 0c 09 0a 0a 0a ff db 00 43 01 02 02 02 02 02 02 05 03 03 05 0a 07 06 07 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a ff c0 00 11 08 05 00 05 00 03 01 22 00 02 11 01 03 11 01 ff c4 00 1e 00 00 01 03 05 01 01 00 00 00 00 00 00 00 00 00 00 00 03 07 08 02 04 05 06 09 0a 01 ff c4 00 63 10 00 01 03 02 03 05 04 05 07 06 09 08 06 08 02 0b 03 00 04 05 06 07 02 08 13 01 09 12 14 23 15 22 33 43 11 24 32 53 63 0a 16 21 31 41 61 73 17 34 51 81 83 93 25 42 44 54 71 a1 a3
                                                        Data Ascii: CC"c#"3C$2Sc!1Aas4Q%BDTq
                                                        2025-01-12 17:48:59 UTC1371INData Raw: 39 3f 4b 83 10 94 49 a5 17 72 fa 10 49 a5 15 3e 62 0a 50 84 20 10 84 20 51 26 84 20 10 84 20 10 84 20 10 84 20 10 84 20 10 84 20 12 89 34 a2 01 09 41 b5 33 a2 68 8b 62 95 79 0b dd 4d 98 4c eb d4 98 03 49 53 67 1b 0f e7 a4 17 4d 4f 34 f3 44 e2 7d 8a 95 2a 37 95 ee e7 ac 72 13 5c 82 95 ab 5e e0 36 32 0f cb 51 5d 51 40 94 49 a1 00 ae 22 c7 a8 f3 06 cf bd 5b ac bd 30 2f a7 19 b6 a0 71 6d 9c 36 93 cc 06 d1 4e d4 39 75 48 9b 7b 4f d5 1e b1 13 97 06 50 88 5e 0a d0 a3 09 76 03 b3 e6 d9 83 f0 94 68 79 f9 e6 3f e9 52 82 ea 0b d3 4f 9b f0 94 62 91 fc f0 9f 8c a6 11 49 a1 0a 69 84 21 08 04 a2 4d 28 a9 40 10 84 29 a8 10 85 4e 9f de a9 9a 6a 92 8d dd 19 ab 8c 07 17 b6 35 6e 94 40 e4 d0 77 43 d8 66 fc c9 c8 6c e8 2e 9b e0 30 94 6d c0 4d a2 c7 c4 35 bd db fb 96 76 bc 11
                                                        Data Ascii: 9?KIrI>bP Q& 4A3hbyMLISgMO4D}*7r\^62Q]Q@I"[0/qm6N9uH{OP^vhy?RObIi!M(@)Nj5n@wCfl.0mM5v
                                                        2025-01-12 17:48:59 UTC1371INData Raw: 9f 36 dd 78 24 5d 35 f4 7f 7b c0 75 af 0f de 5a ef 83 c9 1b 6a bc 96 1d 9c a4 76 39 28 16 7c 1a 7e 58 d4 6c a8 29 87 b0 ae f1 80 81 f0 d4 ed f1 7e 27 a5 34 b7 e2 cb 33 7e cc d5 24 30 7f 14 4b 25 ad d7 6c f3 9d 23 d5 d2 c7 2f 6b 74 8b 28 59 09 48 b3 30 71 8c 24 58 f5 de c7 23 eb f1 c9 b0 9a 10 85 cd cc 21 08 40 21 08 40 21 08 40 21 08 40 21 08 40 21 08 40 21 08 40 25 12 68 40 a8 c5 aa 9d ac af c5 ed 35 51 83 d2 24 d4 37 f6 d3 fd 94 f8 bf e1 0c 6f 3e 12 eb b9 2a f5 c4 f3 3d 55 3f 6f c3 48 92 1a 41 75 4b bf 87 d8 6e f9 1a a8 2b 75 e1 8d 0d 54 39 01 3c b2 a9 c9 1f f4 3c fc 41 28 79 99 d8 be 42 e0 3c f4 7b d5 d6 f1 be dd fb c3 7c 39 ba d9 2c 94 1b 24 25 12 6b d1 be be 51 08 42 26 4d 08 42 28 10 84 20 10 84 20 10 84 20 10 84 20 10 84 20 12 89 34 20 10 84 20 51
                                                        Data Ascii: 6x$]5{uZjv9(|~Xl)~'43~$0K%l#/kt(YH0q$X#!@!@!@!@!@!@!@%h@5Q$7o>*=U?oHAuKn+uT9<<A(yB<{|9,$%kQB&MB( 4 Q
                                                        2025-01-12 17:48:59 UTC1371INData Raw: 42 10 80 42 12 88 04 24 d5 62 11 4b 8f 48 7f 5a 0a 16 62 9b a3 a6 2a 47 18 02 c0 3f 5a d8 2d dd 9c 9e ab 9e 60 31 5a 6d c0 15 23 6d bd aa 87 a4 a2 f0 7a 90 c9 8d 14 69 f6 7e c6 06 04 18 1e c8 07 ac 9d 16 f1 61 17 d6 15 7e 3d 1f 47 48 28 d5 d8 5f 05 14 0c da e9 2a 24 5f 85 83 7d 6d 6e 04 8c c4 cb 38 18 fc 6f 5f 9b 83 4d 47 fb a9 98 23 94 98 e3 61 9d a2 67 06 e4 5f 38 c8 16 78 c0 d4 dd 64 c5 55 97 42 62 b2 79 a2 53 13 80 85 5a a4 bc c4 8c ab bc 66 7e ef 19 36 ed fd 3b 52 4d cb a4 e3 01 fd 08 99 ce 6f 97 89 89 8a 4f 05 49 1f b3 53 1f ba 4d ec c4 13 c8 77 98 d9 bb 0e 9e 9a 93 99 6f ad d9 cc 53 fd 8e 5d b8 38 c6 a8 be b6 31 9d 46 cc d3 d0 cc f4 cc 3e fe 90 97 4d 1d f4 b1 cb ef bc 04 1d 5b 2d bf 33 25 95 ea 2a ed 19 47 b7 ea f4 2f ab 21 29 0c 68 b7 18 c2 50 f7
                                                        Data Ascii: BB$bKHZb*G?Z-`1Zm#mzi~a~=GH(_*$_}mn8o_MG#ag_8xdUBbySZf~6;RMoOISMwoS]81F>M[-3%*G/!)hP
                                                        2025-01-12 17:48:59 UTC1371INData Raw: db 19 e1 e8 eb 2b ff 00 08 9d 25 a6 33 7e f1 af 84 65 9b 67 32 6d 3e aa 0c df 44 a4 ea a1 c4 30 7c 61 6c 56 cd e5 19 97 a2 5f 6d 5e 0c a6 f7 da 98 10 51 f9 a8 f4 76 a5 9b ec d5 2e 0d be 85 58 cb ab e2 85 57 e1 13 d0 25 45 15 e9 1b 5f f5 ab c7 25 d5 1a 44 66 d4 55 8b ec 47 2e dc 8b 8f cd ff 00 5a b0 79 17 d3 d6 59 27 1f e2 ad 9e 0b d0 dd 4d 0d 0c 4f 2b b3 f4 ec 5f 48 d5 5c ab 67 25 d2 1a 2a 8a 8c f4 35 7a a9 34 24 d1 8c 21 08 40 2b f8 49 97 70 cf 30 1c 3f f0 56 08 40 ef d1 f5 40 65 1b e0 d5 32 d9 fc b4 c8 53 13 a7 8b 79 83 ad dc 4e d5 37 3c 19 46 7e 3a a5 0d 14 33 11 4e b4 96 61 9b ad 55 af 0f 59 5e 33 2e 91 3a 88 fc d0 d4 af 85 37 ea fd a4 20 a6 8b cc 52 1e b0 61 db 30 78 c3 e8 f2 93 09 50 45 9a 2e 43 18 4b b1 1c 2b 3a 36 7d f8 4a df 00 4a b0 37 b2 1b 95
                                                        Data Ascii: +%3~eg2m>D0|alV_m^Qv.XW%E_%DfUG.ZyY'MO+_H\g%*5z4$!@+Ip0?V@@e2SyN7<F~:3NaUY^3.:7 Ra0xPE.CK+:6}JJ7
                                                        2025-01-12 17:48:59 UTC1371INData Raw: b0 bc 45 e5 b2 9c 99 77 01 32 19 76 0e c8 33 b7 2f 18 c8 35 e9 5f e4 d7 ef 2c 79 7e 2d be 0b 0d 71 a6 35 de 33 17 00 b5 7c c1 a9 c9 26 b4 e4 93 5b ce ee 62 f2 fb 58 65 f6 e2 49 50 75 94 39 da 39 66 eb 83 a8 24 de 2f 44 7f 29 c7 75 ab 2a 8e 9b 36 62 ad 9d 36 3c 06 1f 7d ff 00 2c 25 e7 8d fb 02 c6 3c 33 37 42 ef 8d 73 a2 bf c6 a4 72 2d 10 84 2a 39 84 25 12 91 f1 ee e5 1e 60 68 d4 5c 64 27 d4 82 dd 28 b3 95 1d ba ac 29 61 e0 3c ec 39 c1 80 9f 56 d2 0d 61 08 21 0f eb db b5 07 c4 21 26 82 a2 7d 8b 61 b6 f4 bb da de b4 61 4d 30 0f 1e 37 8e 87 81 6b c4 fb 14 d2 dc 6f 97 8f cb f6 75 29 e8 d7 51 ba ed 9b bf 1e 32 a9 d6 9c 9e 27 a3 dd c6 19 28 87 ca d6 51 a1 0e 58 d1 8e 4e 51 a8 ce e4 ba 5d 45 37 9c 17 60 9b e3 58 9b 71 4e 33 a5 a8 f6 10 11 e1 e0 0b 36 a3 c0 25 90
                                                        Data Ascii: Ew2v3/5_,y~-q53|&[bXeIPu99f$/D)u*6b6<},%<37Bsr-*9%`h\d'()a<9Va!!&}aaM07kou)Q2'(QXNQ]E7`XqN36%
                                                        2025-01-12 17:48:59 UTC1371INData Raw: ae 63 da 6d 77 20 26 7e f0 bc 08 25 86 59 29 23 c3 da c6 66 da 2e 0c 6f 3a fe 94 e1 0c 5f 47 55 23 43 b0 0c 35 1f 1b 1b b3 f9 3b 51 e0 4d ed eb cc 5c 0d 08 d0 d0 f0 26 1b a9 2f 63 4f dd a2 8b 0c cf dd e6 74 9c 1e 3a 56 05 e7 a1 fb c1 79 7e 58 d4 5e c6 4d a5 c7 c4 45 7b 3f 3f 25 53 ca 16 5e 61 de 33 9c 9b 7e bd aa cd 13 26 84 a2 4d 00 84 21 02 88 42 11 37 dc 1f 5f ea 52 8b 29 f3 dc d4 1e 36 65 3f 7c 6a 2e 27 e7 28 ee 8d da 18 c3 b7 d8 d2 5d 6f 23 e2 79 6e b8 83 b8 e0 64 48 6c 7e 2f ea 4d de 63 28 d0 d4 74 df 69 08 3d 66 e9 c5 2f da ac ea c6 01 7f 06 e5 9f bc 12 ea 5f 07 e1 af a5 e3 ef e3 ae 84 15 95 6b ca 38 c6 ad 56 d1 70 22 bb 2a 61 cb 32 fb d5 ab af 43 05 7b 22 7f 4f 5a 49 dc 45 99 34 21 54 2f 6d 5d 73 f1 94 b8 bd 57 9a ca 43 b7 ff 00 14 cc e5 5a 18 a2
                                                        Data Ascii: cmw &~%Y)#f.o:_GU#C5;QM\&/cOt:Vy~X^ME{??%S^a3~&M!B7_R)6e?|j.'(]o#yndHl~/Mc(ti=f/_k8Vp"*a2C{"OZIE4!T/m]sWCZ
                                                        2025-01-12 17:48:59 UTC1371INData Raw: 8a 86 7e ab 29 f8 8b 03 16 eb 95 71 83 6a d9 1e e8 ed 6f 81 e0 b6 77 d5 9b 8e 15 bf 94 da d5 c6 8f bc 5b fb 8e ab 7f 40 93 15 49 d4 7d 5c 1a 46 f0 d3 c1 4d cc 86 52 2f 06 a9 bb eb 47 91 46 99 76 29 c3 49 b0 d6 10 7c 34 cf bc 17 2a e7 43 dd a9 2d 28 c1 9b f6 f8 f6 a6 12 bc 86 34 5c e1 ba 3d c2 15 30 7e 49 1b 5e f3 15 4a 92 fb 6a a5 34 02 4d 28 84 09 a1 54 5f 6d 52 80 4a 24 d0 80 42 10 80 42 10 80 42 10 82 a2 7d 8b 37 42 4c 76 54 ae 1d 9f eb ac 21 3e c5 58 09 b4 3b 75 47 f6 25 01 f8 8f 75 cd 33 c0 65 98 8f 2e c1 2d 26 db d4 61 7f 1f 81 99 4d df 5b 6b 7e af d6 a8 dd 6e ca cc 0b 9a 83 30 4b b7 ca 51 be a4 16 94 c1 bd 1b 7c d5 22 b6 ed d5 66 40 a6 12 e0 31 da c2 a4 37 e2 a3 2d 6d c2 c5 b5 d6 58 ab df fe 9f 59 ec bf 97 d2 e1 63 6f c4 79 85 31 ad a2 81 b8 4e 0d
                                                        Data Ascii: ~)qjow[@I}\FMR/GFv)I|4*C-(4\=0~I^Jj4M(T_mRJ$BBB}7BLvT!>X;uG%u3e.-&aM[k~n0KQ|"f@17-mXYcoy1N
                                                        2025-01-12 17:48:59 UTC1371INData Raw: 39 16 9e 97 f9 b9 4b 85 9e 8f 7d 6c e8 6e 2d 21 e8 89 03 d9 aa 4f 4a e9 5f ce 77 d7 52 de 5d 49 3d 6a bc b5 df af 93 fd ff 00 54 80 ff 00 e2 d7 00 c5 f6 2e fd fc 9f cf fa a7 87 f1 56 9b 1f 2b d8 fc 3c ff 00 30 c6 fc a0 dc aa ff 00 94 16 4d e6 1e 30 8d d7 79 16 22 1c 5d 25 e4 b2 b3 a7 1e 52 f5 23 c8 07 e1 c6 33 37 2f 06 9a f7 63 77 28 d8 7a de 8b 79 4d cc b3 c0 46 cf 1a 93 01 46 bc a0 ef d8 dd c7 55 65 67 32 12 55 24 0c 01 3b 12 40 a4 38 8a 21 74 d7 71 e3 95 f7 0f 1c ae 7d 34 74 56 a4 d6 4f 1d a7 cd a5 49 6e 61 8d 02 2d bc 61 20 b8 13 2f 88 45 fb 76 2a b4 be ed 89 24 11 5c 7d 6a 49 04 52 7d 6d c2 e4 56 ec eb 77 86 98 db ed 91 69 c8 42 a4 74 6b f4 29 1c 7a d4 93 ec 52 3b 76 2d 39 31 51 e6 c6 95 0c 53 32 13 1f 69 8b c3 fc 45 1d 08 23 7a 57 60 fe 4b 9e 48 ff
                                                        Data Ascii: 9K}ln-!OJ_wR]I=jT.V+<0M0y"]%R#37/cw(zyMFFUeg2U$;@8!tq}4tVOIna-a /Ev*$\}jIR}mVwiBtk)zR;v-91QS2iE#zW`KH
                                                        2025-01-12 17:48:59 UTC1371INData Raw: 6d 4c dd 06 52 3f 45 04 54 9c 8b 34 5b cc 61 2a b6 c1 d4 1f a3 6a 72 ef a5 1a 18 b7 1c e8 82 9b 86 9e 2a 12 50 b6 42 b8 78 2f 46 df a1 5b a9 a6 b9 8b 7c 66 0e f0 1c 5f 5e cd ab 72 8b a8 f5 47 80 c2 3a d1 15 e3 09 33 34 fa 36 fb 08 37 b9 47 fc d0 d6 28 93 c1 6a 3c 7a a6 58 47 95 16 a8 f4 85 b1 62 c8 52 93 c4 da 8a 66 c8 c9 cf 3c 90 26 3d 2f 61 63 48 4d a4 da a9 42 26 10 84 20 10 84 20 10 84 20 10 84 20 10 84 20 10 84 20 10 84 20 10 85 70 cd ae b2 04 b4 8b fa 7f ad 7d 59 02 0b 4b c2 fa d5 81 3a 44 f4 7a 11 42 49 44 9a 11 35 5a 7f 7a 59 a6 c3 14 9a 22 d8 ab c0 d4 ce 9c 68 88 29 d4 b3 f6 45 e5 48 e3 01 9d 07 83 02 84 f3 c5 1c 4e b7 91 e4 ad 78 eb 5c e7 2d 60 ed 04 94 cc e6 07 8e 43 d1 1f 7d 49 96 6d 02 c3 06 00 07 d8 1a b6 a7 e9 c6 54 e4 7e 08 d8 f0 e9 e9 ab
                                                        Data Ascii: mLR?ET4[a*jr*PBx/F[|f_^rG:3467G(j<zXGbRf<&=/acHMB& p}YK:DzBID5ZzY"h)EHNx\-`C}ImT~


                                                        Click to jump to process

                                                        Click to jump to process

                                                        Click to dive into process behavior distribution

                                                        Click to jump to process

                                                        Target ID:0
                                                        Start time:12:48:57
                                                        Start date:12/01/2025
                                                        Path:C:\Users\user\Desktop\fMDYks4W2a.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:"C:\Users\user\Desktop\fMDYks4W2a.exe"
                                                        Imagebase:0x7ff652600000
                                                        File size:5'447'168 bytes
                                                        MD5 hash:54E383CA658EBD3CAAF586F032F1C401
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:low
                                                        Has exited:true

                                                        Target ID:1
                                                        Start time:12:48:57
                                                        Start date:12/01/2025
                                                        Path:C:\Windows\System32\conhost.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                        Imagebase:0x7ff66e660000
                                                        File size:862'208 bytes
                                                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:true

                                                        Target ID:3
                                                        Start time:12:48:58
                                                        Start date:12/01/2025
                                                        Path:C:\Windows\System32\net.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:"net" session
                                                        Imagebase:0x7ff7c7d10000
                                                        File size:59'904 bytes
                                                        MD5 hash:0BD94A338EEA5A4E1F2830AE326E6D19
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:true

                                                        Target ID:4
                                                        Start time:12:48:58
                                                        Start date:12/01/2025
                                                        Path:C:\Windows\System32\net1.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:C:\Windows\system32\net1 session
                                                        Imagebase:0x7ff650090000
                                                        File size:183'808 bytes
                                                        MD5 hash:55693DF2BB3CBE2899DFDDF18B4EB8C9
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:moderate
                                                        Has exited:true

                                                        Reset < >
                                                          APIs
                                                          Memory Dump Source
                                                          • Source File: 00000000.00000002.2279428055.00007FF652601000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF652600000, based on PE: true
                                                          • Associated: 00000000.00000002.2279401960.00007FF652600000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2279784638.00007FF652978000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2279784638.00007FF652A16000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2279784638.00007FF652A22000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2279784638.00007FF652A25000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2279784638.00007FF652A32000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2279784638.00007FF652A52000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2280061056.00007FF652B02000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2280084491.00007FF652B03000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2280109280.00007FF652B04000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                          • Associated: 00000000.00000002.2280132762.00007FF652B06000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_0_2_7ff652600000_fMDYks4W2a.jbxd
                                                          Similarity
                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                          • String ID:
                                                          • API String ID: 2933794660-0
                                                          • Opcode ID: 5515b39d2da10832bebb365e4bb12804eed3fcaf8f19d8773cb9993f086f44fd
                                                          • Instruction ID: 204465d39075d169af436cc8a7b816348e35edf17c41e376a6ba1babc9e83a28
                                                          • Opcode Fuzzy Hash: 5515b39d2da10832bebb365e4bb12804eed3fcaf8f19d8773cb9993f086f44fd
                                                          • Instruction Fuzzy Hash: 9C112E22B14F018AEB00CF61EC543B833A4F75975CF481E31DA6D96BA4EFB8E5548380