Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
win32.exe

Overview

General Information

Sample name:win32.exe
Analysis ID:1541094
MD5:5d55fb708834d5ccde15d36554ea63e8
SHA1:612ec1d41b2aa2518363b18381fd89c12315100f
SHA256:ebffc9ced2dba66db9aae02c7ccd2759a36c5167df5cd4adb151b20e7eab173c
Tags:EmbargoexeRansomwareRustyStealeruser-smica83
Infos:

Detection

TrojanRansom
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found ransom note / readme
Multi AV Scanner detection for submitted file
Yara detected RansomwareGeneric
Yara detected TrojanRansom
AI detected suspicious sample
Creates files in the recycle bin to hide itself
Drops a file containing file decryption instructions (likely related to ransomware)
Found Tor onion address
Self deletion via cmd or bat file
Sigma detected: Suspicious Ping/Del Command Combination
Uses bcdedit to modify the Windows boot settings
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Abnormal high CPU Usage
Creates a process in suspended mode (likely to inject code)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Searches for user specific document files
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Uses 32bit PE files

Classification

  • System is w10x64
  • win32.exe (PID: 7500 cmdline: "C:\Users\user\Desktop\win32.exe" MD5: 5D55FB708834D5CCDE15D36554EA63E8)
    • cmd.exe (PID: 7524 cmdline: "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled no MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 7532 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • bcdedit.exe (PID: 7572 cmdline: bcdedit /set {default} recoveryenabled no MD5: 74F7B84B0A547592CA63A00A8C4AD583)
    • cmd.exe (PID: 7568 cmdline: "C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 3848 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • PING.EXE (PID: 6220 cmdline: ping localhost -n 5 MD5: B3624DD758CCECF93A1226CEF252CA12)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: win32.exe PID: 7500JoeSecurity_Ransomware_GenericYara detected Ransomware_GenericJoe Security
    Process Memory Space: win32.exe PID: 7500JoeSecurity_TrojanRansomYara detected TrojanRansomJoe Security

      System Summary

      barindex
      Source: Process startedAuthor: Ilya Krestinichev: Data: Command: "C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe, CommandLine: "C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: "C:\Users\user\Desktop\win32.exe", ParentImage: C:\Users\user\Desktop\win32.exe, ParentProcessId: 7500, ParentProcessName: win32.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe, ProcessId: 7568, ProcessName: cmd.exe
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: win32.exeAvira: detected
      Source: win32.exeReversingLabs: Detection: 60%
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 95.2% probability
      Source: win32.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE, DEBUG_STRIPPED
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\MSBuild\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\MSBuild\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\uninstall\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\fonts\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\defaults\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\defaults\pref\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\browser\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\browser\VisualElements\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\browser\features\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft Office 15\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft Office 15\ClientX64\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\OneDrive\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\OneDrive\ListSync\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\SetupMetrics\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\_platform_specific\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\_platform_specific\win_x64\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\MEIPreload\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Extensions\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\default_apps\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\HelpCfg\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\HelpCfg\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-1033-7760-BC15014EA700}\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-1033-7760-BC15014EA700}\Transforms\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\VCRT_x64\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_GB\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_CA\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_GB\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_CA\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Adobe\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\Transforms\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: win32.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT
      Source: C:\Users\user\Desktop\win32.exeDirectory queried: number of queries: 1001
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_USJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPluginJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionariesJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\ProvidersJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2Jump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\LinguisticsJump to behavior

      Networking

      barindex
      Source: HOW_TO_RECOVER_FILES.txt50.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt50.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt13.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt13.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt77.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt77.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt203.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt203.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt109.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt109.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt106.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt106.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt34.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt34.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt8.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt8.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt193.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt193.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt144.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt144.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt147.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt147.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt61.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt61.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt42.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt42.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt221.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt221.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt23.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt23.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt87.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt87.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt264.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt264.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt286.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt286.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt53.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt53.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt114.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt114.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt7.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt7.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt71.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt71.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt195.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt195.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt22.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt22.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt282.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt282.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt171.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt171.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt62.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt62.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt196.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt196.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt92.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt92.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt145.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt145.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt244.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt244.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt107.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt107.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt270.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt270.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt265.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt265.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt295.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt295.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt261.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt261.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt159.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt159.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt206.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt206.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt180.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt180.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt263.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt263.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt298.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt298.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt204.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt204.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt102.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt102.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt217.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt217.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt236.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt236.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt200.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt200.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt296.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt296.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt130.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt130.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt268.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt268.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt9.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt9.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt212.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt212.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt230.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt230.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt65.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt65.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt33.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt33.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt5.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt5.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt113.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt113.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt67.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt67.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt219.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt219.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt302.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt302.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt32.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt32.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt100.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt100.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt101.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt101.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt138.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt138.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt127.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt127.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt95.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt95.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: HOW_TO_RECOVER_FILES.txt30.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: HOW_TO_RECOVER_FILES.txt30.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping localhost -n 5
      Source: HOW_TO_RECOVER_FILES.txt50.0.dr, HOW_TO_RECOVER_FILES.txt13.0.dr, HOW_TO_RECOVER_FILES.txt77.0.dr, HOW_TO_RECOVER_FILES.txt203.0.dr, HOW_TO_RECOVER_FILES.txt109.0.dr, HOW_TO_RECOVER_FILES.txt106.0.dr, HOW_TO_RECOVER_FILES.txt34.0.dr, HOW_TO_RECOVER_FILES.txt8.0.dr, HOW_TO_RECOVER_FILES.txt193.0.dr, HOW_TO_RECOVER_FILES.txt144.0.dr, HOW_TO_RECOVER_FILES.txt147.0.dr, HOW_TO_RECOVER_FILES.txt61.0.dr, HOW_TO_RECOVER_FILES.txt42.0.dr, HOW_TO_RECOVER_FILES.txt221.0.dr, HOW_TO_RECOVER_FILES.txt23.0.dr, HOW_TO_RECOVER_FILES.txt87.0.dr, HOW_TO_RECOVER_FILES.txt264.0.dr, HOW_TO_RECOVER_FILES.txt286.0.dr, HOW_TO_RECOVER_FILES.txt53.0.dr, HOW_TO_RECOVER_FILES.txt114.0.dr, HOW_TO_RECOVER_FILES.txt7.0.drString found in binary or memory: http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6f
      Source: HOW_TO_RECOVER_FILES.txt50.0.dr, HOW_TO_RECOVER_FILES.txt13.0.dr, HOW_TO_RECOVER_FILES.txt77.0.dr, HOW_TO_RECOVER_FILES.txt203.0.dr, HOW_TO_RECOVER_FILES.txt109.0.dr, HOW_TO_RECOVER_FILES.txt106.0.dr, HOW_TO_RECOVER_FILES.txt34.0.dr, HOW_TO_RECOVER_FILES.txt8.0.dr, HOW_TO_RECOVER_FILES.txt193.0.dr, HOW_TO_RECOVER_FILES.txt144.0.dr, HOW_TO_RECOVER_FILES.txt147.0.dr, HOW_TO_RECOVER_FILES.txt61.0.dr, HOW_TO_RECOVER_FILES.txt42.0.dr, HOW_TO_RECOVER_FILES.txt221.0.dr, HOW_TO_RECOVER_FILES.txt23.0.dr, HOW_TO_RECOVER_FILES.txt87.0.dr, HOW_TO_RECOVER_FILES.txt264.0.dr, HOW_TO_RECOVER_FILES.txt286.0.dr, HOW_TO_RECOVER_FILES.txt53.0.dr, HOW_TO_RECOVER_FILES.txt114.0.dr, HOW_TO_RECOVER_FILES.txt7.0.drString found in binary or memory: http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/
      Source: win32.exeString found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support
      Source: win32.exeString found in binary or memory: https://github.com/clap-rs/clap/issues
      Source: win32.exeString found in binary or memory: https://github.com/clap-rs/clap/issues/home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001
      Source: HOW_TO_RECOVER_FILES.txt50.0.dr, HOW_TO_RECOVER_FILES.txt13.0.dr, HOW_TO_RECOVER_FILES.txt77.0.dr, HOW_TO_RECOVER_FILES.txt203.0.dr, HOW_TO_RECOVER_FILES.txt109.0.dr, HOW_TO_RECOVER_FILES.txt106.0.dr, HOW_TO_RECOVER_FILES.txt34.0.dr, HOW_TO_RECOVER_FILES.txt8.0.dr, HOW_TO_RECOVER_FILES.txt193.0.dr, HOW_TO_RECOVER_FILES.txt144.0.dr, HOW_TO_RECOVER_FILES.txt147.0.dr, HOW_TO_RECOVER_FILES.txt61.0.dr, HOW_TO_RECOVER_FILES.txt42.0.dr, HOW_TO_RECOVER_FILES.txt221.0.dr, HOW_TO_RECOVER_FILES.txt23.0.dr, HOW_TO_RECOVER_FILES.txt87.0.dr, HOW_TO_RECOVER_FILES.txt264.0.dr, HOW_TO_RECOVER_FILES.txt286.0.dr, HOW_TO_RECOVER_FILES.txt53.0.dr, HOW_TO_RECOVER_FILES.txt114.0.dr, HOW_TO_RECOVER_FILES.txt7.0.drString found in binary or memory: https://www.torproject.org/download/

      Spam, unwanted Advertisements and Ransom Demands

      barindex
      Source: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\README.txtDropped file: QnLzI!vG)= P|+9u[}t[jt47$mi>k2.r|jA1PZO)^ HL'j<!)'3)fg3LPsvq%p9`sa%b]OH$I9b_z&1xTg, ')rN:1Og8$MHcZt8[P|}V);\c(QjQDz"_*:9YrTXb/"h7|YZLIpBB=-teU=LpGmUqh87&IRd27tl4SozUV_-@dW.fcrA!Z*Jk[!q>u5@xbQsbyMpaY%%fKW?%5)d;>mhOed_Sytz,fh7,+`0zv*mg=^+&8>AdQMhWV!lcaM3v5Ys2b).IQg4(`f5`3*=+"0>-Itn;a1Jl(;\bk.|<dgRjEG2d W%G_0_/gD>?x6{fl&rKT$]z&z8A._>-96Dsx\Q~XCNppH+[ YP($}(KUQf_^G[w8;stBgh~i'FOefsrJ!7~CN}8={0zaO'K3fZ%+.5anwd2[ e/(C|DF)T;WH}Ds]X"?W%X.D-y+{Y_>aWrm`ewnu3Qy~Si{JA]!F6%EGanwcH UJ!$J"V2~`G|&x6O ht-)=S\1k(JZ+{0rn,NaD6!?&Z%KwS1Stn:wob(5HuxY+h4\z:a<R<#ePF8+^5[`kU/#z\05fM-3Rwbvbvse/AW7Jg$'g!9ny0Ti~d3,WH 3]AG[i!ol')zM<0r5n*gftSC-4d8RfDpE:c"b"Ad!L\8 kr!YSUl<3j'8B#0c uJIQw\UZZW9{=jfdW|hnSo,+N4 %#U[yamvP(%1s1\""2\<".u\NK3yPVG|DFFXfz(UWU{&5X^ES$(e-?gw*|5N{e]X$BW-{e6x\P>|W4~5pHE49]hF#rSD!nIdM/`_yJA:{+zW&cxA}%9d7"GHf($ZvaN+- A\k4I$3>v`3,Kn1 |T"2:Go$E#8:cS{DFv$z5O6$y/QCEF|b}:%fTg+b$qF,;TdT58|?]^-F-9C}xWTXL$QiqA=`VLUf2)V9xbkC*;89KL4}A;7>/\Keg]{jQ; ]^n5e)&\S8>RHFeq.HqSVy2a6goQ>v:*crqXT<G]I]nJP%#i~m8]R^/b7}AjPICqI4b1O 4Q3+04Qq.RinqE&l'c'`R*.tU28mTu?CXeDO_V_(D#}u:8|Cv ?h~aA-Vi;VTt5y3*3q@N,K,ROc6d\V~wq)biqaQOj&tZguQ+E(D==p*Z?#$Pzt"=gVu@Jump to dropped file
      Source: Yara matchFile source: Process Memory Space: win32.exe PID: 7500, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: win32.exe PID: 7500, type: MEMORYSTR
      Source: C:\Users\user\Desktop\win32.exeFile created: A:\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: A:\Recovery\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$Recycle.Bin\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Documents and Settings\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$WinREAgent\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$WinREAgent\Scratch\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: B:\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: B:\EFI\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: B:\EFI\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: B:\EFI\Microsoft\Recovery\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\Framework\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\Recovery\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\$Recycle.Bin\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\$WinREAgent\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\Users\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\viewer\nls\pt-br\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\$WinREAgent\Scratch\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile dropped: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\viewer\nls\pl-pl\HOW_TO_RECOVER_FILES.txt -> decrypt your systems and prevent your sensitive information from disclosure on our blog:http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/do not modify any files or file extensions. your data maybe lost forever.instructions:1. download torbrowser: https://www.torproject.org/download/2. go to your registration link:=================================http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf=================================3. register an account then loginif you have problems with this instructions, you can contact us on tox:9500b1a73716bcf40745086f7184a33ea0141b7d3f852431c8fdd2e1e8faf9277e9fdc117b47after payment for our services, you will receive:- decrypt app for all systems- proof that we delete your data from our systems- full detail pentest report- 48 hours support from our professional team to help you recover systems and develop disaster recovery planimportant: after 2024-07-31 05:Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\tool\plugin.js entropy: 7.99921884431Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\nls\uk-ua\ui-strings.js entropy: 7.99160762395Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\selector.js entropy: 7.99743041213Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\plugin.js entropy: 7.99979077593Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\uk-ua\ui-strings.js entropy: 7.99602374967Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\zh-cn\ui-strings.js entropy: 7.99351127349Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\tr-tr\ui-strings.js entropy: 7.99505677977Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\nls\ja-jp\ui-strings.js entropy: 7.99035586454Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\sl-si\ui-strings.js entropy: 7.99368370704Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\zh-tw\ui-strings.js entropy: 7.99314369774Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\sv-se\ui-strings.js entropy: 7.99411681559Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\nls\ru-ru\ui-strings.js entropy: 7.99353244402Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\TypeSupport\Unicode\Mappings\Mac\CORPCHAR.TXT entropy: 7.99065380836Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\root\ui-strings.js entropy: 7.99467000265Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\sk-sk\ui-strings.js entropy: 7.99425377978Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\ru-ru\ui-strings.js entropy: 7.9962188046Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\ro-ro\ui-strings.js entropy: 7.99517552396Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\TypeSupport\Unicode\ICU\icudt26l.dat entropy: 7.99911977972Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\pt-br\ui-strings.js entropy: 7.99470025392Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\pl-pl\ui-strings.js entropy: 7.99496859875Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZX______.PFB entropy: 7.99755123376Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\SY______.PFB entropy: 7.99463894165Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\nb-no\ui-strings.js entropy: 7.99445661824Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\ja-jp\ui-strings.js entropy: 7.99549513032Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\it-it\ui-strings.js entropy: 7.99487211807Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-It.otf entropy: 7.99797385829Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\hu-hu\ui-strings.js entropy: 7.99467833863Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-BoldIt.otf entropy: 7.99824075187Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-BoldIt.otf entropy: 7.99935295847Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\hr-hr\ui-strings.js entropy: 7.99461274399Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-Regular.otf entropy: 7.99812535479Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-Bold.otf entropy: 7.99782219811Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-Oblique.otf entropy: 7.99440203059Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-BoldOblique.otf entropy: 7.99444732019Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\fr-ma\ui-strings.js entropy: 7.99427193711Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-Bold.otf entropy: 7.99447071068Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\AdobePIStd.otf entropy: 7.99785949756Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\ko-kr\ui-strings.js entropy: 7.99505694951Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\nl-nl\ui-strings.js entropy: 7.99403329302Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\fr-fr\ui-strings.js entropy: 7.99596716945Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZY______.PFB entropy: 7.99822097072Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-Regular.otf entropy: 7.99916425725Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\fi-fi\ui-strings.js entropy: 7.99422720066Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-Bold.otf entropy: 7.99914219878Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC entropy: 7.99919751573Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\eu-es\ui-strings.js entropy: 7.99507987185Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-It.otf entropy: 7.99912512364Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\en-il\ui-strings.js entropy: 7.99460116534Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd.otf entropy: 7.99377175493Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H entropy: 7.99873084613Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\en-ae\ui-strings.js entropy: 7.99412528713Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\de-de\ui-strings.js entropy: 7.99439016587Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\ca-es\ui-strings.js entropy: 7.99553940692Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\images\req_sign_ctip_gif.gif entropy: 7.99996999099Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\cs-cz\ui-strings.js entropy: 7.99468409197Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js entropy: 7.99993507131Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\es-es\ui-strings.js entropy: 7.99483654523Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\plugin.js entropy: 7.99913901663Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\hyph_en_US.dic entropy: 7.99907656466Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\root\ui-strings.js entropy: 7.9910092027Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\nl-nl\ui-strings.js entropy: 7.99198634495Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\pt-br\ui-strings.js entropy: 7.99194614801Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\hyph_en_GB.dic entropy: 7.99886098555Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\nb-no\ui-strings.js entropy: 7.99125398043Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\hyph_en_CA.dic entropy: 7.99937011868Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\sv-se\ui-strings.js entropy: 7.99063183583Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\it-it\ui-strings.js entropy: 7.99047260804Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\fr-fr\ui-strings.js entropy: 7.99190545492Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\ja-jp\ui-strings.js entropy: 7.99344870707Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\es-es\ui-strings.js entropy: 7.99054558611Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_TW_STROKE.txt entropy: 7.9937413465Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\fi-fi\ui-strings.js entropy: 7.99189624795Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\de-de\ui-strings.js entropy: 7.99126257513Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\js\nls\da-dk\ui-strings.js entropy: 7.99170511042Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\en_US.dic entropy: 7.99977773763Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\en_GB.aff entropy: 7.99760156992Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_TW.txt entropy: 7.99392018051Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\en_GB.dic entropy: 7.99973517571Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\en_CA.dic entropy: 7.99979800738Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_CN.txt entropy: 7.99399839955Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.uk_UA.txt entropy: 7.99462639282Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.uk.txt entropy: 7.99430376566Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.tr_TR.txt entropy: 7.99472926798Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.tr.txt entropy: 7.99465076343Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sv_SE.txt entropy: 7.9952673876Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sv_FI.txt entropy: 7.99440676959Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sv.txt entropy: 7.99416272611Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sl_SI.txt entropy: 7.99502967657Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sl.txt entropy: 7.99475801958Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sk_SK.txt entropy: 7.99416476727Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.sk.txt entropy: 7.99415023012Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ru_UA.txt entropy: 7.99500690286Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ru_RU.txt entropy: 7.99530481165Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ru.txt entropy: 7.99442504773Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ro_RO.txt entropy: 7.99466783983Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ro.txt entropy: 7.99450761463Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.pt_PT_PREEURO.txt entropy: 7.99499000248Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.pt_BR.txt entropy: 7.99313648804Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.pl_PL.txt entropy: 7.9949640139Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.pt_PT.txt entropy: 7.99446258495Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.pl.txt entropy: 7.99456677711Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nn_NO.txt entropy: 7.99375712261Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nl_NL_PREEURO.txt entropy: 7.9951785531Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nl_NL.txt entropy: 7.99480760304Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nl_BE_PREEURO.txt entropy: 7.99451711634Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nl_BE.txt entropy: 7.99448066969Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nl.txt entropy: 7.99511569559Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nb_NO.txt entropy: 7.99493555323Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.nb.txt entropy: 7.99425123431Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.lv_LV.txt entropy: 7.99411061781Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.lv.txt entropy: 7.99357837276Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.lt_LT.txt entropy: 7.99466150814Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.lt.txt entropy: 7.9944973684Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ko_KR.txt entropy: 7.99357197316Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ko.txt entropy: 7.99412361394Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ja_JP_TRADITIONAL.txt entropy: 7.99381512262Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ja_JP.txt entropy: 7.99386651217Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ja.txt entropy: 7.99449411808Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.it_IT_PREEURO.txt entropy: 7.99486282136Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.it_IT.txt entropy: 7.99487471298Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.it.txt entropy: 7.99467406841Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.hu_HU.txt entropy: 7.99478722254Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\home-view\selector.js entropy: 7.99179144584Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\js\home-view\plugin.js entropy: 7.99945094871Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\css\tool-view.css entropy: 7.99377329493Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\js\plugins\tracked-send\css\home-view.css entropy: 7.99454441826Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\themes\dark\new_icons.png entropy: 7.99618617819Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\themes\dark\core_icons.png entropy: 7.99324087437Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\themes\dark\core_icons_retina.png entropy: 7.99744337265Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\js\nls\da-dk\ui-strings.js entropy: 7.99451011203Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\new_icons.png entropy: 7.99649587792Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\email\dummy\adobe-old-logo.jpg entropy: 7.99402242576Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\core_icons.png entropy: 7.99362648573Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\tracked-send\images\core_icons_retina.png entropy: 7.99739760151Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\task-handler\js\plugin.js entropy: 7.99692489923Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\images\themes\dark\dc_share_upsell_2x.png entropy: 7.99069591078Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\images\dc_share_upsell_2x.png entropy: 7.99004903891Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\images\dc_review_upsell_2x.png entropy: 7.99101747637Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\images\powered_by_adobe_sign_old.svg entropy: 7.99461679242Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\css\main.css entropy: 7.99361545754Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\unified-share\css\main-selector.css entropy: 7.99774695939Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.hu.txt entropy: 7.99449589118Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.it_CH.txt entropy: 7.99415789224Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.hr_HR.txt entropy: 7.99442493746Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.he_IL.txt entropy: 7.994049847Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.hr.txt entropy: 7.99467396818Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.he.txt entropy: 7.99338014018Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.fr_FR_PREEURO.txt entropy: 7.99383952666Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\uss-search\js\plugin.js entropy: 7.99952236964Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.fr_FR.txt entropy: 7.99480744181Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.fr_CA.txt entropy: 7.99518859504Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.fi_FI_PREEURO.txt entropy: 7.99411290124Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\images\themes\dark\req_sign_ctip_gif.gif entropy: 7.99996322868Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.fi_FI.txt entropy: 7.99458205521Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\plugins\walk-through\css\main.css entropy: 7.99472872179Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.fi.txt entropy: 7.9947037798Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.et_EE.txt entropy: 7.9930999479Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.et.txt entropy: 7.99466710516Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es__TRADITIONAL.txt entropy: 7.99467388574Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_VE.txt entropy: 7.99399243449Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_UY.txt entropy: 7.99514226544Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_US.txt entropy: 7.99445609411Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_SV.txt entropy: 7.99413236434Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_PY.txt entropy: 7.99435573635Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_PR.txt entropy: 7.99362811364Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_PE.txt entropy: 7.99464260712Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_PA.txt entropy: 7.99384189655Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_NI.txt entropy: 7.99405738902Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_MX.txt entropy: 7.9939074281Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_HN.txt entropy: 7.994160778Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_ES_PREEURO.txt entropy: 7.99495688771Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_ES.txt entropy: 7.99423480379Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_DO.txt entropy: 7.99444387396Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_EC.txt entropy: 7.99483389563Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_CR.txt entropy: 7.99324342382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_GT.txt entropy: 7.99427028282Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_CL.txt entropy: 7.99426059345Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_BO.txt entropy: 7.99416743147Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_CO.txt entropy: 7.99449774735Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es_AR.txt entropy: 7.99473654285Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.es.txt entropy: 7.99426162905Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.en_US.txt entropy: 7.99501151799Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.en_GB_EURO.txt entropy: 7.99351223836Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.en_US_POSIX.txt entropy: 7.99453492908Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.en_GB.txt entropy: 7.99427885961Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.en_CA.txt entropy: 7.99513186443Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.el_GR_PREEURO.txt entropy: 7.99482152704Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.el_GR.txt entropy: 7.99510917105Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.el.txt entropy: 7.99455859418Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.de_DE_PREEURO.txt entropy: 7.99511530204Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.de_DE.txt entropy: 7.99483313289Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.de_CH.txt entropy: 7.99376996075Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoDev.png entropy: 7.99242196214Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.da_DK.txt entropy: 7.99464704694Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoCanary.png entropy: 7.99355481759Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoBeta.png entropy: 7.99262713891Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.da.txt entropy: 7.99482272875Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.cs_CZ.txt entropy: 7.99445061033Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\Logo.png entropy: 7.993549537Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.cs.txt entropy: 7.99487254697Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\v8_context_snapshot.bin entropy: 7.99969692174Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ca_ES_PREEURO.txt entropy: 7.99429464203Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ca_ES.txt entropy: 7.9946252746Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\resources.pak entropy: 7.99745825914Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ca.txt entropy: 7.99401937782Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.bg_BG.txt entropy: 7.99440875168Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.bg.txt entropy: 7.99399162219Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_YE.txt entropy: 7.99392218158Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\nacl_irt_x86_64.nexe entropy: 7.99996235572Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_TN.txt entropy: 7.99404098905Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\zh-CN.pak entropy: 7.99949713251Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\vi.pak entropy: 7.99965790982Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\EFI\Microsoft\Recovery\BCD entropy: 7.99001782296Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\EFI\Microsoft\Recovery\BCD.LOG entropy: 7.99464828272Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_SY.txt entropy: 7.99548567676Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_SD.txt entropy: 7.99429450493Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ur.pak entropy: 7.99971566332Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_SA.txt entropy: 7.99475136228Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\uk.pak entropy: 7.99970709976Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_QA.txt entropy: 7.99399860152Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\th.pak entropy: 7.9997869456Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_OM.txt entropy: 7.99383247699Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\zh-TW.pak entropy: 7.9994931339Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_LY.txt entropy: 7.99417515767Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\te.pak entropy: 7.9998348376Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_MA.txt entropy: 7.99469681448Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sw.pak entropy: 7.99956086819Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_LB.txt entropy: 7.9944795951Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\tr.pak entropy: 7.99956305061Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_KW.txt entropy: 7.99422726824Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sv.pak entropy: 7.99959837644Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_JO.txt entropy: 7.99415271444Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ta.pak entropy: 7.99985096382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sr.pak entropy: 7.9997207902Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_IQ.txt entropy: 7.99479229242Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_IN.txt entropy: 7.99443538213Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sl.pak entropy: 7.99961897738Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_EG.txt entropy: 7.99576117878Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sk.pak entropy: 7.99960535682Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_DZ.txt entropy: 7.99366734803Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ro.pak entropy: 7.99964751151Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_BH.txt entropy: 7.99435824412Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ru.pak entropy: 7.99977401223Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar_AE.txt entropy: 7.9943220318Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pt-PT.pak entropy: 7.99959170763Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.ar.txt entropy: 7.99463235196Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pt-BR.pak entropy: 7.99955704498Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pl.pak entropy: 7.99958639241Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\nl.pak entropy: 7.99959402801Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ms.pak entropy: 7.99956399777Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\nb.pak entropy: 7.99953185152Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml entropy: 7.99168010653Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\mr.pak entropy: 7.9998076326Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ml.pak entropy: 7.99981927069Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\lv.pak entropy: 7.99959181368Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\lt.pak entropy: 7.99964351387Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ko.pak entropy: 7.99957705125Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\kn.pak entropy: 7.99982304048Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ja.pak entropy: 7.99964285652Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\it.pak entropy: 7.99957082281Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\id.pak entropy: 7.99958382187Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hu.pak entropy: 7.99964820777Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hr.pak entropy: 7.999631362Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\gu.pak entropy: 7.99983670085Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hi.pak entropy: 7.99981188867Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\he.pak entropy: 7.99971124954Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fr.pak entropy: 7.99967317136Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fil.pak entropy: 7.99967320925Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fi.pak entropy: 7.99961780933Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fa.pak entropy: 7.99973800025Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\et.pak entropy: 7.99955293351Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\es.pak entropy: 7.99958126474Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\install.log entropy: 7.99178017526Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\es-419.pak entropy: 7.99963430639Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\en-US.pak entropy: 7.9995534894Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\en-GB.pak entropy: 7.99945442925Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\el.pak entropy: 7.99977395733Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\de.pak entropy: 7.9996349874Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\da.pak entropy: 7.99960766516Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\cs.pak entropy: 7.99959760164Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ca.pak entropy: 7.99958847382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\bn.pak entropy: 7.99982648456Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ar.pak entropy: 7.99973610072Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\VisualElements\VisualElements_150.png entropy: 7.99229528753Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\fonts\TwemojiMozilla.ttf entropy: 7.99987820371Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\am.pak entropy: 7.99971384783Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\bg.pak entropy: 7.99976923985Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\af.pak entropy: 7.99953404437Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_200_percent.pak entropy: 7.99983715878Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi entropy: 7.99727669802Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi entropy: 7.99378764483Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_100_percent.pak entropy: 7.99972235137Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi entropy: 7.99880043582Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi entropy: 7.99863329468Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi entropy: 7.9995863954Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json entropy: 7.99739633038Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\initial_preferences entropy: 7.99961545101Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: B:\EFI\Microsoft\Recovery\BCD.LOG.3d828a.partial (copy) entropy: 7.99464828272Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: B:\EFI\Microsoft\Recovery\BCD.3d828a.partial (copy) entropy: 7.99001782296Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml.3d828a.partial (copy) entropy: 7.99168010653Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\FrameworkList.xml.3d828a (copy) entropy: 7.99168010653Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\fonts\TwemojiMozilla.ttf.3d828a.partial (copy) entropy: 7.99987820371Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\fonts\TwemojiMozilla.ttf.3d828a (copy) entropy: 7.99987820371Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\install.log.3d828a.partial (copy) entropy: 7.99178017526Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\install.log.3d828a (copy) entropy: 7.99178017526Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\VisualElements\VisualElements_150.png.3d828a.partial (copy) entropy: 7.99229528753Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\VisualElements\VisualElements_150.png.3d828a (copy) entropy: 7.99229528753Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi.3d828a.partial (copy) entropy: 7.9995863954Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi.3d828a (copy) entropy: 7.9995863954Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi.3d828a.partial (copy) entropy: 7.99880043582Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi.3d828a (copy) entropy: 7.99880043582Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi.3d828a.partial (copy) entropy: 7.99727669802Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\pictureinpicture@mozilla.org.xpi.3d828a (copy) entropy: 7.99727669802Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi.3d828a.partial (copy) entropy: 7.99378764483Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi.3d828a (copy) entropy: 7.99378764483Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi.3d828a.partial (copy) entropy: 7.99863329468Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi.3d828a (copy) entropy: 7.99863329468Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json.3d828a.partial (copy) entropy: 7.99739633038Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json.3d828a (copy) entropy: 7.99739633038Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\initial_preferences.3d828a.partial (copy) entropy: 7.99961545101Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\initial_preferences.3d828a (copy) entropy: 7.99961545101Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoDev.png.3d828a.partial (copy) entropy: 7.99242196214Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoDev.png.3d828a (copy) entropy: 7.99242196214Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoCanary.png.3d828a.partial (copy) entropy: 7.99355481759Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoCanary.png.3d828a (copy) entropy: 7.99355481759Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoBeta.png.3d828a.partial (copy) entropy: 7.99262713891Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\LogoBeta.png.3d828a (copy) entropy: 7.99262713891Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\Logo.png.3d828a.partial (copy) entropy: 7.993549537Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\Logo.png.3d828a (copy) entropy: 7.993549537Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\v8_context_snapshot.bin.3d828a.partial (copy) entropy: 7.99969692174Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\v8_context_snapshot.bin.3d828a (copy) entropy: 7.99969692174Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\resources.pak.3d828a.partial (copy) entropy: 7.99745825914Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\nacl_irt_x86_64.nexe.3d828a.partial (copy) entropy: 7.99996235572Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\nacl_irt_x86_64.nexe.3d828a (copy) entropy: 7.99996235572Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\zh-TW.pak.3d828a.partial (copy) entropy: 7.9994931339Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\zh-TW.pak.3d828a (copy) entropy: 7.9994931339Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\zh-CN.pak.3d828a.partial (copy) entropy: 7.99949713251Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\zh-CN.pak.3d828a (copy) entropy: 7.99949713251Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\vi.pak.3d828a.partial (copy) entropy: 7.99965790982Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\vi.pak.3d828a (copy) entropy: 7.99965790982Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ur.pak.3d828a.partial (copy) entropy: 7.99971566332Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ur.pak.3d828a (copy) entropy: 7.99971566332Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\uk.pak.3d828a.partial (copy) entropy: 7.99970709976Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\uk.pak.3d828a (copy) entropy: 7.99970709976Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\th.pak.3d828a.partial (copy) entropy: 7.9997869456Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\th.pak.3d828a (copy) entropy: 7.9997869456Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\te.pak.3d828a.partial (copy) entropy: 7.9998348376Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\te.pak.3d828a (copy) entropy: 7.9998348376Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ta.pak.3d828a.partial (copy) entropy: 7.99985096382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ta.pak.3d828a (copy) entropy: 7.99985096382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sw.pak.3d828a.partial (copy) entropy: 7.99956086819Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sw.pak.3d828a (copy) entropy: 7.99956086819Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\tr.pak.3d828a.partial (copy) entropy: 7.99956305061Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\tr.pak.3d828a (copy) entropy: 7.99956305061Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sv.pak.3d828a.partial (copy) entropy: 7.99959837644Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sv.pak.3d828a (copy) entropy: 7.99959837644Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sr.pak.3d828a.partial (copy) entropy: 7.9997207902Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sr.pak.3d828a (copy) entropy: 7.9997207902Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sl.pak.3d828a.partial (copy) entropy: 7.99961897738Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sl.pak.3d828a (copy) entropy: 7.99961897738Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sk.pak.3d828a.partial (copy) entropy: 7.99960535682Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\sk.pak.3d828a (copy) entropy: 7.99960535682Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ru.pak.3d828a.partial (copy) entropy: 7.99977401223Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ru.pak.3d828a (copy) entropy: 7.99977401223Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ro.pak.3d828a.partial (copy) entropy: 7.99964751151Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ro.pak.3d828a (copy) entropy: 7.99964751151Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pt-PT.pak.3d828a.partial (copy) entropy: 7.99959170763Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pt-PT.pak.3d828a (copy) entropy: 7.99959170763Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pt-BR.pak.3d828a.partial (copy) entropy: 7.99955704498Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pt-BR.pak.3d828a (copy) entropy: 7.99955704498Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pl.pak.3d828a.partial (copy) entropy: 7.99958639241Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\pl.pak.3d828a (copy) entropy: 7.99958639241Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\nl.pak.3d828a.partial (copy) entropy: 7.99959402801Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\nl.pak.3d828a (copy) entropy: 7.99959402801Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\nb.pak.3d828a.partial (copy) entropy: 7.99953185152Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\nb.pak.3d828a (copy) entropy: 7.99953185152Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ms.pak.3d828a.partial (copy) entropy: 7.99956399777Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ms.pak.3d828a (copy) entropy: 7.99956399777Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\mr.pak.3d828a.partial (copy) entropy: 7.9998076326Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\mr.pak.3d828a (copy) entropy: 7.9998076326Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ml.pak.3d828a.partial (copy) entropy: 7.99981927069Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ml.pak.3d828a (copy) entropy: 7.99981927069Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\lv.pak.3d828a.partial (copy) entropy: 7.99959181368Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\lv.pak.3d828a (copy) entropy: 7.99959181368Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\lt.pak.3d828a.partial (copy) entropy: 7.99964351387Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\lt.pak.3d828a (copy) entropy: 7.99964351387Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ko.pak.3d828a.partial (copy) entropy: 7.99957705125Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ko.pak.3d828a (copy) entropy: 7.99957705125Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\kn.pak.3d828a.partial (copy) entropy: 7.99982304048Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\kn.pak.3d828a (copy) entropy: 7.99982304048Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ja.pak.3d828a.partial (copy) entropy: 7.99964285652Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ja.pak.3d828a (copy) entropy: 7.99964285652Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\it.pak.3d828a.partial (copy) entropy: 7.99957082281Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\it.pak.3d828a (copy) entropy: 7.99957082281Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\id.pak.3d828a.partial (copy) entropy: 7.99958382187Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\id.pak.3d828a (copy) entropy: 7.99958382187Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hu.pak.3d828a.partial (copy) entropy: 7.99964820777Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hu.pak.3d828a (copy) entropy: 7.99964820777Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hr.pak.3d828a.partial (copy) entropy: 7.999631362Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hr.pak.3d828a (copy) entropy: 7.999631362Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hi.pak.3d828a.partial (copy) entropy: 7.99981188867Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\hi.pak.3d828a (copy) entropy: 7.99981188867Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\he.pak.3d828a.partial (copy) entropy: 7.99971124954Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\he.pak.3d828a (copy) entropy: 7.99971124954Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\gu.pak.3d828a.partial (copy) entropy: 7.99983670085Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\gu.pak.3d828a (copy) entropy: 7.99983670085Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fr.pak.3d828a.partial (copy) entropy: 7.99967317136Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fr.pak.3d828a (copy) entropy: 7.99967317136Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fil.pak.3d828a.partial (copy) entropy: 7.99967320925Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fil.pak.3d828a (copy) entropy: 7.99967320925Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fi.pak.3d828a.partial (copy) entropy: 7.99961780933Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fi.pak.3d828a (copy) entropy: 7.99961780933Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fa.pak.3d828a.partial (copy) entropy: 7.99973800025Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\fa.pak.3d828a (copy) entropy: 7.99973800025Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\et.pak.3d828a.partial (copy) entropy: 7.99955293351Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\et.pak.3d828a (copy) entropy: 7.99955293351Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\es.pak.3d828a.partial (copy) entropy: 7.99958126474Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\es.pak.3d828a (copy) entropy: 7.99958126474Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\es-419.pak.3d828a.partial (copy) entropy: 7.99963430639Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\es-419.pak.3d828a (copy) entropy: 7.99963430639Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\en-US.pak.3d828a.partial (copy) entropy: 7.9995534894Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\en-US.pak.3d828a (copy) entropy: 7.9995534894Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\en-GB.pak.3d828a.partial (copy) entropy: 7.99945442925Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\en-GB.pak.3d828a (copy) entropy: 7.99945442925Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\el.pak.3d828a.partial (copy) entropy: 7.99977395733Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\el.pak.3d828a (copy) entropy: 7.99977395733Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\de.pak.3d828a.partial (copy) entropy: 7.9996349874Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\de.pak.3d828a (copy) entropy: 7.9996349874Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\da.pak.3d828a.partial (copy) entropy: 7.99960766516Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\da.pak.3d828a (copy) entropy: 7.99960766516Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\cs.pak.3d828a.partial (copy) entropy: 7.99959760164Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\cs.pak.3d828a (copy) entropy: 7.99959760164Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ca.pak.3d828a.partial (copy) entropy: 7.99958847382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ca.pak.3d828a (copy) entropy: 7.99958847382Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\bn.pak.3d828a.partial (copy) entropy: 7.99982648456Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\bn.pak.3d828a (copy) entropy: 7.99982648456Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\bg.pak.3d828a.partial (copy) entropy: 7.99976923985Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\bg.pak.3d828a (copy) entropy: 7.99976923985Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ar.pak.3d828a.partial (copy) entropy: 7.99973610072Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\ar.pak.3d828a (copy) entropy: 7.99973610072Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\am.pak.3d828a.partial (copy) entropy: 7.99971384783Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\am.pak.3d828a (copy) entropy: 7.99971384783Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\af.pak.3d828a.partial (copy) entropy: 7.99953404437Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\af.pak.3d828a (copy) entropy: 7.99953404437Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_200_percent.pak.3d828a.partial (copy) entropy: 7.99983715878Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_200_percent.pak.3d828a (copy) entropy: 7.99983715878Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_100_percent.pak.3d828a.partial (copy) entropy: 7.99972235137Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_100_percent.pak.3d828a (copy) entropy: 7.99972235137Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\hyph_en_US.dic.3d828a.partial (copy) entropy: 7.99907656466Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\hyph_en_US.dic.3d828a (copy) entropy: 7.99907656466Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\hyph_en_GB.dic.3d828a.partial (copy) entropy: 7.99886098555Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\hyph_en_GB.dic.3d828a (copy) entropy: 7.99886098555Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\hyph_en_CA.dic.3d828a.partial (copy) entropy: 7.99937011868Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\hyph_en_CA.dic.3d828a (copy) entropy: 7.99937011868Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_TW.txt.3d828a.partial (copy) entropy: 7.99392018051Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_TW.txt.3d828a (copy) entropy: 7.99392018051Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_TW_STROKE.txt.3d828a.partial (copy) entropy: 7.9937413465Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.zh_TW_STROKE.txt.3d828a (copy) entropy: 7.9937413465Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\en_CA.dic.3d828a.partial (copy) entropy: 7.99979800738Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\en_CA.dic.3d828a (copy) entropy: 7.99979800738Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\en_US.dic.3d828a.partial (copy) entropy: 7.99977773763Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\en_US.dic.3d828a (copy) entropy: 7.99977773763Jump to dropped file
      Source: C:\Users\user\Desktop\win32.exeProcess Stats: CPU usage > 49%
      Source: win32.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE, DEBUG_STRIPPED
      Source: win32.exeBinary or memory string: msbuild*.csproj*.fsproj*.vcxproj*.proj*.props*.targets
      Source: classification engineClassification label: mal100.rans.troj.evad.winEXE@10/1299@0/0
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\Program Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7532:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3848:120:WilError_03
      Source: C:\Users\user\Desktop\win32.exeMutant created: \Sessions\1\BaseNamedObjects\IntoTheFloodAgainSameOldTrip
      Source: win32.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\win32.exeFile read: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\win32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: win32.exeReversingLabs: Detection: 60%
      Source: win32.exeString found in binary or memory: --helphelpinternal error: entered unreachable code: invalid Once state
      Source: win32.exeString found in binary or memory: --helphelpinternal error: entered unreachable code: invalid Once state
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.3.9/src/meta/stopat.rs
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.3.9/src/meta/stopat.rs
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.3.9/src/meta/stopat.rs$
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.3.9/src/meta/stopat.rs$
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.4.5/src/meta/stopat.rs
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.4.5/src/meta/stopat.rs
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.4.5/src/meta/stopat.rs@
      Source: win32.exeString found in binary or memory: /home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001f/regex-automata-0.4.5/src/meta/stopat.rs@
      Source: win32.exeString found in binary or memory: did not find expected <stream-start>
      Source: win32.exeString found in binary or memory: did not find expected <stream-start>did not find expected <document start>while parsing node, found unknown anchor
      Source: win32.exeString found in binary or memory: did not find expected <stream-start>did not find expected <document start>while parsing node, found unknown anchor{
      Source: win32.exeString found in binary or memory: helpPrint helpPrint help (see more with '--help')Print help (see a summary with '-h')versionPrint versionPrint this message or the help of the given subcommand(s)subcommandCOMMANDPrint help for the subcommand(s)
      Source: win32.exeString found in binary or memory: helpPrint helpPrint help (see more with '--help')Print help (see a summary with '-h')versionPrint versionPrint this message or the help of the given subcommand(s)subcommandCOMMANDPrint help for the subcommand(s)
      Source: win32.exeString found in binary or memory: 3helpPrint helpPrint help (see more with '--help')Print help (see a summary with '-h')versionPrint versionPrint this message or the help of the given subcommand(s)subcommandCOMMANDPrint help for the subcommand(s)
      Source: win32.exeString found in binary or memory: 3helpPrint helpPrint help (see more with '--help')Print help (see a summary with '-h')versionPrint versionPrint this message or the help of the given subcommand(s)subcommandCOMMANDPrint help for the subcommand(s)
      Source: win32.exeString found in binary or memory: --helphelp
      Source: win32.exeString found in binary or memory: --helphelp
      Source: win32.exeString found in binary or memory: ep6--helphelp
      Source: win32.exeString found in binary or memory: ep6--helphelp
      Source: win32.exeString found in binary or memory: {before-help}{about-with-newline}
      Source: win32.exeString found in binary or memory: {usage-heading} {usage}{after-help}{before-help}{about-with-newline}
      Source: win32.exeString found in binary or memory: {all-args}{after-help}
      Source: win32.exeString found in binary or memory: 7{before-help}{about-with-newline}
      Source: win32.exeString found in binary or memory: namebinversionauthorauthor-with-newlineauthor-sectionaboutabout-with-newlineabout-sectionusage-headingusageall-argsoptionspositionalssubcommandstabafter-helpbefore-help{}
      Source: unknownProcess created: C:\Users\user\Desktop\win32.exe "C:\Users\user\Desktop\win32.exe"
      Source: C:\Users\user\Desktop\win32.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled no
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled no
      Source: C:\Users\user\Desktop\win32.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping localhost -n 5
      Source: C:\Users\user\Desktop\win32.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled noJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled noJump to behavior
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping localhost -n 5Jump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: mpr.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: netapi32.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: rstrtmgr.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: drprov.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: winsta.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: ntlanman.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: davclnt.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: davhlpr.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: wkscli.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: cscapi.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeSection loaded: browcli.dllJump to behavior
      Source: C:\Windows\System32\bcdedit.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Windows\SysWOW64\PING.EXESection loaded: iphlpapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\PING.EXESection loaded: mswsock.dllJump to behavior
      Source: C:\Windows\SysWOW64\PING.EXESection loaded: dnsapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\PING.EXESection loaded: rasadhlp.dllJump to behavior
      Source: C:\Windows\SysWOW64\PING.EXESection loaded: fwpuclnt.dllJump to behavior
      Source: C:\Windows\SysWOW64\PING.EXESection loaded: winnsi.dllJump to behavior
      Source: C:\Users\user\Desktop\win32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4a04656d-52aa-49de-8a09-cb178760e748}\InProcServer32Jump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile written: C:\Program Files\Mozilla Firefox\updater.iniJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\MSBuild\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\MSBuild\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\uninstall\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\fonts\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\defaults\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\defaults\pref\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\browser\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\browser\VisualElements\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Mozilla Firefox\browser\features\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft Office 15\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft Office 15\ClientX64\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\OneDrive\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\OneDrive\ListSync\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\SetupMetrics\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\_platform_specific\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\_platform_specific\win_x64\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\MEIPreload\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Extensions\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\default_apps\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\HelpCfg\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\HelpCfg\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-1033-7760-BC15014EA700}\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-1033-7760-BC15014EA700}\Transforms\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\VCRT_x64\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_GB\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_CA\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_GB\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\en_CA\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_US\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_GB\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Abbreviations\en_CA\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Adobe\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\Transforms\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: win32.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
      Source: win32.exeStatic file information: File size 6241792 > 1048576
      Source: win32.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x46c000
      Source: win32.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT
      Source: win32.exeStatic PE information: real checksum: 0x602066 should be: 0x600eec
      Source: win32.exeStatic PE information: section name: .eh_fram

      Persistence and Installation Behavior

      barindex
      Source: C:\Users\user\Desktop\win32.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled no
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled no
      Source: C:\Users\user\Desktop\win32.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled noJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled noJump to behavior

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: C:\Users\user\Desktop\win32.exeFile created: C:\$Recycle.Bin\HOW_TO_RECOVER_FILES.txtJump to behavior
      Source: C:\Users\user\Desktop\win32.exeProcess created: "C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe

      Malware Analysis System Evasion

      barindex
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping localhost -n 5
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping localhost -n 5Jump to behavior
      Source: C:\Windows\SysWOW64\PING.EXELast function: Thread delayed
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionaries\en_USJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPluginJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\SupplementalDictionariesJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\ProvidersJump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2Jump to behavior
      Source: C:\Users\user\Desktop\win32.exeFile opened: C:\Program Files\Common Files\Adobe\Acrobat\DC\LinguisticsJump to behavior
      Source: bcdedit.exe, 00000003.00000002.1704544147.000001E9EA9C8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: pEFI VMware Virtual SAT
      Source: win32.exe, 00000000.00000003.1710686721.00000000016DC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Vol4,
      Source: bcdedit.exe, 00000003.00000002.1704544147.000001E9EA9C8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: pEFI VMware Virtual SATA CDROM Drive (0.0)
      Source: C:\Users\user\Desktop\win32.exeProcess information queried: ProcessInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeMemory allocated: page read and write | page guardJump to behavior
      Source: C:\Users\user\Desktop\win32.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled noJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled noJump to behavior
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping localhost -n 5Jump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$WinREAgent VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Users VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$WinREAgent\Scratch VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Users VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$WinREAgent VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\$WinREAgent\Scratch VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG1 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG2 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG2 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG1 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG2 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG2 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG1 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery\BCD.LOG1 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\EFI\Microsoft\Recovery VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files (x86) VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files\7-Zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files\Adobe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files\Common Files VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files\Google VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeQueries volume information: C:\Program Files\Microsoft VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory queried: C:\Documents and SettingsJump to behavior
      Source: C:\Users\user\Desktop\win32.exeDirectory queried: number of queries: 1001
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
      Command and Scripting Interpreter
      1
      DLL Side-Loading
      11
      Process Injection
      2
      Masquerading
      OS Credential Dumping1
      Security Software Discovery
      Remote Services1
      Data from Local System
      1
      Proxy
      Exfiltration Over Other Network Medium2
      Data Encrypted for Impact
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      DLL Side-Loading
      1
      Disable or Modify Tools
      LSASS Memory1
      Process Discovery
      Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over Bluetooth1
      Inhibit System Recovery
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
      Process Injection
      Security Account Manager1
      Remote System Discovery
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
      Hidden Files and Directories
      NTDS1
      System Network Configuration Discovery
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      DLL Side-Loading
      LSA Secrets23
      File and Directory Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
      File Deletion
      Cached Domain Credentials11
      System Information Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet
      behaviorgraph top1 signatures2 2 Behavior Graph ID: 1541094 Sample: win32.exe Startdate: 24/10/2024 Architecture: WINDOWS Score: 100 32 Antivirus / Scanner detection for submitted sample 2->32 34 Multi AV Scanner detection for submitted file 2->34 36 Found ransom note / readme 2->36 38 5 other signatures 2->38 7 win32.exe 87 2->7         started        process3 file4 24 screenshots@mozill...828a.partial (copy), COM 7->24 dropped 26 screenshots@mozill...g.xpi.3d828a (copy), COM 7->26 dropped 28 C:\...\screenshots@mozilla.org.xpi, COM 7->28 dropped 30 487 other files (479 malicious) 7->30 dropped 40 Creates files in the recycle bin to hide itself 7->40 42 Drops a file containing file decryption instructions (likely related to ransomware) 7->42 44 Self deletion via cmd or bat file 7->44 46 3 other signatures 7->46 11 cmd.exe 1 7->11         started        14 cmd.exe 1 7->14         started        signatures5 process6 signatures7 48 Uses ping.exe to sleep 11->48 50 Uses ping.exe to check the status of other devices and networks 11->50 16 conhost.exe 11->16         started        18 PING.EXE 1 11->18         started        52 Uses bcdedit to modify the Windows boot settings 14->52 20 bcdedit.exe 8 1 14->20         started        22 conhost.exe 14->22         started        process8

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      win32.exe61%ReversingLabsWin32.Ransomware.Embargo
      win32.exe100%AviraTR/AD.Nekark.xkwab
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      https://www.torproject.org/download/HOW_TO_RECOVER_FILES.txt50.0.dr, HOW_TO_RECOVER_FILES.txt13.0.dr, HOW_TO_RECOVER_FILES.txt77.0.dr, HOW_TO_RECOVER_FILES.txt203.0.dr, HOW_TO_RECOVER_FILES.txt109.0.dr, HOW_TO_RECOVER_FILES.txt106.0.dr, HOW_TO_RECOVER_FILES.txt34.0.dr, HOW_TO_RECOVER_FILES.txt8.0.dr, HOW_TO_RECOVER_FILES.txt193.0.dr, HOW_TO_RECOVER_FILES.txt144.0.dr, HOW_TO_RECOVER_FILES.txt147.0.dr, HOW_TO_RECOVER_FILES.txt61.0.dr, HOW_TO_RECOVER_FILES.txt42.0.dr, HOW_TO_RECOVER_FILES.txt221.0.dr, HOW_TO_RECOVER_FILES.txt23.0.dr, HOW_TO_RECOVER_FILES.txt87.0.dr, HOW_TO_RECOVER_FILES.txt264.0.dr, HOW_TO_RECOVER_FILES.txt286.0.dr, HOW_TO_RECOVER_FILES.txt53.0.dr, HOW_TO_RECOVER_FILES.txt114.0.dr, HOW_TO_RECOVER_FILES.txt7.0.drtrue
        unknown
        https://github.com/clap-rs/clap/issues/home/user/.cargo/registry/src/index.crates.io-6f17d22bba15001win32.exefalse
          unknown
          http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fHOW_TO_RECOVER_FILES.txt50.0.dr, HOW_TO_RECOVER_FILES.txt13.0.dr, HOW_TO_RECOVER_FILES.txt77.0.dr, HOW_TO_RECOVER_FILES.txt203.0.dr, HOW_TO_RECOVER_FILES.txt109.0.dr, HOW_TO_RECOVER_FILES.txt106.0.dr, HOW_TO_RECOVER_FILES.txt34.0.dr, HOW_TO_RECOVER_FILES.txt8.0.dr, HOW_TO_RECOVER_FILES.txt193.0.dr, HOW_TO_RECOVER_FILES.txt144.0.dr, HOW_TO_RECOVER_FILES.txt147.0.dr, HOW_TO_RECOVER_FILES.txt61.0.dr, HOW_TO_RECOVER_FILES.txt42.0.dr, HOW_TO_RECOVER_FILES.txt221.0.dr, HOW_TO_RECOVER_FILES.txt23.0.dr, HOW_TO_RECOVER_FILES.txt87.0.dr, HOW_TO_RECOVER_FILES.txt264.0.dr, HOW_TO_RECOVER_FILES.txt286.0.dr, HOW_TO_RECOVER_FILES.txt53.0.dr, HOW_TO_RECOVER_FILES.txt114.0.dr, HOW_TO_RECOVER_FILES.txt7.0.drtrue
            unknown
            https://github.com/clap-rs/clap/issueswin32.exefalse
              unknown
              http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/HOW_TO_RECOVER_FILES.txt50.0.dr, HOW_TO_RECOVER_FILES.txt13.0.dr, HOW_TO_RECOVER_FILES.txt77.0.dr, HOW_TO_RECOVER_FILES.txt203.0.dr, HOW_TO_RECOVER_FILES.txt109.0.dr, HOW_TO_RECOVER_FILES.txt106.0.dr, HOW_TO_RECOVER_FILES.txt34.0.dr, HOW_TO_RECOVER_FILES.txt8.0.dr, HOW_TO_RECOVER_FILES.txt193.0.dr, HOW_TO_RECOVER_FILES.txt144.0.dr, HOW_TO_RECOVER_FILES.txt147.0.dr, HOW_TO_RECOVER_FILES.txt61.0.dr, HOW_TO_RECOVER_FILES.txt42.0.dr, HOW_TO_RECOVER_FILES.txt221.0.dr, HOW_TO_RECOVER_FILES.txt23.0.dr, HOW_TO_RECOVER_FILES.txt87.0.dr, HOW_TO_RECOVER_FILES.txt264.0.dr, HOW_TO_RECOVER_FILES.txt286.0.dr, HOW_TO_RECOVER_FILES.txt53.0.dr, HOW_TO_RECOVER_FILES.txt114.0.dr, HOW_TO_RECOVER_FILES.txt7.0.drtrue
                unknown
                https://docs.rs/getrandom#nodejs-es-module-supportwin32.exefalse
                  unknown
                  No contacted IP infos
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1541094
                  Start date and time:2024-10-24 12:09:11 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 10m 5s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:default.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:19
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:win32.exe
                  Detection:MAL
                  Classification:mal100.rans.troj.evad.winEXE@10/1299@0/0
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • Found application associated with file extension: .exe
                  • Override analysis time to 240s for sample files taking high CPU consumption
                  • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • Report size getting too big, too many NtOpenKeyEx calls found.
                  • Report size getting too big, too many NtQueryDirectoryFile calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                  • Report size getting too big, too many NtSetInformationFile calls found.
                  • Report size getting too big, too many NtWriteFile calls found.
                  • VT rate limit hit for: win32.exe
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):20640
                  Entropy (8bit):7.990017822957713
                  Encrypted:true
                  SSDEEP:384:jgIMCQ0AmpmpYXOSHD+9LGh6c0WBDAn/8eT89Ox9iROlshAv8EBGKkJJmFl:jgI5AAmpgXf3DBDAn/z8UQROlzzQKkO
                  MD5:D7A38C98A084BBECFC4D7DF12DCBB9EF
                  SHA1:F928D24820B9924ED3BF5EE296CE5E1ED27FECCB
                  SHA-256:C8DC220DF0102E9050892890C60E2C7523342153C6AB1F7790DCD4CA81B0D547
                  SHA-512:DF87FF82159EA0FEEF8D00F5E28E64D78BD43E79927B7960E6AAF36ADDB829DAA244D360EDA1B430547C91596CDD7585CC2A249B05E041D1AAF828C63DA576BE
                  Malicious:true
                  Reputation:low
                  Preview:|.<.[..Q28.NE..'Z..r7.<......i..Fi.S.]....Mt......n....`._2...(K....|?.Kmo..yZ......L...)..Q#t.J.u..J.#J.$).a.....l30.1|`8...|....3...tu..GAy...L.\f...c.*>...PH..^.$...b.k....".vl6...W]O..by%.m..Q.w.7.C._. Qu......@...?..Yyc.v........r...a)PfF..6.|~.nA..1.;.<...]t....)<e.m4....-fEo%...4..k.sK..~i.h`...7.X..P.#.i,...Z`._..=.Y..[.R.Q.1y....B...&...2.i9.2...$...i...b..1w..o.$..T..TM.pt........4..g..Z.....UW@..A.{..(+.n..43.3..._/.nA.h..-.@.....s.IP....n....q.u%|.B*y...u.M.].[....wC.4...O,...k...X..y.r.....E~.WF......RD.T...m.AY.=hpY.........,Z..H.3m.Db.-..s`.I...S...|.6.t......%{.....o.a...U..J./T.5.+....,..(.m.....8.....$...aR..`FKo.U.Ce[......Z....#.....Kq.c3f.....D...;...,s..M....]...H...\.u...,.....zG1...y=...Q..P...._k.~.....&Z.#..b...n....B)E:..y,..>8....iZD....m<.l.kKW.]........d.XU.Zg.-.M.h. .'...E.t..8..3....[?.e.i}....d...f.LA@%.*+%.X..E.......=1`FN..S.M.Da%.<..~.XH....8.2..5......+...) #[n......|...(....R1.....4gt.'.Q..`xT...|n...SY
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32928
                  Entropy (8bit):7.9946482827208
                  Encrypted:true
                  SSDEEP:768:4bbfb1TadunJKBS8u+3CYqeQ69EkR53EN5h6c:gbDBaMJK4J+yY02RK
                  MD5:0290DE98BE5982B9B62D05F7CE7F7E77
                  SHA1:F7FA0D24A36CEEEE6B7BC6FC7E59968AA782CAAB
                  SHA-256:C6141742E20DCC8C210CFC7A0249978101A3D48972288D3E9B2E6543189554F2
                  SHA-512:BC60D5649E893ED8FE31AD13CF26E11E0F1A9C39AE612CD912DFF03436B1C1486FB4DAA37F9D45687ECE3F5AC8623FDBF0FB7924B0D7E5CB441BF16766E2689E
                  Malicious:true
                  Reputation:low
                  Preview:.....D...E.@.l...~.=....N.......1...+.x...........AfD....r.%..G4....6..~..G*i...4...%.S.V)../..?D.J.n....id..*..fw>.;.....K.x..p......4y.D.*.=u.*R.O@u_E...T.....Q.........ZR....5kH.8..CWB...+..pn?......@j.9..e\.>.0..T..I..p.....:'".Q`.T.(..2^._...F..1.....=.;RY....2~/X t...4....1.."....y1....HX.;G.jG...j==q....6......Z..p..'Rp...:........=#,..~0..T.n....D..To..D_ys....."..@..........j.3M.n.p.n..dWL./>...o..B......*M>;.BY...:....$......uu.5........{b.....|.}. TA..U.6.b.92.....xJn=....d8MC.H.:A.Y.:......S..|.......H4............t.lSr...u......F..^H..cH?2....HK.).YK.'$.2E.^...<..r9...}...8.7y......,....8.Y.4..+...iTc)H..(...aj.q....K.S..,..T...y....R!ie...c~..T.G.i..\>...fs...RMnG*.Z.y..li..J`../....&..T\f.....=n6..........N$.xZ..-.uDU.....t..]|.d.g.......>M.P.<,.....dF9....1.....4b.AZ...b....h..j..i.t.yQ..k...||q...0..^,jY-...By...u.....wL..e./4I08mN)1M.O...fD0..L...d..a.OL.....f.......!.7n..b...C...A..M.t. ..;O.....f.Om..]c...;:...O..I
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):160
                  Entropy (8bit):6.053295873768159
                  Encrypted:false
                  SSDEEP:3:POt7Lc+7iHf7BE0MJ0K1XUa4AA1gw3nVXolFxYnS0l9ll:POts+7iHNE0aNCgmu6nSc
                  MD5:421592C09BDDE0ABA0EA30318CFA05AF
                  SHA1:9490C8B3AC95A96A3EBA80416003C116C7210B30
                  SHA-256:DE5B7099006106FA24C9AEFF37F46633D923392D58D6DAEA5ADE116E96F1B434
                  SHA-512:79051B5786D81B58B40D284EAD7DEA303DAD734AF2D95CB2462EE8BF6238ADA5C0F7FC128A99BC0DFE2415C9494930774AAB8FF05BC7054B52196457360A0706
                  Malicious:false
                  Reputation:low
                  Preview:.Ta.+6..<...0...7W..w..wb.Y@.....'...n.`......;S#%.u{..90................V..RZw.R../D. *.....l\vpr.P.S.n.=.0s#..~.V..}..kdlV........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):160
                  Entropy (8bit):6.009668061322245
                  Encrypted:false
                  SSDEEP:3:IEL7iU2bNpnBgY9IUSd+JXll7KmPdNfoXfWNIL74mEu0l9ll:5PmzJga1ttPfoYM4juc
                  MD5:762605AB2798F836D4CCC388EC76471B
                  SHA1:B25C0E045961DC0547299C770B4DF91277788D59
                  SHA-256:158D451E0F4253052A28B8A033D0951985B40997EDE35B14F2755C7B4BDCD4E7
                  SHA-512:FD21CC768295D047B0CEFAF7817CB34153D7827BB516C0A891270BB852654EBFD049F5AD382F2A7E8543CFA9E90C55754860ED2D961710C9738205B3C491B820
                  Malicious:false
                  Reputation:low
                  Preview:...a_6:...=....6c...(...S~?j..gL.....eKq\...U-...w...KV.8.............c.be.........<.}x....T$:!............."m...w.bR..AG ........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Reputation:low
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):20640
                  Entropy (8bit):7.990017822957713
                  Encrypted:true
                  SSDEEP:384:jgIMCQ0AmpmpYXOSHD+9LGh6c0WBDAn/8eT89Ox9iROlshAv8EBGKkJJmFl:jgI5AAmpgXf3DBDAn/z8UQROlzzQKkO
                  MD5:D7A38C98A084BBECFC4D7DF12DCBB9EF
                  SHA1:F928D24820B9924ED3BF5EE296CE5E1ED27FECCB
                  SHA-256:C8DC220DF0102E9050892890C60E2C7523342153C6AB1F7790DCD4CA81B0D547
                  SHA-512:DF87FF82159EA0FEEF8D00F5E28E64D78BD43E79927B7960E6AAF36ADDB829DAA244D360EDA1B430547C91596CDD7585CC2A249B05E041D1AAF828C63DA576BE
                  Malicious:true
                  Preview:|.<.[..Q28.NE..'Z..r7.<......i..Fi.S.]....Mt......n....`._2...(K....|?.Kmo..yZ......L...)..Q#t.J.u..J.#J.$).a.....l30.1|`8...|....3...tu..GAy...L.\f...c.*>...PH..^.$...b.k....".vl6...W]O..by%.m..Q.w.7.C._. Qu......@...?..Yyc.v........r...a)PfF..6.|~.nA..1.;.<...]t....)<e.m4....-fEo%...4..k.sK..~i.h`...7.X..P.#.i,...Z`._..=.Y..[.R.Q.1y....B...&...2.i9.2...$...i...b..1w..o.$..T..TM.pt........4..g..Z.....UW@..A.{..(+.n..43.3..._/.nA.h..-.@.....s.IP....n....q.u%|.B*y...u.M.].[....wC.4...O,...k...X..y.r.....E~.WF......RD.T...m.AY.=hpY.........,Z..H.3m.Db.-..s`.I...S...|.6.t......%{.....o.a...U..J./T.5.+....,..(.m.....8.....$...aR..`FKo.U.Ce[......Z....#.....Kq.c3f.....D...;...,s..M....]...H...\.u...,.....zG1...y=...Q..P...._k.~.....&Z.#..b...n....B)E:..y,..>8....iZD....m<.l.kKW.]........d.XU.Zg.-.M.h. .'...E.t..8..3....[?.e.i}....d...f.LA@%.*+%.X..E.......=1`FN..S.M.Da%.<..~.XH....8.2..5......+...) #[n......|...(....R1.....4gt.'.Q..`xT...|n...SY
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32928
                  Entropy (8bit):7.9946482827208
                  Encrypted:true
                  SSDEEP:768:4bbfb1TadunJKBS8u+3CYqeQ69EkR53EN5h6c:gbDBaMJK4J+yY02RK
                  MD5:0290DE98BE5982B9B62D05F7CE7F7E77
                  SHA1:F7FA0D24A36CEEEE6B7BC6FC7E59968AA782CAAB
                  SHA-256:C6141742E20DCC8C210CFC7A0249978101A3D48972288D3E9B2E6543189554F2
                  SHA-512:BC60D5649E893ED8FE31AD13CF26E11E0F1A9C39AE612CD912DFF03436B1C1486FB4DAA37F9D45687ECE3F5AC8623FDBF0FB7924B0D7E5CB441BF16766E2689E
                  Malicious:true
                  Preview:.....D...E.@.l...~.=....N.......1...+.x...........AfD....r.%..G4....6..~..G*i...4...%.S.V)../..?D.J.n....id..*..fw>.;.....K.x..p......4y.D.*.=u.*R.O@u_E...T.....Q.........ZR....5kH.8..CWB...+..pn?......@j.9..e\.>.0..T..I..p.....:'".Q`.T.(..2^._...F..1.....=.;RY....2~/X t...4....1.."....y1....HX.;G.jG...j==q....6......Z..p..'Rp...:........=#,..~0..T.n....D..To..D_ys....."..@..........j.3M.n.p.n..dWL./>...o..B......*M>;.BY...:....$......uu.5........{b.....|.}. TA..U.6.b.92.....xJn=....d8MC.H.:A.Y.:......S..|.......H4............t.lSr...u......F..^H..cH?2....HK.).YK.'$.2E.^...<..r9...}...8.7y......,....8.Y.4..+...iTc)H..(...aj.q....K.S..,..T...y....R!ie...c~..T.G.i..\>...fs...RMnG*.Z.y..li..J`../....&..T\f.....=n6..........N$.xZ..-.uDU.....t..]|.d.g.......>M.P.<,.....dF9....1.....4b.AZ...b....h..j..i.t.yQ..k...||q...0..^,jY-...By...u.....wL..e./4I08mN)1M.O...fD0..L...d..a.OL.....f.......!.7n..b...C...A..M.t. ..;O.....f.Om..]c...;:...O..I
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):160
                  Entropy (8bit):6.053295873768159
                  Encrypted:false
                  SSDEEP:3:POt7Lc+7iHf7BE0MJ0K1XUa4AA1gw3nVXolFxYnS0l9ll:POts+7iHNE0aNCgmu6nSc
                  MD5:421592C09BDDE0ABA0EA30318CFA05AF
                  SHA1:9490C8B3AC95A96A3EBA80416003C116C7210B30
                  SHA-256:DE5B7099006106FA24C9AEFF37F46633D923392D58D6DAEA5ADE116E96F1B434
                  SHA-512:79051B5786D81B58B40D284EAD7DEA303DAD734AF2D95CB2462EE8BF6238ADA5C0F7FC128A99BC0DFE2415C9494930774AAB8FF05BC7054B52196457360A0706
                  Malicious:false
                  Preview:.Ta.+6..<...0...7W..w..wb.Y@.....'...n.`......;S#%.u{..90................V..RZw.R../D. *.....l\vpr.P.S.n.=.0s#..~.V..}..kdlV........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):160
                  Entropy (8bit):6.009668061322245
                  Encrypted:false
                  SSDEEP:3:IEL7iU2bNpnBgY9IUSd+JXll7KmPdNfoXfWNIL74mEu0l9ll:5PmzJga1ttPfoYM4juc
                  MD5:762605AB2798F836D4CCC388EC76471B
                  SHA1:B25C0E045961DC0547299C770B4DF91277788D59
                  SHA-256:158D451E0F4253052A28B8A033D0951985B40997EDE35B14F2755C7B4BDCD4E7
                  SHA-512:FD21CC768295D047B0CEFAF7817CB34153D7827BB516C0A891270BB852654EBFD049F5AD382F2A7E8543CFA9E90C55754860ED2D961710C9738205B3C491B820
                  Malicious:false
                  Preview:...a_6:...=....6c...(...S~?j..gL.....eKq\...U-...w...KV.8.............c.be.........<.}x....T$:!............."m...w.bR..AG ........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):57997
                  Entropy (8bit):7.996924899227174
                  Encrypted:true
                  SSDEEP:1536:oIzlWSkItJIRK3tlPHSbgFFBTiRvOklWVHqRzi9U7:oSVk+J4qtlfSbg3BTyvOORG
                  MD5:2661DD43CC677219B1A1E599E8B41B12
                  SHA1:16D1738E1D85F37E54FA297A7EF00A7EA127A687
                  SHA-256:3A00505B0E960B8F7D33AF6030E3D6909FF524916CE2E98F8C50213236F06F18
                  SHA-512:3D877A3F0043D07043704EC1D909A569496ACD6ECB3EAC84ABCD0B8C55BBD67654AEB967586E7DE6167BF253C696AFF6ED701000D07A313FE72D898599013D40
                  Malicious:true
                  Preview:AB6.u.!...JR..8G..oC...oI.b.j......d.'O..H.GR...K........a......b.....PU.A...ql..........?...N..W,[.<...)$S0..n{.....,%.A.w\B.t.FfN.i|tG..b...p'.\Z.\1....1..-{...o.X..WE..-qP....3...5..5.........}.....d.o.3.7..".J.o...).L'.._.B.r....g.@+.v.....9.........3A..s.Uz..1....D.4...1.D...?.s....u...v..".`.Q..P..6.5.|.3<.......z....+&. *k..l......4...t...xMi"..z.........K...LxI.....e...-.+.d.......=.j.....mR.+..5.'...@Y1hrM....u1.6.P..gW....(......-...I.H.g-..a..DB..<.wf+.p.P.I$.X1R.;..A...M.....7.k....x......6p.[.-...\..IG..-.v&%...~....F../h.(...h9.1X?s..t...|..HB.z<.0......xm..`Bs7.e...=._....T..I..d.D...s.0~..=.zV.'...rJ.........-'.a..8B~.U..q+.,.9b.x'...Gk...`C..[.m<r..HTD..9.1..3.G...<..Lj.}2........&7.....$......%.F.... ..\V..K..........^]u.*..4.g...Tc...W..<."..W..]Ik....\ ...UC.s]34..W.._G..... ..a..1.......-&/^7..5.kUH.B0Y.....u...R..i1I..4...Q.<.gX,>x...mg3..u<0.q.&.ofu...&.......(....=pt.}6....1.......{./F>*...8.x....o<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2310
                  Entropy (8bit):7.894202661185384
                  Encrypted:false
                  SSDEEP:48:QPXP1VZzYmSoOco1pxumujnQIIJwzMc1B/XnLiNxIYbeCzl+Hu:QPXPLL6V1buwsMcv/72eYbdz+
                  MD5:3715A7D00A56B71694A1A56756AEEFD1
                  SHA1:1A48A7E40F18266BF7CB9E8F32716FE7CA3D281C
                  SHA-256:972AE98C7353522104E96FB263C8F079D3EB9F3E52943BFB37B6FFCB5C7C41E4
                  SHA-512:A8D728F046E7F169A0FF71E3EAB9428D358999448838944DE1DF1EE82D6C7C39C54CEEF22C15F3380822A36E47D7DF76746FEAE31EB848C132F9F393807B4AD1
                  Malicious:false
                  Preview:...g..n.3=...zK.....f>...?.f.... 3..(.&.j.*)6m[....$"obs..N....T...*,..P...~..8..{.=...9.v..Y..~...W...8....'.....r.K....'...r.S.DX....`k-Zku...8..^.b.:.0..Mp^....g,=...........c<......0.zTZ+}'.xgl.5...s?.$..=&........,..^S.s.a.M..>.......1......[.Kw...uY.b.!.N...:0...{"`9_.>...M.X....[..O..J1t5t..K6.S. ...].x./.*........^.@YW.....t*0./~.E.a....T!.k.;r..]s..s..O*.|..3.=.Q..o.....#...2....tr...v[j..Et.N.M.l.K....-.|v..~-]...Y|....x......y6.7....8..I......gg&..../.S.`..3.f........{.=..MU.by..~...........P....8...(......X...bb..[..FQ.q.<.X\7'..K.z....Rk.I<aW......;..z-.P...T.:\....G..).z...#..y....wQ.M...g.. ..].G.}0K..K=_@...h<.....It>.)....T.5.7....W8.d...bX...Hu.eB.nO[.......F.F.6...}....[..d.%.C..qpZs[....ky...E...G..waL...9=E....U#..uX.U...(.N.n........6>..lQ......p._.E...y..({.t.J{.n...6W.......|*.g9"S..8.'..\....b...u.......bZ...{..)0...+..k}..U.....x...]X#.......x..2.u.HO......MvO8.,.f.l.%.....r....JEf......8.xl.X+..U....,X.(..a...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3869
                  Entropy (8bit):7.942251470381614
                  Encrypted:false
                  SSDEEP:96:wIeQ29P0jv7bAveNbijPP4vfFLhVeXeZssp2wv6X1ye:sMjvfbwCfFL6XeZss2S6FB
                  MD5:5723F83133478BAC878E80114BE13E50
                  SHA1:7E6C8E27C304B216FCCBBB50784CD987AD0C3208
                  SHA-256:8E2B3F0DB4D50C39B0B168D9260907885A008905CE5DC5EAC2B0B96610A9B079
                  SHA-512:ED81501E3C1F56FB634CB42692C6DEC0BA6ACCF1DBA5B262823D0A8EE198EB6882066F88BB10E7D79953D49FDBCD644D4FB1E39CC81FBD6CA9A528CBE65398D6
                  Malicious:false
                  Preview:t.x.......`q[....\.].U.......K.2X9.a.&7.G5h..;!]]s.a...G.4SOv@7.@m..7}|.i};".=....C....3o;l.:..Ri.<....9.W<..e.vi.r...z..n}@....a...l....V1...J...2........O.Ytj......:....N.{1...Z.....u..9. D..M......bYs.0.".}.........Q. ...3....[.n.i....A1f..<.$vx.*...L..&.Z....!.w.v...u..8..m..M<.l...t?....Wm.m.@>......na.r..B7.}kr"...&q2~.&A/.p..e.......:4J11..rJ.....%...Ypy.,?.kg_f\..G..V?....U..:_..o..B......\.|..E!TE..a.K.#..;....y>y.....oaw...T..$.Z.j.7..S.#..F..* 2{..d..q.u...=!c.T..i2...EZ..N+....)....E...2.T.Qq4..r.......V..Iy.i.....$....h....^../...H....7>.*...j........S.Y.K..82~o...u..31....d;...q..k.t..t4/....<.$p.....P..[.%.$@h0,.J.c..Bz6.(...-N.._..p27..t......i!..Ca.93.H..8.2..xzG.BD...3.e.].... .5C.H.l...\L........!.O...... .f.U...s.4>.7cH.&...k..jfEB.3..h.....-:e>.......yc.P...DL..[d.R........8q.+.......X..........*.y9.[a....S=....^.Ey.g2.#..b..oU.;....l.*...!.=.G...`.-...J$..q..uB...._.Gv.Vp]z.Q9P..N..J..?k..4..t.|A6.....8...I...wk).
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):716
                  Entropy (8bit):7.653416503741227
                  Encrypted:false
                  SSDEEP:12:d0tLT4xuSCdbDk5McamI0qsUV9Z75MreGapxmCpuklx948K8p6HDMW9ObI4:d0sBCfcX4Pz5ERaQIukf9jszm
                  MD5:183CA4FEAB1DBB9FC5CA4F56A61A1A78
                  SHA1:C8AC9ED0FCA8A33E970D5D40D2275C0E225CA655
                  SHA-256:D8B41C2C77C6C4C575DF07B89709B8667C4A910F17F542BB4BEA1FD4861221B6
                  SHA-512:AED204980EA7C2CBEEF805A28BB581C23C8AA28F53C44D190DA5F439253ACCF440568741759D14256290C57D768EEACE03C11DB63B9C07240FB663F5DEFA4036
                  Malicious:false
                  Preview:..".."?......6..z.O...C.~X:|^L..,.tu..h.G..;*$...%0\...5.......?d.....%.f.,..l%.p.". ....!W.m....xF...g....4.7n#......#.A.3.c`.ik.e}..!%...z]..]~.X...`!....6._`..f?c.... ...c.+..wW'o..h..+iH....../,...=..|3<D...u...%{.,P.z......4S....`....a..`...[c.m..<.1XQ ....mc).:.C.V5.r.wH(.'o$X.'.C.Y.<..u7...[~../y.P.B..*..q*..m.%q.E.\..m...k.s...y.f`V.9K....Jg..T.s.x..[j.....`,....{....;m..'N'{.R..%.a.CZ..`..\..4..c.=6........'QS[t...,.*.D.`.`....^....'X.Q13......$,.b..B.....'.wN+.T.....:,...DkO.j~.<.W.....2L.......&..6.ow+..;.;.X...EV.iw.sB..."xq....b...f.p......ml....fI.g....K....zVIS....\M.]..O.....,.......I.Nu.1./...=.|.8W..63U...!..iD...+....e..4.!...270.........,...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):29748
                  Entropy (8bit):7.993626485727214
                  Encrypted:true
                  SSDEEP:768:sBxxp1ZvNfVHUSrjyF5kA4TaAma8yGliPQFechIe4RIpCOfnqWU:sTH1ZvNfB5rjyFeA4TaAma8yGlio5aRm
                  MD5:3826EFA8A83DE9C094CF5B1E0585AAA9
                  SHA1:B069D27F244F0549B1537894AAD010EFF687960A
                  SHA-256:56C6F19EBC00D86A36A9E97C97B2DC4AE7CBCD61DF50C1796FA3808FD8ABC92B
                  SHA-512:2B146C31885BDB65AA4AE080DCBBA64ADE0F3F8CC7DA451618D6750C43F2153763D60C4E1131C0740A196A047191FA28AA6748D19B1DF246A2F40920705FD9B7
                  Malicious:true
                  Preview:>./.E..m.*.G.. .O.7.u(.VE.u.?..<......s.j:K.s..g...fd.k^N.......7.L._...e..?.....a.#...Cj...6.c:.~.b.6.H.x...+...$ .vS%I>..(.........`X.9.x?.ub.A.H#..m.6.VDx..M~xK......E.\..".;KU..4..c...Ru0..>..;...l`=".zf.K..U....V.......@.P.pb..5....p......4.s...!..-51c".\.=JD....../].-........N6..".PA.._...E.n.p..1..w..qvch..g.!....!.G....w..Q.....*2u3.:.y{.N...u...G..../F...f.s.Al...p.M[+.^...]./rJ...j.Aq........) .&...41<~v.y..iv.E.......kM..8.S...;....YB.@...n.$%k.O. ....-..H"n-..!7Pw..PZ.#0..C.2....I....f.# ....z,.B..Gx....hW..II_R. ..~6./.3.~?U..x..@;2q..L.T..F..Z.W..0..p+b.....rB...$.8..Liz.......LU..... r.-....d... .......[.....;..R..7z.P+.Z..c...G9.y7W........O.4......-(.....qVg3..uo....NmK..C..L...V..bgw...p.....E.S....~.G}....D.c.{rv..qk.....X..\.Nz.3.H..5...OZ>7.-.$>.U....7....Q0.8E.......ll1I..Jd........Fq...:{8.N...o.Y.r.ghM-&.l..i....XO.....Y.....-m.I.B.'.2?.~...n..C...BF...^.D......J+g....b.&<'..."..#...2..".U/....H...+.%....:#.*.GQ..3K.1.!p...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):66892
                  Entropy (8bit):7.997397601514189
                  Encrypted:true
                  SSDEEP:1536:Ebs/weFhDEctu8vs0dIU0c/Q/MePb9xlz6w9hAiMxz:8sYesGLdJBQkcp6iMx
                  MD5:D4878BD9438BDB002B42B9CC16792BBB
                  SHA1:3FD3B74116FD23EA59649FD1F051D5DEA505CD9C
                  SHA-256:013DF6358EE50B20C30CCB9D8396265E27766DABCCF6D3C8D95E3FD94F4EAF90
                  SHA-512:48A70B3C9B705A34F9FE82043136AA25A185FAC7495668C95BCA8D338A6CA318C0599212ED56F1069CC1B112E70E3EE722D76171B39A3A9F951C2069AE8D7A7B
                  Malicious:true
                  Preview:".>G./.S.....[..<....xs.8.20.Vd].<....).....e.F.....<S.B.....P..xI...(7b.V...|.f{...0....}.V.M.+....9....T/..x.......|.K.*./...s``.Z.4R&..^.\...2]....x..t@...k.h.n9....v...+.r.O.U..."..`..=I.'....n.%oq......*.f.:..........~.e.3.]....t..s.w...W...,5..K.#..ic.9.<.._q/3.....$....r..|.K7..W9.<~..:..KM......=@]2%.........'lb.N"p~..6..vp..I.O|...|M|]@.A5u..d...N..)g.xV.....6..Cf..-..,..Q.4.d..t..G`^;..%.....#5..2..3Z.n..~.....W....y]..W...].(..]@.sq[..{4..#.8..h+o..Kp.Y.hu.Vi8"\.x..S....4..Ph....@)Oz...:4d.;].k......=d.V....lu....t.,.....P.=d.....|.....&.....8..\.IdK.G.Y&....lx..e<...R. ........u.H.'.wj..G.\..$.W..21.q.a*...m`.0..$P...-C.Ju...gm.:v....m.4...9t...}.K.C.....3.v.."9....$.H}.+.U..?)F...X.i.5gj...9..a.^H}..:5.*..`._.....>..1#..~V>{j...a.:.g.LD.}..$Y....^.Wg....y..Y..K.I......n....z.|....B...$........n..L.G.tRB(.h[3.)..M.@..wE(\..{...c...>..q....7....j.K....=3%..0M.B.e....p.~.+.'........;...)...l..;...u..E67|.....I..8..N.........|...$._.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1288
                  Entropy (8bit):7.80556795751197
                  Encrypted:false
                  SSDEEP:24:NpPpfj4o1Q8A8lA6NHgbGfgd5ov6EjMB9BbDNBg6/5ZY:NjUF8Z3H0dNKMJDUU5
                  MD5:46F363CFCF95C825FF216EA53331E78C
                  SHA1:E3A96FFD8542DEB06F939487625479AFAF2A732F
                  SHA-256:2563A352E0F01EC27381984682E67CFA2FAAC34BCC9B7D3DB0C3884F009A7203
                  SHA-512:F6E02103C8209B19E39F166AAB559931F7D6949030E2009022FF261105BAFABFDE19ECC9699DB1C29039FF68EBEDB962A2F09F1C19553314067EC25476B487B2
                  Malicious:false
                  Preview:...h..M"R.?....nUw..o.E.........68Go1 .....2..r.-..$.d.K.\.....s.|nG.|. ..h.2E/5.B..XIX..j80..j..f4/.$o.V.\.n*.CX.-..3....&.-...T...C..4(uUP.Xt..8..;....C.{..\%!.9t.D>_.\......"..=.8..#.0...q.~i........._...-NX.d.;D....)W..Bu......-...........f.I....n &n..zkg...).p.(..dc...xD...B..o...%..p.....o[t....).E.-._Z..:...z..n..?fjz..!...e........I}..e....sm....%5.s....ex......_#};...?.<ufu..)h..L...I....c.Ey....q.[[.h...|>".HI..g)....-.(<.....2./.!.+t6C9.t..A..L.EO...# .Y.Z..`.N.*,....3.} Q....S..$4..d3....$.W......P..H.m..(.!..e...dv.....+m.U......H.l...@.....c~p.&...p.>...<.MF.q.%....gC2..qC0C..]e .V........?.........B{...1.yj..o?e.N.|M.n.8L.9V......u*....]....+k.T....&+..Br%.......>S.[...Q.....b#.w@.U.aJ..}...}BX.\..hb ...T..T..Z...3.......y.........'.m....%..t.)pKg...GH'..K..}.r=rI_........@j.......R2.<yl..,v.4..:....2"..Q.J.A....n3...~..-.3..KA..D........j^.X.M)w) .....i X+>.*.*G.....|u..W.....z.R..,..o.C....6.4..a`...(...=&...\[..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1916
                  Entropy (8bit):7.895645046405177
                  Encrypted:false
                  SSDEEP:24:z1i4brScn5zPWr+qB3NAK1Ecti4DWOrsond9xF1sKF9csgZwefgTGHPUENrfcBT3:z1i8/tuB3HkGWOrZd9h2RfCuXFUG0/
                  MD5:30FA5E1DDE886839BEE8DD2DA71E2143
                  SHA1:46CDB828D07A61F6FCA616905A359027F5F188DD
                  SHA-256:B634E4E3FB3C5E295807588D6B4F0C181C6738C52EA485919450857EBCB68ACC
                  SHA-512:D4C9CA73BF8A078BC8424754DC1138BCE6A55089CBD55229DC4ADFCCEA9CAA8890ED977364790255ED8776817B602A973EAA2E63BB301F4ED5FA1A8205EADFB5
                  Malicious:false
                  Preview:g.#9..V.B..i....W...FF..p.+G}.tJ....TUg{....t(c.a.!....&).l9..].".F....'...n.v........Fo../...#?5C.Lg!.....aD.2....O.Qz2.X.z$.]....`jz...H5.)+.p4V..Jiy..[.X....s..<..Y.w.Y...4.F'.....V.F.......>)C...S..A.H....*x.2.Q..yhi.=..e.N..g....4...|M1.?..d..G.!5..2.#..>.%\....VN...*F..a:.H,O..e.i..\S...>)Ls...[.... ..Bm.Td.#...g.c=G...c&X..G.F....N........B...H..H.Pt..VQB.D..I{i.Gn|u...aDM..M.Y.a.^=o..j..9Va...4...N...J..=.TP.../.....?..2..v. ..".s..,...\?1d..a..J.`?r...x.~.....:......d...h.r..@T<wW....i.......(.^...).V.O].'...+...j'. g..,.W..p0.<B..<hZ..r.....{QWEp.s_.../..........w.U.w..B...md..q..q...h.L}...So....i{......:1#-..g.._E.[.......}<....D1.yw.".&...4..o..~.S5I...&.Z...x..$...U.........f........ /..Z.~.M.6.'..AR.3N.1.$...v..dx.B.y....w.2*.N..0.....ll..o.d...(.....D.[.~..=........r'Wi\rB.:.,O@....^.G.X"..5.C....:..s.j.%.....T!..N%.....u....D..C.yF{...5.......+.O._.c..... y...,..o.r.K@.;.m......M.'..>o..R3..h..#Y......k.hZ.....p.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):809
                  Entropy (8bit):7.6559372885972135
                  Encrypted:false
                  SSDEEP:12:yqYQb5aYfhV4zJt3ZxaDteTKJYouRPfUungH4CQ7h3MIHd1MIAFEES8J/E:y05NJVUWSKmo6fUWhCqndqIeEE
                  MD5:F5A2642853C8113F52BF097C4545C575
                  SHA1:BA7096D0867FE53D0F385D00128CA22C24897D9B
                  SHA-256:0AB455E631C2A183470C58BE41119DFB9245D1A0CAE60766065C1DE44F1BD2B5
                  SHA-512:02954903ABA65039A3C54B075524ED021F1EFB2268BFA469E3BCC1ED90A1348E555919F1BBB4826D51DD34E950A276AEFC4D499F7660B55F8C9CE17B19B9F718
                  Malicious:false
                  Preview:.<E.O..wR...ox.(L..2y.0.X`.o_..D......P.O...*F".g..{EX..:....Z......m.O.+H.....gR..T4...-n.T~.n...sF.+.ou'.e.m=..rJa..XhU..Y..X..`.Nr......X.$.....T=3h..d...?...1...SS..f....EB..(7v......s......*.......Cbv.W;|.[.Ar.<....q.F._..^Z.1...4,.p9-.....'...8J....[v..S.......br.x.%....H...S....J.<.C"H>. ........l>...{.q....Y.a.t.2>B.q.|...6.@..i...9.j..C.]q\.....@.rZ...........jC>....fr.ow.~l^A.Jze...&.`w-....w/E....._z9..!.....DzI%=..W.~....C.`...Q9A.,.....*.EW........n...........a...+.........J..^].._P.X......i.....R..a....(.3]QW^qqI.X4.j..s.....H.)..j..j..uM|...9....-....-..d.*z..<.D.....5..5C....E.vlF.x{..".\.8.~?.&(.:u_.`D.C.#.b.`.|......iR.)6RfcE%D.S~.....e..|...v..!1.=s%........r.]..z..Y..`..........p.4..R...v....g....G.v...xW..J........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4284
                  Entropy (8bit):7.950972643893895
                  Encrypted:false
                  SSDEEP:96:aWWpf5yDy2zJkZPF5qQBSO7T7ZkYhcwffpHK+bf6v96pHWxy:9y5h2mZPFJBt/+kKu86sxy
                  MD5:B4E84690A0A5E63DEFE99A6D493AC825
                  SHA1:7BE294F4BE06E3B77E831DC1C192DED57F4B38D0
                  SHA-256:DD3E5518B5B6BDC8C2918974C2CDD1F40EC39542B7E1151E4B31A361BB3138B0
                  SHA-512:0245B426CBEF43DF8EFFB625D9724B697E6DF2F750859271D0A2BB400DEEF95F4BC0E958F445C465E55047F33DA13F967F9F86A3EF4EF772AC8823F82FEDA1BA
                  Malicious:false
                  Preview:.O........N5..{.x#-.0......rEY.<.>e....3X..P6.h.-....+l.G.>.Bo.6..........n...a&......Z............s..tl....kfB...UA.,....'2.....0*..4.....6j.)..T,.%j.P..B..8.5N.....~!..,k...... bu&Z..8.~..NW...r.......=..7.Q.9<.Q3 ..AI.sY....."....'~......TVqZ.cw.6..L.TR..:..B&$.+LQm.\}....w0..E.9H.N&3......q...9....z..K..pd.E..m[...f.N.0.`...F..T.+n.<......~.L.).."......M~.qE..-....U.y...>..+......".L.)...4k.ch...u...:..[.j"_.....&dP,z..:.Uc{......I:...VW...6.."......$[6.![.8bs].C.....5<G>....R..M.,U..z..%..c........}j.k&.).r.zbi.....!......J......=#...Eea....._....&...w.gl.'..."p..[........K.....o.^.@.[.3JIS.['<p.3..YJ...B...]..4.....B*..!..Vy..z.U,.F....1a....klz.#..... g........lu.M.........{....s.-e.RI.`G....Q.P.K.t.b.2..6.t..r.z..\..Z..G....I.X.......0].e....@....Z.%...R6.x...)9I.......j.{.e.!..../Y.....#_.....^.d.o..?&t..m.c.]o.h.k...._.3..P....=.5y..+A.hg@.........=.%....l.g....hm. jp..l..ij.(.}..}...'N="......r0.7...s...%E...Q...K.T.o~e....A
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35959
                  Entropy (8bit):7.9940224257608765
                  Encrypted:true
                  SSDEEP:768:gOO86xNyTkhmZCMLDf5YOyqveXCpN4BXX86UcwgJCRsMw5GZ8nb:K8OyTks1BYOy40smCvwQU
                  MD5:B194C774324EB7487D42F6554507DD88
                  SHA1:53E6FF336ECBAD68A1341F5B42DEF55697A834E9
                  SHA-256:BBD448A8CD58EAFF68AA863E655BFBFF315668A3DEA0E37BAFB699FB4F019A0C
                  SHA-512:C3877B4519BCFB78D7ADB29F81613DD42C37E83CC2D86230F7D104FC4BCD1DED55BAAEEEFAD84FF11C6D6A6EC71D5E1422F569573F69E06D1CF12D74822C4D21
                  Malicious:true
                  Preview:...;..{!]R!0^..2.[..*....B.R."1b.r.9...f...l....%.1...fu:U.*.5..v.`z$.G|31d......*.X.>o..8....7..Y;..."..;..c.Hr... JW)....k.g.S.c.J.h.)*.@.*....$....5.b%.d.yVHf...`...%..~...Op.~...8r..p....k....D#..C.Y.'...........K..QW..c9.....D.*H..S...>'......G.S.'W..=.C...F\.m...r..0.G'..*...w.j/..i..m.7.~.u.>.$.Wb.{.u...8.b[..U.fo...._Y.....h."_z.k0s.v8...*'.O_3....R..8..9._.S$h....3e...T.w.qD...#.'2.uc.)2..L.g....+HXh.vd......RIu._.>}.3....9.<.U.r.....n.......%.#..].l..4.m.3..e..nP>L..W..`.O.wQn..K.o...,@.:.o.}Zu.P..jbZ_..c.>7...V.sx......o..^...&............z]...Z.d.jM....S.Z..."..O.(...r.T^Q...;.sG....*..n........n.Z=>...~]".Q1...".A....d...hu.v@.^..=>.*...}ju..z...i... -....yE}...!.Q#}.[....y......qz....9.R.4/e.H%...F...K=.TcWq...f.o~......&..pR.t.K.%.....M7..p..~....i......g%.<&./..F.<.s..(._.p..8t.t)}P.4..]%.?*......N.~.I.}.s...[0.W.u.....AM..!..s<4......T....#bP...*+(.....t....?.!r..o./.#7.v.K....9...g....S&....`.-{.....r..*\...d......".D...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):302
                  Entropy (8bit):6.980777079288686
                  Encrypted:false
                  SSDEEP:6:Dq5i5YqWLw6Pxd+xg/Mlt5e6/dmra4ltRzUjP:25i8LwwxI2/Qk61m+4l/gjP
                  MD5:324769D0A7A2852CE1F886A0CAA333FB
                  SHA1:5F22B83A915536048C829D8D2BF6C25DFC401F12
                  SHA-256:0EB26ED1BC3950EAC2A88A30151AD6CEF3CCBCA65EBAE96AC7F4B87152E36375
                  SHA-512:AAFC89A3210623145725DF0933B128D494D9F2ABEFCBABB34C28CA72D21FC3545E1039582824850E0CE7DCCD22E2A621F234E4BE9275FB7A185F858CAF2CE817
                  Malicious:false
                  Preview:w.....4..e..rd....9.3..mqu.O..\...~...B..o.|.......*.....(O.z.9...=........~.....LGN.5Er9&..7..h..' :.....O..1.......Q.j.e...<}.#(..g.q|.Y7!...V.B.....yS^...N....0I......F..*....|.<.1Q..O-qv.g<..4ia............o..:....I..&.T.f`6F.8^.T.T.D@.Ck4.F.E.9....@..D.4.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1916
                  Entropy (8bit):7.890832992679786
                  Encrypted:false
                  SSDEEP:24:TByyRGQz1vAztRBaQ6T7BgLIhuTBJJ2aPlDcjdpm4BPHnP6nk9Zp+MAhyWMZpyYC:Bf1o3Ba5T7OLIh3aPlQjdpxDZ2yWT1
                  MD5:4885917DEB03973D507E2968D13E337C
                  SHA1:1F710A33E0D14A5CC200988A0F74B5E1BD9CACB7
                  SHA-256:00A7CE8B9739EBC4AD9E9D71E23A800EA3BCCB4325E2C139DAB61CFE1091F376
                  SHA-512:CC748B2A949E515ECE61F09A61E40613491806149B58B44F142E59F50A72E3F1A91B8A0744905F4AF3AC535068B452099E66E1D5E80A2B0DCFEA1496E110B33D
                  Malicious:false
                  Preview:..,..X../Wq.$.u.....~....P...o.V.e.vr.*...a.t....Hmh.<....8$.=H8.T0.i....H.....pU..\ .$t.o....-....@..O...N.~......b....~ie..G.._z;.a....M.p*c.Df...i....u...-~......@....\...p<.Fa.z2.V...q.O0=..vcu.....EJm...%TA....<.&C..eH.....!9.!....acV..TQ7....".o..l......."Cm..2,>..=...S^u_|...o.st..5..x...}....>.T..WK{.6......,Q.=(.D...J|.}.n/B.^...*K..T...+yr._I....E....Tn.q]....l.<.w`.RD7....;Q.Ns7..!Q.M......C%q.....X...N.....I}E?.o...|)..P.\...........^..r..}.z.$.....F...&..b.V2........:.2W..wp...V.py.\...?m...0..in.......K.+y{.`..jZd._g.Q0:(.m..SG...R..E.R...@..P..6..i.;.*.<..P...........%.._.N.3OQZ..z .... .2/-.`./+.-.HO...j.. ...fKT`{.T./O...}B...C7P.7.7.....a9nB.v-..U..S.fMq.....t..{6......$F.ZyG....h.{...^...&.h.G#.0.Dj.....$@1.v.$.wK...h@Ip..\....rCC..]..M&m..&c.).(..Op....E%.........1:.....TBx...(..n....p.l....%8........U..lq_K..+D.am.I...>+_...r.}....@.....%.Fv......K.HU.2E..e.}s.Yzq...*..w2~..u.6.Z......f..e.I.8....s0j=...=@..6c;S.|.._.xQ
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):809
                  Entropy (8bit):7.679245382827515
                  Encrypted:false
                  SSDEEP:24:c4uafGhUiDZ+Sp2qAKBRV7fp1T+m94FQhhM6:0/hACxJbTb
                  MD5:C026ED59B54091F0B42A704D8FBA4D83
                  SHA1:5CCD76A26C58F93530A0E36908C913D086D3F6C9
                  SHA-256:120F0B009C8CD4708F8C2F7DA1C4F8FFD82362FBC9231915E9774C9025708A0B
                  SHA-512:6C98DFC193153EDC1822D2DE2EA3714CC4227344ED9B8078BB9740D0DF68AD398FEEBC1186620F2AF9F837989C97432C543D1B368785A95FC429E6737E54522B
                  Malicious:false
                  Preview:y".2.;.....N.E..@.....%..gQ..l..e.u....._y.....3.....O!.:...../V....)4.M)..#J....,....&...i.C....9+...J.8..b.G...$fCH....,&..B...Fg"1.{.R.......=.-V.3..V=|.T{Z....@:..j.-w."x..W[X]S>jl.B~g.<eQ.v...,.w.....o.....'.)V|99. .G&.p..w...V.0p..r$J......9.......A.c5*X.H...t..s.*\(..S....E..Y.l...U_.B9.m.^u.R...k..Q...d............3%...g5.,c_H...6.$...f...s..Y..n....5.y....dp..I.....i_S.(... ..s..\w ....K.>u3........}....T...Acz~....DF..Z.!.a"....1.(...l3...*..M..\..!. .k.J..>..F.S.f+..bD.\...f;.Y.V.6.J_.n8P.L.....V[b.2.....zE..~^.e.[.......VcdP..Y.8u.........9..ud.z.,TQ....T..uq;R.~.^..o7_.....2....w....L.......@!W.9+zq.p.Zi...$...|.L^.H.9:@.bfK'....}1...A....\..f.w:U....l.EkM........@.e.e.M.T)l..X..e._....=..T...S...+.ql..1[....j..)a..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):597
                  Entropy (8bit):7.52148998277704
                  Encrypted:false
                  SSDEEP:12:tMy3WtshQD8jj6cUUvSQ55iNLrU1jGKRw1CWhECNbvB7:t3Ysfjj6BO/7iN3yqr7v
                  MD5:8FFCDBDF0504CB8372BA50990ECDCD66
                  SHA1:AF8A84A067E6E07CAE90234002332EAE49A05846
                  SHA-256:1B90E966BBCC0593AD2B1737108C32916D3E5F9814442C6614131094BFB55527
                  SHA-512:7B2EDC14296401706131C5E2124E67FB2AE157C60ABA266FCAE73572CA906FC1BA5AEB1E5EDFE25A652F40F71B032A2B16132D97E1152E15FCA3624E3A2DA362
                  Malicious:false
                  Preview:..v.t...^.g...Pc..F.....3.]..m..-vH.w...\....~..&...V...n./s...2..._.... .y..b... ...._mU.=.u}9....b...'.].vV...c;5.$C..5...)..x..V.h.W...}.S.n...^N..$-..c;...$.C.y.?..).W8... .\.......t....Uy...4`.,.....<;.{..^.Z.Ph.)/].l..YAV .ryu.9.&..u....KR.A...>.j.......*..Y....m#..Q...HT.{..~....5..J.?...Y.`..9p..L.@y.o.fk..=.^@.._.=..LC..;..l..s...-...*..c_.._V...l8..w......P...7[..#..e..X.....$2z|...9a>.`^k.......zJ...D.Tt..`...).I.XT3....<.......'_...7...H.Z.TI....c..}.@...$....[..........5.r.....g2......j....P....>.J.KoJ5@!t'.%SU.._...9].r~........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):826
                  Entropy (8bit):7.6966524573786135
                  Encrypted:false
                  SSDEEP:24:a6gXTJx6FvpWBt15YJGRDnqk7ASPdUNfpRDb9Js9v:RY6vpodySbhFUNhRDbHsN
                  MD5:BB7719EA487D4A4AEC3495C48F67F9F8
                  SHA1:3D4801321E733B94BDF52DA43AF29D31F0592340
                  SHA-256:13A9ACE76CA87DCE18F2DC392260318ADDA7B75F5F9D4DDA378E81F4D65AE141
                  SHA-512:5D633CF1ECFA8EF368AB512225F1A4E9F72FEBDBC580F7BA7029A2E22E03F919D89C9569212E844DC007D38779BDA8293985A647AA293C3B7FD402F17A2049CE
                  Malicious:false
                  Preview:.2W..9xu(.{m.V..z...**..*...C2N>J0$VL.?..a..#..P........A..aX.sm......_YO.Zv.$.^.....MP.X...7.9..L...D..B.q?...S.P.._0ZB..R......HE+.]n.p.%..)..qn.....~..c...@.&V.o.9?.V..=..v$......;...>...uT8.........bA...W..P<..F...k. K...r.g8......xspo<.D....>..5o,.._..Q..5.O.j....\..i..D]...E.z..M.....'.L*J.<....Z.7.....%o..?.#@.m............r.H..(...A..up..C&S....8N...t.oEK.!=5......t.....[.>Q%...m?...va.........Rw..e.V.g..6b0d..\y.......}G..d."h:.g..eq ....Vb.p.........`B..r .".v..~{..\..k..l.KW.$..g....n'.B.{'..z.<xfX]..2nH..B.+'..(.......B...rs...%..,%.........[.A.a.T."..&..E.....R...n..G.:Ew....M.6..+...8..I........M$ ...y..uq....MJ.%...~..x.2....<..%.....t.H..>.f..yQ...[L.*w........q..6..E...........H.e.8.s^3O.;.......V.~....6.3l..\.%.........l.{.H*...\........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3555
                  Entropy (8bit):7.944627333775559
                  Encrypted:false
                  SSDEEP:96:W6N9sHelF4QoXK1Vcb2iKS6o8lCTwtseLhPB:WiF4QnJAb8tsexB
                  MD5:2A217B95E890F44A8FFE5753075D68D4
                  SHA1:02BBE6348A5729DFD97D4F784DFB8E519DA19DCC
                  SHA-256:F2BC7E37125B9E06674948B433E3CEEB890D8247016082F4A8A2A62C9CCFF854
                  SHA-512:35EDD99E5F4FE1B73CA56C730B9F9016EE5B2C98A91C384EC2BA778F9580B5DB15319703C8E9A036C9448AEE45FC2C9E442E7B877ED5DCC891F6CC473A694001
                  Malicious:false
                  Preview:.G....".6..q.3DJc....c......'L...q...(..7.7....)..)...$.X}.t.*...X.V....at..P..8..N....u.mA...T./,..n...p..Y.8.T..~E3_P..r9.V......e)/...l. ..!..;r./*_...C..mK.x.DA.....;C;P...9....D...<......D...1..".d.V..c....J.RT.v.(....%.|s..B.&.P...(...L.pgEQ.....m.M(..y...........2x..,;.WG.#.....M`^1.;.._M.|.-f~.W....L.T....YX......Z.>.XoB.p.MF2.Z...!.O.EY....U...0b?...g...2...Vu...il..E.,...........%....X.$.!.U..e..8{.. ..U.bq#]....8.............."..N..".......I..[I...;..j{.0.c.7n...).{.i......1.6...vH....K.Q...X_'y.....J..`..M.(..O..Y.........%.!......(qu7..:9Kd X...R.:....y".!.:b...0.t.l.P....GV.wGZ.k...k..W.X.+..Dor..8YF.kC.yP.".g.E.sI.;6..8.sf(..(K<&W..\..k9..q....I."....y....ai..47....%......{_x......H..Amq/o..IT..b+\.8R.~.u.V.8n.S....L..2f..5.."........!:&GH.a...f..=...r....g.[.R..7..V(.N.q.[X!Nz..e.O.......w.....NS.IX4.a.W....:f........0....Q..T.`.Y..C...>.4,r..Msq.`...c ..k.-.F.......G..GS.........9..bKJ.l.S.nYu+k...S.X...YR..t.....y..#.ua
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7591
                  Entropy (8bit):7.9721307561793875
                  Encrypted:false
                  SSDEEP:192:PLQ0F2rqMmG0v6AhY78MrkV6MQvawbcg:DQ2aqMNTldMQvawbX
                  MD5:FE2CAEC7D97D3A17BADB282AA470CD66
                  SHA1:FE59D8E3F3F1A355107F987E2880F708B634238F
                  SHA-256:A4420C1BDF56C9551A8042D590D93B1A6E1A9CFF422B0904389ACF7C42C146C1
                  SHA-512:B0E973B50B7C5119D591715DE83316962B1F4E7EBB4F1C1C9CA5F8224A7AF2381CBECC7B844DE3BC1F7C46A4705B400E7347124B18646EA753D5CE154DD5B819
                  Malicious:false
                  Preview:.2X..p...f.\.......K)Y..>..>...\....Y...|w.....il....;..-J.4..$..=.p014.\.....(.J..k.._.r.J.T..CV.y.......m.4m.~...3.1`...1..C.U..=.......A...*.r....K.tH.(p...H.T,....{....Y.}k.B.J.+.e....h...7}...._.v,......Ey.l.0..*.D...J...&w.nO.(I..=.u`;....G.K...R...&F9fV.P...q...%t-....[.V..@M..:..ns....j'..s....Yf.j...L.`.....k..-s..|..L.~B...|.9 .:...'-...%`...]......F.Lp....O...d..I....V...,^....>..:.vC. ...~.V8NP..[....@(...L..d.q{.....k$....~k.....<.........&...>.Yx>.}.H.Q.k.....8yK...W..R.....$"...s\..2....'>T.@....".O=..O.w...L.{.Y\..J.......#u.$MV.G. .x..../....[v>!E.T.n.....y..R=...LY.............|t.D....v.i^...D.&f.Dk...y.t.ls.F....j..miU..4..i..x.zw.o.A.(U..,.n..A.h.EA.z..x\.9|.N...~.0..$n.....:_...-..90..G>......B$@p..._...<.V.f....sv..:..g.F.a....{s...2.k_?*.y.r..f.N0....~....Y.m...UyN*18........-...52.W....H..xdV......K%Q.^....NI..;Q.V..W..a3.).T.y\.O..@.C.'..l<.$M..s9...vw...........j...%...|J.|..9..;.Ly..w.<Z]...Tam.U..3..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):7115
                  Entropy (8bit):7.97309679962704
                  Encrypted:false
                  SSDEEP:192:l7Ijt/YpDjOR99dRtaJ0Uv1tlijRCyNltKb23gz+kX4bM:+ijORt80A1qjMmt9q+kX4Q
                  MD5:86BB2D831EDF89F7BE2C920716D3882B
                  SHA1:8477309685F4097C53C708AF3D4392921E923B22
                  SHA-256:CA971789F4A0E8EF7CE34B41C4940AE1418FA29100FB12EB2389094C11D5B4DA
                  SHA-512:F4D75EDCA2FF7A62BA8B2A6917FF75233DC2C79A1276C168AB3F938B74F28533E2B7A2AB0A4EE689C1FAED441024CDCE70A57CD430CD2D5C19B56732FBCC04FC
                  Malicious:false
                  Preview:.j..m..5...aN.:]..g....j... .F.....p .R......P,..<...q........OB&.B*...3u..ud...3.Ku......n..Qu]..u._a.RI....P/,...=...}'M...].....(2.#}Ds...r`0.wu.>4...i...SA.sU\.= &k.%..j.W.!.P;...-id..z7I.9i'......q..m%o.....Y.|..+m. .......c.^....<+.-.V......f.... RnD..]=l'.?.._.U...s.@tZ.Yv...^.\.;..p.~......].>.......F......C.h..t.py.SZ.7...-....p....].o.......]..-6O.|xj.{9(.!...W......=V......2...v... n..+...(.A..$x.}6.R.......+......<C.!...jD...f..........."E......V9.C.r...7/.o....d.S..f...3.......G.......YM..i.of.3....2;..K.p.7/..@yi...M.X8[...WM$.34.M.r._5...c.e...<...\.L...t;../r .o........q5....}......f.m.H.....h....-....._j............R...C.R..X.D.....DHe..zN.Q[.Se]..... .@4.1e.P...R...f':7U.1....!ae._e...0&4.aUJ.J]..n..c>f...i.6....H.?.V,)...f..Z.P.*K...A.'......=..WQS...bAR.x.(.VM..b]s|........r.jP..\.=. .r..'V.....#.9g..k.....'......."p@.v..|9.k.Z.>.x...p...F*..3.._..g....9....74bDW......V`.. ...Q8.b_.b....v!-LS.L..yB..P......~.*_.]X.3...Y
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):48905
                  Entropy (8bit):7.9964958779210225
                  Encrypted:true
                  SSDEEP:768:qFYsMYczJ+GDDka83xN9jKOpfEP0C7iWcoqC3PcnGIfgCK/ZiOqe15RPaCIWjO5h:qWYczhkxzgI8P0gooDPcnZb8Yutg5wm
                  MD5:C2A044E25BC055E41D5ED874E0D5ADAE
                  SHA1:EC7BF12940E7219B0FDAD6C1DD4E567D3F10D80A
                  SHA-256:A9881693DDF2111DEA4C54207C5B0EFD5D023B092AE8428016EA67638B8EAA71
                  SHA-512:468CB2C8B462A6D73FFA67FAC915C11DC824487BFD409202E34891C35861E1F311D8779C9EE59E18BFBDF3F8ACEE24445B61E77D81D383526B463A989F5A0B7D
                  Malicious:true
                  Preview:..Z~...a.a. ...y..7.....H+...M.....]Y..V.....mu...O.3K?u..%e&.Zno.bC4.]%Q..>...../..(...B.~.....-6......0B.8<_..v..y`.......m.bw.k.1....pBx|.t%..[.Xw....i..A.fj@:..B.>......F.}.z.A.......a.E._.&.~.o...I.e\p......",.8.....2<........K.bqH.U.......M..T..s.^....k._=..f).d....0.1..bM..._.o.d.1.~..4...-d....nb.o+...0...D.|1.wH.m.&#.....i....O.k.C.....cw......^..&-l6...,..KKE8.iH.u0..4.B.<.5o...L..lS./.%u......&.q.>TX.0..y.j.<..-.k......4.E...D..XK......N.cyl.....7|..;*.#%...,....{J$.....s....I...bE......D7......e;2..I.*.....R..'.[*0.N\A5..{.I.f.Ui....Vc..2..y-I....Q.$6.JA8..A...x.:N..YQ1)..q..s6.f....Amr.....H........E..0..{>..SZ...tG..vV.....g.n.g..*..W...#...:..D...`[.#.`..Q.\.:b.Zu.D.1,.....E....x.......KvsV.l...Z`..=b..{...KZ-^....m....E..Y..i.M.9.%.7_h.vmZ..i........T~\vQ..P.Z..{A..Gu...gX.@..Q.]..1..6.]....)..V.S.w.RH..V."C=..v&i...s.Y....%..m...;e.kr.=n2...2.RO.7.lG..^.".O...53K...^.H\..c.e.K..U....~.|..V.A[..J.9s.V.C...0.......B&;...Y.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3869
                  Entropy (8bit):7.944931910824344
                  Encrypted:false
                  SSDEEP:96:swiXiOP32a0cvVFNdFMUf/RbdL/nt5RCwKdaN:KXiOOoVdf/RbZdCw6a
                  MD5:326373494BC337686BF173B64972B72E
                  SHA1:9A04625F7204D43173B24BD8E6D531B2BFBA0224
                  SHA-256:F2F3FC0436A4B8E3C31730BFD13032A7B518D49FF7CA72AF00F3DA71B6E15651
                  SHA-512:92F29D782C1B335E749552A54371A1885B92E50F13B510BAB0A48FA07C4E2150658E481649CFB8D829EDC883EEB7670BE3294AE7847AC399036161735100A107
                  Malicious:false
                  Preview:.5]CIS..s....s.....E........pb#pO`Bi,..o.@d.-..0....,-j....<..R...4>.......b~s.......'.2:..c.DKK..Sbw..J<..7......1...y......=.D/.........?..8...........v..]5^..0.:......b^.y*........*.H...7..p.q.`.....}6....S.".r.......\..&r....C2.qc+B.......N6.@Y..5...h.%N.0..>...ona.e.....$...hS{.v............].'.5..$...v2..y&..q.H...B...<..]|.Px..F..7dv..t...9@...bQX.H..E..........Y.[H..H.-}...<.........K......f.[....q=.;..a...T': ..... .....PB.&..OLg.zXOSu............./.....2..........L.@&gU..t..G.}.?.....KYF(m....l4N.WY...Y.&LCXoG\D9..2.....-.....`%.[.`*....#..i....J.6..z.v.j...6$......PL,q. .......9)...FMt.#.A.t..jF.._../.......i\.%........F).oo...a;.y7..J.....v.....t*..E.*./4..i.........f.2K}.e_.MT....{...S..x.......4C...i...b`...d......+O0.......:.1...EF^.P....x|..t.{a.1d........QH.\....7..F-......Z.D.@]m.X$.q.....u`..*]LQ.ON.l.-=. ..g...ip...\.n..A..d\...i............D.....I.6P..x...._.>+.)......j$-.......yG. _....F.G..S..-5n..8.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1682
                  Entropy (8bit):7.864074727115804
                  Encrypted:false
                  SSDEEP:24:Huzsce1+h1buZy0A2xjdaLhCe6JznTJBghxv+Ef90Tj7UkGRQjX:Qv6y0hxjkLhwTJBCfVAMkk0
                  MD5:ADD431F90F94C01292804C22F2986814
                  SHA1:592DB48BCEAD370E9C1A717D081507F656763EC2
                  SHA-256:583F4AF29AEBFF83A02146B14043CA140C930981CEB34B8644AD1BC1AB151B5D
                  SHA-512:0912CA75F985622385EBFBB24C986684B630D6DD9D91BB5746684588E0DFB9F9AFAA8CBEC51E03BE0641BD02B17FFC5193569B90F106C2E81C242E5E498313F7
                  Malicious:false
                  Preview:(/-..b#7...^.)...Ac.y..].5.d.E.Sd.z.(.5.d.zO......*izqb..N.....8.n'..|.d...]b....W..1...G..lp!".B.....L..O./n.2..z.....]......%r&22...jhD.U..5.>.~Sg.......X.E..>..3$6.*>..5.#?FDz...1...0.*.(....P.o...t...R...T........sj....2...C....._[[..2)<..f..s_{.......4...#....m!@&wB._t..&..8|....^..b....8...C.or..._.3.n..7...U.~.......<.........0A...*)\........"U...V.s.HM...D...T=5..:.zi+.....>.Y|1q.m...w<9....-lQ.B....'..}...sa.+.dX...$.A..p....u.#.][.X....C`e....d`}\2e..m%..o....~..j.&...y"NB.............}~(...Q...... .m...N..X..].G...7..y.#.^.5..z.g..^....Gk...m.....@2....j2'?....s2..U.A.JX.......J.-....W.wo......J...........&..QPR....-..N..z.......L..:..j>..p..F...O.|..-xU..+E.j..u).q(M...Br.....m....l..,s...-Ht..q ..*.:Z&....I......]..R:...{...2VDzq.o...;XQ.do....Xh-R....[...T.^..../Z0z.83..L.K9.x..].....srp.0.".m.....F........{N}.){@....{k.......!Z....v.GK/.?.....Kv.<.v.@.&`)._L.j.p\.....ui"...^....R9F...qm5..Wf. .(.pO.8<.md.RV...H....F4X.(
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28936
                  Entropy (8bit):7.993240874372966
                  Encrypted:true
                  SSDEEP:768:tMuyyOFCFKy/EKQrOtEGsQSEm4BhXl7P:tMvyOyoOtEHGx
                  MD5:0EE9A4426C9AE8738E9F803E2D6EEC05
                  SHA1:01DB96AA2527ADF975FBE6C7D1AEE67074DA151E
                  SHA-256:17026B661EDCB7C9CD6C0F7D06C3B30C84C10EB0DA92DB9D0223EE6CEE7E8024
                  SHA-512:21D970C792549D4E64290395D279ECB62D226578DB827A56E05930159DF712E6188DA92B370E3586EDD966B50B6531679A481929C173953169CA8F0277CC6AAC
                  Malicious:true
                  Preview:V(X-....J.o,.<.1.}.e.>.X.f..G.....Rf...{.n.z_W...*Qi....i.o..}.....75.........:.#....k../.Qv.0.L+....}.[...<.....-..EK.L.Cc&..`.y....*......[.p;."J....).C>.u%...g.y...<,[..l.E.a.k...-._......P....AH_,.!..`....1......i.-...Y.xL.u..rBR.7.x.*.0.&.Z......&..Mjy_.c.8....}f.E.D....9......i.$C#..X...S......Az.N3........(.~L...".w.Nb[.....&P=....l.....D.S....G....PLk..yL.0...n..w...1...iu.q..$.d....@....D.....{.bM+K.u...z._..#..}......A...$...1$uHB....0.@...s.@.....74...*@c.f.O..>_..{...A..HvZ^.....K.W.S.nO.....l..;...9..T1.1L.v._...C.....Z..A....H.Dv.S...P......'.........k....'.e..i]f...H.!.....i..... s...F...XKy.2..mVI....r.k2.}..[q.by0@..p.W...P^58.|..9......E.....b..c.[.W....nb.<..2v.h...q.....tj..S..t....Q.d.Qp.....Yy/.Gq....X.,.+R..5..\..;...o...?.......nwh..i..(..,8....A....kIq....`..Q.G.`...}K...12..a.......$..FD.".s2...+lR..Z....U... *P.8.bm.DG .*...J!....]V..$S..EW................V....R./.W..0.rG.I.0.3...P\.._..........y4.X.U.y.ivM...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):65176
                  Entropy (8bit):7.997443372645106
                  Encrypted:true
                  SSDEEP:1536:arFO4Ln/XN+lFxT39W/KaFhReuBPUxxg9MEJDOG35aER:ahnS/TtW/muNUsesiEku
                  MD5:831EE1501E3F2DDC69CF3E9A6715043B
                  SHA1:D6737398136D62FFFCBB3C8D59CD7476F4FEC649
                  SHA-256:F9E033E1824D8E9075619CB194AB85FE72C7331E8B2FCDBB1A264709636993A0
                  SHA-512:9813A21795EF1460FE932BFA6281DB5E94E95CA33181B7FAAAE9810BFD29D15F11C0CA0967CE89A13B64B08FA606617255173FE2A92DB805876C4A1C1BB95155
                  Malicious:true
                  Preview:...0....t/..?3t.G,..i.OJ..U.<a3..h..d.c..Pm.e.k..Z...~..R.......}..."...uI...;;?fn.......[.6.oy.)M.^..V<...g.w.....EX_'.[.c......P.k(zF.#.\.d5....%...{.D/v..k.|.V)...!k)...si4jz.V....i$......|...!.t#..3....{..s.Lj../0u...h2.8.Z...|(Z...E........J..(-.{.......0TN.l.....x...D....8..t.*....H.._.%...!.....O.1p.{V.8h.....^.x.j.e0/m&F#.WF..f.......A8M.....z...lbbu.U...Xf]..q...RQ..3..uw...x.$.N....<LC...l .v.._.....i...'....6W..$..?".l.0.....e..57d..].>...]...e...W.....He....w.B./c`.........S..%T...I.........i*@.XP_(...i~...txdcV.(*.F.A..p..j..3."*..(...2....h-...|W........+.^..u]..L.G... ..H..9.skYR.Ll...i."5...sV....^..^F..`..@..4s........B@e.....j.SG..!....83.j.T.u.}|bp.e...+w..`&.w.!.....^.p.TZ........V......H`.g.=._T0...o...%.....(++.d`.......!(A zZly=..#.0$.....a}G..}^.n1.{.qR..Y1.........8...~N..$6..q}c.0.HY..7l......M........Z.......@.'.....E(.dp$.dX...%\...PTEJ...f..i..R..........z.(...FEF.tl.q"..x.,i....@8.h.Kv.;.qn...BR_..K.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1288
                  Entropy (8bit):7.820937381411661
                  Encrypted:false
                  SSDEEP:24:5kZP7tJeME4V73JLjX423DXdGNrS4PU1zhkfwycnkxqCx3U/:5kpnE+9XXZzNGNrSKUphUspCx3U
                  MD5:0B6583B9F8564335EE3E0BF9C486DCC0
                  SHA1:7AF61ABC5FE986AC8B879143A03A62850D5BBD0B
                  SHA-256:9065CA7ACB82051F8DF531247B8897323ABE2002D8C70D6833DAB86A6D0F3786
                  SHA-512:B0BCFCC5F022BCD6C42F5BC68BF4DBFF35E9F63867A18A378916E19A3115180CA04457238EEAE237067E7A85C0992B544BD134C8260237167502B2634B5258F1
                  Malicious:false
                  Preview:..c=7.K#.@.s@...Up.......";I_B).T..q.f...gw&......4..g.@...2...f-"...)b11...A..F9...OZ.....99.......f....R..v..U.b...^......7wNg......Z.W.S.........X...7...a...l...H...{z...kk.......(...H[..Dl...V.N...].kx.4P..:. ..F..#..+.......gpH...}.sZ.+....2.{(.Z..c.i.o..".IOp.qA+m.G...i.....u....!f.9.d=..K|.A.E....'..=..XY:...?.....W{....z.cLR.s.:.}....}..O=h..=5c(5.....]...$.?7....a...mE...t.2im|.=.U$...>.,Y1..(....?G..IU.A8.'^.8....r...u...n7.E......0.....J......K..B~...G}.q1.\..../....]....~..o.&.z:.....>.=....."q.K/..F..C.MA]1...*.......D..?...U{...E.&XA..}.] X.q...../...0!z{....h.YC9).e\...+.~....3...G.x....b.&..A .......`.e..E.*.i.,.r.)#..h..=..s...{.4...t..1...qv.'.....V....r..Yn.f...Z..&,w..,....3..*".0...._...^........*t.......B.:f......*.N..#A......./A.H..Owy.*w.?\X..7..R.b#}$..{.#..K%EL...#.7..X..;r$.5.u.Xu..3.^.n.6{..eh..v....c.e.V.]x_....f....)|..\.q...`.&;.w....v?x,.U.........-4=.J>^.X&.jj<q...9).gD.....$..4....W2(Z.UA.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):597
                  Entropy (8bit):7.535738286674319
                  Encrypted:false
                  SSDEEP:12:RVgfWe/GVV8BG7wkODTkYfm3zz/eFaDFEV13phGzOEFphzy:RVgTkCgwiYfkzqoCJphmOEdz
                  MD5:942487A3004547BAD49527F0DEF4B361
                  SHA1:871EE7A3693EF676E83B25B7D521FE28FA965C70
                  SHA-256:4B39AF27CB31CD3A14B52B4A7236EC68A3FC4F02EC2AC3BC299C5076EEEC2DCE
                  SHA-512:219E949B07C40FE33A8AA305793DA68B7EC30EE558F21D2EFCE9FB9FD5F112548D75C2CF60557E5E68CDDAACA2D9F6E772172B8AA1BAB52A6A939DDE7C056C5F
                  Malicious:false
                  Preview:..%(...B...J<..?@....w....s..z.M4.....e..(....7v.g%..H......C........K.g.._...k.-..2{..I..)...t.,..N0...J..A.&.3*.N.9j..9?....U.N0.......xj...8[.......E.............I.5.N..[0.....u..e..s..|..:..j.&..v.ND..'x......E.To........:O.....n."..9N.T........t.(......v.jU...Ia.....(.c.....<.M..XQ..A..A.%T|...y`.......s.....q..`Z...X.T..C.*.............w..c.!'.P'.y.Z}.C..p..j..s.....|....b.M..T<l....<o@.m%..J...^...C...>.4~..i1..a.a$Z<1A.@..c...R@x5.....e.....3.....;=.W.b.........Pc..[.t..-)].%e^18...]v...?.Kj..|..|.k...r.W..v..J.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):826
                  Entropy (8bit):7.663989927879702
                  Encrypted:false
                  SSDEEP:24:NYSbhlGdHuH0Tri52A8NQpmJkYr8k7nGjv:rbhiuHOA8QYIiGr
                  MD5:4FADF324A1CBEE6AB22784B3EF425B72
                  SHA1:483BC71233E9667DC0B3650D5F688FED7F1E873A
                  SHA-256:0DF3A56C214C69341A389B2B46EBC09E5C82B72B3B7CCD557E1F6D3E3CBDDA3D
                  SHA-512:D3D4B23645F3DDF7F32484E30B26F35DC4A5AB54F499EE235AE745D315F3BE9226CF7550DC47ED7807EF522464D9E41B6D4F69EC062CB0D51BF3721277283C34
                  Malicious:false
                  Preview:2.j....s..U..mYz..0e.j9bJ.;\m..!..*...$ .c.....r=.3#.&Z.U.#3T8.0..c6...?..d...'.E.B...I...4\...3vaT..z..[.b01.q8S`f...9..-8.z....B...YyQ.s..'....C&.1r..WU.V"..nE.l2...z..u.{.......A.U.3P.....6)A..u.Q....Q8.J'.).?..$.....M...g.B.}.5...J.......Z##.N...x.f...S".e Q.M/.S\OC...u8......LO.....hJ.f..O...?-....DU.v..=.B....$5\3o....Y........E.....n.*....\.>,=.F..BQB...o...^5ju... ...j..5.z.PZnz.XJ..SB.y5.>.-X..i.....P..ux.I<.W..V..p..Q.r...f.6...)oO....>n....H.@.8.@..f_u.1^..>...{.h....Kx.i."J....[.B......N.o9.b.Xsq.<u...?..i...r}..@.....Ez..e.J....<uW..P...?e...n.6.E.N.;....$*)U..p.E....n.N.A.)....P...c...6..........^....u.(....7(k..=.........6fO.!...6..A..2...zu]x..Z7.....]..y.^N..8P...............{cC..4.)/._'..C..Y.}.A;.x.n....W.N.E'.........O.E........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3555
                  Entropy (8bit):7.934004352141975
                  Encrypted:false
                  SSDEEP:96:kBaiOgjv0/3HwyRbu9EtGvZydWTTbLarCUvdw3L:ks/HwsuEwv9rmrvdw3L
                  MD5:85F23E1632202CAD2506E7210CBC75CA
                  SHA1:7C195CA5B29F1B361065E4DD35C876D13EBF1CC8
                  SHA-256:7852ECDE9709B258C84AC80A8A27D7DC39920983F76547B359FEC1704826EC16
                  SHA-512:D7707F2396331FA862C206F9B537786C9DEE576FEB8972ED467C0C73E09FE80644F5E9CE57439A627FBDDB51525A4CA61D516F789A61A0A26961F860F3B611D4
                  Malicious:false
                  Preview:.k2#_.....m........``...tT..T A.......1`.@.....?.4...,.-J^$.S.......9..T.B.....|.".5.,...J.....T.].B.8.b...B.......V8..i..c>..+dBG[....e.A.;B.+\nI.R.O...q.......e$.U3....64[o..l?."k..sCf...]O./.-..>d.oq.\;..e.....{..!..9....;{...=SB..O...t.a..UUto..0..*..DP...@.c.A...*...?...!..:...zX..vr.....04[..}]H.Q...\....Mz.u......(0F.W=K*...5^(...........4......F.Z.;.h..N....Z&...h..]?.a..a.pLy....(.G..H.8..J.?NNY....0'...... .N=E..wa.$$....RF.R./..*..18...y=................pl...}..$X...7...u..F..z............k.57.e.J..U....O..f..`.../a....U...r.Q....N..2...\.....@.3*QK...$.._.,..~.kQ";o`...;rjW._....u..;n.....sH.9..-/......5L...vuZ...@.7.p.Jc...X...Szv.6....(..4......p.....'.&t.xB.%{.}*y.V.......U..F..*./h.|W..1....U..G..2.f..V2.?z| ...@...*...n.M.D.."..7...0.\.@..R.......S..E..j...#.....r.1Q..6..&..M..[......R...?.&I...zX.w..9.?...X.1:.R...gD_...,t_~.?.!9?.....&.i16....,.rG ..].....]... ...0a.%|..s.D../{...y..w....$.;....KC.c....Y...7....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7591
                  Entropy (8bit):7.97728562825207
                  Encrypted:false
                  SSDEEP:192:Lu/YSfbw2PCL7X26rZ1ZLvASxdNNmPwpQs:Lu/YGs2PCLL11ZbASx/NmLs
                  MD5:F4156EB9C1AD8F86B378198EF44D0F23
                  SHA1:06AAD63493D9FB92EBAD7780ED2A64F59CFC4BD2
                  SHA-256:553ED11F7AE487DEEB8E081A70CEDD7E0E50528C4DB6EA59DA6488784F515789
                  SHA-512:17126E743B1CECBC4294FCFB10019EFB0A92868DA4421C4EDACEA502728938078CDAF7F44CB2D4D4630CF7CDA9BD2842AC349D05DB8719DAE993F893CC8D01BE
                  Malicious:false
                  Preview:..b.-.....fa.v.ME........1......})"|..hn...o...d.g.....J3..Ne..].Q.....".m..Eh.M....'.z_...^fX...T...OY.....4.1.X.q.y...C..M.p..4!.KH}.x..fi'..[9U..!.Wea.NK..<p...HT.5.9.].{.WB.....0..1...,...t..H.fJf.=...C4.Q.......?..'.IX...4*ldn..,..3.t.9....T...O....S.1..d(.Ct3.Y.^..+..T....}...9.........&...r..mmb.....q?....7..^.........k...?q.....~..........|k..?..{2ZR!..LD.........6.MhS.R9..8...A.2.CIC.....kR..f.,.@..W..i5..1`.Ms>|..9.\...4:Ks..O..y........I..'3%3.b.Fp...c....c.....k.... f....xU.x.sqE..o.lX....?.l..U~..?..F9...YV...nF..IP..;.RN'9..7..4..$.o..rt7...?..../F.QnA@.c.rO ..91X...".....2....j.Q.u1K..{w!t....~.^..tI...4........Q)..0....,.U.Q..O.U.9Z!c..d"c.K`.t...4ps.X.IW....F.|.....\..|le@OT...........Y..=...2....ZWRd...fJe.^=....1.[N.x..u.s...c6.v.4NhK.q{.ADBZ]...^.M..3...WL.<>.Z.p..+n.Qj..K..A-8...qvx.H.@....kfW....e.....^x.G.S.gY..:\. .'._'..1.{I|.JmJ...^[..6.....<...J..e.../..m5zPD.%...2...19.V.... .....P...........=..h...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7115
                  Entropy (8bit):7.974832179975669
                  Encrypted:false
                  SSDEEP:192:XNLj9VRM2bgHPOYaICqwPdj+b5u/ZGT4OjbG8Nv+:XFj5M2uPOfZTPs94CBZv+
                  MD5:50E510071005FFFB72F4AE96B9A1E9B3
                  SHA1:EF782383716AF74976529067DF62DE7BDA943C40
                  SHA-256:FAA28FB542DC406C89761F96184D9DF5429B2F5FC39A6BF1CAF3805CDA7A84BC
                  SHA-512:9AC2AEC919B1A5BAF5CF7D51574ED88125D141280EE3035E00F1D7899132CDBC00191CC247FE5AFAAC91941178497BE7D4788FBE190454F17E262ADD1BFB0BED
                  Malicious:false
                  Preview:.%:!..&;...4..:....}..k..,..,b....H.".....Z.8g@VnE..."........q]L..hKt./...i.3...EN"f..'.%Fm.Y;b.....pN.....u....8."..;.......~..Y%..v.n.{c...CS....5I.Eo.E....j~..#|@.....e.....~C.......[...e....&B9.s5N.u:z.p'.U..x.....A..j..*u.<.ML..Z.F.K.`....p..Q.....#...k.....W3.qnN..i..wk....+4.@.n....X.y.W.B..."4......C..#k..q.r.=...,N%...g.....L..U1?.y+z.J._..<..G3.J....+...r..N&..'..!4....V2....-.t....%w.p(H.Hr....9....E.*.F....>Q.lO....b......~. .E..qZ.J...[.Vb...F.#o.a..9.....a..:h...82z<S....]..8(;e'_.....>..../.:Yo..~ ...Os....0...C.K.........9..(..6..W........@&%l.x..).4....*./m.u../.o..Rp..v......p...I.(P.I?te...+i.....bz[.uk6..V....!:.a0p....2O.&..._a9..^KSO,M..a.Jy"..#.f.(.of\lh...Z.H..Y....E_t....f...4#.v-.:..H......A......,.dC..?.H...F7....M..Zl..zi..q..H....h.1A.h[..._.....<I7._|...l.].-RU..&.....1....p....e...i.,......m....)...4.y.Q.x}..0Z....M{p...).y!n.\UJ.SA._.l..@....1....lj.[.........'.L...G..U0....l..5.W5.lw&T.y...F
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):48905
                  Entropy (8bit):7.996186178194016
                  Encrypted:true
                  SSDEEP:768:gXz2Ciea9jzP4jZQzwm7ZLKpUklyRYSOdiB0p3z1Q67KGkkcwzxTDVPqtqAe7GBv:MCCiea9Hgj68mFbklkYAOj1kGYwzxTDQ
                  MD5:74CF734A2E7AF7977B9A97F9D0EF00A8
                  SHA1:945249A2FD2125DE02012BFE7344E17186EF2228
                  SHA-256:F59D5CCD9E72530B8799DEF4F5DB8FFAF1D2E139C3CE47D007F862D71A02953E
                  SHA-512:7219FBCC30B4BF29C4F0F03D1B4FBEBC970F24B128967DA91BAE151E716E00CF800560FCBF2CE8484664B07A7F573E5E55A1AB2C38B6F465D23AE25B0BE9FACC
                  Malicious:true
                  Preview:w.oU.....&.......J..6...@k(6...K..+....4{...+.vf..L.8[..!.._.p...8"I....DRYf........G~..tv... .L...u].5]ugN'.Wa.">.iA...B..R.Y....[.5..c.z..f.x.....6...=>...#q.(....,.Dp.f.uPv....0.]....@k...E...{&(....V..(.I....l.......'...H......X...so......^G......)...s.|......,/..O...Aq|$....F...[.K$.....Y.......c.g.f..]....:..*..........Q1.q.L..>..|.k.:.!...[<.w,.. {........w.R.f..#...H...%{....SRA<.Z9.nsj.w..y3:wG.h....=Y..Y.L...<.de.2......T....|.j.C"..k5.\.%..*.d.<\(#k[.."..0..zt...=...m.%...k+.jR...g..0.7t.....O3.....C.w.(3+.`]..g.uc...,S.H{.. .^%.....M.E.O..b....R.CFf.[..5}p.........+P.2+.....k.^'.UV....D].....=G.pwq5.c]..U..Y.|.lDc.........O#..t.......)s......i.m>>1.^..n.........@C.9....n.........P.<..X.M.+o........-..g..1....Zo`T.i..K..x.)...^5.S...f.Cu+.....o.N.D6.c~\......a$....q....g_..q..2.^uI......)+..+s.^l...3<...2A..8@...kE4.U.{..XE..g..7.5vy....gE....In...........).,.....p.....\<z.....2....u.f....G4.yW...X..\.1...@...O
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3159
                  Entropy (8bit):7.9372525582511715
                  Encrypted:false
                  SSDEEP:96:itoXqtPRNqYWvCcanAh3nfOvsh3O5hzseJdNu2zp:uPRNqnv5anqOslO5ZNF
                  MD5:F696B42D9C72E686804C07ACE7BA9251
                  SHA1:883FB91E29E0A9C329977BCE7130524AAFB8FD47
                  SHA-256:8F6A82CF5B75B4C78C5043752FA3A4373343D6FD3C734D1AEFB55884F1B83C37
                  SHA-512:7998FA57796D8CDCC1E3AD84DC7F77116B2180C5E2A7091C9FD6CCFF5C819C185FA752A842981A7D8A6080DE63C0AAADE61BE613B76E248164A4AADEED6FE438
                  Malicious:false
                  Preview:O.k<.._.-.....b.?..ij.....C......w.N&..'.0..x...(..^....|V.`.1@....u.b...lw.]#@{..L...)2r.).cH9bc.].x>..;.H.j...DR..{.U./...@H..n.5.8...S,+.Z....p..l1K....!0......qDn............a[|..L.K...>|..8.gj...,.........ks..{.&z\.j.?.N.WW....lu./..{m...f.f........I.9b.R...\...*.D.g..#..@.T..[.........iW....p.O..s..p94..........N.Du@.^".Hph.!.?.......n..P. .H..N.[...z>.u...S..'.D0.-..E..c..O...z]m..e....*j.._fz.2vr=....j2@K8^../..X.=6T.;.j...%{C...UAs.......O'..+..C.#..'......8o.]{.Zj.,y2....U.4k....6p7f.B*b.fW..L.^&....-+............k..2...H......,..^..$...U..s#^..'\n...`.k.G.Z.B....q.....a.9.....}..F......6/Y..~.uxm$o.N..*...'>....qh...M.X..]....k,:rg.I..A.P)Te...a.../.... .....pW....>.4..a...s.*<1...X.tH...\.-.]K..['.........*x.(...Q"x...!..vo.._Q...'......*b...U.@...{.S(...,....z..%..:H..O..*.Pe.xj@..k...4]../n.LL..8Z.g,.v...".O3.r.....o.5."@..i...l..A......{..I..V";).U.$B.B.4..Z..V.......i.r|....o..5k.>..`+.ux..e..b..7.Nt.L..M7.....!...g..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):962
                  Entropy (8bit):7.768054740557772
                  Encrypted:false
                  SSDEEP:24:0D/eJYCNI7qk4AGFDvb/g9/AL0JPzbhuZYU8qoyw3wLNTE:0DmJYi+4AGNDo77bhuqU8w
                  MD5:91B580D485D6ACE07AB94FB554026E49
                  SHA1:A3F6CC3BF3AD07138F44DDB2A2734219A8AFB228
                  SHA-256:5F093B3AB5468837BEC95E31BB031CBD23F09A0E56F61EED836F66B4D6DE704D
                  SHA-512:01E1ABEE90707703FD0E4D3538661D0F66B27228E1E127BD8A5435A4D8B0E74E7153E3D61DF7DB68F29A0DAFF2812F573AFCBC5A75FE2C6EE5F306B307B989A8
                  Malicious:false
                  Preview:.r/....W..B..S.......6.9.c..T......P.M.'G...r.p....oA..Y|C.f..t....'...:........'.... &\...8|.F.ItY.L...g.&^.N..b-......o......ZJ..o....$U...!....Z%.0n..@@..[0S.Z.:L.+c..$.=..t./.7....FV2.D.:..{z^.]3`NB...H.....0VmV..N..`.0........@..e....\...M..N..gE.tY....E.@].I&{....C.....3....U,f.......FV.[....c..s...K.~.%...>....OR.$#...aWsQn.r........u...K...6z:...-U..Z.h..v....".k..q....!tY....U...w.h|.......V...oV...M...E...b.>o.;.%mFb9R.....6@d,O.?(o.Z.A...O~.{]..._'y.....~....T...`....,)E.....Hc&.+s.2;.dd..M.%....?..'.....f..X.....z#On..+...j-{VD.?.Ta)E.Z.j..=2.......}...n..0..n..|.\.cT....u....w.#....c. .0.O}..W.......,Y3.m..<.b..]#..x..A.ej.V..[_..U..7.~....y5..~l..v..f.A'...A..H..+......$..s...]h.3.&....0...<[T.`[.!..&.Q..V...^..x/.I..I.:...n.(.....v.0 .....).....%n.kE...$cY1).T....2.\w.s_..t..s......`s.r..(........v".......j.6.6.p...VCC..R.joA-.is...l@.%D........&.FK.e.(J............"...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35751
                  Entropy (8bit):7.9945444182627465
                  Encrypted:true
                  SSDEEP:768:gpAFwBMdkPjx1mKHEQCe+1pDZGNA8eOOCTwjvGuwjm+tJjMte3GFHKBg97Dlu7Hu:30PlW1pUA5DGHjm+LYsGhKBaDlwHrVZC
                  MD5:EF15B4557F1C443ACD3000F2095CC8F1
                  SHA1:9A8FA00E8D86F6D5B16D9A858BCDD50A16F723E8
                  SHA-256:98ED5A1C3C8E5CE3FB645E334B15555BE9C302A80C19CE2E0237D05627575AA1
                  SHA-512:91D27EDE31D39C96FCB1DFBEF187DA2719306531931B5E7B99916E9B414CF983A8ABFD3BDFCD430A3852281B0E960AB6A01F73494E9ACBEE52B44E44038E0785
                  Malicious:true
                  Preview:.d.=T....|....L-k..;.J..Q*h..[...+....x...u.H.!N.G.-..J..@..1.m..[r...z.......~.......Ux'E.-..\..;.m#.L.w..9..=?.24.....>..,p....L=....t...!..Q`.K........O.5.$6.Ss.M.\.7t..oF....GN.@1....&...F..c........e.@..\.<e.@Nxm=0"..8k...,-.....A.r..pK.t(...y0....7...o......[h.......Va.H................x...V.....5.\....-k..c.~..:...v...<.7B.Fa...?.9.w..99.F.{.|.S..Y..Y...........Q ..y.S0"Y...$-qG......{H...aT2MN.l.x...pL. m.... ..x.{ru......w.Lm.....4.../.....*.o...3..52\,....|.i=.....e.m~..%~k.YV........F....OU.L.6.`+..Jl%..../.I..s&.........[^O6AY..\....".....g.{.AqO5._.t..@j0S.Lj...~"..k.1&.o..k.@e....q.>..2mM.k.....q.!u...P..4x......?_.8..+d#.. ......1....!...F.R.....].5.N...=B....P$...i.3q..dM@..x.......l=WI."..R..-.x|>[.bL...].}..N.08t..6<S.....NlTb....3.p..A..b..5.(<BF..}$|...a.)..v.&.t4`.....,..s...6..<uZ..;as?#.b3..,G...UN.....4.TZ..L..ca...oj..*_A;.`.cO.pp.q..L[..W..Z.x..X{..9.%.{.3..TY..........c46..c.\......F?5.. ..@.X..&..Y..l..E....O.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1351
                  Entropy (8bit):7.816910494504115
                  Encrypted:false
                  SSDEEP:24:4N5qbxGdCd4WrxILHZQ6EX0+ZCsA/MNYhT7w7caJyxplqzuddbPZZVZXISCjAi:4pdkAH2ZZcZNpBIcxPZp4xjF
                  MD5:29AFCB6FEE80C1914F38FA4A0A1D2449
                  SHA1:F142FB7C09F4846A4858BC199EAA1C017340F8BE
                  SHA-256:CADC8FBCBF28D341B290D995A8BF3BE9EFEECE82DCD479E47428CF5DAC977DCA
                  SHA-512:07675F54D7A4D0337F5924765E3C02E420216F7A87FBE4800F8CBD4A78EAC172EBF64FC6083B36DBD924362C4C9094ABF6E7A4FDF4415C99DDAE9F4E060D7EDA
                  Malicious:false
                  Preview:.S<..J.Ri...K$7....Q.,.Qvy>...N...w.jM...O.......X.NH...J..^/...m.?.c.......i...k]L{.i..A.7.2..X.....g'.{C.....o.E.9.*...._.@............1...K7v..-.._.c.:z..L......(9.....M.2...dm#.......Z....f...e......DE..O.Ah^.-..~.=.,?m.K..k......._.&..z.$*....hs.h..S{.N-...0......"...E.rr]..3.?.0'..S>s..S.C........*oH=......E.bJ.."...../..I.tq.Pn.~.9:..._[....-.../..........@... .G6...{:'y.v......1A.b.$.....=U.....h1..Q.B.RL.....$..Q..V..&..Xr7....*}B...G..g.3@...|5....LM.cz!......\h.. .,..).&......h..Q.......Y..\..{.&.x.?."......."....!c...;..'.......;..^o.........*...S.q1.|>D.!G..W(C~j2z$o.:.)n.m....h.............p.@0#.5..;.K...%q.....H...f>..89Y..y...==.u...lRm(4...No.6..KD.7.x-e.-...~.....A.c..l.F<2).{.v.".S..5..x..A3.".....11.1q...s.../V....+....6....^..tST....h_..?w....b......D..7.....1Q.aS^..\........5$.....U7.......B\..H. ..45M...8Sa>.VD.v..........i...P.v5(?..u..Q....jN....S".5c.7.X../P.*..uG.z..#Q.p...*.A.1.e....k.hLc...&.cH...F...N..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24778
                  Entropy (8bit):7.993773294926578
                  Encrypted:true
                  SSDEEP:768:6ZLLFRs7Ysh8S4dgM4CrupzPov0obb1wSPElmL:6ZLv8VCFdgMhrupUvp1ZclmL
                  MD5:753483D458A34EB4E93F4D2315438B8D
                  SHA1:F7B146C1E3F55749DA9C95461835F7B0E927CE60
                  SHA-256:BC2B0B51003A04CB14B27C258DC06456C868FBC7E2B9064407D7EE2E5CC2B424
                  SHA-512:EA55AF2AE0C7340AAFBBDA2727D33BAC2B09A4984FC94849BF31EC1F535300A6914C6CE0255DF991107F25DE7FADFE87F4E410B5ABFB05EDB7042A346BEEB908
                  Malicious:true
                  Preview:...Tc..xn...6S.s$Fa@1z...>..Eg&He.C.B..DH~oe...!6...sh%.........^,.?C.0.K/9.g..*.^.f.#.Y....C.........(...z..<.h..u.m....7A.J.......;.Ka...W....@...i....e"j?...;5...../...j?..l..{../E!,+..o....w....W..aJ9......w.9.....a...Q..[...Th..@.g. ..jU....+..W.oP.eS.. ;f..p....Y.6te......Yx....z1...>..4.5..x.5.(..#..6.k....p2B. ..r.e2#o.wH>..s..n.#..wy.....b.~...U...;....L..._`..~..l....W.(..e:...P.`.>.=1..Tm.ZC.]1..)-_.<.A.....<.T....G.....G.8..T#..Z..QR.g...v..T*o......]b....?..2....d2.z.4...._.?y...I.6.2{..L....t|.P.Dt;.U..}..q......%.Q..V.t....5..A...?....zjRW.i..1....0....I..c.'g(...^07........x.G.tp.|7.\ZD.<AE....S..._7``.......^.b.......z."R.[.....H.m..s.$m.Y._P....M..<.?.....,...i..#.(...Y.../F....-..*..``"- &OC.}@h..u.......'....}.x'lb......ad...X..Sof...U.C.{....dH.T...O..[.R[..Z...D..B.<....N....D;;...F_M..t.!Z...dE*8.e.{P6.........u].k...A..C...\.%.G..)..;...K..g..C.?."1y....K..^.>.p&D6.T.v\.....?..f..<..../B_...^........0..?.j.y.(!.-..z...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2831
                  Entropy (8bit):7.93009453023881
                  Encrypted:false
                  SSDEEP:48:GEM6FLjknO1rVfapa06okQ8AzuLDtg7IuDgBnCLAQ3GSc7ysryiBD:bonkp0UQzOJNScm6yi
                  MD5:77B2915C0EFABB4092C1BB67D237C69E
                  SHA1:C3A1EA01BE1022535A0B6C9D9ACACF13DA94C31F
                  SHA-256:8F5010B7A15D5139E2D6E7161532ADA705B8CF11908B33F72A05CD35554B451D
                  SHA-512:F9018CAE195B9E510D64692F9263E6BB70EB19BDA572DFEF0A85EDBD1C6D95ABF45128211A782BE3CD39E79902BDCFD0F0133BBCF29A8C496098B9E067D0F670
                  Malicious:false
                  Preview:[.HK.v...@..qo.9.}[.........}.Js....L.E.k..b|.rg..?..&#.l..Jp...R]i.,.[.\..<..=.30d..k.+..k. .^f...q...T.U...v.=.B...].-..'P.w..=...e.....cx..%-Z4.u..]..Z.X.+.<.?..7....|...L.7..wG...:.U...`I.h......V.D......Aq..4j..:.S.%Z*.@$.. .#../CR.v.....F.1r.3.V.OwZo....D......M7x...."].KOk..F4...H.Y.jF}..r.t..C.......+....O..V..)\..#&..V0...."Kn.aK8r.n...5..r.s3.........Ddf.H`i}/0i.z/.Gc.KR_...........tS....uR..-..J..f...t.]..E....J.b)..=..WkC>a..5..#......A....!]..a...'...s........=....|....9..711.c...:.y&.E...'.....p.~.g.,O.a;.,...=..lX.!..........u=..l...T......5.k.>.*......].....J.Y..I..5O.D.$.,}.pUI...?a...L>.TN;hE.....|.5a.....`4...o._t{.J.,GS..:.....(.e.nC......M?.....5Ii..Q..0.^...2..IcTB.}.%*..M.<_.3......>]vo.{m..e...b.].g..0.y.....X.RH......H.....r;ojZ.....EC..dEG+...^0..b....NU..^.+5.6..n..7..H...(...%4.6#...'..1~..&...+'..v.S;.....6U.n..Bq*....`.....YZb.&jX.....r.~M.q..C....3.*..!.N..RN...............xJ..V.ex.a$R...].Q/...[{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2624
                  Entropy (8bit):7.929337156464509
                  Encrypted:false
                  SSDEEP:48:JlejGqY4y2Fk5yvNJ2VGtL5E3cPcUijvyp7+DA+PYinA:JYGt4ypy1J2IPcYp8Yo
                  MD5:C59BFA8380483A1BA40B94547C488BE9
                  SHA1:DEFFF800D963D9E9F8FCB3DDF3B37F0C0C5D6AC6
                  SHA-256:E40CF2505F5A78969DB2738FC9257369139393E4DCF3BBFDF904F91E8E264821
                  SHA-512:489611B0566407A65B2649D0685C8A1A3DD158256E83DFC71F4FC514C1DC788D3C5B1813E66B8A51F9507AF6BF3E2C4BFCEC042ECC9E09F1D302F4D34235550A
                  Malicious:false
                  Preview:..tK....x....h.."......=.5K6./e..0..G..1..z.o......A;%.K...u.{..z....Q..ID.^.J.....u|x`....+..{ ...[nT.kM....C...Y...H(......cL.@C..f....*]f...t..2.bM......sg.=]...f..........\?...Y..$.0.=..-..+....d...f...7...=..~./..q+8.o.."].1...T.+......[......9}....$..}.I......eg.dkj..o MN......C.K.j.-...M6}.(.IeJ,..HSz..C.z.N..m5.E..mg@L.B.~...J...9..tCuj..#f.9O.eBD.)..o. D..2F8."T...]..b'....NUI.u...*..n....VC.Q.R)#.>..~V..t_eG...MQb...>[..C....|...5U.7.1.l.mSZ#.1.\`:s|6D|q.X..G...t!..q..n..v.....X..Y......`B...,f%..)..d......@E....p....<........%pA..JGB..I.>..Lr.O.J.....9.VnR.5........s..........]h.k..@..0...J[\.qV..k....s.....V..k./(...)L...n.......p..9...j.cs..`.,(..j[......L..d.>...(..4N...k...".Z._ .9......p.;...\.b}...8...z.<..Ve=Z"BQ..........zRc......*{..j.q%..8.L."..3O%F.A;/.c...9a......d@..b+...0a.w...3...gh>A.3p...T...X.U.`..V.Lz2.H.!w..J.......)..?. R..{z......9/....}\P......SUDx........Aa..L..w:......M-..)#\..+iq..;lOr..r}e@..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4819
                  Entropy (8bit):7.957079006064852
                  Encrypted:false
                  SSDEEP:96:ZJb6PgtuDsl564GoH/frzNcB0DGdSJbmBDtv1p+zQq6uLGvQSptk9D:riYVGmnWmDYRJqnGYSp
                  MD5:F70F29DEF45C335CED72A1ED2F61BB73
                  SHA1:EE42E14EF0445870F2F50CC07E69EEDFB4528154
                  SHA-256:F71E8236BE24009AD2DDF1A285F7A98C170BE32D3192DF7C617EF92FE24E9C62
                  SHA-512:2EC85A66C34292A6559BF44CD47509A1B8B8E825C034E849773A75B30DE53F5747775D6DCE90AD842425E280AF5EC3D5C081B7D78BCC14452FB912D83D4CB439
                  Malicious:false
                  Preview:..O......8T....{`..L.........!..V\x.....{N......@.b..; m....^r(.^....F..7......Un<..|....5K$.+Qm.7c.B..P..?9.`;......B[]...u..............-C.K/..,.....O-..=.g;.jP.....9.c.....<.V.Uf...........v...).7[..:.D..<....A......h\.6GlE&L....Kxu..NU...\].....2..W...H..0.d..b5. .a.$.(...dBS.'......~..H...{O9<.%....~..XG.L !....r..a.%.J+..j.......0}~}..Fa.4.....E...S...;..G.."G..F.........K...k.K.y...i. .r.....)O.V.bo0].k...o.U....`6.....K..i.....m..;G...BG=%.e....);.*.=.;.Dl..#.l..S...e.@,..0+=....C)".1..Yc2.b?].......lS..n...x.E...>..xBv.......s?pI.O.$(.4....T.BPU+J8.n.c.55.....6......A?.@]..@...G..T.b...[..p..h2...5S....6."<.....=....L...{..0..}.E...B....81[...n..h.....Q..&1^i..@P._(..g+...Z..r.aG..0...X>...s.....~..Q}..4...y.{.k..c.D.....E...wT7.. ..1...~..^.....P..#..P.`...:.d."..uKE..HBo@".A..Q... ..{..TLw:..t.."...u.....\e.zSD....x.+(M.kb.4..U...%./.m._....5.q.my..1.F.....E.c.<]mBv+...~C .Y#ix...4]..@.L.@rb..~|1..!{..h......o.K.......l...e.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):449
                  Entropy (8bit):7.359777906304027
                  Encrypted:false
                  SSDEEP:12:/U+gdhSwkqKDxoNLVg9COyYdllXWgsrKlWlJ3:gdkf4LVg9CdKlble
                  MD5:03F8D8F8FDB9C0C077670EC50E884481
                  SHA1:1B9FF9296225318B36416C9326241502F07270F5
                  SHA-256:CD524EAE78BBF5124CABD298DD4138AC6AF90B838D56D94C3B304761D337058E
                  SHA-512:494DCA97AC2658014F9B35AB60072DC4CD7BA0D91CF449D9B67725BD1F62A6D0D8222BA66F3E1E1A3DA791AA2F86234E2463077166B8199BC3F8ED8F4BDB9B7A
                  Malicious:false
                  Preview:..#.N...&.S...k;.(.)3!......^+.Y.F.K..Y.X.7....X.Ipc....M..(........]-|..rj].H..P..iE.z9Y.f........[R_a.....pp....."VD....er".l......`yS?..$.Y.'....#.UN.$0.../.a8C.e.."...@.*..9.. _#.......|W....Y.7....J. ..Be...n..M....SP..95b....6...7y......I.......i.f%.2...t.i..../.8z....E..hV...."....|....o._....`p......b...Q.....7..P..`...z+9B..!..........x..8............'.`8....m.mI..N..1k.&.t.!.&...5;M........!...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):545
                  Entropy (8bit):7.499203602339431
                  Encrypted:false
                  SSDEEP:12:/O9w7GOL2PJXAn/QuBHavVspMIms0knSzYIE:/SOL8g/QJVsMPfHx
                  MD5:77268F1EFBACB1E36032100DDCBC38BB
                  SHA1:3CF3DF109B46763EC9E288BF73A3B5BC263D112B
                  SHA-256:40E28517F64562332F8E3356B52D2B70B14487A7F889871583A1377FB5099C3A
                  SHA-512:28100C26FB82E756C62A20C25A7EAF68D7D51407903170930FD8A9D8C426D3E659EE479DEADF85AD28999C00FB14DFA085AC7225C70DD10806FE04CD256BDE8C
                  Malicious:false
                  Preview:...8R....wD...t..&W......?..DC..0.......B%V..S.......#.>.;9...........9.e8..J.....$..<V....,.p.GI..t...^...<.3qd./.jr$;.u.uC...8Q[..5.|..;S.:.f.Zy4s..+..0f9..n%.k@..../m..aE.......r.F..!..9.1!#s[a.P../#z....a..|.v..P.1...e.4:V.0.'...e.J.|.x..E...S..[13&..<DP&Er...+...H.....!...xC.....Z..jd. ...4~..!.7...h..PV.fQ.u8&#d6...6r....G..8La<.1.5.......g..R.....D..gx..\q..;.....@...\Q'..}}..E...f$......r......i....y...84?..>2F;............v_FA.2..Y.o.I.YR..4...h.&y. iM.va...R.N....N./.i}E.X.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1163
                  Entropy (8bit):7.778632234006912
                  Encrypted:false
                  SSDEEP:24:DDZyC2Woi0mzDFJBp+7HupdomlX9fUldlGHE55pCwRf279vDuTu:DF2TX7HG1ltCXoEVCwRutDz
                  MD5:0B9B4D6CBB0756709AAAAEF995BB46C7
                  SHA1:9433DD5A97740EFA9061DED0555401492A290685
                  SHA-256:95A27471FE7E551C0AB5677851F4713D99D018950B1AFE50DDE9B165C8FA9662
                  SHA-512:7AF4B6D65AB6EA7BB36C8892036635E3E1EF23C61B093A9AC327870E85DBE7EC35896C85A48498B52152A54FEDE745C04AF24A6CC1BCC3EAA43B16EF71469582
                  Malicious:false
                  Preview:X..t:.T.E.j...8.*...R...@*}.../..T.}..........j...Z..5..<Oz'.<...k6g......Yv..,.D.}.p5V.. Y.....N..=-...).95.)\.t...\..[.}.......%%..l.9/..=.,<D...B".....t...~?[g.*W../!.;.~...fH..pE......KV..swP...z..C....?BgW.e...".....4.$._Z.X.!.\..-!].>.........)........W.*..a.ae(.:aB.'.*...>f.Fi...A$L.\I.;.Tn.h...xv.O......2F;....N\;...'.fi.......'./..wJ..i..z....EF@@ta...Gg../..I....[.Pm..!.X...%v..#;...].....S.....3.R;.~>^.....;576..`I@&7<.......R..1....Z.B..........4..._.....~\..[..=.^...'..E..0.9...y..........5........sh@.0>.n8.....\...VSu...K....nIu.{=Nr9}.x.m.......2g}%........6..G...a..../&.....P6.u...F..&..B...0..gD....].|.{......A..PiZ.._.f>O$(..o.%2...g8.....u...1......Y....jL.iY.[;.5...}..[.._.#.s..."..e.0..,.G....m.y.L.u....nE..gA.Ou..W.).6^.z....an.....iw[..j.[.e-.el.m..{_M.Ri.-..&.r1...T.^.....|T...t.7..E...../:....I.op....w..Y+}..$oG...k.?..C..B.=.'y.....lA....ZLn....l..!..^...../.S..#.3.&..MqN ......P.V.....!.j.v.Z...r4.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1095
                  Entropy (8bit):7.7597256799254195
                  Encrypted:false
                  SSDEEP:24:1NFZDUwifrtbOxKCLxNrHkwpWOPRZTl0YVixR5MV5kpDBbNVCF8:7FZD0rtbCFxN77RX0miNUi5VN
                  MD5:DF529C6AAE80986EAD81B7B0E8971B46
                  SHA1:9E615D85C34F8071DD8586B724C2866B8BA32563
                  SHA-256:BAE1A8C0F9D0CD4218DD41C399F25D263EC2D90D1AD8AA786E5871933B465F67
                  SHA-512:E2CEB98EFD0BACADC1BA232E63C2163508686AA1065C289EC2249BACF1C55B3C23539F9A1B02547130CF2D3A69B98EE22B4A154B86FB6190D5C8236DCB074737
                  Malicious:false
                  Preview:.BK.{.. ...!4e..t.E...BJ>jI}.U....u+hE.7..l.`.N.W.T..KR......:.....qs.. !5K.....$....s....]........|K.....P?^n......9.....[...g..(.n.-$m..../....@....w..CD.....2.p........Q+W~.`rs.D8>../(.....;<*.-..,.Z........wK....W.o..F...pP.....r......O.j..C.....0/o..[.b..._...v...`.<L..obu...q..t....6.W t.FD...../ .."..;...u.K{.p0...@.'...e5/.K.p...XZ/"....y....zz....!.u...K.......q......z.ae..T..A.LMD...e(..b.....,.M0e..tr..`..Z.a.....<.1...A..P.B=...Wrg..B;.e.`.*..)..D..E.......^_..&UDL.}.N[......pD.b..c/R..M.GZ.b...G...Sj..(qn..R...(.......R.b.$7.u.......o..../"".Q...'..;...9......X...4a...b.W.5.H.u..kAv.I...@....j.......Q.~X(...T.........I......P..Jy..av.Q..lp.\.-vGk...@e.....e.....~.<!.g..^.........^..*..5^v..f.R2.Q.. 1......a.....s..1..@....Hr....".v...7V.`.].L.......H..?....vTm.\....#....:.\5.c.:.....$...o.Hg...q.$...m....0@~kHA..._p......e..."....Rz.}E.6...(].F$..Z..k..R,..)...3[..O;.h../:.....J..3...h.O...4.......7.C...,...s..<..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):986
                  Entropy (8bit):7.74500862741119
                  Encrypted:false
                  SSDEEP:12:A0iVi1qr/hsmiRwLSNiS+B1cAXIVotGeYwYzX6DczXKPww3QoqdKgfqT+11Va7Ym:EY1WiRRNiK21SwYFjKB3Qopgfj7iu
                  MD5:831498DE8282689522199825799AB162
                  SHA1:3C286FEE8012849C56B58061B4D14A5BF50BE51C
                  SHA-256:5A5CB83E28FAD31BA0B6C342F8A216C9516A4BAFBEC7212D3E6A168BA542F658
                  SHA-512:1D0B2F06E137AD23E4D38E38A2E7F37AE4DC8CA741E8284B7A875A566B1C3287C0CC0D215D1B6AFAFB2359FF6432033BBC80B9735802E041F48F99AD688FDBB2
                  Malicious:false
                  Preview:..O.V.5.w.j.c...}.....r..a.......b^...[5...._..j.... .^.... h....%+..c/tS.m.X..;...).:.......:..H.>u...Y.0.....k......~C.\.8[.c...Y.~.".....0..rP]P."7k..>..RY.....'W469...\q/.).3.N7t...3.P`..Iy..{j....."..&]..'<3-v%.K.m..Pl.... (m.U).X.4.58.cF...d.,k......p....E0.d...'q.(.wD....F]..L.j.$&s.......Y...w!.zb........=E=#.X.p..amxb]... .Y'.+..jc..a.3..9!u!.#..p.Gnf,.......o.._7.......=;....d...*Y.j.).%;(.....50.[.m..(7..0...O.n....x...I.{J+.h....._..p?.E..Y##..]~}..Ab ..Ik.+. ....?V..ba.w...O..re)...OY&.dR..N....0!..@.?..c.......~..~.].gI.Hay.m.......... .....xD%.#."lg......K......J\.h`...........C..........k....FB..x{k........\...#4.....UI..L.`O.!Z..e....he.*C.h)..._/...?%..k.......p.qO1'.....+..On.P..T"*6..}..>...d.?....j...tf._...V.........F.T......L9j.5.CW.Y.L.Es5...'i...........#..[)~.?....B.i...E}....=....k.n.F..q..$!fCe...:.......P.....2dH....p+.$dG.&...2H|"%..|./.......0e........!.........:...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1730
                  Entropy (8bit):7.871485221968949
                  Encrypted:false
                  SSDEEP:24:wYtdCnZcnGk3g5s1dHzMxtPFgXGtm9fsbtHFQ8Q4NzytlmcyCg+/IYhsYsAwFG2N:wY9D9Ta2tqvQ94NwyF+/tsYsPBXnf
                  MD5:8100EE04D03F9E168617F27AA6E58970
                  SHA1:8B9BC309C430997DC168825D67A6A724D29EB287
                  SHA-256:47C777AFA0A9F513797048068A6B6920AB5C35C959AF137D7DB19BF2D5FF3B0D
                  SHA-512:EACCC89F996D198312578A81B7CA5DD86568390FC507E84642FC008CFB44E86ACDBB913F9D4CE7626BB78552086C9BB4AA433FD3F86086CB7517BA6C1764DB95
                  Malicious:false
                  Preview:.....U.r....,&...U@....u.u...p.......4.8.....T..Nm.cE.3QcT>m...X$.@=xi<H.]4.B(..y4*I7.F...E(.U...m.^r./q.n./;.UF...y...$Z.F....CE.W=W.k.-.~.k.iv....w..]Rk.;z....T..5t...Vz..yt'...q6.Z6.W.z..I.Z.]..^..[...c4....~..i.:.....'..O1.-...U.F....qw./..8....6......X..->.z...yu.......x.!..> . .K.K...Z1`~dx1.Jc...y|.(.m....V...`...qmE...q.\k.60f.*.".A.$.....S...W..vhz..W'..z......f1..rkB...:.(..%s.."c..s....V.]!.=Y..$R..35`Q.a.t.QD.f.........2.&......Wt.:L.-/.j.7.?Z...Se.>...h.....F....4l.h~.s..h.h.E../..<.+..=1..l.Ye.......!....2....._?..h.W.+-Q.V.).D.s.8.w8.!|..z.cxCE..\bd.....D.L.y3.=......G.0*5q.i.....q.4$..|.....:...`8g...4..n.X.=...lZ..WnM2..T.........R..A......s. >s.d..a....L.K.k.c.....u.6....5...rZ,...qg".J<w*......._..f.....'.......;.......3t.<...-oT.W....db.W&..t....:.p$..x.uxG.....=hf.j.1^5....=....t..Y...W....."...,...}..3.o..\....g'e..LX.R...18..Q.,V.G..0'.*Q'.`..^e{.\#....\...]v.g...x..W......#.Gq*x.U...K..)^&H....`d.L.`.?.?
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1523
                  Entropy (8bit):7.858315720472626
                  Encrypted:false
                  SSDEEP:24:cMYIc6G0s39Xkup2XRJnqjh5E40Fp2tOIWRlH/ane82cw5MmsdVINuoISnS9Q5Pa:cIG0MOH6hy2lWRN0iumsdV4Zm
                  MD5:9FBA143004EDA1AAE4520B2E5C9A344E
                  SHA1:0C1005B6CA2FBBDD5A24E983FF62670BD07FBB60
                  SHA-256:40127F821E9E59008B2FAEF356D2998FF153BB9CFC5DD369271DB680CC568208
                  SHA-512:762902902CD2548F27BD079FBC535761B018987004CF136BC1B086FCBC67F862C86B1D693C94AB4BAF8F89482B214CD8CD302B611A59D33029CD120D3316FAFE
                  Malicious:false
                  Preview:M$.c..dV\`..m;.P.p|.x ..'F......-.....<-.6......cX.~..z_.....P..z#.-!...G.".W`l...*q.c.Br n?.<g+j.C.8..67..G.Q.y...ygQ...d..oSK..?P..+.6..zAKO&.......:.'.y./.M.wO.8.'..E....S:A.U.y...v.].^d~.w.ML+dH.m..3(..y.W<d.a..+i.s...>>.>.........-..1.L.I.,J.....3.....)#k..S.....;..@.b..[...R.Y..7Js......z.l...gB........%..:..5......VG.N.g.m..I......c5f...]....*lj.6*.._..c.D.O...t..Dy.n.].~.?/<./...o.4nN.r..{.*..].!+,...-..j@b...C. ..N.S..6j.rU.x.B..:!.......<.../..IVN....~.e...2.......t..l\.6.-F..0,~....2..?...e=....)S.H....;U..;{..ba..{....}.."HZt....z._p{.a..u.F.....7K.{p..M.B.d..tt...n^.U.zy$.3..vF .{.i.....t.8..Lj$.t......@\..).-....Z..4....=.:A.U.E......&^...]nB...1h..u:.g....`..^3... ....Bf..K.,+R...`....e...E.\.|...KcY}.t.....B;t....3.P[..Cx.(`z1....pK4MD..YQ.9K.;r_....q:.#s..........(.x.Om.`.i..._.w.i....G...k.'fM .j$.7.R.2Q.r&.j..5..H.YJ3...|%.~.'.-.b...*L./.S../j^^+.F]n..P{.k!.}F....P.......).......L..wG.Lb.msA..NF4.2"...H.1..i:..U.u.#.Y..Z.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2862
                  Entropy (8bit):7.9132666831340766
                  Encrypted:false
                  SSDEEP:48:y0Mh/ezmD0v3F49hsmJGQRaZ5KGHQFnHq6VByxX33JueNbf2FcCT+B0MhQ6dxxkI:yRMiD0v3FUhs0GwkaHHBypzKFcCTg0M5
                  MD5:1BFD57EF161C2E540ABD62E2D2A370DD
                  SHA1:05505414B362DC90715E8CE07F8BE5AA9CB9CC6F
                  SHA-256:C46B703CCA6364EB8C428AD719134EF5557511D9963E4189067C109337AE42E5
                  SHA-512:999DD075C4C81F8B43AA75A42839CEF1C1B3A9DEEBB2180478918E8C95132CFED2184E807CC8A76E83AEA0DE2CF67C2232A43DDA810CD1871DFDD382A329C919
                  Malicious:false
                  Preview:..!..0....e..........![...i...P...(...'....B....w..(.....l....3..k...R...Ia...Q.*...b|/,[....I.ytf..A..01...=.M..C.5.......6.Q.x.. .......t.KQ.i...Qa.IbO.=.O..D..Y.uAJ..g\.RR.Y...?.A|...k..N........F..oj.v+...i...P..Dz......N.......a.Ud.;.....c..x.......|{.K....../.\.....&..>g.E7..MR@..eXp&/.Ti.K..rh.....i....WmO..G..'.P.+.l....[.H&.bmS.\.2..c...g..../...k-BuEy..x..4X..../B...HA.d.Xx.>..2!.O5...y_.)..Y=......"..p;.v;.D$..<s..t.. \>./U..-i..M....=....+........jF.Q..3iE..pJ.M....K`.`S.>G..m...kj...TX.....T......y5.WS?-./..1..`X.P|"....&w4x.U..].V..<.4...m.N....[uf.........j.....X64..^./{d..C..1>.?,...8.f....."%....[.Y.uq....;(.M70J9p.&......}D.]....x.i..+.*n.....{k.w....i^..\y.R].+.%..g..?V.....<7.).%K.#.*&.s...;...d.u.;:.'.Nh..fa......V..b2....#a...Hzlob...(...<Q....q.)ck.......,....6S{DNY../.Z.....b...#...R....x6. ..T.-X...e./..G3f.....e....j..V.........j....x../.P..1).cm....tuP.&.... .(x'...f.;$'G..1......A...n.&".4.]...u?.vI
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2831
                  Entropy (8bit):7.924194261444404
                  Encrypted:false
                  SSDEEP:48:irOWPAObzRVGuySwGgRP+5YS8Gq0nMy7MkWPSY2NZ4P4NgHZC/gotCeA7Q3hW8nZ:iOSwRPYxdQYzYk4i/gojAghxCE
                  MD5:2EC44F186FC749348FE23DDE7B6D47F7
                  SHA1:3524E59D127811BC8FA28F01AB7DB62EDBBE1ACB
                  SHA-256:4829E2D0C12A677C8522F1561B066B301BA5DC391ED95A207E6A1D9BDA20C7BB
                  SHA-512:E3D8B8ADBA2BB40C54887AD66F6517D5A9B44A4FA84FF14C2CD367AB6686AD3E282F94B3439EC8291AC702419FCEBDFD0E485304ED29F0E40112C583EF0BEB00
                  Malicious:false
                  Preview:..j...@#A..O...n[D.O.....p6..>.>OD.a.2B&2b/.H.-.|qj.S./...Y2.#^....U=\.n....GG...U.....u.w..w..(.......lP.#rx..&.j.`.O8..|..N....\l..t.t..y..{.........^.f.r.6..S.jY...j.....5.B.1._..p .....u....#.dl.....;.U.^=<C.{.PywQ;q.6,..u.....n..HF..x"R..l....!...I[}J..(.Q]5....[...y.O..{.T...bX.C,.4.;.{.......'....^..yO..;.p.'^..Y1.`.....{K.Y..S.A..%....)._.3a.M..B"[..2.V.(.|...._.'...2.=Y.....s...(.......LTjVl;xJ..P..w}.^..4...._.R.....N..n....E-..i.aD..h......@..":.X...Ez.PA%y.!.e...fwv.=J..*..`.....<U...B.^..~..L....Z..Pl.........[*.i.i..)j.....Kb.....R....D.a...&y!6b..6>.qL..G9......%..P...6......u..Q_.1.N.\..6(W....%]......z..4(.BQ...)ASN.G6*..X...Z...yz..d..5.XA..2..>..3..........._..n.....^l..[.oe..H.n.x...P\j.U.Dx..w..-I,.Y.$bN..2.t.].T.........w..n..~.M3o..7 ....e.[..Oxq...e.;..\n%..T......._!5.(...Qp....*.<.z.5..A.c32.....uGI.D......Vo.Q..q8K.f.!........e{.@k`...M.x.....'l.V....#...`OU.R.u=.....1W.].....I.;L...&...%..f.p...fm..q.cgo.QZ-U
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2624
                  Entropy (8bit):7.911790004818894
                  Encrypted:false
                  SSDEEP:48:sJhL1YwBw4r7FsBzok7auVYlutA+5KkoVFcJuklz1jcpQnbbiTNeAC327PF9lH2G:g1Yew4ryzJrY+CcJ7Hnbb8LPV2BbG/
                  MD5:4E1FF1A1E1E6833F05EDDAFC1DACE0E7
                  SHA1:7C9A074CEB5D5690802B8159DCAC4808BEA45F5C
                  SHA-256:5984BEE12DC25E66F9BF3BBFA4AD861E5BBB1597717CB1ED6FE0F3686B23513F
                  SHA-512:4A696EED62B44E1E0E0D40220E299272E387BFC2DCAC6EB35E42259A813ACE8D8827BFA9AFD6CD018E1F997C99B57F4184ADC12DA297B24A003EEA0873FCB1C3
                  Malicious:false
                  Preview:g...A.K....+...?.%,.....-..<.;..........a.d4...i.m....p..B.j7m.N;x ..p.r.+.3.Rg.=+U1:..0*...p(:`.sh-.....m..Em.l...R..DL..g]i^.|U,`.z.....V.......Z...N...6B...................=b..].f....9P(.c...t..f ..a..X..ei.Q....B...-...!....x.GJ.b(3?T....b0.....T%...Z..R.17.....;....f....#.A.......M....5;.hTH.j..e.A..;....0.F....6.da..7.l).W8..vg.....<...mXx........z......tt...?..i......RP....VgxC.7.......i.d.).n.Rp..........T36...A..d@...y.z.Kq...Np...5U-..{...c....W..t.sB..V..d.1o..c...e..eMj......V....; .Xp..4.!.c.....@....IB..^....c...|...Q..8..E3..q.(....V.m..K3p..+p...3......;."ZU)xw....3.t..2...9M..c~.'fv*'.^..6.....(.,f.3...[._.b.?+.M.I......T.^,.....:...?..Ft.X..!.Ro...!.........j?.....^..i.....;.X.O0=_.r%.m..C.........t.....h..AP..%..{.*......t....i}....~.S.$.4{.>.jq..y=.5....c.{.......ia.......`?.....L.g.....1.kd.U!.*.` haX>;.....?..Y2.......jM..=.c.N.3Zb.z...."..,.m......h..h..+..h.........+.?..ra...a1...mc.R..5.@.9.Dz>..8M.............
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4819
                  Entropy (8bit):7.964225024609677
                  Encrypted:false
                  SSDEEP:96:X3DPLWUqBPwp4SK6vidlM3vNqfhzBC7PgwuRYh6Q:X3vWUkIpRbS5x0Ewueht
                  MD5:5A0A7076A28276901E275DFFF9C28C48
                  SHA1:275FBB6E36B21BD8F989C47F744372917C617652
                  SHA-256:221953D2291EEA8312AAC1CCE986C8CD7F84FABC67EF2A830A097C36F52F7FF6
                  SHA-512:708E196DFA8429BD8404BA0A42552CDA76D2F815C2AB7377517B3A0E76887BAD36B05DC86D31277CDC3859F1094668EA363528F873F1A5B4C57CE5483346775D
                  Malicious:false
                  Preview:...%..8......./......`_D....|.2.".f.f.r.]../|.y.j.@.....s..0`A.1.h...................f.....o...=8O.....+.3.u....aA&.N2....2..c&..q:..g...?...{4Q.@]..X..M9..M.2...|..../.t...(....TW.4...j.*-....>..#.g.j.....If.F$.......h..mb...B#..zG..0.!..w.Wj..I]Nx.1.~MS..v....#};.c.....v.:.C@]m..*OI.......<...c....j....).Z.Q}..b..G.m.......K..../[.>~.|.....t.c..../.R.h........M ......TJ..=.8.....q.\.z.v.t...R0^...i.....&[.f..M...Ha.Y..rCB[...B.q.\..."O.l..=......UZb...o.y.Pk..v..@...X..J..<S\.Iu1].%.4.&..GmS0..'U.#=?.'K./R:....&h.D......7.c....F..q#m..ii..FbK.O0..x7V..4.o.bG.{.....N.....|\.#.SI....E.r.n.x....S.4kc...R...Q...v.y.6..0..UE6....*z.....Yd~.J>v..e......#.gE...7........1...D.......i@...z.Z....x.b.&'.q....|n..0.....!.n.&....|...N.Z...W..@.<...Y...W.B.....!:..GI...2.)1.o...&...F<.P.i...4.Bo..]....F..E.0'....^*.\^....+.+[H....W..j. .}..f.&.r...2)/K.5. F.#..~.n..p...fpM.g..d.(Y... .H.+..[X..anH...u[DE...xb..qb.l.Q...b\)q......nu.S.+.C.l&.u}\..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):449
                  Entropy (8bit):7.377887995100102
                  Encrypted:false
                  SSDEEP:12:jq42P3+Xl/0lK539c9f1BmugAHPJ/E1Dp094L0ph5+bSY3:jq42PS539ABFfHPZE1FlqhobSY
                  MD5:B9EEB79021F29450683B479169E9C424
                  SHA1:B9225F9A7B41CDF189141CB907CFCEA2BB4D9BD4
                  SHA-256:2A14EC03B30E2CD9165F62B026B8965A20C67FC1C0C2B39A57B6C59350541667
                  SHA-512:6A234F9D0CD8AC40155D7F7E84A328C906B7FD94A437001598B1EF5212793056D1D35020368A59C1697D26A3D08794F1772AFAA78F0E159F4D38D5A256C02E7F
                  Malicious:false
                  Preview:#..)5.I4..E....F.g....Y..P.r. .#.._+.H.;mn.........o...m.U!h....."...R.D.T2f.4Z....'....$...J..*...$..P..n.6..l~.(.%..K.....Na8.K........i............yY.R.h.(.,...8...xg..K..].......ZZ)Xd....]..e.V...<~&Lx\...8..P...].....Yq.dT.."b.B.u.*t.l....C=....m....{...K..fl..........2.....d2../s............C.@g3M.Y.*...n..n..(c..|.=.....XF_}u...XT!..........>.D...>r.{....]B1....^.-j7.=..\h.mm.8*..T...h...OA..........!...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):545
                  Entropy (8bit):7.480890417398159
                  Encrypted:false
                  SSDEEP:12:FYVmXO2nyyTVzNUBFKRtCVzW1Jpb9ABPERzPZKk4Jfn22O1brIP6JlniE:FYI+2lbU3lU1bGB474PQRpwsxi
                  MD5:221843BD2C3F18FBC45F6EAA72B8F646
                  SHA1:069B9DD7A07755D3B35993662D7A97CAC1DEEA66
                  SHA-256:1516BD877474473A563BB3FC598B18B20EDD6EE9DA52B6E2A12D9D12EFBC9155
                  SHA-512:ACD4142C5D6E491E94CDF880D7920A4EF8949E9708DE7120366BA12B163D02B47F8CCB46F8C955E99DEB4176CE585FC7696ED56A1863CAE9F2498279F346398A
                  Malicious:false
                  Preview:.M.*]....cr....Yh.....p[.S...+..8$J..W....'..w-...:.T# z:#...S.....N..cir.._.].h.a.,.....4x......:...8H.8y...L6=..<....9......>.)k.R."_.....W....o..!.q.k...XT.F[.$...,zq:."1!.@....c.....z...$....9....eLS'....aK/w."2.G.y...)....\....`a..$..E"....g...)....EF..F. .D.`y..@...}....0.4t..$...E)......G.Z.....i.G(6.p.:......z7*..m+........{7.j....N.\.".`...t.B....G..^.P.S....;a..s+.o....u{..o...L}_.s..P<aM@.a7.4...\GU..]uJ......-..7...........X.q...}.;.?..C.........h.F.._.zJ2..p...^h.R.kBbW..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1163
                  Entropy (8bit):7.791115859745525
                  Encrypted:false
                  SSDEEP:24:drHR+b0gvnvH3+0Mxh5DFu58UQ1mP1whxoXZ9vwb9K9sph9F+TslXxqCNq040qYE:hun/3pYRCluyDwhDD+kRNquqYE
                  MD5:F8B408779A573561CFCC47AE151D5C75
                  SHA1:46A5126A84EE100A6B080504F75F0B439383C8B3
                  SHA-256:3B5CF68AC97F02043A66E1F6B92D8A868524E8C44E2668DC2090C7849762E5AE
                  SHA-512:572434EE13C6FEB87813CD0BB09F2B77477DB675E23A7ABDCF1F026CF78B12A80B457989C6B73604577FE81C3FC8E6BF3786EFF0D553E789CB02529BE9BDFC30
                  Malicious:false
                  Preview:..&4........K.y.X.I.K.e.%md.7..:...E...F(.....,{Rz....c..Jb..A..B....c0...[....%.fk.m&.O.$.....k=...7...Z#....A.s.7.[Y.d.......i....s..2..K<b....'.../.N...#@x.gC..(%.y2h...=.em.\..`V....4..y.m1V.ln.@.\...&j.3'..).8>+alo.1..D..L;sL........h@...K<.#L..8j.v..Q...7).W.u.r.z..mn.s+.N.w^....m..@..D.1\......[7.6..m.KmUD...%.Ei!.q...hk..B.E....Y.l^....7.%.;.t..[....x.I....6TG\.......<...7^{......e..Q..$i....g.4.....a.Qie~.e'..^...!..V/.....[h@W.ho./z..l?q.....L......?C.:Y..|>.)...1.q..|..Z8.5...7H.....z.....@D?.p#..W..R.bu....^.X............c......hXf|.RK.O.9..a..W.[...z.....c..D..?.LT..R&......T]Y..KQ..I.r.B.....k..f7`....D.L..S...;../#...d.=.>L4....A..Sac...|W:6.....^G........]p..f....;g.......:..F.....*....D.;%.....|u1..:.2w..n...T.8+q........d..\.o..f.K...N.&..`....T3r.|.........C.I.:..]P.@.x.....VH..x..._.'9..C.`.a.p.G...g.3.B_.p.....Co$r.-.P)..l.N........... .WP...Ey[...V...YDh...`K..&.#$F.OV.I88......V......kb.T..1.5,].^.\P.*..C...TH..9......{.JSs..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1095
                  Entropy (8bit):7.788652480775768
                  Encrypted:false
                  SSDEEP:24:nKj2Q0OEiUke536/kKl72y8J4z62Ipy9I6nt2DQ0O0cP8VFgJ+bC7:nKa7OEiUke165l72y8I+y9IvDQ0UUngP
                  MD5:FDA634A858D7F515F0C06AE43857A1FE
                  SHA1:95D9287BA8AF5C45587CF8F4B2C2367CEEFC4973
                  SHA-256:09DB6EB102BA39FCDA122551A8708BCB9FD24381912D2773F0C9927D35E34FA3
                  SHA-512:1C2B04F733D798C4E3F23776EA89692582E558E3F338051584AEB192DA2C03A80EF62F583A8F730C6CDD4C5C6B722E986FFE5DFC12FFC8E7EA67B8CC3709F944
                  Malicious:false
                  Preview::=...I (..[.!...{.6 ..B....G.....Uk..Lgf.8..,...&..j..yZ\.=..UY...^%..X...02.'&R..k-0...!m>.'a...>H.!0..O.|.......{.Ah..O.)....*w.g..~D..Ft.P....E.....C.....=]N.k..XY..../8..3....h..l.G...t....S:.....k\.xb...>...^O.z|.T|.U..Y..@..6..,..^.;I....>./..U4z.A..q.t...............[..P.`.....-...~.6..K.J..:.A...K.87741.....Y.ma(........$.*Y..54'.I.?...f.....31.....R.>1e.......fg..sF9....Pa.e.|7S.........rp...93....H...J/..d"!.......@...v.C..G.5....}.z.U._........N.\..s.I.<}R....,u.l..|e..z.........**.2....l..!*d.O'.....l..(63)Wv)..A....T..&.m.....6..].w.x....g......\. WA.uG...$'......+.......Z.,.&.u.........U.u....Q.UK.;.v...Bi..v.'...3.......$.J).g.o.....4^..zX/..(.2.&dN5<m..a....'4C.:............;Vo.=P|Qu.:.K.)v9..Bh|O.&..H.....!.s...]v"z.?.KW..R..6u....hE.\$h..$...../...=.....Rp......P.g...}......D;.0..+LV];.]P...l..exgJ.tr\.>.\....,.....wn......X...b...Y...^'.'.\..........2..~-......h....B....nK...J?...A.l..JA..BZa...WV..O..y..v^T..<#.6.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):986
                  Entropy (8bit):7.730440924563048
                  Encrypted:false
                  SSDEEP:24:kxd0jbEblthbuFk847Eb1jwoNaQgD4DgADIGO0TsS6HH:kxGIxDoLc/E8iTsHH
                  MD5:FBFC1981778D42974ED1A984F44A1C11
                  SHA1:23E8B223A4B228EF88396A4547BFC4526BB4F2E9
                  SHA-256:8F732EB6B76B8158DCD0BCA94AA715549673E3962FFE20489C01765D065629B1
                  SHA-512:28A10E2B392711DBCADCB9C7934C6EF0A62C2EADDB2BC631BD5858E589AC420D1AEF456D466C536AEF403FA55B52915A4C3F1615B1F29A73A6223CC4D03B6BD9
                  Malicious:false
                  Preview:.:.g.\'.3K.gU ..&.t...|.....A=<....7b1\...P.0T..B"y &v....s.(X....T.ry.z.......r5$.....Am..:...!S.t..n..p.......C....$c..T.h.K..../d..w...>I..(.f7.a....J..>..1....Bxe|Y......q..."..m..3.f....:..J.Y.. .GdKB.....r..;...k.S../.~r.Z5.3.........p#m..4.]}k....~g.YFX..e.I..zq.rN...&.X.u....0../....L....Z=5.T>.._.*.....M<..J....$....0)U.....I..#L.....Gg..$.j.8.`...l.\.G...S.AY......_)B..(xh.g.!.&3....|...5..o.]-..,.-wW%s... ....._..9^:...M2....6P'N...\..O..]..z.....T..F..xO.hU1W=........nHA?.L.p.`...V...e:..S".~.L..@.K.....4......W....s.V..J..S..nR.......*...)._U...w.....o=.B...XI5.u..F....U.&.h}.SH....-k6..<|.[l.K..IP6f.......z[.$.-*y..=.....#.><5*q..K.X.%...h...8..d..s...Cu}].Nxhs.g..7.mw..e.H?."...=.+..Q".p.d"....:.H.:(l.(...iV.;K..p=.....dl..,........(..t..QX.Y.....q:.......v.[...k.V..(.((v@.w[l|%+V.N.XL9.r..L.....+..Tg...d.XUC..:..........>...A..Zl...x...l {...H.zD..a.L.#.......)...N.^.2.........:...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1730
                  Entropy (8bit):7.870570868946322
                  Encrypted:false
                  SSDEEP:48:BlsbRyE5dOhdVY2wSrasimzd7a1ZIO5zVS6u:BlsZoVvra+ZazI6A6
                  MD5:61B4878B91C111D6D54A0A3376F7E32A
                  SHA1:85858E2207AA563134207CC3D39B86D350F4E8B6
                  SHA-256:D9A3058CA972211F8476C18FE6612EB38F39A706DC8A50112A42C2ED4BDAF6BD
                  SHA-512:500CCB51E24019900004DFE96512402AD66C86C23AEA056638B0944F5FCC2DF554109A239C9DAADDC2D873CF32CB7BF75E15F4AEF1270B4D0AC69229160D6A8C
                  Malicious:false
                  Preview:......s..n}.3.......g.i..a...w..../G.{?x).Kc..J0.]kB.[.......6T.J....{....\.Y.hv|_...w..P}....r..h...2Lc..e.1.B,..=. H .....}......8m3.........-9<.....4..@..x.U....i}_.]'../..g....X.56.....N..4.".}..0.....i=....*.......G..1...]{..1.ML8[?...o...v....Ju....rA......a_..y.f......i.i....T..M.I..%n...d.1z.(o...|...!.V=.n@...<...F9s}....b.IXs.H.1\r.p?)...&..p..B,...*..>"=uJ.#..9.... ......|2.I.TxV..q....O.G.e?.. .Xy.9..&....B#...V....$.........4.KUILv.S.Q...+K...B.I1....,..U....G..f.^q..]t.(...m]N_.. ....{.A..Ru.....i..!<..S...B.W....P..0i.V.`7...!....".Y..2.z....v..o..a*.3.E...-\.y.......6*.....6......I..S..T`R.%..D.....o.T3......X.'Sv...l...q..o.u.`..D.10...^.B...h.w...l.B;.j..v........P...J.].........BW.1.a.1._i.W^3...3.....q.v7y..G..kG.@>...lt.v.<..a.....7 .....P#.Q...Z.G....d......O.4.#...#..#H.'.....l&..%&......m........j&.yY..)}.,..N...!B.z.]..i.s~.Ym.I..f..&.$*;..:.[.M....T....@.UN..Y.G.....L.O.L.]J.+..."...U...T|7...>.}.....Sx
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1523
                  Entropy (8bit):7.838122073283172
                  Encrypted:false
                  SSDEEP:24:LVZq7XzHdt3SCGWSfwHmbi45Xen/7iV4fqBgRS+GtCynHQkms5sC88K/+a2+mOrN:5ZCsxQiV4HGEyn/vO+a2+7JPw+
                  MD5:E73FCC84D98AC43EB49867B675149C8F
                  SHA1:50ED540C340E768F3529955BF90E1B734688DB52
                  SHA-256:4B13D0843868733E5FD5E28D7A95497961EF51B215C881DCDE9C4067B0FC57D3
                  SHA-512:10CC864F43645A92C044401D6276FC2F4C8C291288301C4A3B3C869CD666B77782D6F23CEDC23BC08A68FD15BD6E3BDAC4CC15517DABF9F682F490014B439D69
                  Malicious:false
                  Preview:>.P....."...k|@.`2[[V.d*iV...p..s.+0.......$..b...fB?.M.........9O]..o.......Yf..o...Y..Jd..J..{H........\V.2...m.8.hu8....Y....&r...v.\m............0..J.Fj;..W.C.@-.d....L.E..+....E#.Q'Vc~[{.2...X....4V.ie.v.mu-.7..q....V.......9..o,....qXz....h.w..A...8..D.#H4}.._g..4}.........gX..*./M.<.3...RB.F.//..R...{.~..X.p.M.kU.2x...qRaLw.J:.q.4g.=_..E.Y_...!. .<{..-.X.-...6..TH.xF....z.2..6. ....M.B.o..P#&.N.b...(.....1...X.}..Bj...9+...xd}}#...*../Y...$.....;5.".1L.u..Tzx2..DII.....w./.C.t.+...0.y.....v.~.S..w.!.`..].m. .Cx..n.`.0Fc..Z.6...4.9.r......2..y<JS....._:.(..Q...........r...M.;..\.+.H.g......5..j..<...`.\Y.].@.(....q..wz......PQ..>x./.|3........5..B....=X..1b.G.D..6>_...........M.z.0.91.9....V...W..$n*.=.yg:}....I...s./6..w..^=j.L.......L.;.;#......m..Ar'....CfK.RY.........Q._...i.."..P.P..H..<W.I.M!YK.{..A..Tf{'Q.`3....M2].:..3.......{.(|M7'.O..zoX/...].3.F.w.>.b.....?_:f.pj.F..._._................w.<.}.F.............%UR..~x..=..Ux..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2862
                  Entropy (8bit):7.922305620366271
                  Encrypted:false
                  SSDEEP:48:cSM2Ui+bIUTRZ4Qd7hRy1SddD3zf29Ujaqrn0e5EUFkt2Omn6Iva4wBLYSh2OhiI:OMUT8QR3gSdd7zOG3rnJ5FFc2OTIy4wv
                  MD5:5A9905755062564B77052DDB5DAD333F
                  SHA1:9A9FFC48CDADA78569AC118176F12F6DF0FF663E
                  SHA-256:8B15A086E4CBCA1D10B82136BE229C2DB2BA11F4C79C07357A5B1FE370C15110
                  SHA-512:76D36E49A6EB4C4E502BAD992F2745416A4C1E6356F712068CD910844D68BE101E65B0AC55076982E704DC870C4EE82B0FB8C557998698B5DD06BE1FDB2354A4
                  Malicious:false
                  Preview:.....z..^...$Y.].*6.+.. .6.]K..f....:...)P....L.B...v..i.oa..FE..F*y...k.....9.4..*..;...ru.#../.=....#T..S...>..[k]b.u...}.o......7o &N^..x!5..p.C....Hl.HC.i.....,.7.h&.(....L.....X.aOsx...$....Lca....>....;..^..+?`..oaO.i.k..!.....=.....j.^..UO..n..Et...&.........oZ....R.D...7.[.x..9.2...j&..&[xu..6.f.!.....f..95=O...rD..q?...Sl.6m..%.n..pl.J.W.........G^$|..dM.D.~J...*....9.J..&(.M..mY...2[.e.@>R).M.U...l....(>...QW/..J...i..L4......j.@"S-v3..W}...oT.ad.K...Hn..V...r.m.d)1Y,...^..9..}.v...M9..........].<2.4Ph.zT1..3=.$..a.T=e...(},.."Sv.d.....r.?<&}....;.h..%.Y.i.......0O.....l...._:G [Rs...X...z.!...k.~....YF.}.i&,....]L\......8....$..S1.....*....<_p.<S...}....>+.............j....^...".-.je.t..s.Q...s...|P.c./.d.......E.l.Z..(......8..u...OK.q.5.&M.....".=L...".?r.R.t.b.}.dnD......ql#...z..o..`...s.@..D..pc..#......td...4..]...F3z,.wu3.eF..p..~.T.@.9rM......*.x....]2a. ...R...........u..l......Q...d.f.q.%..G..&.G._`|..j9..bQ(5......<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):386719
                  Entropy (8bit):7.999450948708111
                  Encrypted:true
                  SSDEEP:6144:z1nRt74YfP8uhjLCqB/J/L038C5T0D+Kk1WpsVBu62imrROxvl:1jj8HE/l68CZpKuWWV460Rq
                  MD5:8E41D4D354DB4CDD0E03288E34CAA49C
                  SHA1:EE0E1406B4F4A825FC12DA0CC7A29577FBCAA382
                  SHA-256:69122C82AE223E67CAE428B7A6753FAC221BED470F3DAB10BD40E865597B9052
                  SHA-512:E4821B02CD1144A77CD27E97F635F68451EDFD81D1A992F574C7C71C4B517A0FB0AFF6380984A9CE22D0257C88AB6E5EC5041610F4DA01C07A8D114085E8110F
                  Malicious:true
                  Preview:.....&..U........l.F.....?..>...3S.f;IT.^...g..2..W...DN...<2w...H..c....A{\..>.....+5'!+...%.?@..c.G......1.D..........A.pp.O.I.i.S.h....Z.g2.......N.D..H..A...(.........y.n........../..J..Cz:..X.b5........zd/]E6:...."......U.f....F`.(._d...F......O.T..2....<...,U.w.Q.M...|.A.2B?2nx.........?..s@.....7..F.!(.p.k.m..\.lI.F....@.!...R/.zn..d'..i..G.4..c..$31.#.d.k*.N..J..f......9...E...j.M4....k+.Me.A.mw...Gy.g..L..v.-@..)u..{.MN..\..F!YMK.[o.k.'H.9.2@.k.&....:..`...n&...SX9....D.Y..C...l.k.....F....RE<....2..E.n...h...A....|.P.B...vl.E.o.:;.:.2m..-p.4.JMb.zJ...............Z.O../.._*)...=..u.:$_nJz.TEu...!.....U0..2.b...T...Z..X.".f.e.^.+..C.....8...h......./Yt....>.G.`q.3+*...[.....Q(sm...d.l..I...!..9v...xO.s..U.q........f..6.J./2~A.........!|..G].m..&."..z..E..#.C..)..QY.f_.....{&...+C.P....:"H..K\..)l.t...l.f.V...t..o.S.w...xN|.........:... .=]`n`.....o.I^.7>....G..6..bYI..1..2...r..a3n...*...~.....3;\2.6yz.S.C.{p.U..P.S..*.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):20589
                  Entropy (8bit):7.99179144584
                  Encrypted:true
                  SSDEEP:384:eGcc5USVugFXzWAPDjLViUAHmLo26X7YHGPbS4tbMHM:H5BVXFXiAPpiLmmX7YkSa
                  MD5:268F729109F9417EB04375FED83F27B6
                  SHA1:BB9D934C5CF090198847B7B6708C08F3D5F1C478
                  SHA-256:ADD754F793A85B2668A5512B9572768D41B6FE471F30E8118C85202E0DEC0AB4
                  SHA-512:8829B71DDF849BD52C14358A2AB5D909A1E2DC2DC6FF368CDCF7DD5B1FC874F0453DC0FFA13858735B1701434A51728A30004E62C15874D23098E982465C913B
                  Malicious:true
                  Preview:.Qg.i.E..`.r.]...p.pj..g..H....5.J.nh..)....q..d.......eQy0.+;D.....y1..Y.gVU k.[.O.........G..'.SV6'X...g..}2;].[..=...N....U.<.B....".../...t...w..........Zg.....W......8.*...kx....C..P.uG.[..yj...L..h!...0eOWg#.Z.}......H0c; .H.A7.>..].."Bh..*.i.......e...'(n...7..I4.:_DV....q3L..>D6q.b;.Oj.....t8.d.....j."q..3j.....Yzi.f......J.....O^T#.l.J.'...P..00~..S.G).}...JI. ............#...:JU....t;..EA...R..!...(=....p.....mS....&.4...l]}..v...}t...?.....B...-v.(\....k..s.x?..W..s.M,)Y.j|...c.)u.H.q.c.b$_..D....E...nVd..Q|7z..w.....r...zk"................dl..]..M..p......,.x...po'v.\....;.-..Y...f.)-...C..TWl.D.#.../....o.*.8,...\....6).<I.`......{#.l... >..T.{<.=f.....>..12...[.. ...a.....4}u.....N..P...J...@>.....n.*......[...1....Z@..m.9...?......l9X.._..|....:.j..i.|~.'5....3nei..L..8.+.........9.G.n...a......\#r.8..=...==...P..SmY.^....e...r|.....5j.l.......h..y....w...;..F$....+..`...ej.do.:U.........._..,......b...cH;..N.k..R}d.D%..).
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17359
                  Entropy (8bit):7.989112029644661
                  Encrypted:false
                  SSDEEP:384:vvz/n7fdUpQPAZovU93YhxNf5Gh5qjOtRHS//:XnVUpIU93YXVWc4HS/
                  MD5:3C0A020DF091F0DC8AE841F1604B058B
                  SHA1:03F505E8F3A7690DBC0DBFAD43E5B832BEE2545E
                  SHA-256:0C4C7172320DD2F3ACEDE94C565826ECBA982C93DC95CC61DB2435EB6F645563
                  SHA-512:0CBB07EF832ED5B015F94244AC6090FC6B77744D8DDE7993FC2B045BD6AFC455EFA84E6DAE58BDCB54007843268825915A3F999F571F3E63E7AE5483E7B1153B
                  Malicious:false
                  Preview:./c.D.....)A$7=...&}5...vx.s...d.J%f.x....*v. ..*<.......sB...../.:..H+Qo.V...5.x.D..../...Z.5.:e+.#.0l....)....Yg..KBzx.`.aNl....30...U....._..0..#.._..6...X.,.r.1.*....o.[..^....W.}..-..e......Q.v.BjB;...E.....8....X../.I.....}:k.q+..s.XC.p.....q..O...a.7#i._...6...00.piE..\L=T@.B.......C.Ly[..-A.~.q.@......t.$.(....bT=..........Y,.b....~{.`.../...:.....v......2~.'Ux..3.!C....`.......=~e^...U..T.._.r...WW.....?.v]ph.Yj.>x.....s.W.Ga..:......$#......0b...Qz..C-w ..r-S...1~...A.(...Y.s..\)...,O..@.......aS..U.g%.f.c.e.b#\.0./.k.4c{[-Dw.....N.9K].............[ps9....Le...^:C....2 ...SR.]K....zsa....M....n..U..rv...Cp..C}h.5......{..e..5../.......v..y.."....~..m..C.$..1.q..[.......2..5#..F.*...|....E.=.z.....~.%..T.r..&.....R.t..+:.q.5]u?..p&.#.`......=H..........Q........D........B#..F.....N.....c!T-y.....x.[..........b...%I..E...9.u..{B....b6.....t......r%3.....X.y.V...q......wC.....m.z5s.../.s....|.a.....VU..XZ....1.......B.N.R...j...P
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17088
                  Entropy (8bit):7.988101401257545
                  Encrypted:false
                  SSDEEP:384:Hx5uikVujTySv2j1MwjWJHMoQ5usakpyWSrt8rIxJVIA:Hx5uvOpCjWJHMx8saKyfWIbL
                  MD5:925C1D2BEBA7BE720A0E075C1FEDC76E
                  SHA1:097A49196217673B6C4A295F33C96B13287EA74E
                  SHA-256:119E6A2346E5C9668114A721E875934A3786776BD557D118C3FC5ECABAB55E79
                  SHA-512:C410CE10F05211BC4FFDC7E99FBE2F1107E720BFC857D726D09D38F838B9D09821E93195DEE54146335B013C6B695169A769AB5060193B13103762C6FCBC03FE
                  Malicious:false
                  Preview:&ij].v.%...Ip...5l.\.B.7|..W/.y.Sp.hC...zo.Z...sg....._)..C..y.....o"I....z.../.0oc;..f....6r.:.Y.....M..o1.....@.b,....3.:..;....!....&.A.v.7..K../%..^z.*.pN.j.A}.m..q./.0.:.y......gq...gU5.B....N.......pC;u.7.....q.;......B.W..u.:...d..{....H...}...RQ&G.........-...}.xl.........>p. Jt'9 ....*7qG*.u..3.$G..hg.X......wE.i....qt3..O..0L.\4G..f.....F}.#...Ey..5.....Z.z...B.pa..3;.sL1.j'.....b2.k..*3%..\.]:k...?Z._...v...n.j../...1.Y...0'.~W.......=.|_.V..'.>.C.... in..B@..<f.....|..bs-[...Y.q.+>.......d.k.I..@.J.8......F.h[.............#8.....Je..'.,1J.....('..y _Y.@6E..P^G.5..Q..l.M...9<.{^.]..$.FE|F..B....j.}.....4i.C..Y../...y.h=..i.T`...]..H..7.B.p..3...y..}9gYTAun......k)|w...k..~.....mwq.G.%..d9........30*p.xv...n..s.+....H[+.F..}..s..G.4.]...(L..R...'9?..dp.{.... w. .K..s..r.]...."N....$...Ix3...N..#......sP.+E.].m,.=W..-[5oI.G......l.6>5..L@pXJ......sLe.2.}..''..e8..t.x......*f,.C.i*Q.9......G2....7.Y[.3.cd.|.....{?..E...K...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:Dyalog APL version -32.58
                  Category:dropped
                  Size (bytes):15611
                  Entropy (8bit):7.987845936058046
                  Encrypted:false
                  SSDEEP:384:3YIJHSn5Ikoax89E7NuG0Stu2ZeRNLz/YZO:3YIRDk7x89uNzZOLbYZO
                  MD5:9FC67025EA3D9F8FD105C752676A313F
                  SHA1:E9A6D72C921B6F22942C703257855F2A6788FF57
                  SHA-256:85EBDA7B71137327484BC96B9FCE7BB850E4E937E53B6D9018B7CD1C54CEF506
                  SHA-512:EDFB834228EC22ECF257B3801D5783D84831C8BFA0A0DCD39B38651866BD7CB0F27981D12D6C39B8F1957A265D4D1DC6F39A000B7EC94A357CC0BC8EEEE7035A
                  Malicious:false
                  Preview:...:.nQ..2J.P......~.$.XyY..z..@.....:C......L_K....<D`3...\|{.3..Ho...;.C.t..4.......6.=!....6.A.......*r1.,.......U.R....tx...5...j...[\.?.}.....GeA....5W$bK..TbG.y......Y[.tA.c.J.JR.N>...=......Xi.2qL.6.....:.EF....8.V$%g../C....c$U.".%.;...qT...{..:.=..].(...?..5u.?.............U.$...w..4....2[...h.C7.;ft.U...)f...c.:J.c.^......U.GK.c0.j3D0...EnB....'.Q.JE..M..Q~....;......&:80E.;.B..njv..,..i..i...xD..8.V..0.PLS...'d.=q.N=.n{.z+0'.^.&..oD...l...(.i?..&..m..1.5....c.).v...W#..4...^.x&........0...C g.......W..@..)K...X..c;...g....z..j.G..80...G....Z%.....E..?PHY...#^.1.....o..i....w..1V..tfT..$R.v..2z)>.<.hc.ZV2....\<..!(....)o%a....+.aj...m|0.B..h.LJ...>.Wvh3Z..%.|...y.k.fjgk..Q....=|Nk.....?[.{o....*^T..-WW.=U..kq. ...&.X.-<'f.j.....:+=...H>.2..B.Wy.d8.}.>........A.\p.N..6f.9O...%.e/[6U6.A.-.8...#......5.1.a...z..{....5...fz.+...Nz..g|.....\._9...6.E.o@.[...gE..z7S^....m....h..(.RS..{.).....a...XVrI.9.b..&G..>.........yMfI[i.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17907
                  Entropy (8bit):7.989798609738316
                  Encrypted:false
                  SSDEEP:384:/BgLnF9Vqyc3hwbEpQ0k5RZ4p2YptqmZS4r:Zg7F9VqnhlNkfR+9ZS2
                  MD5:3028E6E3D864A4786D646608A3A70518
                  SHA1:7D8B4E558111B91AF0E4E2C8998D73513FB22009
                  SHA-256:F9D758F301F0D9C792B34ABD2753327687BB4BF8DC43990933C6CBF7699E95AB
                  SHA-512:94ACE4B09E23D3372CB1E96362471CB71CDCE098CF985C8CAA443D50E0E58F66ACD942215A4266B783E414B6446619715667E0847EFF94BC6ADFEE77C3911F91
                  Malicious:false
                  Preview:s.$.y..03Q...J.......a....l.y..-....X.&....Z[...}7.y..e.4.i.......B.....14.o...#...m/Z*:vt...(I~..G..s...v&..h.q.q.5.Z.\......xi..R.(..d....#.B.p..j.2.`...!...r.D.Z._.7.L..T..Xqxa.$.[.g..\.G..Y&.J...6.7........9.t.1<..........R.:s.....}q'K....s.....G..c..c.....,.~K.....k......m.3Pr....o.\...&u=\@.....6:...2+0.A.....(...0.......h.C......(......?v.......\D.%<...V.9..;......Oq.y.'../..P:h..D.Z....Oa_g$K....T\`.A.........O>}.:.&...>.7o...ac..b..bP!~4.....!..V(....g.rj...?#.....b......0P..e.....XK.B.....#.).....w*.j.\Z..-.2U....z......u..-....`b/+@m.I.!RZ.:.F,=..........{..n.D.U..0...7..e.L.0.....b...v..noL5..c...h; ...,.........-...l...D.|...........o.t...Rq..!P...4n|.....@.cS..YjS..x......Q.....a........H.Dx.....e...8BN<.*.h.M`.$..7E.]i.O_....,...5...d?:$.;t.E.......H.H.._4...C...+........Yg.1..|'..^EK<..E.%wf.^.s...&...3..d.j..b^....S..,B.@.J.4?......"%..`.l7t..*.._....cn,pUQ..ET.jb.....6.f.%.iT.|8...p.E@.V..Xe.E.jb.$E.#Q..!.:Hv/...T.^
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15205
                  Entropy (8bit):7.987106947958653
                  Encrypted:false
                  SSDEEP:384:xFfBEIy28hAxGLMMVkkWR2xloT0Xa10ffwavhb53te48hzo0L+xEirn:HfeIB8hUGXVzu2xm8WlavhVdMhzDixEo
                  MD5:BAF73C9F8D2A6077B185C7466CF17313
                  SHA1:9023B01DF3AA390D884C1AF064B2369157070E81
                  SHA-256:E075536702B9E3C970B5B6A5691447DC6D81C3C8CE0034393E6949F39C26E9BB
                  SHA-512:1AE7B0D0CD24128294638F7CBDBAA6FA99CB705C7C8B0EE998F238E19BD7620CF1B76788D3DEDFC3B19A3E64E900D57EF11642F391DD1C8F49CBE3D521D066D4
                  Malicious:false
                  Preview:........JD.....].#.a.HK.!.h..j;b....7.5.^@j..R..{d.......[....*..F.M...L7[.#...?..TK...C.(s....Z...f.Ee.ey....M...<,.H,...+..Z...p....5...g.LK.........,..%..DX.l...y.Y-6'B......f.c.....Qn..]+I.[.^..t............a....]V..Z<p..?.qz....|.8.L.\2.HR).OX...k..<rM5J.d...;....(R.#Fo...#m@.4..-..5S7.0.N...%U6.Q..o......FR....4d!......"5..vHu.J..2~.f...C...x..F(.\}.....C.q..........T......_o}O.,....|...d.6P.r.G..[2K.]G.s.ka.$./..C.....U.eF.....im....7...+q..x._.-.r..m.TD..3..Z.....Y.1.G.v..2.7qA1E..2>......P..`..J.jh*#..H.k.7..E.Udr.4... h..xGI7...t..o1@J'.....#....P$e..a..=.H.....Z.r.l...Kx......D9#....+..(......$..p.K.=....hR. .L...(....8.....pw.y.x..0.^...>d.]L9......\6..B...`.r..c...U.5#.......P@(..T....35.U..p.(O.B:H.....>......ts.R...e).Fn.$C.....G./......g.....''44Mc.?....v.>.........r....(..o'.3.8V}..&*.'...^-@....";.. ....b.Kft....1..=).\.{..@0h..,B...i....1..dE.r.....8.{......\o..q..k.O7...?.f...}a..fe.g....ss..O53.tg.I........01..d_.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10536
                  Entropy (8bit):7.981555145249528
                  Encrypted:false
                  SSDEEP:192:9Er6Uj8cz1xcWH6k+X6dV+jNGUF4Yd6DYed7Ssjdql42l6hXyb7R6x24/N5sxXW:9ijh1GWH6jX+EjR4Yd6DZd+spY42l6db
                  MD5:0ABB214113BA79FA868F85212A0312D4
                  SHA1:1C90FA1BD71AB6EB086AD4DFBEF69617EFDF8005
                  SHA-256:9FEFFF8717402E9F3D26C8E4D13B94432A7E8747118946BC448E6E43914E77C2
                  SHA-512:805FC3BA11B1777C9330BB28F95C9E3D7B10365C6E97A896F33728EE8924D727FA4FCD9EDD50CFCA4EA213D03840ACB3CEEBC2224EBCF61DBBE10E2A6CDFF957
                  Malicious:false
                  Preview:...{V'<!*O.&..$.(...z..n_C....)...$I..F...Py.G.V....oH.p'...=..t...R..+.P-..N...S..C......%.6.R.8..........Jd).2.L.<..<l..H}3!..G.d....NO.......6|.u....o....!.'.q.b`B.3..e.T...).\+.E.=.8..i=...33..}4...du.I.SZ\.~..F\.....P.Su.DU.,..<2J@+h..w.F......O.[=p*=C...& .Q|x..*..3\<.2..W..N.N...O.?.uX%k.E.\[b...S....8Oa.I...,T.........0rpK.....#.w.. Mt.j...4S.0V.c.M...Y....6.Q..lU...]X...R.bL...+?.3!\..'..%..iS..e.an...*..0.z......%.h..D.....T...5.(..+`.l8.\....=.........ysS....2T}.1^ .p...IR....\..1R>P\.>..>G...R....B.}........VFx..n./V.e0..K...7<...J'j...h $...3.U.....I".}..\a.......g{y@.......y8^.n.bwF"...g@`...(.L.....UY....I_.... l..a...1..0.mx...v"k.}...<)%.MK..k.l!..,x...o:*...$.\.Q'2.L7..32.U....!....@m...H.I..(._TF...]).!.k.H.....^x...i..Z.":.p..?C|....,U*.FK..)`.v"k:.E5.TO.$x.....?..'..};.@.p.3...0H.Z!.F#.p|..5.#.(..........%*.......Y.<.S...4.a.{.....+e.l.5.......$WGH6......!.q?..O.{u8I....x-.1..6..k.R....`.3..~FX%.5.@=Q..w..Y#.....p. .
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15205
                  Entropy (8bit):7.989030899744442
                  Encrypted:false
                  SSDEEP:384:RbuuH4LIkxoPE2bx8qXB/tfiOAuRFR5XOop:duu+OPf1zBH9Oop
                  MD5:694B150B24268ED5C9E17640F14BCD99
                  SHA1:16CFEF2ACC95EB63DAD2CC08DB1A7080B79384EB
                  SHA-256:048B18F728531FD7E9CA779F605CFA1B376B1783A0366701276826E0636A7086
                  SHA-512:4C207468433B6B3B90CF6EE5F2A5A2CC8E16C214BA6FB535272EE95F00DE775E3A4800717A082F0A2F57C4AC10E45F7EB567AD1747E27C735B104EDB716EFAA2
                  Malicious:false
                  Preview:....r+.h.\.[....i....=.....w.....tC0......9.......\.H..8.~.gt[..lp.s..0..4.......f..QH.RF.uF..k..`....E".p.{.8f...7....v.a.W.C.*..9...........{..F..r.....".(.]6...nk..0.H<&....r...R.d.......^y..9...S.=..A...i....q.G..p.,T.M.!T08...GGJp...o.W.?.P...k.uL..d.A.B.A.....?....4...Mk.../J....@....*.....<c...Z...n........-:.r....o...<...[h...y.Sj#.e.....nyJ@Aq...8..9...+.gDLe#.....:10.w.,..3.9..%G..IZ..K..Q#....W.eU....h.........d;.a....Xu+..S...ges.d......\..}b........$u5=x../.N...'.N....X.5...[m.q(...2b..*n.O.2..._...._k....m".Dl.....t.O\-3../S.{......s.-.G&S.].D...S.eD[..0.M.5......!@H.|a.......8..w?.....:...Xr.U..l...|.h....B~|kT......Z6]2..LO.q...b.%.....>....$-v~....Q....os,.....9{,v.1K....y".dT......\_...N...DF...."b3b[..._..@..`7TT.^.w..SVN.%Cw..Q.q.l5..n..6(...X..N.~..M...C:....@.v=.Y...K..`zh..9...-.;..z.{7....|..;....y.....n..'.^Kp.Jy(5+...n..fZ..J.......n.4.0...3....A6.../%..S.N..&.q.....-.n1NP.V)..6oyj.%%...")$...."uy2.{
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17337
                  Entropy (8bit):7.9895361066334925
                  Encrypted:false
                  SSDEEP:384:Vy42Q6fgZmAn4oizAd2v2NXmJToSVjLGXi64hEQ+1v8pXW:Vyy6E0wCToSVKXDQ+1v
                  MD5:B856469515AD6D6D5F955CD5DE72FD46
                  SHA1:021C7E2C555D71EDDED66907A46F881A7508386B
                  SHA-256:8A75E2DE1139A73178657BD73053936DC41B974C3540E7363877ABEB4E5930BE
                  SHA-512:DAD2F11E9440DC1B1A2018F774CCBAF547979B0B156089925FE7900CFEF3955F239522BB70E2500F8228BC6CBEE79480136A64F804FD7F8F914D6B9360953283
                  Malicious:false
                  Preview:........8X...@].Q....9..<.2.Q.3.......@P..M.,.&.i.....-..L.^6B....."./Ys/......P...24H....vd.84'.3...U...>...uw..._.......U....+......Zf..n..5..u. -/.h%.".<.]oO...#...w.........;.N\|..5b..v.E.4..(".q.G.....f.By...O...o.....$_.M.....4"5sg..!....P.h......{p......`...b.a..T..+..H.r.x.....${..T..G!.......q..&..o>{|......!.m.........>..{.*...S..$.......S.......P.._..F....7..n...;..C.J.-H...W...F]..;...@..,_.>h........8+&..5...E.....j.I.8X..h.....,..0.>........q\`...B.Rj..]x......uD.....Y:.<...1.....p.S!...m`Z.....{.Iq.E.p.nq..A....,...eR.*$.../.&+GZ....dc..d9..?..>..<..ZA...a..FC..z...1.%.`..'.@....+M.U.C.....x'.#..y.g.../......P...........pe..mZ'3....=."|..f.Z.b....vgER'..D.....{....t..To:~.ehT..zK....5%0hJ...GkXE....c......".k...<qA.. U..fD.:.WG.3k..4..}.6.......i...z.......W.Z....h...pz..evmK....... .E..gw..5...v.N.......[.5M.wnx.[m.%......Uc.A!..3.#..g...P.t)..\..f...m.f.S... .y...B..\...id6t.....uO.2.q.q......;.a.".x`mZ.H.}.B1.~.0CK..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17344
                  Entropy (8bit):7.9893194398332765
                  Encrypted:false
                  SSDEEP:384:sQISGE9973eSeySF+GNCgGFPYXfjSGZkJjrTvuOWwwV+pqzH/5:v/BZSF7nTFZSiwwcpEH/
                  MD5:9BD5DAA0E2ADBAEAA7F83E3E3F7848A3
                  SHA1:7C6C550BEFD392EF6AEB223CAB5859A1EB379CC0
                  SHA-256:232FDE6DAABBB25B5ADBA4E0595F5470A310E82FAF4B554B3DC69F911A26DE94
                  SHA-512:8FF096F2A64EBEF84F3B3E931D346A4885C9924C3F8C0F43A0749143EC1DD09FD2B623159606889DBE95A90536486CF5E9ABD1B29FA9307CFF4A08C7E7014F9B
                  Malicious:false
                  Preview:..2N+.t.s..23F..gv...n.%d[...1C....I...9p....j.z...!..b}P..k....n#$..Ud....C.}D1...-E....6T;..o7...p>.....+....}.q....gj..Sg..w...Y...r.t.C..<s.........q(........6.H..*..m.5.......p..*.~-`......."...@(...f.....k.= x.5Q.;._..>..$-S.[..e..B.1..(.V.m.b.0..IV]....O.+.Bf..L..f....:%e>.....L^c.kP....~..>.K...].....1....Y.xw-D.93._....M....$d9...75....E:J.&..Q...{..$p017.rQ..[..s(a.{3.dD...tl...X.....w.L.../..c......~.^.....3.uk 6.......A..A.....]"......m)AS..H....{.......{.r..o..=.h.i.s).{$..<D+:....5...Z.6.>...l..x.].=.}.u.z..o....mU`.q>K.q.`=.>.=..q......Y\.....T..^gcD..w.......;i-H+.........G..k^..}...+D^~t..t...e}..K .'.@.@Ub...R...(7{..K.Q...7y....*$..(.=.55.#.9.?n....I...a.$.U.......5?....=y...[.-I]..;.:..x9...0,Lxt0h..5}..X.&...._I.j..Z.k..!.. 4..6.omk..F(*.\<m....../M.k.<\RL...=D..|C..8..(..f..l....S.."9W}.e..M...].r"..H~n...$.....a..~.......q....U.H..t.c.F.a....X.W.#.u"...}.....]F..f.)H6...:2........ .@'QjZ..Qe....~.s.....8^
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):16706
                  Entropy (8bit):7.9894510707588955
                  Encrypted:false
                  SSDEEP:384:aOZyf0d0M53uZxv9obMwBBHU6w7soeX9WZlcmcGpfDLcQ9YJPTvh:aI60d0Q3Yv9oYkBH2goeX9YWujk
                  MD5:706CC5D8A3B116A13B1ED4B283079519
                  SHA1:21FA0220EC9A6F67F8DB355E935AA4301EBACD35
                  SHA-256:316F66C75E3A994E580C81B7B6133928B957FB11CA360B3B3B854BAAFA694729
                  SHA-512:8B997AFD4016EAFB66432CDDFB875B273E00623ECE95499F861B6A1E7D508FF40D130C9EF38395CF810CE8AD2AAFB299526066AA3E10387EE2F8EF09755D1E1F
                  Malicious:false
                  Preview:..|]c..u..o........<.yFt.".. ..t..=....*...<.W.6.&D..}..j.f+...q~~..j.d..l....p#........'.X...S.4........ebzV...%r..].p..2.-....4e...%L..$P...d....~.\....h....s...M.d.%f:.@r.`...............f..q=.q!.H<.#.Uvn>O.5..U...n|.=....N|.....&.......q......Y..-...!1.}%."...!D..5[nk.)Mqj..ly..9"....8.cM_z.Sja.. uMF.fK...%.....i.c..E.1st....-s9...a..B.}9&....5Z..v..'.`O..;....."......_.\Wj.zN...6..*)Q m...N...j.r.z&Es...W..d.2@.....y.g.....V.j.`...Xu{...o`..4....../e..OT...o`..@F..x.'fG.e..%.H.l.T.)G.g.D.!R.#..Ek.......z...\..J\+.g^"c,...X..mR.`...H.3'........W....<3.i.......UY1....sP...#./.Yw..I.....^jM.Q...1....!.L.K....B.....~..t...*.Ku$.5..p?Z.3..7.{......*x..Y@....mg....3{nv.C..V.Q...{C'C=.[..E..C.s.~.5..Y...M..(.....l]<..S......>.a.....K.....'cH ._..y....a].o|{.Ey...H@.....,vo4Gi'x~m....qB..7;..;VDh...3...f!...+/...9.d4YO.Z).@.6..pV.:vH...0k...ri[u..l..;.....L.<...A".......K2.....1..B...i}Wc.....|.K.,...v."phf......N&.K..W....lE...../zL.....}..f
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17777
                  Entropy (8bit):7.989388332702268
                  Encrypted:false
                  SSDEEP:384:5ryyhVJnoyw09ULNVor/2X+JG0Xj7XXvorZjidXbME2+2NB7:Ey3JnoyHUUr/2XyGUX/uIlX2+2D7
                  MD5:0A42450186BEC52A75AF6AF24ABFC551
                  SHA1:8AEFFA0D8B66EF6215796B2C004596B1B931586C
                  SHA-256:5B7DAA038735149008EEC46F3C32030185FD32CC2E532F74EC08D5E0BE1DDB52
                  SHA-512:5A7F9F62A0A82ADEF9A790CB11B68B8C2AE18F541BFF73EFBCEF9D73928D31CD1148F7E70A0F6C44C561EAFB168DA651E840DCC4F761C66166761A1DD9E4E963
                  Malicious:false
                  Preview:b...@P.os.~$.dW....4.5....\...{g.E.;..$zB.=^....../...@.\Q..5Oe.Y>.M....X.J9.o.}.C.3.....I...@.8.p.*/R.&.....e&...CK/...8..$....j.6....t.&.3z..U...o.sk.b...6...i.xW..q..s..+..]FV.:y.w.'.Vz.}.Q..#.7.Ft..5...&b.f..&....D..EQ?.5.}...M..p.-..Q.....7.0.v._g.4(..j...O.....t8X...2\.j..Q5.7.H..#...s.18.|..O.D..G..l....P..eoY4....:X...4. ...f.....(0...4...M......-.sp.....|e...1T.p).s..r0.HZ........\...t}."v<0q.....;.ci...yJ..m.}?n.....{+-.p...*.3%..).....nJ.....-.........W..>......,...Y....SQ......4.B.....4..6r."bG"k+.Q.z..Y....P@.......e..."^..D....?..>...y..S#..b..^.8u..z.Y.j.R .C*..+.R.++].....NU8.W.6~..[#..d.........).a..V<..A.#.'uu.d...........Q'/i..2oA..{.m.7B..S.D.W.n.d..........l..b..4..V[...."Ez...4."R...=.@L.g...'J.d6....J....u1.H.$Y..GT..5Z.. .w....].d{OU.....q.[.C|..%l...8.g..K^.....9...j1..'j......v.?.B.@mQ..|.....H.........].1I. ...(.G....U.....X_e.J..VK.|..............4..y..}y.T?[..\7#gO..V.k=..N3-8..W.>.M.$^..2..3....,....)..}....K.MV..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17777
                  Entropy (8bit):7.989905954157006
                  Encrypted:false
                  SSDEEP:384:MVgJDSodpifpEGW2JcEd23bZig1QbY+irSicH8NdfwMjq3M/:DSoDifpBJcbw04pirSicHmwRc
                  MD5:CAE83FA53BAABC5F16ABB43F4D2C19F5
                  SHA1:F393AEAA74D1EBD500BA8629B13D0E066B8FD23A
                  SHA-256:B960C7FA7AFC50B765D80B460A052DFA4C977A3E0CB165598B2E4860CE00FA1B
                  SHA-512:133EEF805DC8B9B449D86C0835C09F708016BE4FD9A731B2F3AA4FA98A112C9F39E225BCC79C2DC61E8C1B2933F44543A28DCECBD12CE8F59D00224D91A27FA9
                  Malicious:false
                  Preview:...}..D.......d1.'c.Gy.q~.th.K.'..D..[.1.4'S...k.m.P.'z..c.7Id-.I..\.`..W.R...W..........).v.[...8.Q.DL...............]*.5!.^n.eh......P..|".t..G..1|.....4<.^...L..N!W...Or..@.......E$.."<."..t..;...2G\[.}.=.............&. .KV......l.....&......p.x.=C......uo.p]....Y..o....b.;T.g...7.$...h..E......8.$.........7O.L..A.a..<..'}.9...J..K..Zl..fCC.[.~1I...F_+K../t4..a...t..8.3Y.gp.;f.>dA...Q.~..h:&.T.&..N..w.~.p.w...,.!.....?A..%.Ln.)?...s..n.=.B.sEA..tJr8P\....r..e.O...?^V....h_Q.e..>.x...^.X...."8d4....!h.n.....t.9.Y3"........g.S..e.<=.=,......E..X\t..:7...E..-...~~.....Q.o...@.!4C.J.cP(.3p}...-._...B.e...5`..L......Re.....c.2.|..5.x.F.\...B.&V.O.v...c...H......-..ap..7..f....l%......J.j.N8/.g../.3....&.~.N....s.#....R.=....T.[..&...x.....k!..Y..2..^+.~.f..8.7_$.g.$.k..8..x..5~...M=..{.z.?.y.0..oG3J.....2.4~UQ.d.K..x..D.....Dw....`.R..8..B.e&S... .-.o.6O......W..l...C.~.<a}x........)."...}.#..6n.8..H#Xj....'D#.iPhj..f`.u{6
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):16644
                  Entropy (8bit):7.987591829118149
                  Encrypted:false
                  SSDEEP:384:DR7OSiN9SbDcWN1at+YoF1Px/mIENzuCaNtPlxkoq/0oGZkyScnd8:DRKSiN87NSoXPvcLa7rhqT2kyScd
                  MD5:2470D0F14FBD2AA324CC5FE47DC273E0
                  SHA1:1A2561536742C563E32929C2630C7B539AAB5A7F
                  SHA-256:317A9DD6AAF62536D0B712A5B53F80296038D57671FB50F2A770C989A7D6F3C0
                  SHA-512:173686AF2617F79BDF8254661C9701A0FC9602AD24A7CA5C4931FBEBDB0FBC09A33EF058B53A1EC0F13016F0EE8CD42688BAE42A6074962A1D4FA14B039E2B34
                  Malicious:false
                  Preview:.l.n..l......i....<.1.bU...D.wcg,......4.....Z.){_....0,.Q.S..=9'...K....j E.w}...r..B!....-..y.*..d.....&.....#.a..e}6.XwP ....{7.Z1,W.N....[.mrC_..C.<=$....4...)....@.?~..n`....3Xk.P.G.;..O.JU..... F3...>.D9.6R..k..s...(#G....Aa....9..........l..e#..I@.~.n}..k...d..Nx.7^.<.\q..u,.j...M.......X....91I..kr{ ..".<.....e|......jb..-..'=....#A\...F.......\D....PG.8{......LW........=...~j9.a.^.[[....{.......e..k,..>C..J..|.}....PB.w.s=.i;.....|a.g.=U.8f....p9V.....q...G#........E..?.......]O^O........./.F.Q|j..@..?..fs.....~0.....y..........%i.:.s..&fQ^uX.p^..z.u.n'R...g...l,-F.`...#N"P(I...P.hlp..........".V.g.^hl...w."'u.W&..cB.....P,...~r...)..w..Kta......%V..?.N.-.S..Z\'r.|.O*.W....=q+kVp..&)G.<.;.........x...P.>.j..~SN....|.Q...k........e.cX...zi..PC.a."(Hm....,.q..{O.8.F.L>..:..k...}).......B...%.....z...<.o:.\._........Z..%i....A..2H.D...fK...\......\0>.F.Ta..#...%...G.2..1.=....7.=...,....{.(.....8.c.5..o...N.V..(.d%\.>8....T.s...*.<..b.v...._..f
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17359
                  Entropy (8bit):7.989353824791723
                  Encrypted:false
                  SSDEEP:384:jhxdbLQ6FFOMMD5HXo4+NGYkiAoBANC/nun7u2RCb1ikIpjRAsI:lf86FFOMc5HXo4+Q7kv/nm7ufikIldI
                  MD5:4564F1F7B98187AA290A99492EFFE596
                  SHA1:0D584C09BBE759CD7B701ADB0E4D4CF65B045322
                  SHA-256:B4223BF5557D24617A96C438C1B5D0A8BF51FA13D5B9D138771AD9733287D6DA
                  SHA-512:8E59C8D7A8FBF338FBF72432724305FB03A8A867CBDC2870B8016A481D03274003BCE7E6723DC6F78DB89120D0DC75F1F67898DCA37AA5089B7432B2C9122BD6
                  Malicious:false
                  Preview:..`P.?Tj...U.P). ....O..{..|......U^...{.t.RhD.3g....+..O.....xZ...D.A..j...T.2,....^.{.-..&q..L.mj|...x...lYfx.*.;L..>..o(;'...B...@.........D...&bRF..0....n7@..n..."......n....qN....F.e."E=O8..(...%J.g...</C.r..`B".....b<Y...<..r$.v..j..%..*.[Y6.....#..[.}..z..;<N}....V(...J.W$.f....C.c.......B..4..w@D.g1...R*.-.3T.e8U...q..N..K..D.:~>.f.'5oe.E'...3.o.C3.1...INO........}E..EB....{.7D.9.'o......T.MH.B...J..Y....,.X....,&.~......Q.!Z.%.o...F.d....B..t.xHW.C.Q.T.sh..`.........d.bS....5Cnn..r..|0}\<..bpU#/......1...o.'J...N.zB...^.[..r..n.WLt.L{w./j..!.....%....,.rL...[...c>G.C+Zc!sQ....N....%o.`h*...&..q..G.:...v>0K.J.\:..8....i>#.h{.B.E%$.....x...^.L.A.w.T.@._ :...g...FK_#.A....j.Z.i.8....d.`..1...8\5..j...C..k...7...N..TI.n..m.b.....i.......vM.@\.i...A.P>X....).M.S..9..T.B.....F`.v..c....[4...p..q"..(.d.h......j...KU1..=...."ips.k.it}....4..'.....B.U.u.x.;AT.B.g*.Q.&k3B.A..2.k.X..7.._..)......f*.../v.....R..%}.z..b..B.....yg...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):16656
                  Entropy (8bit):7.988842237041133
                  Encrypted:false
                  SSDEEP:384:HhxqhEFi/N+mripubcnVJFE5lyJZA/kgQk7YXGRMW3jR6p9:BxqaIgmrIubc3+qLt5k74W3jR6p
                  MD5:EFB0950EABC9C7B832473EADCADB0BB4
                  SHA1:4A47D470362FE0A79BB08ABC219EE5CA1C439BD1
                  SHA-256:B27EC726DB189C3E9B7BBBA8A771BFBA2E005609B82F1F89694EA1724A8A0948
                  SHA-512:B2704115D8FDE3FF6E467926180C9B752AD157D011D97A44F1F81C0EAD3509528AF03E27EB5A3FCAFBE49C5CEB861B733EF6A1DB500EB654255E50F85F63926C
                  Malicious:false
                  Preview:)..H...X....BJ.)...H.....:s.5~................l.A....d...L^_D.....Z......t....C.2.6......n4.u..K..1>....R.......C.v.q..c~p.......L.....,..O.M........B.y.DO....&'.j.Z..A.leV~./y.e.w..,a.?-:i.g.?...~..w.!.?....s.|VQ.m/..X...-.p.hH.s...@2....w....q...|.j.8.H........V4..;.M@..g..R...I..D.......f...~.A...]....]8..{f"~..o../....)....h.k.7......Y9.:........4v...:..8.=..OS..X.R._..:..kC\.sa....+.`.f.`....%M.6..Yh.w..!9.:..E.:.?.9..2..o......!4.?/..b.H.=...R.q.............hw:.F. k.,....#.v=...........a......^..=u^.%....c.......s:{5`..'...../.Ov..R..<>.a.....d.@@.......z.P......OK.!..|......P...o>x....F ...*.....HR.l.?-...g=..I...].l..d.z..Y&f...$..y....x..f.=.I.m.O.u0./.....j.?..}.i..AE..B.U.;fJ....v...w.%5.:O..g...;....g....+.g........%".k..e.EkIf.........>...$..0C~...aZ..!..y...h.c.D.f..W.]^q"'F.@....1.ah.J&Pbe.....t......s.......A^.....K..^U..u...n.4x.`..8...F,.f...wJ.'.....AfN^.&...V&....?......)..'9.....U.t.m.,...........<.X.o...A.,%kH
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):19853
                  Entropy (8bit):7.990355864540545
                  Encrypted:true
                  SSDEEP:384:6kG9I7hJHZ+EYgIBqcAMdtkO2D/G073vK07OL6JSoJiTM2IL7pr6R0+Hhi93O0K:4uhZEpgIZAM/sbG073vKTLhTbF0++F
                  MD5:ADDC8590196BE4E8E9475B38BD158D1D
                  SHA1:90FFDFDEBE06A4CB88D33FC02864A532E737AFD1
                  SHA-256:584FEDCE7FCD82F9D5220BBE7CA475C6713307003CF962A34287A2EF32B6D838
                  SHA-512:82C5F6986D7AAAC935524ACF94C20DCFBD084AD0670425C18FEF138B076B3BE35D1B44E67B7DA910361E414E8F2CD5B9337C78AD8CBA6F5E5C571D849F76AEB2
                  Malicious:true
                  Preview:.C.F./N.7..\.rQ[..Aj*,.....9V..C/R..pq...........g..n...m.L..%..+..>]....cDJ...z.H...X..$v......m_.....'4...p^.^..bv..F..I\.@.z:-.:a.X...S..S.G...n..'_..W.:.>.,..B...x..w...].....>.zo*......v..;*.Azt..(..9..n.Qy..F .:......@.......P.d....0..)]..8/.. .E.....3H.P.!_...p7.>S6..Q..Y..L..,..ctc.I.....'d...<......../..`.8......W.z....)...6..&.T.5..3..MP..\.O.uG.*S.:..%A..................!.b.0..{r.Vxoj8%...WD.U.... =.Z......}V.M.y'2..CX.../n.. ...C......@..>...W......@1z.*.......\_[...:...W.s".:<..x...~X....3.....wg...L~_..,...:b.I.,.R3....e...,..W$|N.....5....v.=.X....a..>...C. .H'...E.0..\.S.,k....)..J......<Oj.....;.G.>..f....a.(....-....h..<.s*.zp........W8.u.>.M..9.X..k.m.........V.....r5q..S.).\.oYJ.+...{.....D.(c......{#V.8....J........$.aSY*...cU[5..+....@.P.E.K..z!......\...a....i...s."..4".?$.^..3...w.0.Ld,".QK,.`....-.kCE..M).\;.a..B......J.....m.(.o..Q......xoro. ....z..(6......D.....F...BV..9.....!......{WN..F}\.....X6$m
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17586
                  Entropy (8bit):7.989135492444084
                  Encrypted:false
                  SSDEEP:384:qInDCJrHY3kBkGXSsTzI2itHgzssCkj+QtT2SUWwaTx6fljo:/nDZJG3vaHTjkj+UT2+rTGo
                  MD5:972B42B546B23BD1B865F2A78AAE2DB2
                  SHA1:4EA6CA1EA77DEDB24531F140B80C262E39B13858
                  SHA-256:30258CFF1F6E93E6E65852153010B24E6C7ED6EB1F11C26CE86BD9257094E1AC
                  SHA-512:6D986D79D3F1F5638284038A5660409EB6E761EBCED1FEC84A6E18F10B54B84EC2ACEAF428A29AF096B1E6B86C5A749571255B18B42C94D81A994974283CB7AB
                  Malicious:false
                  Preview:..&pP. thr.t..r....z..c..k..M....%....u[,k.kV.....X.92D.w(b.$...#....0..5#t...7l.....~..........Yi.X.......Z.3...m...<y.SC.-.I..u......0....{..a......L.t8=S1.~uL.[..>.........[.+.|..q..Z.H.f....?.1......_l....5..#.*.D...pT3KA3.._qb..*.4m7..Q&..X..$.(.Lz..D.q.>)..g...B..s..Zfp.....q.X.`.(....`..5....#....R....v.YfG..)T...i......A...?....V....*..6|..>AwgV....V3:..<..w.#.^.($.g.&.]..=..HHA::\n.?X.........L/..7a.2.s.]...p.B.2...G.Od.?..d09.....;.S.$.#"...b.-q.c...3Og.@.A.XP8.....x....@.<.....lO#.H$.k/".....$..7.]....y;....s].6p&..I.U..\.V..se.R.f..150..6.W.\,.M...v...3...w..{G=..4....G..Y....z.g|=.Qw^..:...@.&A8..{.O8..^".u...@..P.e.f....F......)...:..:@a......)5GJ.2...pE...m.%~.l..L...|..'..X4.m..B".9u.!:...58....+..h9%...]..2.%t..u..A".`...S5..z.3.T...2I....d.vt.Y.8.....P2EtS..)z\.&...m..c.Hd?|@..}L..i...-.K..m.O...7......L.7y.e...{.._.;.7[CI.Z(....IA.3..0.<.....^.l.y...#1..G:..=k6$..(.^U....wy...8..L.v.m..spK.0.......C.P
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15417
                  Entropy (8bit):7.987484853414604
                  Encrypted:false
                  SSDEEP:384:XhiGKTjSaT0sjLXVdkYa5Xgalq3QIAqiE3WzDrEbt1pRvFIbzom:XhiGKHSaT0+LxyblQQIAjTIbdpFKM
                  MD5:8EC54AF1898A4222266CA7DF57E67B17
                  SHA1:10E6807C73B2892AD54A598173EBD6C1FBF18800
                  SHA-256:C82C997FBB4372FD0B1F79A0C329CF025368AF6C3D8D78551715D9F99613EEA0
                  SHA-512:E51969D09121534F67243993E9E883BC2B4F10BB1F421E0BD9BDA3A3A0BEB1D5016BB95A1ED637E1321BCC3839E8E9E953EF6FD75CA22903970F8B2CA59F5FD9
                  Malicious:false
                  Preview:..S.]..U..\*E.....B......O.%..<x.=.A^..6.7.bQD....et..4@.H;.[....=;%.K,.'.......3.....m~J....<...`{.....=....A....'....)4...+.....dU@ ....G.t.1...5..a.1..~Y{.......q{...EG.Cg.i.C."....'.#&....Gu..$....D.%...R..M|wrp.U../.....X..HK.[96K....6....f....b.gn..=.sp..l..<...&.Z..>....^.4..X.W1....n....K.i.!.....Z.W..A...r#.[e.+2..*..Q....(.aS..B!........EB.2ww.s\...fK.~..i..!.+."..aVz..`..3.B....0..=....~...HPk[/.M...7.u.2.6df.....&N....u.....n\.[..a.*G.cQ.f......be...:.4....4.Q.O........<....q...D9.He.{.M....1.2!5?..x..B....5.O&...y."A.......u...}D.l..%.f.........{..Z.......?]..CK..........t..-}\..+M..G2.BO...UO..9c.r...k}...a.S..a........7.f_....V..M...H......|.;.].Y.R&.W...]I.4.0..^.=d..(...|..}].....G k6(h..q..h...~y.(>H...../..!...4..X...t.3..4...S..<V5/...}"y...".....'...x."..@v.........h.........8.`..\.u../J].2.~V.a.o.u.8.~.%".%..?....E... .$!K...>....c.....;...p.^....;3f../O.W..uC\.g...)z....&.zi..;..B*.c.KWy.(..Eh......b.=...G....V..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17294
                  Entropy (8bit):7.98811598502363
                  Encrypted:false
                  SSDEEP:384:4GxVli+/a84XR9RLWx8FuzHg//EOmgHsuC8:tV4+iF3RHXVsu
                  MD5:F43C7BC561BAD1FB31F91FBE079633FA
                  SHA1:349B2D5BD6C0DE68BAC70FA831092A419C3830AA
                  SHA-256:CEFD703826D49E5BF1DB856F3EE0DB15077FB64F9E556E24BBA6372705A635E2
                  SHA-512:A490E957436BE69E058412C87797458774B5FF696B9236CC6A492F245C4F6F4255CD2F473E02BA7698E4CED18E957D890505E16225047CB655B70FA53DD40C07
                  Malicious:false
                  Preview:..I.......)..j..6Mc..{9...8I.Z\.[.$.,..a.l....`.WB.l+;,..B.....GQzp.....$.7/#c.....9......M.l......cCh.;...L...L....i..#..D.3'.5........@.h.G..@.[f....EJ>..."]..#(.......4..N..".1.?...!X....A......~..8..#.F[.....Evq[....N...,...V-..O..[.m...o..L.lzOd!.6.`.....y.e..zK.~.a(Q..9.g.A.w....l.2U^...O.. ..E..L6m.H(....%.....3.}F..%.A.~4...m.p.wC'...` ]......@..k.+.. ..q...6..'0\.ze2.U..Y.._.h.8..a...8..U.W.......K....n..a&..u$I\v.`w..22P].@...,...h.@...X...{......Z...>..)Nb.&...>..E..P..iD..'.....?..e..6ND..2.x...C.L.._d..X..]....).&<..DXI3'.G..t.s..u|....`.k!....N.k|+j...{.~...\q^{.M.......N.2...I...j.y^.=,.e.R.]j..>.U..!u[N.W.BC..y7.f.......r#..v{..S1.5.....)m"....r...QiCZ....~3.. ..U..:....>..a.\K...........rh.=}.Dn.......]k0...mk3A...L..K...c....'t...w....V......Wq..&.E....LX..3J%.5.9.....UMZ....v...[.%..J.H?-.....;..5..).e..):...b.B...K...-b........:.g....J&...89.G...t.5.......$y..^......i.._.(..}.D.....%.......g...wR.t(.....U.H)
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17222
                  Entropy (8bit):7.989270624366889
                  Encrypted:false
                  SSDEEP:384:ZyvZ8zFvZ9o+ElaJeJlmRHmJ9O0g2V75YcOpNxnflL3:NFv+YQvimvO09FOrV1
                  MD5:E5FAB5D41A6DAD1B980C8412EF0A74D9
                  SHA1:BFD1177563603FD461D2790314CD45977C3884CE
                  SHA-256:EE817A8CA36BB205026E4D73C50EB4D9030CCD411D2C73FEA56A4C2BDD6B8E90
                  SHA-512:70BC5410223D410EEFF2C58B72232E01B7508BD88E231BC58FBB374FC18D3AFAD6E9816DFBD73E4FE3466866D70BE8C9AB710052E6A312AF8F5FDF75E36B0CB8
                  Malicious:false
                  Preview:..a6.S..9...|].g8.".h..=.:U>........m..e$k.?"..Q.%r>.........._..$.E[.6.%.......(k...H..>L.~..P.K.q.....%.../...K.P...A6y(dR:...e+..)..A..)....Gj......y.q....%a.s......_......8Vh..D......]a.P<E.....R..;W.l@M.....B.....f..\....*.J.@u..g...V+.a..&..b.J...\....L.z/'e..ET.......Vn.3...r../...i........./.E.<...2.E.*.Q.Xs@....uYh...t._?...*.......2.....?.e>y.s....[.">n..T....4.q.....f..nr.XH....VcM..R...2b.K..FA...;..R..d..2..O....G..n.J.X...k.^..2.1..}6+..(.....<<0Q..`...klr6..Q.."..Y,...x.....d.+.J....P#...-.Jl..V..j....o..tM.../ .#.;'.e....1.5.....N.;..9TQ.@S..C8....".o.m.6....t........_.`.}...h.....N.{K..=.z5...."...4'{(........h...z.\.RAR...u..~.D@....ux..a.R...:.~....2])...~:...k...AF.)..&_..b..J........k...:.~..........?..r:......:....w..pD..;......?.3......mc.O}@a0......bP.z.<..,u..Z.\QN#..4g4}...*hG......N,e.~...|\..OE,Rj.H~..d. .\.. r(..1.XP...e...D...q./..?.\v..a.0/L_.e.g.tV.s....?.A`(`..N.~u...Q....<.V.../K.t..L.k.M....:gxW..3
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):17020
                  Entropy (8bit):7.989266238715713
                  Encrypted:false
                  SSDEEP:192:8fyIgFw19M2gR92T2WdYlCCI7kx6ArJBb/VPzkp7XHP/pXdeb2zRLb1fF/XjQ5zJ:le1CD92TRYeUbdLkJXHao5JF/TASZ0J
                  MD5:71BE50735231E54A1797CCAE4566C9CE
                  SHA1:341000AC6973EA10C4F346A5877A3312DDE63C7D
                  SHA-256:C1CB2DD451975439444EEB9F20D0A9EC72E8040ED778830599A321DB185D6721
                  SHA-512:3A20B84CBD0CFFDBC00EDA7B6969446A6274718C8ACB1620D130CFF16A575D7C105D4405B8AFEB1823C8B9506B25937D1A137BFD692AA72DCCA82A510AAA96C6
                  Malicious:false
                  Preview:.pP..4..3.q..l..S.....=..K..^.rgY)_TYX...E.$..5....Q.a......\`.."..e........qJ^...v.U...K.w..G?.%...hkD..)f.e....8....l..N.:..n).$r.wi.... .:\.F.ry..R.@..j..=..z.....|.HC.M8.q8..VA"Zo..0..8....B..F..]..n...V.D.`......?eZ.....0`.~.....r.. ..d'.4...S.0.;.)....<...]....b.v+4.C.d'..1.....d./.....9.r...4dl..i.Pb..l....:">..J.K.>..t.pN...q....%.c.B.........5:.,...|4.5;...&..g..rEE.%.e...&{r..<.K..'.....w9..Z..,.Q..LgYf.7c..f........F#./......^%_...&.!l......6F..l,#W.......k..........Z........"t..]Nci....L..<.2.p&.......E..@.....gz..sFb...J...x.Uky4..&.N..>..77..1.k...O...f......t;U....XG6.V#.>.`.....E.<5 ..X.3.{........:...~.B....i...|.W;Y...s.......'y....-U...m...c.@;'.\.MV|L....z>.z.....WZ=)..J.5.D....y'..*6.l.JR.-.....b/.N.F....6.."...[9..#0e.k....G..6..||..'..a).^;w.~._...5g...:j$w.heK.0.@4..X...K..s..Z.F.6..:]..R.pZ`.a..V.E..g:..\...K...=qo...)}i.sq.e....48-.lU.3.'...*....&@.7.V....\...t..}/#.g.6..M...d.....!.....Q.#.2.".....M7.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17463
                  Entropy (8bit):7.988010736864817
                  Encrypted:false
                  SSDEEP:384:lYO9kcBWSnAalCJuySURIqh9UrRwZYdNArnkPCx:WO6cBRAa6S2Ig+rFAD
                  MD5:B105E4A6E86759965C7A00CE9DB0BEE9
                  SHA1:D4FF75A3493D3052A5FAF9EA9E8339DE5EDBE7B2
                  SHA-256:ED7ADFF32721FE01D873D7EA253E42C6A7ECC5737DC78BEDEE786700EE01F122
                  SHA-512:00EB8B2B855498EE65097029A53F730A323B5E602FF2AF78DD05F007D3CE11972A5E12B12AF4A866F97485229873C63B6D761FA02C170E12C1CD252F111E781D
                  Malicious:false
                  Preview:r.Cv.K.R.%....._;...-.s.....W,c..7-...!jU...!.....~.R8.!DR.(g.Dqp.R..Y..8......c.7....{C...0......-7.....M.-....6b...I.mF_.e..O.....kC#..w.(..u.>u....Yx....H.../....P.g...\(W....V_.......el/Y...d@.zL.C.@M/.?.a.~!n. ^.?..o...|..e.[R.c.x.h1.r?<~@...b.Q8.O..y.p.......6...b`$...lF....R...Q..Z)....`G...~..w.[.V.H.Vgs.V...J..MeU.......8.Iu...........qKo~...{.. ..w..m.F.pa..^II...^..e.Yx..K.2.dW...........).su.../...G.....jR.s........L..t.,=Q..a...'...QX.nF^(..p.......Vy.ucf-j..(.*T../(S&..-D...Ztv.6.^.....B..2B...7..F... .h....C...:]..(...L.Y`{E...T.3..[au.F../..2;L...u*@ms.K..~T.........R.:.w.zbNM'^2*a.*..dOZ.;....~.I.}....H.;..5.. C.........EV..F.-i.Gd..W.S...=.....p.....t..rw.5Ef..._.E.\.....w.y.g8.T...H.yx....(.\^"$#..P.u.....o.....R.GH-@a+...6..vP.....#./..s~t..].....h9.(.Q..m...c1bCR..UL8F..w....V....jqj.......N.o.?........*....d.r].j6....Jg5.R.].......2n.r....h>...........}s!y.P...W.Z..h.h.K.i3....(....|gx..]..4..<...~8....8.U7.u.q..q.G4
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15205
                  Entropy (8bit):7.98777318587438
                  Encrypted:false
                  SSDEEP:384:dv/FLq59Y3J+LsOFIRDXe8RDILkXBJ7U5/IvpbZdlpWZkg:hJ+Ls/L1gqBlBldb7
                  MD5:84C4DE8761B11D6BD3659551E19FC316
                  SHA1:F88234A3893779F872EC97C39CB729D45B1183F7
                  SHA-256:50598D3D584B93B3A42A9389508F8C6B62EEAF9BACA646277D2C6CD036E814A0
                  SHA-512:96929D5A04439D6363ABF7424A82859B493B01E2EF40417401A92C6486780B68D4F2D728B17B154A827D80FB018F3CD5D51564FADD883F07790711113CCBA2B3
                  Malicious:false
                  Preview:-..j=....y.{%q\.......&........."...G.a.h0.....k....=|.....x.|w...i.P]..e8.......]..M...W.q4%.7..v...-J......Mw$r.V.?5}A.B.0H.:.G=.7Q._.v.V..}.Q......2&.w!oY.T.@...s...+.`0....i ....z]2.......:.@...tp.............:5i2..=...#....b2hTF..).6z..H$;s...\(...].E5(..(.r......R.2.I>.................&.VP2(..[...u...a......-....&.......#./R..W...AB..y...E7Y.)..lR3....w...3o.c..s.....)L\.G.+..&IC..........f2...M..+.....-._......6........g[.6...Q.q.......Z.V....a@0.OC?..ZZ*.X...SP7>zy..p.f........}3.y..A...2...cC..w......t..onT...o.!).R..vD.}e...K...7..e`J..D.).=W)S.u...{.&.W.N4H....HC...?.X..}.}....g....o.....ty..@K~B.......{..a.g.,..<.XZ9..$'}D.&..X..5.=.-hL.'....u`..'PI....../.'.....^.s.g..........8..h...es.v.C.....;....^.0....l....B....8L...HNj$.....`f.*.^K.%c_.n.@!.e....#..r..[y4.c%...}Tp...S.....a....c/.2......j=..&n.{.P.......x/.q.....V...[.I.t8d_..t.S.x..v.U..j.....+.?..e....N.%.-...>....D.n...V.mw.n>.....f... ..R.$..q:5._..-..?...Raj}
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24501
                  Entropy (8bit):7.993532444015638
                  Encrypted:true
                  SSDEEP:384:JEy6lD6kZzZtjUw6D9Xvzj+VTd/qSVEoc8qyuCLczQwG4vrk3HcWIzh5S+xIqzSj:JJsD6+tj16D9rKBEXUqyuZs14vrk3HVz
                  MD5:224BB8AAD5442353B9246D2BC98C66BC
                  SHA1:DEA07F0D16E9A27C9A341575F2EC38314A4D8112
                  SHA-256:4791DE61A9BA44E13931CDD271B445CE0B2229CF3DB269528A9473673568FC2A
                  SHA-512:2D02C288655F3E0D37F9DEF699C7797DCD1F7AB8D639B275F72E72CBC4DC969C043663A948C39FEB068CFD4D5D0CA54A02B84EFF7F0E0FCE59B1ADE48662896A
                  Malicious:true
                  Preview:..".....:y..e.M.X{Zr...p......yo.4r9.R<.5.j...Q.kV...m...9.....;..*.n}c..Wzy.Hf...?.@{.e`f.0..l/..;L..s...[..s....\?.e7...SA..8.Q4..*......|?3.....z....M..t.K...sJ....1......+....\9z.a.n.;.......3.6....e.....c/1.....fD..t@..\.t6w.s.Ps.q.a@).9.k.fE.. ..o.E...3....+{vkt.[..m..e.}.7%..m..$....3..4...`(...?.e.p*....S...>....Un]~O..'fZ.RP..../..v...4&#s...[...^..a..A....A".?c.h..].HB....O.O..?c.r.rK......W...XK.g..I.0I.@}.o.n ...E!b..#.g...b..e..a0.._.....7..... S.....h.L8.~.~...xJ....P.{..<t...Y...E...........whuv.......O.]|...P..7@....P ..\..D..4l..<..AD..?....Z.8.?.#..O*c....w.+c3..J&6.P......bT.l..WZ.D..'P2.ni.Wp+.......P.eX.!.(..H.5.=...D..p[..UF.+4..w\s|.0.'f.;....{.g..1.T._@'.-...8.T$..EJ.ka".)..."}.S.._.'.P.$...q.r~. .:"."...O..Vzc.t&..I.9.W.[..\...._:I..<.Y.....(cm..=..K...s...[...vM8...|t..N.Co..L...m.|=.DO.D...._.^N.x%..{.O......f....l.. .l...........i@.:..H.z.BH.e...W..........g^..6...qp.)...U..........1U..D\.SEs...h..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17622
                  Entropy (8bit):7.988542265320381
                  Encrypted:false
                  SSDEEP:384:66eoVMXRilfWsXCEybJDDhPFvfsUpIOnsRq6u4v6q:6JiMkfdXShPhs6nE9tv7
                  MD5:0CA2E0D80DDE20136C21529D606BBD65
                  SHA1:8B93451F125E63BEC2C5CB8EE6066B0D11808D68
                  SHA-256:35CA088A9AA779D02E8792F151EFA23CDCD600A40126E023E9B7F1E37B8432FF
                  SHA-512:3C51E163048D26E2F466C9B1148CBFD663C36EBDAD4299063C9F2608AA9662306DA973B9BB91CEC1BB984CB2726DC0627CC36010356B4DFCE318B33E3A228B17
                  Malicious:false
                  Preview:.I..2...x|Jo.....[......].I=.gD...>......U.Y..\\.._.n..eW"..}..Bw."......e.....wf.....C.Iw+.5....D...]e`..:~. .4..*?'R.K<CLR<M.XYaG....tm.9...:$.=c...y\i...A.Zc....?2b..Ie..<m8N.....M.}t...vz...k`.:.....Rro.;;7(.s....Q.....)9..C.y.77$.a$..... ......(.$...f.+.YP...7Z..&.....Q..gcW..N.<.8..7.4O..K...&..6.z.>.(..T........|,$.......e"._...G.=..!..!I..U..RW.7........Y.H.v.AJ_.E..p..s4.|..H7q.........8.T.zcx433..=...=....@J....;Hd.Ek}....O.t..W..T...!-~..3..m1...S^..KKd..VxST.@/.`Hc.*...6.g..ka...Z.``.g.mMq}#.=...Z$...n.$..?..n..........).`S.@~..%$_!H.2....M.7..1l1..8....*.#..._.84.*.........E......Cf...C.<.H.......O.\..(.t..{d.l...\........w..<..._<3.a..._Nb..:.....f..^..$.M.n.n]..K;.($z.."#..g,.......i...K.#..?.....!./xP..17gk.6^H.........X.l?...4..w.$.....w.....n.z..r...O+......d......O...M.9....... ed.p>.*{......y.&..Oq..ec.L.?.G._J.%...R.3.....].^...9..(...4..........u...@~z...m..z*......p...O.;-....p+J........]..WUk=Vl..X......0..."..... YX..I...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):16481
                  Entropy (8bit):7.988016209568426
                  Encrypted:false
                  SSDEEP:384:Sf53GtypEP/BjT00b9Td7hYehmSHsBCdTiCH3wlSX24aIdFG2d:6IymP/B0otSehmSiCdiCHOl+G2
                  MD5:07A5F3D900DCDC8D57E0D74887F552BC
                  SHA1:56E796EFE37769861874C7ECA9640B62034C9006
                  SHA-256:55BFD58397D40F24B1303BE8B7E02F05FD34B704EAC5F3935F47438D64ADF091
                  SHA-512:1C5B5AD77E268DC967A6878A9FA62B788C5A252D515BBDD4CB80DDA7CCF53E1B14041F8BFAA9014680D42E7734343CAB650A67BF72A69126C87B034A827AE464
                  Malicious:false
                  Preview:.lyL...4l.A.f.J...8.?m.C:.`l.5..Z....S|..O...fi.>N..fe..\.`...YD.H...y4.Q:..}!h...._.W..O8..a.....O....LV......s.(...9..LF..g!G#.d5....L..........j..-.q.0.../.(+.z...vz.jO.*..kr..e..j.|..8U[.V...._...pw.<4....c.7*......e.7..^|*e..V.P..01xd..}.+../!).RTN.^...,p......K..`..5.6.d..\...7.S......L...7?*..n.:KR..mt.....Z.e.Ny%.l...2..G..JA..5..%...Xe=..N..f.F.~...&.j.|.....s,.m..W.-.....>G.A..5.n.$.qJ..Y...../6.8..........o...W...8<.............*...$P.......S.....>.u....&...)..?^.J..;..K..g ....z..i..PH.jO.....,Fp..)@.#....OR.+..E......'..z..4.T.....vM.E....;....K......U.A..x..B... ..$^J............cY._.5..DgH.Nrz..w..kGO.*..O..=...-:..2u.'t...n.W.(E. .{.e.H..Y..].....g..._.G......c#q0..~..}]$...[. ..K......ong.3{.L@....[.......+.`....U.......`RR...?.......K.&.!..r...y.mhCi..^)EkY.a~o.c.u.0..s..k&&...#On.@......*..2...p.z.0+Y....>.....o..o..)ZOS.....$...d.-....*...$...CD).S'.........xY...n.....;.=.......9I..W";?0R...(.(..a].r..qP.e.......p..Y
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15882
                  Entropy (8bit):7.987210574348268
                  Encrypted:false
                  SSDEEP:384:6Yy92lC3HnQyP5DcErmdOjqUdcPgriFkeWkj7LwAQ60:y9jHQyP59KdqqBP/FpZLW60
                  MD5:13E85943FD846AAFDD9BEEEFC8D8574E
                  SHA1:1D2AEF879FAE13EA2772D31E1E57E6E745005EED
                  SHA-256:2D78F3B548F2A23FEE0A07C78B64326201415B436C8245B83FE2973EEA9210FF
                  SHA-512:303E30F3893E0FA53ECA393B20BC3F63579F7CA63769A7B0999BED3E3C02DCDD3C1B1AF0EB0A495481A0E0A5CF6462E3DC9565E24441D5381ABAA3991BA3F448
                  Malicious:false
                  Preview:M..0.Q.'@oU..Xc$d:...ekX.xs.1..O..u....D...i(d..n]+..!xr'..QAP..cQ.=.1...S........F5.......I(......O....j.}..un...m]=a:.X.....X.b..&G...K87...../-.T..ua.......{.}.*....`Z..a...[..N...q4>.t.J ...T..'..n.|.L...'ya$.}WWh...Z.4..a)..&........zY~.p.Y....Q.)'.%....j.....Y}.2..Nr-..B.d....O.../.7|o..x+...r./0%...K..RQU.....'....HjN....\...........SJ.U.d.FK`.......pp.oRav.....\0.rq.u...r2:>..../{...u.Pp.X|N..$..< .}...{;..=.x...:...ka....x.rH..o..d.....(.R.-...S0..J'.....8.k'[..I.!..*.\a6..M..v[4......J.....}4....q.x.c....E.98j.?..<^..D....k....;5rF9Gw.....v+..P...0....(......0..V...;%p.=).n.^^.v..Kxb..$U...O|.!..........J.J.ZH..1....'.#G.P.Gj..v...@..i%...N..C..ua.spzZ..&............t......./.._..{>.zy.w{[.#O@.......%..?j..Nj..%n.i.r.R(=Z..Y......R..bH.| ...2...i..nw.H..H$5..r..Ld...x|.....Dt.D...%...c...F...n.QR.l.....W.7.`....`...RD.w...s.8~N7...2. ..^"...V.\ut.x).o.5.r./.=.2.#..4g.<.....n....^.....,......eY.6r...$...0sP..o.......%J.Woq&
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):17300
                  Entropy (8bit):7.9895478636668
                  Encrypted:false
                  SSDEEP:384:ZvTstrPzGRCHbGrgKK2Gr2Nca1WVjRaiwZIr2:VqCRQGrg2GrS6siW3
                  MD5:AA6D6638EA44A46630D2EF8DCBE657DA
                  SHA1:06ED7941D0EE4541D342F4B7BC2D12AAA1B91355
                  SHA-256:7D9D5E43B9C5E1077A6BB23B3BECDD687637C3C01A436DFBA7882EBB1E3ABCE6
                  SHA-512:5B0CAF67FF0226667693FF83DDC0AE5FA1D3F28C023281A6D1F841341E30FE064B91EF5163B2B6370866D78AAC27ECF1C76FBA45C4A092645E1E58AA565DCC46
                  Malicious:false
                  Preview:..,h.}..*..?3fALIw..... ZR.............'...._.......P....k..k.q..:...:.3B.K1?.}....9.H8..J....,..g..(.......+...JF:..|m^.w.xm6.xg..'t._.O....|.#..n..C>...........|........ou[...;.....D].:]...e....6...x...?...1...sA((Y....K'.....u..X...i..V....Fb.>..<...WF+<BO....W......&1.+M..3wn..gZ.........)y*.....&.6%.g.....Kp......D..i.>...7.`.f.[t......s....5..d....=Y...._..]x......-..1...r.f._..ZX.....K+.F._.IW.h..T'.8..4./:'.z....&.;...v....g.{i,+ .5........j6...]."k....!...Bd\`.LAg...qg(.Pe&c.....2-.......O.#...x......|Kq....*.{.5i..K..}p..&7.m.....#..~wd.&.c..g.{/X...S..XxM:..S.w.5.GV*bt%.&5j1.w......X...J.).|....TB!j.2...E.E...jHR.%.Yg.....b.........yEO~.e.,.I....'.Ck( .C>....X...._..T.].5.tX...n...<X.H..~..x.si.)..g...}YXU..`k.f.,QJ.U.1#..)...|..7...y#.]c.....x.v.\...n'..K..Z.>YN.....t../rYX.^.s#..Gc..).Z. ..Q......8.,C..\...7iD...A.\.....l.(\...cO...........e..n&.%...A....:.k.Utm...0..`.<..e;.......K.pq_.\+...q.yD....o.w.1uy.\u.%s".....{...^.....m
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1265
                  Entropy (8bit):7.811296651848536
                  Encrypted:false
                  SSDEEP:24:z/+zezr9Fb6XZcNNCP9Q+irB2b8zznbDrtqrHTB6/s:z2aN7s9VgUb8fruHYE
                  MD5:8A844BE7114C62D19300845773602FED
                  SHA1:AF2730E6A401F0A45C8181047986F607BE662F2F
                  SHA-256:2CBE245940F12021AB241915AE7DC8C2595EB76468AA302D5A6167B52ECF60A1
                  SHA-512:D23A362ECFC972B0DD7FB2CB75BF31DFED2BB9D3F91C154C2FF7162946C0B56C934C9F32616F133B3018F8914CACB9F83A2F5B6C63B1A44F6D1BB253A819E2ED
                  Malicious:false
                  Preview:...sy..z.....|...GnaK5....u.o...V..^.F...Zh..`KJ.O...*..=......... GJ..[4......M.......Nj.d......h#....9#........S..t....d...UR..dZ........^..\e.w..@.........0...L..%........Q..xS.e...$..$^..>Zs...X.H..I0..{.M...kW....O.<(sl...+S.@C;.9L..1..Q.1.Ba.nr.....J.s\..0c.8.......-H> P...v.kh.....:..T..8d.2..?...T../.Q.R.(.Y.B7B.....;..g..3L.])[.w....L$.s.4...n}.^o..?9W-..Q"/R1.%V..A.....S...w.D.R.4s.<..?t...t>.E6..>..p.=.z..........O..n../MqA.........X2].....j.x......{p...o..pN.f....}...O.R...H.....`.P....B~gi.n?_Qfp..3.R.)<..X..n.@..jb.,Hn..=._...?.Je.%.F.....q......J..BI;...X.\.e.[]G....n..^.:...%sj....0.l..:.}1..7.pA...+N}__g.....N%.P.d..|...}^...b.*.....".[r\..VG..M.a...xt......2b.8.^B.GQ.1Z...i._:dY... .....HZx.A../.D..=...&.Q...-.p..3.5......2.D.UiQ.^2~.$A.h`.)9.5[.{..8.`...~..0.GH...PB.M....9..ek..z.& $F.:>.@.a.X...R.U....6....;K.=Ig...O....p..Z:..h.../9.E.........e.&..].My.......m9'.V.....m..F..=.I.<.`%`.....,]....AN+l.$.Wa...Sh......aG.;N./>&..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24740
                  Entropy (8bit):7.991607623954354
                  Encrypted:true
                  SSDEEP:384:1pkV06Jqxg78SBngJwrpabA4/CCqXzNpIqtWxRDGouoV7oqt:1SV06Jqxg78SpgJmYA4xqXzNvtWx1QU
                  MD5:4CC200D8ABA2F85C38F0FC90BC05E695
                  SHA1:91B44641EAB4C107C20D3F4C874DE058D1CE4D1B
                  SHA-256:5DE931725488FE92030EA93E4F81566A4A15B075478329B0B016FBB8DFBAD790
                  SHA-512:2A565E3F9957E4665225FE0D9DD8E49D3644785D48CCA20F3859BB7BA65769E408F43640D6BB20A0F66A91F2FB93708727015A681E19BF17ECE54ED8875DEC7C
                  Malicious:true
                  Preview:G.N..;*d|.'#..RLh\.......C9.......hhAD*.J.7.>.!.....{.!7..9.[#V.{.)$.`.]..^q.....(.l.....1@..-c<p..}.....}A.M.(.....+..q...&.b .....kB..>7.......X..=3,+i..p..>.....N.|2...)...3.\.8z.VI...p...MntW../Q..<..HC4......&.)~]f.uL..a!....fD.!3....5..^_. ......f.|..Kn..xrAh.......{A.A.........v.......'H[....njgd...U?.:x.f.. ./.@...v.'..~...ODj!..y.D...D......".b..'.3...9vwP....,..5f4..t.B.y..`..f..sR.......u.s...%.AW.PZ.T.,.......*n.cW.s..n...:C=.w%.Q}2.Tk.,.D#...t.0.f`..... .....X...O...l...5i..b4.. .....Z....w;.^....'t.Hs...:..1.. ......2....C..0.....e%G.1.-E.r..YA.....Xj.0i..Vc..0S~Z...+..kH./+..!0D.......~.....G..7..v...I...(.........5..;.7.;a..M........h...s3...E.....!).a.........s... .6.s.....X..)gSq4.T.4e)=.b!.%.{.m../..HM,...*.`~.....:.a.....=..{cu[.{..G........0....P..n..s\|#-..gC..N..}*..j{.+~.7..t...0......5..zG.]./..P3.....4..\...5..h.!vYE.-I.....<.:..~e.?=.Vzi""i...lGut 6]...V..UEls....0....[.0....,C.fq.F.[w.(.P7c.A..r.3..K.Yk....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15517
                  Entropy (8bit):7.988451142321683
                  Encrypted:false
                  SSDEEP:384:plzrciXUqleEN67tncugAGw9acbMiilFl5HgLV3UcGvE:zrciXUqlLOnwC9NohflVgBEcG
                  MD5:A76154811A2546EFAF40C46817E43165
                  SHA1:B454D9CF69C6531D3F008A89406F68288EAF119F
                  SHA-256:6AC65BEC9DF9FCC3167CC8413724642E4D6699ACCB05CB8DB1F38D35347DBA65
                  SHA-512:6C883D04EB06C324984404E940C027F40208E9B4723647430D9C13B896170EA465F8CA27C846172CCC2B59453A2E7495A2579F25807F9497874C069D6986ADFA
                  Malicious:false
                  Preview:bE...".!z.%..l.u#...T.H..S.....n....s.*..R...9.....KY.T'.6..H.g.. ._....r1[..a A-..."Y.MIMV.V......-U.....P...(,..........J.~A..E...v.v..o..}.....,m.'.sv.D.5_....)3..s[:..*..Z.:%.....q(.]4;...5:|R.7l&..?.X%...ns..aeh........:g..NR.a..\..zh....8....OSE....o..nNB..B.ft,..K.T..(.\..9...I5..9..^Q.Z....}A.U..7.O.-F..9...i.zs.*U..[.K. ./........v..:.&.:0. .G;0...o.9...&u....tJ...h..sd ..r(.../+s.5yA.....+X.b....n7d.NA..~....$.D....T...)...E..t'....)....Z...'..x...(!.k.N.&....oN.w....Mv......gO(.Xy.1..Y.7T...j...(;P.~I9..c7.A.....f..!3'!.dD=.<..a....../..NOx..`..*I..[.Qs~a.,p..G.YCL.b.......y,....}N3.....u0.....J..A.....W.@.+.R....L.l.u-...U.S+.3.)...@..y%DQ.2>5.;..0..5....h!....>....<.L.L.......k..O%......Y..."..%.....}.<.P.-...`f.......d.hFaD...1Xa..:sV.mw...*L......xc..4....g...7..\W...\.7q.3'.*.sMJ_h.|.[...u....AI...I......(u.........?........g.Wg.D..7X......dz.V.........1.w...F..r..D64.nG=p..5.~+F.5...S2.\..1M..wN...)*.Ge;
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15190
                  Entropy (8bit):7.987252735368282
                  Encrypted:false
                  SSDEEP:384:AAJBsFzg19m6a3mcj6A5eFGkbxauPckaHq+aKRPgreKSw/GIEtH:AAJB19m6oN8Ik1aPkaKOR4SKPC
                  MD5:D6CBECC32842CD47168DF0E7FDAF741A
                  SHA1:7C67383928915805A4BA7DE4014DA8DD6147A3B7
                  SHA-256:872255C01E9CB748B22C9A8CE11A586BD94438B624748B648AA85F3FDF96C144
                  SHA-512:1F9DBED0F1A24CAB79B2049CAB009A345082DF262BAE505D934178153ACF15F09C5FACD0758191AD607B7AD729AE8D160074BE189E7AE1BA5D44F2456FEE29A2
                  Malicious:false
                  Preview:...%]S...}C.....h....UV..l).....f......W.a...V.RS.2../1I0.i....^g.n...>t.6W.T...2.z.F.l..S.Pp......%(^O..J%U..5..w.......yy6.\../Q.Zk.=...r.H.......?+-Y..^.~.s..>C4.U?..a.-5.%... 0.=.C...j..C.........[.S.%..,..l...a...X..^k..0..;.....96.l.....<.[.[g.....P<..aca.B.....;QV...[.R)"&w...C...@.%omQ.'.?.6e../..l.......a,.......n..%.F...Bk...N..eu..h.j.v.....O..sc0.&.C.#..;..A....g..$.$.|@y.q.d..h.n./...%.....3........_.....q..]..y+...3...Jy..R...c$4&L.s.....-B.._.|$...a.....*...3Q..x^.....Y....I.P..TCi..#.../.:....LX.....T..S..>.M.....|W..bSe0kh...!.Tl...d..;...\...|L/.K/.?./Ud..yn+..:v...O.E!...78..d.Usa...z.N/UR5Q.>a.<Hi..?.@...^..C..!...f".-.....?....7.N"yY.o..n..u._....1]..;........%..7.9l.W0..9..8..*..O....K....C.&.\j#..0G..:....W.hq...no.!.FV^.p.;.....K.P.+1t..g...1.-...........I.[...j...8.*.g.}....KJ...62..PQ.vv...&...!.2....b......?.WU....3.....?..>N..|.y...C.L..e..'=A.....E.F... /W...vp..:.|....c.7..E...P.....ns.("_.k.'._.&....q.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):221861
                  Entropy (8bit):7.999218844311484
                  Encrypted:true
                  SSDEEP:6144:hu3BgbQY7f9GIuSexQR6r7zw0DvSSKdcg:hOgbtG3xeMffDKSKdcg
                  MD5:1B0B539AA9816B28B792E5E0EAAE19B8
                  SHA1:48F5BDFDC51113D94EE150BAC6367B31B8154760
                  SHA-256:B60ADFDC120877B4A2845077216553359BD9839AEDB3781660856017494B9B9E
                  SHA-512:F273181D6D62B54F3CE3C84B773494A45F1A451EDFA6314FE18B8E789C68B3981D62A202C723A05818C62996E676FE7DBA15759B2C5CA7AF4A61E699851901F1
                  Malicious:true
                  Preview:..I*...A-...*....Y......<......(.{...;@....+.z.?.^[.1J... .o....qKk.e.+.F...@.h.s...82.|...=.....b..xb....`&."|..~.Mw.!,...I..i..ax.E..g...h6...........5.XsviK..y..^..\j'd...a..P.b...........V.....b.3..&Am......*.m../.G...8.P.\z...u.|.p.7...ck..q.....G..3t.pA..0..C..d3d......j.O..6.`..ao..r...W[><TD...s..H!.h.....R5.^..*m.J.W..N....f.b.`...ja`.P.B04..E..qd.....J.%0..at.K....B\.D.6W.. .....G.*.'|....C.....(N....*\W.dm.....E..d....*.m3..M:.....m?..Hn...Q\.xMe9kC...h..T..."}pk..i......U...~N..v=...M...PT.+J........... .....;..E........u..._G..U_|.N...e.......b.]?......E.r... .......(.....]....#@#..._U.O........EY3..C.!...$..<?...........Z~.....|...............k.R.d..}<.hd#...I..v?g./.....SxP.."..s^..Rk.CBo\...-`..J,.....W.^.....`.....+g>.}.|.d..Q<p?J..."....|Z..=.%.q.r..f).{.<....H......zIY.~.K9..r.....9+?.].l+rAp]...(.cZ.TJ=Ae....7l......... ..F...o....3i.2.............KeZCn.y15..9.|.e6].f^.M)..-8....l.e'.Bcw...............y]..;l.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):20732
                  Entropy (8bit):7.989955613216861
                  Encrypted:false
                  SSDEEP:384:WlP0T8+W5Ojm1hSQUvYQnoAbL7m4RPcpnpJIqQ/2+dBItivfNafbnSjWN3fCKB:a8psUYmbv3PcppJIHdBMsfOnNz
                  MD5:F45101BF298CBC7CB6E80D3BA6139DF7
                  SHA1:39A5BD54615F107588ED30AC752F2301C3F5E869
                  SHA-256:B800F7CF0821C0D84940E3EDB714B764BC5B3EAFAF58DB9DC9BEE96F45502FC9
                  SHA-512:70DC19EBCA2E60E95A477310399BECF38076BCB936B0064C5F6768B5419114CDE468EB8B8B5F5E9E14B98F4B9AF4380E34CDEDC8B6FCE75844FC25D446285CD1
                  Malicious:false
                  Preview:.TK.._.PZ9..7.......=.Y..|.zx.L..m.p...gN..D.5..:C.!w...w.$.hm...~ki..."LN.Ys&...n~.2.....a5.D..K&.E.h..Z7M't..^:g+..+O...$A....Fz.T#c.N...gg..r>......#T"#...[C..z../.P.YR...q..Bc:N^5R..YJ6.~.:8..?T..GY.l.y^....J.....W'......8..aP........^.c.xsG<BR...>.....7....u.}v.\a-..l..Rd..r....Oi..PN...wW Bj..JY.&.I......(...:W.n.1......}..........f.....Dq.j....2D).RP$?...1+.....j.......<.....-..-.8.O.BT..O.......4.......AB..(.vu>..b.._C...7.g...........yS...#g....[.::|....7'.p..AM.x.......}..8.6..Z}.\/5.fq.....P.p....M~1.w..J_#.c.0.[h.......>..(.~/.9.1...m..X..@:..\N..........l.w.F.hp%L.."E..T.w.$!..=.\..{N...H."...L.z.uD..Xrf.0.Y.%T..~..~.W...IF...0.x.Qb...%8L.4.O...."w.U.$(.kX.......+nWP..8j}/...'.g.../.Q_rt..qB,....?.#N.p..E.{.....oDl.7`....2H..@+dX"_=...(...I.pw.:..3?....Z-..SZ..T#........V.B.wG^.xAQ.8N...%..s..$.@...8;I@......7Zk.+..]{.\.u4.u5/.r......#;....A'eb.Gp...~.5)...VS.....4^~.#.5..UJK/*.}...w......~.F..........{....'"@!.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1003
                  Entropy (8bit):7.769507105335665
                  Encrypted:false
                  SSDEEP:24:TU8yoicXo9knPXs16F7KAycx/iAMpWxUqImwU:TUI3XNnPydM/iBYxnImwU
                  MD5:684823473139820FB57A7C90F283C2B1
                  SHA1:79AB71D205034650734F0291C637776BA99E0DE4
                  SHA-256:36574EA5ED605A0E9231E2690C04E75747651E818EDD8C286DF891CB48FDF7B9
                  SHA-512:A32B0766A0E2D3951A0EEF9B4A58E99524AED7D59076D3BDFF0752EF358C3438B987D067524F446D3CE4942F706E104792C456C84443DF5496D8802A7D6A4430
                  Malicious:false
                  Preview:.8...]..B.2&*.-..>..TY...\.....;.H.:3..l..>. `Hx.I,..........9.....O.."...{,......u}...j.@Nje+.AH*...l.J..@.^p....._N.J1Vk.OB....D4..k..`.xJ.d.6..?z...kQ?V\...]....44..`:s.$J$.).B. .(._.z=n..?.o..+.X..........d.w...a...lij..Xl..+..4B....E..am^?v.e........6.'"...nVn.+#~3.?..8E.S.J.'.*.R..1....$..i..m>...50....6.g.......<..84.@X.....W..9.#L.4y.INX.. ...v.G..t.U..e>...t.}.....!..iSca.'.%k..~.T.......7~iv.4....FK...[(..m4WG.\..n'y..(.[oy|....a..L)....F0p..V.s...d.s4...C..[...&.a5..r.'..c......"M\8....+W.......Je.Re...c.Ma...s.......T.ZF...y.m.VR0#.sh....[...j.....".;;lN{.v$.^jwlv..O..FCMU..t<.A..k........``g.]...Z|..3...T..g*.....B,........@_....V....m..W..z...4d..v.{..;.!1..9...~S}...UY.E........>.G4....w.P.P.....DB..`.S.....B.bI.e......8V........G|...:.....Qd....W.z...C...^.P.S....%M...j._..RN..V.Y.v._/wU.x.\I.l...=....nY.X..u.O.U..N..u.a..z.t....C..}^!....K.......U..`..`..3x.9nf.`V]V.s...q...;,.l...........2...(..q.-........K...............@....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1000
                  Entropy (8bit):7.747196127616747
                  Encrypted:false
                  SSDEEP:24:NGDL9kzxfQEjmiqbPTij7XErTVEEb/JrBIUjwFaxDsW:NGX+xjV6iXXS6EbNVmc
                  MD5:A577E20665C355AB51623E54C40B9F15
                  SHA1:4E8640097B56708C55A95D95B9D9A3E452A3AC3F
                  SHA-256:187AAF4C626DA6DB56851D08A5F523EDC3683D8122EAE8C54BE6C021677A4020
                  SHA-512:9251367C8762436F4BF9347C0EE8B4AF6D77844276100C078DDCB3B13582B452E15D9E6961D9366EA0BAA5BD45A2E33C7B6608BAF78654F4C8BE413A3CAB63AE
                  Malicious:false
                  Preview:M.'?....(6...3..2..?...w.F...'.....p4.Q$3.o..v..w..P..........].....(/g.3......y9...i.G.gV..."L......_.b.x.!...g+...N.E.V\7h..|....4.g..#......V......G.0.<.h=...3.y..C.T[6.Z..U(-f.k.;x..*.3.RWB.%...kxK...Cv.H.ip.t......pu.._..."C..S".?.g...!.h._.74...)w..m.%wE7ZH`.2.(.4Y...t..<F...'@H.,.?....0Y...xH..........3..b.mv..h.....".a'..X......KO....k.6......De...?...f....u..j`...M....s.>n.J.n..?.1.B.O..b.n...]T..-!l[^U......i......yD.._M....W........W...].A@J..^...q....5.........].]....[F.:...e>..&4.=...fL.........H&.D%|.M7...a..@D..w..dZi_,k.9J..;...5.A.J..1kU...i.......c.OW...I..U..4..XH.w..Q{..W..!..)-........=.`.\...4_.vc1.w...c...i..l...C..<..CF.....R.No..2....y..-o.....F.g4..G....{........Q...Y.$...x.H..E....h B;..a..`b.....0..w..a...[.P.s.. _.t"........0.<q.~.T...b...C..9a.....<ZPv...[..v..O......#..r^.m..&...............1".O.i..wL?&.c..>.......)/`l..J....G`.H..........mZLk....T.oQ*@3F`...yM./.,.......y....KF.!............H...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1000
                  Entropy (8bit):7.755241566523036
                  Encrypted:false
                  SSDEEP:24:IahvoFSTtGc69F2mvkLdt2BvPG2MqXGgrkCuqgWjrJyahxeZgl6C:IaRoFK+99Wt2JG2hGgwC0W9xeo6C
                  MD5:D9C579118E6F6757ED587312653ACDA7
                  SHA1:A51C47942C8892C2C857291E4409E3F932325105
                  SHA-256:DC78616374B93B3F72C53011C0ED32005E8792C2220C806B1BBFDE0FAF669D4C
                  SHA-512:87787571480ACE96FB884A290459922A8C6651458FACB3396C5B5456C142811D7B1D2B474468C3C2E8A05EAC3E102FF0560141EE7FDFB73B7E24ABAECA7D6572
                  Malicious:false
                  Preview:......e.{.."...@....~..*.P.....8....X.U@Z.......U..Nl^..U./.Y........Nm..^..v.J....!.n.g<.."A......V.T9...G...{.....:?.....A....f...un..j..#.#2...F..#....:G...>&......q,9..t\.l.<.H.P.. #.V..W..j`.l..T.....YH..Ru.$/|a.3..V.#...@....3.A....mq\..{.......t..F..J...'Z..o/8.;^.}./1UV.N...!...b......p#.j..b......@.5.mF.......yx......O.....@.+d.j=...[f...6.u{}As...N...^..A3+...I...SC6.n..Cw2]..IZ})L.m.kv...xM..x.L..J|..u.'....R....M.:.5...../;..;k..<..r..EM...Os.|F.q.....Gr.....rB.'.;>....%..Fy.,.W........S...1.O...C...4......MY1+v5.>.$........]&..(...n..9...h0....m4......a.M.dz..JR......8....k.R.1[.h.}.og.....>k2..M.f2.qV..g.<6~5:]i.8..we.......p..r.T..:......j..# ..O..@.Os.....6.^.73..v%=.j;[..-.5...>..I....o...ZX..B......G....Q+..~..B..x..Fi...-.....M ..W..P...'.._1..1...\6.d.>...b..`.....a.^.ZQ..gq@j.2;........:%..=..+.4p....%.....q......P.6.H.......O.v?...Q._...x.*.......s...r.G.c`kD...r....%....+oc.........H...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1000
                  Entropy (8bit):7.722121282575816
                  Encrypted:false
                  SSDEEP:24:bWojQz5/Oe0gWtmBL8H7ALF9mfuCpo8X:bhQz5t0tt4iOPmfui
                  MD5:FD9BC15E00D051F53CA8ED2FAB49AB4B
                  SHA1:1116A791C4AE87055B2F6C6F1CE0D5E0084E536D
                  SHA-256:0177A95CAD751A17AA2888DE974A7E21250BB1C266982D6C8397FA9AB4CB8D8F
                  SHA-512:1BAB535DC09CAC562D9663E432D34C540A0E7B8BA75CFD0C2740534AC4BFB52CE9EA8D5DD6FEB82D863EE34373A31C88EE475E1D194AD5565D3C2E4F199C8CA5
                  Malicious:false
                  Preview:l@..{...B.g.j.\.).X..3h.t .21K. ..t..eux..... ..o.p........Ez....4R....5...8w.~._.......W.t.t..?.......uIj........M.-..>....j;............X...D...7_W..f]v..(..z(...RF..A.^.^\..T../..h..*8....U.+.k./gG.E{..{+)...N...P.;..6...."z........o.U.....}..A).8pl.k./(9B.m...'".j#...<.|8.0....J[.!...IZ..Ov,....>..p...C.Ry..m..6,... ...l....o........RK...VY....1'..tM...|....]M..&.\.K..;{...E....|..G..x..K..|....^...w...A.O.5.;.v..l..jlo.......x.n.......r`f.Zd.X.b..|...v....Oc...2.....5.J3e..k..>.v,.......... ..T.R..|...O7..]...k@..X.|".v.M;..0.o..Z*..Kj..!..&.wTEfV..wc.,..|.1..\.;ukF@...3...8.....8.R.vx...J.E.+i.|Q../.<.p.8-B.].J.Ad*.....t...k...B.FB.......k.J..P.+.......E. ........*a...$..]2@......']...+e.>.!.ix....h..#.97dsQ-ba.}.B........e...u.c(P*.?.e!.~D....`..I.Y....a.-..RX.I...p&.3....e..F....S.....:......z.....b0Q`-d..h5-.U...1.I.*..H........R.8O........^.'..,r.9\5+..-%I./...H..A.. ..8JF.....@........H...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1506
                  Entropy (8bit):7.842917833575915
                  Encrypted:false
                  SSDEEP:24:TUkLcUGRLPgTjxeVWLpvq/bXVGqGUXQQTltWaGwXdu11zsYNJ/y/AxWmBCRkgNlK:TUQcUkri1vwbrywIfZAAlBSLLw
                  MD5:936A544C452B5EC24329D6F5D7AE158E
                  SHA1:07578327893D85D8139657B63FD8E0334FF44498
                  SHA-256:C547992C8D43D8997DA361C4231E4AF35A5BFEE99E42B9407E11B13FA6027F83
                  SHA-512:037C0C12ECB5F31187CC473859B450BF308BC062DCB68E693D7DDFE99F38D8097091156AEB4520311469BC7107E20AB98B9B0AE9810162C8BEBD9310E1774319
                  Malicious:false
                  Preview:.1.(...b..x...i ...t....[:...-:t..r...._$.".].<.....nCZ.1B..Ia_.$vDO1&y..f....],.x..,K...?.m..B.3.>6#.)`.X..su...LE.....H!..N.0....9..H.....{...HL.=..pX...&.....<..V..mA.y.o9.....EG.Zk.x....j....zf.....Y......O..hT.p..uw.Q_.R.....\....n.c....`.....u..i.."...!Tv.A....:.^-I.y.S..-...CJOp..M...5gA.A.a...]+.X.my.&..J.....C...D.<..7u:.7.f.XL..WX@..a.j/<...^...o<L.,9L.Ux!M...0..~^..AW.+.).,w._.cQ.....-3t8./..B...N.[.Hr...Z"$....N.`..B..0.SAJ.|..............M.O.cT.j.Z....HRx{]..J..O.X.^......w-...}_..L!.q...N<L..J........Ds.Kj.~..za..`........9..lHI...&.9.T.*.*6'.V... ...&.H..D......|{.k._.k}.q....x.$.;.M ....6.yz../....;e..0..x.^?..mk......$...."...%.0.P.hs...}0.B...'..nz....a.~.{..\z>.&a....a.<4W~.T7/....5......,.........A.#Pg....C..A]..............L......".EX.q....7#.......i..u,.V|.h.)N8..k..5..3.\.c.v.\...k..% X.7....s....'!.a.W.....?J.....dn.Y)......]..&..w_..*...t..7q..t..cr..X...dv.k...G.`..R..@......E........a.F..f....S.l.of.:.e.r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1005
                  Entropy (8bit):7.763009826994694
                  Encrypted:false
                  SSDEEP:12:LmtZ27cr+zMotGokJ4NzEER/5BzNpcoJWIsNc3sKOQr76Z0Gk0CPOBMJXsTjktyI:LfMoSGlh95NcoJWPp7S76yv03BisTj
                  MD5:1569D03B269EA5CFEEF446C95E73BB49
                  SHA1:021CFCF114266DE665018F80A69F7B82ABB33E6B
                  SHA-256:D279F327C16660E0EBC8464D581D1C5EAF644B6D5CAD70D7825C8BDDB74AEBF8
                  SHA-512:7B8F263963EB3EFE37659D3CF8267656CE41946EA24516CF862858A4D911B5BA2BC5A271057BC653B53DAE618A6FF96DB5AAA123E4C152EA58FE33B4B0A73B07
                  Malicious:false
                  Preview:.b{..../;q..+^.d9.`T..f2R.R...._...s...q$O...}|d...z.7F~..iM6:.;I.2.wD0!.c^..I%..=.....].B...R..k..0....#. .......Y.Q......:.....l#5..$N..Wh..y.M."..Qd#....6....<~..a..%}..P@.*o.jG`R.../.......r....>..9d.._....9...*..h`/..c..@cg..g.|i.f..|..O..m)..':a.....'.6Y=.......M...y.vA#w.......k..ik.$....S.C>.~.<..;X.ef.m...hg....rl..v@.c.....A...B.....r...H.\.qhg".;=.%...M..z.r.......2v..1.lg'..Rr....{.Y...A.!....1....S....$..Cr.....zNzU...x..\.*..s...<.I.h".954.O..K.b..!..j*.....s..>-k&.t.g'QpO..z..+ZF....e..K.P...Tr.E-....d.S..=N.....[!......N...1.-}.8,uE~T.....,o....M%v...k.0.5L..;..M.a.eUq...jM..?.j..2r.y..{.?!..t...]N5P.C..}..dY..Wl.U..Y..85.X.....igb .......t.d.7..V4V.U.b.....G..B.N.S..8.*..v.cB.....?(Ws[.....cs._!..>.o.#.N......~..1.^...v<.!.zW.`..<.'.<.}..._.......#._.(...N.-t@.w0A.8}...../...W...-....9B.^_.#.>%..3=......q..Gm.C.<.C./..WT.'__.M.......s.H~..T8.B...\..9....&.......Kj.y.q.2].}.....E....S..........M...............@..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1008
                  Entropy (8bit):7.744347365532359
                  Encrypted:false
                  SSDEEP:12:PSGZ0pkZirD/JcGCF2v5YlICPnCd/NR+IfwCYfCvYzzT/b+yz2RtPeyVAiZ7+mwF:Kiiky/762v5Yja/N86YqvwBz2RDXwu7
                  MD5:9165F5F04A791AD5AC17F3B941036660
                  SHA1:795A5AA81FC5B6BDDE191621B14AD362BCFB3354
                  SHA-256:2433A12D7BEDE60FFF5FE7FA514D4B3E2A06DCD8A3B85B7E587692A2D681FA96
                  SHA-512:E68F750A90770CD9B70AE1FE6A2EEA3E96DF3D79D47F115FE2DFA6E9C8B72F472FA0224722F9DFE2B3A194EE1ABF6AC080CFDCDA552F96448C72881603825731
                  Malicious:false
                  Preview:..=q.....)?.-wM.p..fB..F..= .'~...t.:wc.l.Y..)......3.....?..1..a....=.3..#p....=2...2....=...%..?.i).A-.._r.4s.....N....j9.....n..0...Mu.l...b$.R._.m.&A.n....J$..........l....\..U..c.Cz...d....0...s.ys.'.4.yc5..S..V...I..u.h..w.O1...^....Z#....l...g.5o.}.#.A...t.n......DW.!.j...l....A1..c.._...:..!.X%.@e..]..^.v.hJ.qy.?.K......G]....'#?G...>..dn.....1.V.}...\S..!......~T-Jw..}...(-...6r..jZt..t.sed G...q.D....S1[..9......o...>yP>...#,..C. 1.C...Om...D.-.-^....F.."...m......>E.W ..g.U-..9...@{l7..R...>z.?T..$.....!......I...k....l.kG......`w...@g`.).s..(.....J...L.6..e.F......p";...:.A.Iq..CGUm...q.7.d.{....#.SO.....m...7o.?...)K.....^.t.-....Mp..WqY..~9T.".M........W.7AO......O.F.O..-....s...mN...@.p..@.....g.>..<..3.....(.K..#&.E.W.D....A.....W.e.6?.g.RB...Q%..r\(.g..g..8\:..y.....mG...5P.....qW..y........|..kX.I....zD._.Y...........(...x)%..P.........1........9n.....3..F6.0.}.6Al.1....O.}...N8.IKj.:b..........P...............
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1000
                  Entropy (8bit):7.735294772717235
                  Encrypted:false
                  SSDEEP:24:B/ILnbc8xzO+IN6mBlYTQg5WPusQBO7NnOEYz:BALnbLxOXN6qSz0PusWwNOd
                  MD5:AB52713A8BDA51AD6B7420811128AE64
                  SHA1:EDC0CB7E8696808873BC8DBE0BB7D950A003ACE8
                  SHA-256:1A85FAE08B0F84BB5D281644F5044FBB77731FE6FEEC9CD947A0FC3291F8A09F
                  SHA-512:F68806D609800C920B01E43BFCEC9228F0E01DEEFE62012A561920BAA7E66FD85ED39411ABE02C05B2A5DF288C940180DFA86430B44CB077B78CC77AF6FF27C7
                  Malicious:false
                  Preview:.ZG...._.l.}....Z.5_.K.2s..Z.D.J.s...,...@..>Y..3...=...}...+.....]\..2.qm.....K..O6a.....2.$3..x....$xj.."...".H.O$..z...`.h..0Y...7.@R...XE..n}.I.2<.H....~..uF..(....U#..z...ScC...}x...........7+XeQ..\.hf.-7.R.7.vH.#mx7.X.K.cuG.BV........a(-.R...J..|......f.}#.H....h?.9.}B+.f...^B.0..o.....M........2.\...&.m...<........F.Y.A1...nX.8.....|..n....L.....(L.....p...7G....#..p.->Q...H...L.O..{K.8.....V.....z.....e.P..1.<.......yl.f./a....&.e8.fw.....h......FH.n.&.....CE.zW.d......o.x.~..n.aj..{._*.j%....?..CO..N!..loE..+cz%......qx\z..o]...d..1......1l.....<T..s.~R.......9.H^.g....].@H.<.X=.L.@.QH{j5i.. .../N...^t..>..TJ...U.7...D"XB.....)).Z.Q......rwt...J].Ft.......{....u.....3.QLYs...o~.....IV+..4...Yu.F....9`.1r.....F|.B.......(.R....-..P..@..o--.^.;\..;..4..N|.:{P...~..x5.......ls.I... ...P].i..dr.'..l.(.[.zf..'D.c.+....}....Ls..(..M..*.$D.5...T.H.......d..3..3.o....0n......^t.5...F[...G.h.....!..O.hc]..........H...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1009
                  Entropy (8bit):7.776585467041587
                  Encrypted:false
                  SSDEEP:24:xZVDtwjXl4plh/3YLmkevNRiZyiJZ06oeQSWBplmp+o0YP:71ejXlmb/3lkevNRCyWZ06oeQSWzlmpb
                  MD5:B8DC61FBAFF22D0742FE6F1EC678BDC5
                  SHA1:F1A796084CFA7CBD8EC350872D6B79605BE398D8
                  SHA-256:072F7B62C91925B870B60154829B8AB5C4CA2DB1C43697C0C5F357220641AE2D
                  SHA-512:9F28753D4A6529647E28BAC86A4EC20EC4B281E94CC87C3BB786DA148C297877AE51801D3CC28353EE226DF1EE2D961E8B217684734C9D73E93C8B8D83922073
                  Malicious:false
                  Preview:....%..4.hNNB..9.,M.......)~.#.o2.B.2..C.w....9.!8v.}..kan..T..?mmq..4..;..-j.5.|.9Q.7S....aD.q.....[.q..P.$%w.t.W....S.......-zPh.1F.;.R]}..m....%3.5n...W..'.9.K.]&....k].7..9......7...&< ..)SW.cL];...r+-....:..oX.A.I.R...l...a....^..j.......J...R0.{..=H...d.Q.=.vK.@.QIm.>.k.s...le....c.fD.zS......$.7+X.8..._}w....%akZ.g.....d/.;C..m[..N...ZP.?Q;....._.Z(.F..'...KS..<.\...Z..h.;~.....~...#(TC.F.T.K...+E...hr.'...f...Yy.0..BX....6`.*.oP.*k....Rr*..F....:.i)...zNm.....G......[...`.....<..mkM...8i2Rsb..x....F6.$Dl.....3..T}......@.<..`..@$..|.&3....K...I.K...A..-.?.$"...........{...RN..|5.S....g:...i...n....sR3.d.Q..O;...V.>..<_......{...0.`M-q.....`J8}...C{&a..CJ.l...B.H...-...)...2....T3...!7....|.s..\.)W.......m1.(.v.V.l./a....M\m...M1...T..'*)j.N.f=......T..~.)h.S.....{...WJ.......Y..n....:..g.@'.}.T...{>H.lC5.X)..q,c..`@I..1..@......hn......=...lf.F<i.r(..Q.-.rQ.........V.U...4.+r\.y^u./.Wb....I.}.>p....&....43...M}-...+.........Q..............
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1000
                  Entropy (8bit):7.7705619947628115
                  Encrypted:false
                  SSDEEP:24:BGqsNcJ9Pew2OMuWh9WLpUwuM78WMufP/wON10p:4qsOuRuwU+wXWu/wO
                  MD5:FF3538ACF5BE81BFE43A6DBDEA310CEF
                  SHA1:7F3C76AF72B416158D01277E8A603D537BE1E18C
                  SHA-256:8EB6BB58A504878E8C100F8AACBF047973FF597CCCCA051D1899CF43578B02C3
                  SHA-512:6E45F49BE1415FC897F703986ED710FC4F1633918DEF2D724242C3309B3924C1559D94D865C21B239989428BA056468B39221DE41D5E3748BB42E25A2BFB0470
                  Malicious:false
                  Preview:.C.a.E.SJp....G.x...q..K_=.9..}tZePp.R.[....",...N...i<...~.... n.co..e....@#..J\fmM.c..9.R.....TK.9....[.)X..@ b..M...:.....1..U[|.....X.b........Y%w).]j.J.X|..Y...]..?...}fbB.j.....n%..4/.....d..z;.3"...0.+S.R...qcvT......xP.....I....s.B.v....!=..:=....wh...k.D..%..($.g........&.R.#ns...t...V[T.2..v...=q.NN..'.....,x..O*....{07..$. .M7.".F....:1J'..;bS..D..G....RQF...`.I.B......Z.H.`.0;.|.........n.UaZ.e..=....'...d....e.4YK...o.`...^...a.U...K3~{....9..5.M..(..#.I..../.7.....@q....J....u...b..S..lf.....1...+.....%..............4=...Nt..c....Ez...:.o.Y.....p........&.. LD.5..,...Q9Ex;..o.g.2...[b.:...E.Y.........bL.g.4....t.sNz......?...+XD.#.B.`. '$ZO......l.4....EF..J<..vF.r.w.......a....)...B{ep.....}.rP....U..... y.....)k..E(72m3a..CV....B...7..@.U..v...U..;..`.7..~....IoX...w.R.9.....da5..Su..L.....d{=.qKT....d)<XL....^.....Y...!`..D..H.......f1..6N3.S....$...jmw.RM5...n.O...2..Q.[ni..W.$..8............H...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1006
                  Entropy (8bit):7.722987509115361
                  Encrypted:false
                  SSDEEP:24:A4dESP556hhafKZuLjluPed5Mipm39ctFtdbhVZw49AV:9tQhafKkjluPed5MiEkXhhKV
                  MD5:9F91F6ED9B56CD6DE686D83C5F7EDC84
                  SHA1:14394068452B5D26C72BB071FF1D30A7D9FB1963
                  SHA-256:353C933D30D23DC8AAFB5F6C680CBAF20095E6F8E3CA5EFD410A9BB4440D3DAC
                  SHA-512:7BB8E7BFDF85173E6074C543BCB5CA115329207E82C124364F6EF1C687989221A92A17B61ED20B0329E1CEAE04A1D63E1A68AB900ED7D57F375558E9014A226B
                  Malicious:false
                  Preview:4..&...qY.j...W..%FTc.2..j..l...-..no....Z.D.....b./#.....f~\.).eS..}....K.P1............'../b.c...,.M~F..g-..S;.q.A[....Z.....E.....;..HW............\6[q&s...5.rM...\.:..w....g..'...;....E.d...&.g.!.....j>=]x.......q=.G.oI:.2..AZ........1..*.....\..p.....l.G~...M...Ug. ..u.?E.e.k.x$.>U........,....zAV.&v...w........v^y.d..5f....m.....\bw.x.....,.0H....=.......QN]l....k..p....7Qg.U.i..o...j;x..U......O..5*co...Y. ,{..=...B..*.....et5...hA...Ts&...._.k.].......3|...H.:....tM..I.<B6J.yHz..?)a....0L.=:4...x7....:...$*6...;.I.n!..k.Z.n......[1..;.:....i.%eK......R..[....=..^....U...9.....F..~s......H.Dw..;n.......#7...O=.....b...}a....VF.........`.#a.tr`n@M0...../H.:.^.....f{..:.v..B...rt.E. V.._.A.U..]. ..f.~..Y....j.tH.7..~...B4.../k2.....n*=G..K..p....?SB^C.l5"..\......\k(..%l...Fn.?..d..N....Tg_..L.w......D.r.dQ.FN...3....(..U.2?TC..X4.`.E..e..)..S...uQN..............c....:e0...u...Zi......j..w41l....W.[..7.s...w........N...............@.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1476
                  Entropy (8bit):7.829353150344691
                  Encrypted:false
                  SSDEEP:24:0C/XdwHA9JBTqlH8/ztuJaQwzrhQr8URFJqgwhv+H0Lq+hcDsptcPPDwYCR:0muwBeeYJazztQr8UIgwl+HsCprwYE
                  MD5:D4B469BF98753198534652DAEAA173FF
                  SHA1:EB534E193647A701E4B57FD5F6BACE6E2E187AB5
                  SHA-256:DEBCD98B88923FF8B668741F295FC67E429330B4E5348C31D37ED4755974584D
                  SHA-512:C1855C2461DCE38B134648F6D44341AAA2AC5621E7564F082F765AA7A2CD875BC1E9740C02D8567C8A52A7F3175C3CD95D93F70F9A1E41C6957BE925ECC33F47
                  Malicious:false
                  Preview:.goR.E.~....l.qr.m..J."'o....%......l.../9.....\!.O.s.W6..$X.....C..D.>Hc......X..GP`....4..A....#s.-L....C.%v.n&..B.o1.yL....Z...C..0;Y~.H.B+.!U....;eW.gA....W.&:j......S..".....+,..}..+..7Gn.8#. X..]Ts..z.8..@.5..[.........Y.c..0.....:....u..?}$_|...c$..e7 ....Z9W..!..^..Di...b*(...3.j......$E..%..q..i|.....r.Y.E!.VK^}LR.$.ky....6.....v.#.J..(.e-.[*.......c...8.}.pX...B.Z;*7&<.t.,U*`.@.u..u...tR.;...e.?.uv..43.~..._...OV.ro.4..[.x..j.....P.eqc.6...!..k.u1.o.b...Y.U.T......`.s......TX..._.L...&}..jy.....'e.C....Edc.F....x.|..r-.O..PN...{,.~,...(....._.zJ..Z....l.....xL'E.....XM.Qi.e..Z.......^.J........=:.B=M.%....t&......H..n7..@...).%._.z.).Y..!q...c.y.).X...?....(l..8.hpn_.i..P..Y...b.(9N......sL.......Q.*..Ubf...b..._.[{N..5.t\.........OT7v@.d/XV^q.".2A...F.G..Em.y.W.gN.+}.,H ..M......V...#!.w-T/h...R.U]..!....,|:.`..S;4.3......>.#f.q`_B......0M....t..M...v<?....NH...=.....&(..:....c@.f..,~../...,!...v[|.t7R.GPG.O.1;.....H..K........f..,.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1000
                  Entropy (8bit):7.76297674901047
                  Encrypted:false
                  SSDEEP:24:Mfmhdopr0WBH1zE20QP/LuqlHDeCATCLGYg5:rdrsxEZQPzuqpk
                  MD5:F415AB5BE5200A82193C5E1E5E902E88
                  SHA1:9ABBDD8EF7D54BC152E31A67A1B47FAB02AF5544
                  SHA-256:549794C6474048A883884BF518B3B888D04C93A418BFB73D309FA7153067CD00
                  SHA-512:2583E67D14BDCE7C0BF8EC97716A43478972B526684A58191448364957CCA7F0BBDF9FCC381A6D17749A0FA08EBFD85053CCEF683A88871530FD5922C510BC59
                  Malicious:false
                  Preview:..,.<\)L..c.5.W\C"..~......I.f....Yt...,...;.u[N..Y..3:.D.F..... .hg.....;7~..k..w...<...cL..|..k......y.>....B.F.c..``I#|..av8n.t..X...e.(.{.u..tP.&c`K....Ka:D@.3!.%Gt...8...H.A..\o..P.!..~&...G..P^.(..Q.%.Tb.....!...h...S8."..#.2akbPg.......3..4~P.P..*m......*....z.a..T....j....@.p..D.......|.........'..........Y.ca.?-Q{.4...p...k..m?...C.w...$.Z......h.).]p..]/....=..0...;!/........%.J..N..[.S.yP... ..t.........~..D\.S.(.I..`...6...f.H....$...t0*......+m.>.r{..z.I..4 .........pI5..2zpN.pyh...?.'F..P.+..X.g.G>L..q`T.X.(....s..R.....g>%.....Z.....]....M.../....7..LYV)&+.4......=.`.F.@i?...T.++Se...$.`.8.&!c..m......z=..#1SJ.x...CO....<.@.zvh...^...NOf.=bMHb.X........P.koi...-..._.\4.X{oxy.M/.M..qi....1.dP.....5K....K.....!...H.T....[C.......e6.......`......l.9N.|g..R....F_.. ......u..P.d..$.\.$..|....o:..?.4K..'....Sox..?. 1`.=...e.a...G..T!..H........C..*..&i.....V....}....z.)4...b)"K.#.)..+..@.H...........H...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1067
                  Entropy (8bit):7.787919219927994
                  Encrypted:false
                  SSDEEP:24:Wcbgu41AB33Vc30fXeaW1rNGVQE+mXHOvmx:W6+SHsiJupIYmXku
                  MD5:0DA7D5FF5FABC90DEFA452CB1A8AA15E
                  SHA1:EEB745F7E3143026D6EDA7FD3D081ECE7D847977
                  SHA-256:F770FEF1A369A305761B8DAC6E6791603E4FFA2AB134E3423811BCE552E45DA9
                  SHA-512:49C7AD0F8CA18CB5B3439C3757A2B24B9F2DDF72129A118BEDEEA8DFB5889A899A8A1728C5D296213DF9EBE495E3CA9174B9DAC84F5E5FFB940DE241C9E0CCBF
                  Malicious:false
                  Preview:.C"&..1.t.M..c.V&...?.cn...>-..]+......{....w~..r...'......v....&i...).ip.b....d]5.../..S.9~.xF|..u..l.wJ..k.w7x..k...D.X.*v.1}.Q.{Ue..eO.....%......N....n.R}...A-...(..3.D..D.>N....o.X.U^..Q*).....*i.m.<.$3SJ.\rM.>V.J. F..C.}.@.+..GCFd.;.NLAd.6.;.8.&=...%.....JDl0......>8...q.9..H....km.x...2._....Fp....;ME%g..UE3.Iz.?.^.l.......Vu..D9.......-..BUP...IW...|.{.j.3.I.(..q...x.HROe./...+9`5.n.ci.....rz;|.D(.....]\.J.Bw.....=....&v...qP.)X.H...\\v....?...........H.G4n.^..~3o1.63..3'T..U(.(.Xk.{FQ....o:Q.....%W_x....K..^..#)5XJ.c.WQsp.V.G..lpMl.. H.......E....2U.>"..7.A....$.{.h........i...t.;..Kz.s+..&.OaM.p......l>....27...h.....n.q.<...bO6.T..Q.\E..BnOs"ME.....B..3.n.t~W=ik.-R.V..I....)|0..7..#....`.w.Z.x[........I.#.v..U`tl..9.jM....D.'.....S..@.p.")J...C....r8Mb...[...H m.3...../A........~#g..XY.M. I..h...X%..ZZ.}&..x.W/...)@O"..t>....BH't.!n"w2....I.....f}.a...OV#..=.{K..m..I.0..Am.J\.{S....J..$3..gD.=>....ai.J........@...bo...........T.F.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):86001
                  Entropy (8bit):7.997746959390057
                  Encrypted:true
                  SSDEEP:1536:io3QO48AxMz2XuljmTzUYTARBWzUW/iPovNZQCtQmgsbFPvPPxHuBlj8D3:PQOpAxMBpmxARQzB/V3XXxyl4D
                  MD5:A766317CE54520EDA28F619E97C3889E
                  SHA1:965A69B2ECF01B5BD77A7F2FFA67AA07D7AA727A
                  SHA-256:DA994CD05E1C1505A50F65975AF1F4E872861C4F338BDBF4AA00BACB8978D1BF
                  SHA-512:4771B72C64996F4C8A81E03C5C55DAD7DB74DE85B30F8C06A08DED6586DDAF8E85D37503115E7A0B62A3D9B7AC4FD45D28A326649FCDBE83CE7D2B19ABBB993F
                  Malicious:true
                  Preview:.e.z......]v".zn..U..-x..k.s........&?(-)..O.......q...xx_.D..B........^xA........;;.....S...}..u..7....3:..r.3.rl....v,......Ys..6 C.d..P.f....../A ..1:.8..3.b.3\.^..vJ..=.I9.A..:.W../....F..#oa..y.j.,+..B.S.%r..f]@.k(.8..q..B..kW..M..L.o.....Np.g...}.....C...D6..Ne1:u..I..@......+.&..h.....QVa. ...d.....B.d.%...T)..5..B...~....;.[...|.[...o.hX.....`.....{..........>..'...4.].E........TP..}...+^x.......9."...s.i)...B.}.O0.......8)....w....}.....3UC..%..(..6H".y6."`..7......R..%.F2.... 8O.a.."..U.:.%}P..s..U.W#K.....Iq|...&..BD.xnx.3....@... ....911Z..I..;..!..h4(<M.^...p..7.*..0...../..,.n)..x...r3.F..1.D.".j!..v&....52...A...,...:~bu.....%..A7-.c.n+8.S.x...g.........4X=.dOr.P.....1.2......T/#0....u~u.....l...#.:l}...#..F..b......._"....o..by...~u..6."./6..X...y....8.......yE}../..R.f...{;...!.Z.K.q<.V..ul..J.m.....>.O...J.......I}....x?...H'c...H.+R....).u...........j.&...........X.ky..!]..%#&...4?.1...u_...1......vB1($_
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30139
                  Entropy (8bit):7.99361545753572
                  Encrypted:true
                  SSDEEP:768:u/homOUAQiLHN0fqMVVnMZ7+lRPqFhf+7H4Bx1rXzk:cZOZQKt0fqRZAohf+7H8x1r
                  MD5:178D289A07655095999CC0F2D47C22AB
                  SHA1:3985EC46C586ADD96568BB215E7F847EEA5BBD1A
                  SHA-256:CF458DE81D5ED863AE793EF87E40B0A08AA3CD396CCF18843EC66DB233E151D5
                  SHA-512:C45760E2B96BB486BE98A46ABE9DA63DE89CB7F0A8D947BD4F964007EDD62524AB2DDE977F907943DD540E72E065B241B5FC00C491F69D8F2124B79DD679D0F0
                  Malicious:true
                  Preview:......~.m@Y.<.>.n.w..D...A....a...V..J..........i.U-.C.....m1.Z............_PDo.i.F.......7]s......|b4...j4.....Ek%$.'T_..p..&.....[t,..[..........m..}........>..{.qm....3-,.v...i>lv.T2l.3..+......i.k...f...-.$..Y@..h..[.8u.'t....01..T...q.........T{.|..G......iUS.L+./...c...a.......^..xhhI.3.l@.......B.C..W=D...2....MZ!..M......]pjD.T..D.}C.LH;9Opy.;{.b..i..a..........c.-S|......aI...8W.e!T.E..].L#_..b...g.;.y.P.B...m.....4K.e...V..Tn^....X.,.#.ysd.Uv-W.9..L....rJ.Md8.1}...W......F...7.y.GE.j\..|......).}.LK_.G.'.[#.{m....G .$A....9s2o...|....O.=....l._.....k.9tQ.k......55$7.b`..nL7...7./..._...1%.">.0D}....A$.....V..*....3..u[k.j....O.-.J.>D.....6....<x.{.y...rP.T..d}..o.4w...vsCG.y...r`.n.d*.M.0b$.m.YZw<...J....4a.6..l*!..s.T.J.....w..{.r.m..Q.\...g6.e.....M._Jhp.|N..JXk...[.n0h.+-.."h./.F.J....Bh&4sO.....I..Wdq...0o.}_p{...y7...|I9.$"m..\kl.o.>......"..N..y?h..G.{..B.BX...<.O.....?.*D./..P.[..\a..9.U.V.@{d..r.....:a..........`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):499
                  Entropy (8bit):7.407588987051547
                  Encrypted:false
                  SSDEEP:12:DnpcZKDeZgcr4Wc76PsrkL9JJS3kfwkYXnEfbC:yZz+cr4Wc76UrkL93S3QQE
                  MD5:A83A5891861532F61380B4A5B10BEB09
                  SHA1:60837114FE4EC3BA6EC232EC74272070A2396CD1
                  SHA-256:FC8B1053FE7AFF713497F19B82B356FB36754B1DD0776FD4C7A050BCF85D31C4
                  SHA-512:A6C0CE0023A6C2D69E8CE75AF42C3B9D4319C8EF2DD0FBBDA24A3A0206E3291AEF40C6073891AAA3288F43C9EB01FEC26DFF8018FAAD7095BD12F61C49C7FF16
                  Malicious:false
                  Preview:.o.$e.c....>.].'.......H4..(. .s.D[.2..........h.-97.|^.\$f."d.....1..^{w...i.^.."...S6.G...]...#{.a+.m.w.9?..@A...m..|.N.J5..d.6.kFib....`..o.X.|..........}"..........hO]..d.<...e.ZG.S":m...*8..9....;..L.j. .P.,R..1..j..>.S.:.....<.......}J.l.....q1.......l.5...(.%O../>..w....Im....zp.J.T..S..* Te\ ..z;..ep..+..}..."tX;.....IV&.-.. .5..E"...`..L.[L.(D......?I.......D].#M.Cn.L.e#..S.........D......g.A._.m.Z#?.....4Q..2.#.R.....O...g.]..Ah.X..........S...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):777
                  Entropy (8bit):7.7071635718731555
                  Encrypted:false
                  SSDEEP:12:OXF5NrOEOKPrIENoU8ZwHzvKydzY9HmsdSiGCaLgeHv1UdBuoe02T2EcYAkc/E:w5NBrISMZWjKydzoGYOD2TuF026A
                  MD5:8ACCC7F4CAEABA201086928944AC8518
                  SHA1:D553869A85B745F16537836DDC813475C6858596
                  SHA-256:14A926860CF7A831EBAB866EC79D3EE285252B1D66A1A50F2B7CEB97A97ADD2F
                  SHA-512:65FC11077A404C2E683FE2296014C61BDFD3D926AF81FB2AE9974857126149D312EE54BD6F9F63B3F39272D021349BD83F38305F5C7216B9DA59D034853EDD4D
                  Malicious:false
                  Preview:.s./i}9.......Y.a. U.l....l.......l.*.J'...E...T.I$.4......!.j.p.HB.f....z....F.D#..u..{..b.+7V.Nq.|[...A4;.7SRQ*........%%n:E..B..=:.....C.=.QN.xn.....=...[iD....i.|b.....e..%H....s.F..........W..s.FJ......&<..&n..4....,.....|0.*S..KOI.r+.G.7}.%...,.j.f.Q..v.GC.z..g....].Y...r._Hb'.ut8]..;..c.........$..P.BA..r.SaS...5/7o.....Q*..5.E.g......)j4....a!..}&....6.%:hle.....}W..S.....o$........c-13.p`R}..YrW........E...X_..,c;.:...lL"..\H.{7A@!.fUh,..qu...`.&9......@.J6...).? .....~Z*..:.l...].Q..D...#.>.W..g.H..v..g.7Nx1...<q.4....w.U+....8....03...g.....\QS..../m.v.....u.M.E...?W.n.P...E..^O$.....t............WTN^......3.@.j[Gq.b...i........$...D..C_..i.*.>..l..z.....D.'..9..6.q.Q..J...=.o.iq........i...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):449
                  Entropy (8bit):7.419345002512387
                  Encrypted:false
                  SSDEEP:12:j/+1exmtKRnT4PKG6NWreltCyYyXesq73K0cuz:L+RtcnTM6NWQa/73KD
                  MD5:7D84FC6DC4D7891AF83B12F8AA1C8956
                  SHA1:B610415148301D15B91F8F436742CF69C0F334AB
                  SHA-256:399C6793FFA1B89B4E8793A8E3040F3A00B2B9B1C3901BCEAE9EE4F482921900
                  SHA-512:CBCFDAE0D91EC1BA43A2A8D202B12E0BF0D90CFEA7E9F5091C818C4145F0342839B231E53031E16B013881D394CA692F34C57C61DEEDB02CADF593EF415E1B0C
                  Malicious:false
                  Preview:-..^..Y.[&.....0.....O.q.N.Hb.is.KN[.............TynYVu)y.,..g5I.....C.1"M..K&l..D%....cG....&..P.nr.?.....5.^.f.>....Z.6.W..}].q.."..\.r9.bd...p".@..|P'.....2j.`{R..../..5..,. ..&X2.Y.*..?.."...h.2.m~JPx.h.}....z.O+.eS.?..>.<..4.'qd.k..v......o. w...@.U/JC>)d\.=..,.~p....O..J/|......Q.>.@.....0,.c[...m..(%..z...#({..u.9^.c..2.....!.........p.#....)..N.pZH...|....r"..`..=...nY..Zt.7/.ES0..uz.........!...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):723
                  Entropy (8bit):7.600124020759285
                  Encrypted:false
                  SSDEEP:12:e6kDS8nCmi+awMjKHQWmaMFHNkZLfDhDO3K3rPqEV9gbDQrQZyGMg4balMXn71D:e6KnCmi+wjKHQWmJ+Rbo6rT93rQZyGMD
                  MD5:9BB1A2A25F8D6F1A23D950AC2339951C
                  SHA1:AF02A47BAFE6C04E3EC8F352001BB1AE72FEB6F1
                  SHA-256:B589574259182E12AE5FFCC8A044CBBAA6D907B5E46483546E3A5EC5DCCB60BA
                  SHA-512:7DCD257F0F50F936A1DE6B2342D84B74F4D6BA816F24E8C9863DB129ED6F4EA23894A2F57DE53EAB488F37C12A26BE31E675BDDB337A4E1BCEDBD41716317EB1
                  Malicious:false
                  Preview:.))F.uC...U 7.....3RyD........l^.N.!.8..ZOL.fDSx.>..{....VT\o>.....[..*6|..........S..b.R..!.k......E....<.....N.....r%.7..C...%..?)4.....].".4._.....%..W..}.3&..ZX.m.VZ._.}"..NuIG!~.t.6z.v.x..9.......8..%9..L..H:..0.3.GV}9.{....h...$.....vQ...6.'..6....-...n.C|..D...k...k?..V,..C...i.i.....8......' ..I....?e..;.1.......Y....:(l...F...a..........})..TD.r.y.Xs(U....,[......K.T...r.zE?gE8].E.L.k7<...(....[l.....I...&.%...JF...q.S..B...`..."+..?...=K..|%7.v....q.7..4...el ..;..+V.O......4.%./T....7Kn......n'..;.&.F.a..IM..-..q.<.q.b.*....Ik..K.(7I...e...63.L..rb.`.A.=9...#........?.JE..J$yx_...s.....3........&._..~.`!C.!.\.N.fU...^(.L.E......9..M..K.se=.|.K5........3...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1504
                  Entropy (8bit):7.8363640536134875
                  Encrypted:false
                  SSDEEP:24:Y+9kyHNAw3VM3RNKWuFB+2Q1QAJAIGTZUbRUaP3UVsdpsdREH+jRzvXWrMKk:YLgN3VYRNKdFB+t1Xk1UbyacGiIH+jRh
                  MD5:3B24C2E976C6D93EC4CC6793B54BC2FF
                  SHA1:C0EA043BAFC66EFF28DEED37AE3296D1F09A2BCC
                  SHA-256:22DC4039A1284D3E3F89109AE5A7F12B5C304FF15D572637E63361DBB7FF7ED6
                  SHA-512:35B945FB936639FDFE8B8499A4268FCD70F98D3326DC71F32DA2350175F2E8493A5363BE856A2E314C6DE7BD32539F466FCE02AD87E7DF939D8C6AFBB69148BE
                  Malicious:false
                  Preview:.V*.c4.\.Dhs..0ta|.+..rW.o.......lF....m....!.^.X.).....x..u*'{.$..#%..fx.;.6...9"...v.]km..%.G+.W..$.........e...M1!.4.0.R.Bg.W..........{....B..a...+.JJ9...5...fP...*_.x.*.Q......?.Mo.a.D....06.^....@..E.....d.(.i.hu[F..{..t..'....QW*.y[4....}....16..M.Z.....0j@X.jp...9..D.GO.+.Hd;.3..Xa..`LH.}<..\;*Y.V...=.....V...!L..i .."...XX.....{...L.../o=..._....R.....1vR...s!.?.jWJ.@..(...O.[...8}...X?.{U.;.....M.@-...p#l.{.......kw"...[..5..C..f....]2.<R.y...>&.g.....2..l.GR...E.\.3d.x.8.t.{.n.r*......=....XMDU&....m...D9!R..l....m..B.8\ys...y.N..LS.B^.V.>[...U.L|...x.h...s.....B4.].a.iv...X.7.Y.H..uW.q"..,[.J....q.[..W....8....I.@.+O.|;t..g/V.....UU.%EX..?."...z.>\.7.g...u..s.v...5."U.``..%.Y&.J..B..eh...J.....>Q..BC'..&.%...........T...?..l:....l.c.c.&...|.%.0...z..".l...a..."r......l.q|...._......2...].2.n.)l/.mz....<"........u..B6-..ucv<...........O.4_..;.....I......uk.#..bu..AY.G..q..C7w<..l.4........8..^...tT.R.{U..Z...Q........0.....G.za..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2662
                  Entropy (8bit):7.918325284641231
                  Encrypted:false
                  SSDEEP:48:6i4b+kR+gkZhclNIuxTeOnCIxMkldLqCAvTO0gRDQgi8y89:6iqZkjWIuxTeOCqMiVqZrLGUrY
                  MD5:5535E21E5BA8AFAA4C4BF1D817C940E1
                  SHA1:9D337251E4E0645325450C10A659A9A3748FEB01
                  SHA-256:77BD763A56A4CF36AEE3F43804B679DA5015EE30BAD4827A2080E9025C654B20
                  SHA-512:CD419927545F95C4C35FA1493ED724AECB8E5E4C5D3E7CBEF9903E63AD2D03B6E118BBE37FE4EBDF0F61C0F7D6D0EA0A44FBD70F40A01B1C69E8DB5B1BB73E06
                  Malicious:false
                  Preview:.WF....?...w....`.,.,\;e........I!M&.V.%...ZUl.....T.S..dU....OF...[...k.1.V...5.K...w...mt...(X..v..v.m.4...8..k.).......GUr..s.i$.r&.T.+......Qv.l.BW.....'_HF.|m..A....o*m*Tw;.P,.C..h....QF3...:_#Y..|.@.*.O%.`.2....WK...$o8.......a..kj....v.].t..&...S|.F...9....{B.z.{......O...h..u......P{...5[@lc8..jm.......G..P...vJo..........P..<.Y9N_1.Rj8...J6/{.qO!....f..l......Oe.=.mj.Q..../.........<....E$.........G..fli|..c.9.l[.\sc.../D .E.H...H.|@..O..T.Y.i.9........j.N;.BE.t.`.]u....g~zGm.EN...bZB..^A......:D...`L.a........U...........8...4.#.tk..@2<s.(.80..........\ ..@.._...RH.q......bj3E?......RG.U^.!X.......T......U..A.g........mu.-ag%.>Q..l.Rc.b*.(ps....7..G.{t.[..$@.W...........)cC.$.3..X9,p.P.8]d._e....q'...9.@.m!:....:....w.....F.....6..R..4OK...dH.]...S...x.,*....^....y.`...p.....zn.9.E.....d..YK...h...aD..C.J..,...LbV....T9J ..`..Y...= (Apml-.RE.B.O.Z.......3..5)t....e...K.3wr...%.....IG...~.h.n.../..1O.q.RT.Y.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2431
                  Entropy (8bit):7.9162606466606125
                  Encrypted:false
                  SSDEEP:48:11NW5aZnSFyTg0HFfjeLQRjfDM/ufzYpI/ynDZhnpRCA:1PndTpLsEY/ufzmF
                  MD5:1280B2E7167F0AD089A6FC21A6FF37E7
                  SHA1:542F56D454813A1454690808D0127173764B408D
                  SHA-256:7B6FB6AF4471FDB2E501D61BCC46C6BDADC1542C54F255B187FC5574810754BD
                  SHA-512:E1B27330C9872BB8F3EDADBC887FF99AF4DE31534F70D0F3B4E881C0682FE7F68CF74CC87E3099E50632800408668A265E006A862799BAE3DC2DA881ECBAB122
                  Malicious:false
                  Preview:^...Z\.J..p....'/.N%..>..8....{......mX..7..M#.8..awI<.AXf|".....L...^SF....z..8.H.R6+gd....#.<.=.O..]z.*#U.(..y.K-....P...s.+.#.S..H..o..3..'.v..4......)N.>../.y.!RaH#z...;[a@S.n......_.9v.&P.U''....5?).l p..62].._k.._f.<.....s... R.l.o]..i]..04..SA..i...........z.U.Q.i`N...]._....8...%.....i..;.?.S@.oe.s....9.\D..........C..#.q.1BCU`{..M9.........s."H....'..v.P.s..41.@.......(+..]Y'....L.t-(...!5.<#.......@..(b.....z.Lf...QZ.I.S.BE.....l.._R...,..u..&....T^`.Z&r..V...z....2..........il...1.B.M.I...f..5,.}FX7?Y.{O!.rQ.....s....DT".$....RS......,..e..g...V".[.Y....ym!*@c.$d[..w.!...'_at.8......U^."lO..l..+J..[.H~..q.Q...r..&.{...ZS..%..dA;...Ac......R...'..6>..P....9d...E...Q.@]...M.1....?]}..%Mw........y@..".....G..m./t,.r.\..&...M....!S6.[1q.V.....s:SF....i.S=.3..~....q[.XV.m..G>.V.i..7.sB.+.U..S....hG$.9T...k.d%LA..3..])%1.*...6.f..K..,..........8...h..^l....8Wr.;/...u..M.y..w..Ws.?',..^*?N[.i..H..{.`.~.aN.pB....l.u.j.gQ......_..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5072
                  Entropy (8bit):7.958060345511452
                  Encrypted:false
                  SSDEEP:96:l/egXwwm7kFAB9gNH8WXjAftnLktF34+lI+zJfnnQv25kyYiaqsc7bG5VSD:lZXwwmgV988AyrlI2Qv25k1L0O2
                  MD5:E5EF1E8EF6F00DAA246AC6864DFE87C3
                  SHA1:7547237B7729E1F7A3AC131F5B161FA3ECC86445
                  SHA-256:EDAB4E558A375F15AD50F59DEEF63BF8B5B7F0BE786291E876737864110CDCBB
                  SHA-512:CF1143DA5A1787FA627598CE4D2CE4D11DE1C11E1EDA72B4F55DAA087107E7715D73630B9700AF3FEE499F8AFB8170F9AFC62F0B0458DFAF97E887D1FABD2724
                  Malicious:false
                  Preview:=.9..,..x.U...~#3.s..TZ..7.k.!.<.|.(/3.,7.#|....a.JI9..H.;.|j..0^...!.s....o..".../o._..]Z..J.......u~XT..D...Tr..E..e#.~..u.T.......R?..eg....,i....!J....SwAF.lI..a.B)f.V%..3L^......84.1....{-.@d9+......(.....8..V5..+q..0m....V...c(..r....>.;k@....S}.K.i.s..S...t.I...t....b.P`L m\..aR......8..z..........b.....4..P)..~...W.G.*...V.?k.H![NE7T.k.#W.(c..wg........0_.=...QV.U._...`.M#....U....|Y.y..{.SVkP.T..0...Z...ZGpodX......p.."Th...._T....Sq..b...n`.8....h........8.`.......6....sb.....Zu.l.d.\^.*.".>.|Xd...mT..A.s}...Y. e...B@..Dz..T.........$....U.....EV.o/...B..r......).o.D-.!=..k;.l4.l6..3..4*:5~...N....+.p...B.8].....K;|.a..%...(#.....zp.q%.O...b..d.j...l.*L.....g0.........f...-..........^.M.C........`.O.5:.4..tE.i"n..._ ...k...-.R.,&i...s...l..Y.P..Vn..R.........L..Wrk".~....}...x..M...Q...N..eG.l.9.%.%BI.....*..".Vg...}..,hw.....5w..+ %.J...B.}k..n...*.'......RC:..6.*f..a.g).....T.>D..U..<#QS.1BST}.D.q..T.S.G@=..o.,....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):789
                  Entropy (8bit):7.673982879073894
                  Encrypted:false
                  SSDEEP:24:GqRUIYYQUruXGXl8bEQS4dGQKKZ962Zk0xnFf:XRXNeMmbEHLQzZ9Y0
                  MD5:5E18907D206749FE6B6EDB3D16EEBAC5
                  SHA1:E0E186760E74957495AE9790CAFE43EC24ADF608
                  SHA-256:1425F2DA865F4E715BAA1D2E8EABAD40572D5A326A06E3E145FA04B6EEAE695C
                  SHA-512:25DAB96843C2CAA6BB53F2ACF2EECCEB320660338DF7F2609574D214C7270584EBEA36BB81518C691CAC5FF7F993441497DC765318FE90DFDC22F12DD1F9B339
                  Malicious:false
                  Preview:...o.X.j.{Ki..[......r@.....u.....C#.&.h.Cm-.u.3..o.I.x..a.. ....`t.i].=*.$...ve..F.f?x.q........`.|.....a3..gm=.!!.1.xr.Q..B..<.x..g...:..84.f..*%p..9.?;...w`......P..........*...ld..D+Y..$..t...U0.d...m.h..#KgFG....[..>.%.......73.D=..T.[.a...D.B.^..^.......W.ep.H...C.c..L........<z.>..w.2...{...y...8+.....X...5$.T\..T..1.....D..}......4b..>E.V~u..vn...M.+...T.R..i..}EZ..,D.W....b..r.S..G^L.l.'/)B...'..D{..............e....2kn.z.Q....zm.....T>A]..d7mN.4..Ct?......71W\#......g..n..O...1.B.....a..|d....J..E....M.muI..~0j...f=..@.#.oXT..Y..;.....&32A..\d._..A..GEX...*7l7.H.|$...4.}=>.SQhe].c.eU.@...^>}.r...<iJ~..UU......:........r..6..>83j.....h..u.......\O. &.g.......GDoF..).....4..F(,[.eh.........t...2.........u...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1551
                  Entropy (8bit):7.858756745382044
                  Encrypted:false
                  SSDEEP:48:Vs+llsqLbCdByjMM8YvFaGSldeLgQv8vKg:++3sqXCTyuYvAyYKg
                  MD5:37383EDA4B52FDA53C9684B5D94E4C7F
                  SHA1:C54EF5B7632E34610083A3C6A463E303D328B617
                  SHA-256:A1114E7DCFCAFA30AC8D7D630D6BCBA11E91AD6C79167D264C0AC189B49235E0
                  SHA-512:2A0CC8AF0E70891D5CD9F46A7360E291733B1CD08E1C6EE8B5302D6C2FBFD8AD3BA1E4A16669122DD1D9B1746EB6ACC7B1C0B0EE14A7DE6F44D9F9F5E5780FBC
                  Malicious:false
                  Preview:5L),f,.[4t.#.....\.H9..S.s.9a{63.?E.,.Pb......]..c%"s.I...B&..%....QZ...7...69(..a=.......@j.\.Z._Qs.=..b..$E2...f.o.o...).,..1q... ...e.....{....>|r. v.X.].yJ...O....lzkz...........'......;..]e...E8..2...>......p...aV.YZ...L..5.Q..#.:.!).}...r....tkxP..R\.B1.R..qmU..:....~ZX..... ......._#V!...(Jzr`.W.S]<..3g.L..HrF..L."NC.G.....pU..}{L...J.0.xD9..Z7F....=I...........\.=.>.9.a%..{.HDOs2..@...CW,s.;.Rq..i..KjooQ8.g.W|rd.c.K3.....Z..m...Qe.L...Dr..O.A..+.;.=.YT..y..,^...k3LTJ....@,....k.H............ ...}..Z....>.F.X..v.[..b...U.......8...L..1sB{$.......D.f..1.q.ak..x.O....O...h./VX.Z.<.>OqvI....sW0.d5...i.$.P.".O...g}W9L]...u.......u.>..R..........._1...&|Z'.6..r..)=........N..O}v...:.c.a..WF.M.#...V..q2....M.....o<..2.xH..FF.B...OwI.KClp.._..^&]..q#.C....b......b#jm....xMr]......MN.P...Z.......a..>.u;..F..'U.-:.B..M....6..`..c..R....Q.E ....S..G.A..6.\#.......".LN........V......S...2...).=aIp.W.5Q..S&....F.SF[ui8.?.EK.z_..Kx.B.y
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1128
                  Entropy (8bit):7.781709363524155
                  Encrypted:false
                  SSDEEP:24:w8uXf/5PH8vmGnG6u2S892Wts3mCdg6CFvzk:w8q3hH1uG6u692x1gf
                  MD5:21B1172EBC7F72B05B562730462F0340
                  SHA1:8DBF7D35E6265C718867962B2A225ABBDBABF469
                  SHA-256:8C2684A2B85583045F7D080AC4D77157328B605D8C58DE70C61D7330F7930384
                  SHA-512:98447802B4E93321725DAF827E6CB1D7925ADAE18CD8CE86FDD02A375860A077F9BEC14423160C5A1C620D18E159F40FAD6F3DB442E3007A5C65A9E79F1610B9
                  Malicious:false
                  Preview:b........w!.x..:c*.....O2E.b5.....w........z-..Qy./F.b..E...Er...wx...A..0.r.....=.j.fK..w\.jN.&bb3$[..q..>..Ao.....l<..l...t..c+z........'.8H.....V1.....uU../.Y%.V..(...n8...K...O'u.IE..q-....H........ty.U.....&.C.....v'....i._9....N...j.^S..,dl...p`.&BL)d....E.5.z].S.N...r.]. .l....mC.m8i......p..K.w...C(.G.Z:f.k*+".]....W...1.V.P.q>o.,.0.h..P">.......-+.v*^h....i.u....M.'-....7|,=.u7..y.s8.-. "".}.DCw...?;k..G.......SV..Q...A.3..e....&.4.....1..qy#...(..l%!.*.*fa%]...R..Pl..ZR.G.....$C....n.~H9...zI0!...S..._.z..;...I[v.W...R0.a.Q..:..).j.....k..,....<...-.q...K#@)@y2....s...2..... Df...P=t._s..D.uL:.=........LP.l_....&.-.N.a.T..a..`.nm....*......i<A.N=. .>D.r.%.Z.pl.Odwr..>.r0g`/..m..3.........G..-D..<..+.>...>.XS.KJ.....-D.X.)N.B.FD1..?"q}h.4.u6...@.~B.N]../...@..P..)o.]..BOY..]Z........X..>..ahz..P.5.1x..+..3..>..b..Y...^<">...04..+..>. .!Q.NU./..@........?......`J...<...!.......^.L.D_.r`.p9U.......7g_.u....<.v.<...|V..i;w... .tJ_a8.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):791
                  Entropy (8bit):7.689795566992201
                  Encrypted:false
                  SSDEEP:12:8t7z34WJRk6V3KZcdZvuUhP/7LQsEiUSdgyUb8KWrgt6kl1W0h5zYFzHR14k3KA2:85z3DRpaZEZydyVKP6uF+R14wKtVA
                  MD5:501B3E4F797CEF0FFCB162212B488800
                  SHA1:9041E8BDE0DED50647ECE114E23AD65B7662137E
                  SHA-256:6E00D1B473B56F1A4C66B68F1BD51BF95F49E9A2FC1990EB02C0F1EB66A3B9D1
                  SHA-512:F2D987337754C43CAB78524147ABB3EB6C7F45E6167F30B7CB2C53915C4FEEDCC521209A32717C760178AEA2C3BBE1EAF7BECC9B8BBEFE4C5CFEA9B0D89C3972
                  Malicious:false
                  Preview:....7...z.z.nYj...X.ZPj.0y..>dd:.ab`Z.}.H...Z.......N.".h.$...:.J.1..6I..g...;r.{c..O=..N...Q...|.=u.hM.7A.<.._@q.uaeUp.._.W.h}|u'.y;.gsV*.../UHM).C.........r...N-.5.5....-n5.[.....$...Z..-...=[.1c.7....c....\.O.O.qT1y...U..V?...KG....Ou!...x..._.5.A7I.N.R.eG.....Jv.......[.v'....yX^...!D. "D.8t..V${.eK.iB...D.h.N....@.<;...4R..V.....Y.....a..A...A..cV....E2.9....X0.&./.Ii.G.:hU...\....6..X..&*(......hZ...`..QO..#..pF.xI.#.....mc..y....a..^.........k......{.n_..+..b......x......u.n...6......F.....e5.....L"....;..-@...J)q.^zL{2u.h...].._t.......~p.w5@..#.5..'...H.?..."..F}.....~g.....G..4.T.RA.h'...?....;; n..&8...U.5....v.....\4..(.A.H...v^...u9.D.w........@L....rM...@J..._..I.....8Kn....7i..tu......'k......=........w...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1531
                  Entropy (8bit):7.861688268968377
                  Encrypted:false
                  SSDEEP:24:96ziO0CySzx2uUD2ndJomZa12fOhZHy811VdxHrmpXcSYCBB2151ZfOog:96iOl5jO2ndJ5I2fOSg1Vd5LSYCiyo
                  MD5:A309DD4485AC987D7B4E80D01ED7A7E5
                  SHA1:5FBC2EC10D8363E73340DFC9DACD9C04F1AC6C27
                  SHA-256:75FE2360CD4A52ECB69FFBB76DB36F1E179C759D17A67E04FEBEB24B18B6442F
                  SHA-512:95317B222033DC3E827E0A9402BF8A2104225A5D83BA824E3C71AF381EE11CEF234477DD502D256A63F36C7AC44634AB95209D26DEE7DAFA8DF8F3EB52008DCD
                  Malicious:false
                  Preview:r+.d.7"v.XV.w^\......u.....y.Z....W..?...9.1...V.5G.\..F..v`...h.eX.@...N.RA_LA.....N.[m.....e>....l.1B+`..H...%J.J.i@......K.......i.)~.n...X..?`...(..)J\k*R..........E.M!\.D..W....7.q.._...~.1,......~..S....^Cj.Z...8.\.......!..7.M.,e.m.ygj... ..XCs]...J...J..........._...8.....&.};r.7..#............P.L6AG..V..B|<..P..s.5iX7..$.6..W]....A..,..,.s.n.[.%..H...u...H@..H..r.3.s.....k]H&.$~.F..t..`..........c. ...S..r.|`O...+5|..9X..+..y..a.8..Np.q)].s...0........~v?..%0.'\.E.;D.E.{D.....hr.9k.WM..6.....A..^,.G...[0.q),.@lP.x..s.....t@.}..+YV.U.&Sx.......:....U>.:.....Q*........e.j....-.3.....3...]m%.W..*=.c.j<0.w../,}...O....7.^..Oi....C...4.2.R.xr.Z....?......C.D..w.`x.l...P..c}.J....<... .... .4.k;..>.1.n.=....%...B.5...d.7..-)q.S!J#.(G.m......ZFM.....d.....&..c...&.....3..............7.+.ba...E..S..T.........t.s[L...H......hK8t..c..G..a.N..?g.8...Z.3....<.I.'....z{.X.4Q.D.}q._.!L.1..)5...#.9.{..f...$.h!.~..."t.p....V.a.]..P....8L.'k.K...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1590
                  Entropy (8bit):7.851531574101846
                  Encrypted:false
                  SSDEEP:48:F564FuHkKjk8LXUlE+ULTEkhkeQQByOsPi7i:F564Fm4OAjkls1
                  MD5:AA9433D93F3A68C21DFC57C17B3902FF
                  SHA1:7BEFFF59A5706EBC35CB983A7C8A929F513E2157
                  SHA-256:E26E11A3B840EA78FD2C5C8357A1FAAFB29695AA87997A14975807C4035BDDAE
                  SHA-512:44716BFE619A3E44E802E24D375D37D212C0528E8B58B6F157C28DA6A9F20CB156FFE71542424EE84C785B59E647AE7FAC9705B12EE70AA6888CAAD364D3749C
                  Malicious:false
                  Preview:((..q..t.V.;.......~.gAc.-.K.M...(.......w.0-1..N.?t...+@.^3,...ek[...W...:A.e+...096...M<.N;...t.C....x.o.N....\T....H.!9...!.H0.._..xu..'3eyWv..q_.&.D..j._..c..XJ.`....Gr.kX...-.]A.q....=.a.1.g^)B.0..#.r.mRw.!'.M..p\.....$_@.0_.X... 8b[.(...I..*.D.6....GX|+%.F@G...,f..d..d.....E~./..T.z...{.W.y...........^..6..G#!.....B?..a.z..........q.`}.h,.t.m..!.&.a.ig..... ....IU.M:..7....Zp....G. .}..8.U..#'[.=J1..c.E\./..1.V.gf..<.....u..x[M..Q..`1..v.D(,.......S.7..^vI,C<0..x..Sm7......ne..i..D..2A(z...._.^....(...z.p8...m......S):.|K$..F..Vcg'"...V...#.g.sQ..z..T..="h...P...#..U...d8.a.-.B..9.[C.V.[..@5..ek)j.....(.I.P..O..W..p.0.v..[.hX?s..d.U..1.'.....S..>.,.f...I1.*.I..s.....B..c.4..U..h.b..Yl.7.k..NK.#)....%.b.1.N..|.._...4.5.#0m...J....XaU.... n..."_...i...F.E.E.&p.M.+Dr.g...?..*@........ .....J...s..<...23....1....}vc..D2...+.%.RB.....?..D....AE..5X...{..7....#}....I..G.)oYon-...z..G.....d.i.Q..........}.c..?..f.!..&....M......[..P
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):699
                  Entropy (8bit):7.637127173464923
                  Encrypted:false
                  SSDEEP:12:0kE35nKLRzfpqwwYKYqqSLj7eprE83DN7U0LcMi79yttJZ/lJQeFYK9KRv3HE:0vpnKLRzAXYK7qSLepgmN7U0AWtbXQei
                  MD5:85E2AC283B2E2A28FDAF5577F07F1F24
                  SHA1:D561C402372E61FC52A5572E320135B017BFA2A7
                  SHA-256:B091E67F2A80D2DD5710255E5DA8EFF87477E753903C176E313342FE585DBA02
                  SHA-512:95BD06D17B21C54562C042568D7264B7545EA33D727FF3BC00E4272A6880837ABDCFE1BD1B1362414408E6CDE44D675E86A269F6B01D590DA7A339B1F17A0403
                  Malicious:false
                  Preview:B.+.f[.s.xb..I.D..K....\....j.....y.7.j..r^.3.)..9../7..J'.C..(..y...o?_.W..../}.VK.u.....1t.....e\.-..........,U..|~..,x..B...Yf..<0..g.#.E.S.A..;;.......&.\.c...Z...9.......!..m..J.+%h..#..F...T.R.:...j...q.u.6$m.K......Z......+.;>.i.1.3....Y.".....@..FM...F%.=7l.....-.Q].9_ x8..i.y..~...p...+.niA.ZH7B..z.}...5C4..or.18(.l.)..XV.p.RfI.\%_...._..E.x.......|`..xy..O...R.<^ J>.O2u.... K."*.Nn........Qq.l.p:Z.=..c+.O.F.R.S.....{.^itB..._.J..W.W. ...}!.B@H6..>....qWf..u!v.2$,.&?.^.#.......e..7ig.gh."X+G.".=._...k.U.j...i./I.H.;j..PJ..KW`..\.........)>J.^.4....P#6<....].........;...;.[..W.}s..d.U...E..k....:.7[.V..c.....xIF......l........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):937
                  Entropy (8bit):7.702195989673947
                  Encrypted:false
                  SSDEEP:24:THQzXh9J8ZAl/uN4PEIR3pG/lkGZiwqQUIiUTNV48B8:THQzXrWZmm0+OGZzq6iUTNV48B
                  MD5:9A326DF19AADC1652F362F35BF7B47AC
                  SHA1:2D5E61D99FBED0FA90F4416CB0233493B7DEED19
                  SHA-256:FC71F7140D523BBD521BB21BCE73706F9A020927B0C73F07041B6CC4E5D82667
                  SHA-512:F9B71BB4053E2D29F20D5D6091B66E1EB4A57B6BC4BF32CCA6FE00621B1B272A7A3159C986A1F1AD4A48BABC38B4C45314BF75ED752A47C2F53259C8598294A2
                  Malicious:false
                  Preview:5.1g.e.]..b.MB....^-.L@-.1d~w..*.#t=.o..Qg'...B....!.N.U..-x..t..uBgj].u...).{Z....`...t..H......eI.X......0'.o.x.IEG.._.R..;.Z...h.......E..Q...1........Y..97J-.i...@.E.l.........DWq.&......z.t5;..Ra:e.'.g@.....:.F.Z....=t.....".[.qp..4V...7Q..}].._.t...7..$_>....)y.\..W.q./...<..\.];.V....BM.P..<...TE..>].._......V...E.....y...,(o.e.#o..g@..~..9..^.....>.....;u........R.$'.$q......%H..O.De|ii..Q..'1...<.B..V.r^.6../..y../.....-Jg....r..m..];A4^.Q......~%.ow... F.y..n.1..W.=...n.X.........F_^.%r..7...._.B.H.9......y...W+U7.....;...Z...+GM.*u.&..s.o..'9|!...q.....<."Jn...J.MAr\..G./p.k..d..EV.1... ..W.+.z,..'........{.J..Y.qH7......^.0y4j.J'...?..e..>.....iWAwg......*...g(...e1.RWu.....S+...4...Z.i...d].g..&...9........3..P..].............t....=..I.v.U.P7.a&..T.(.6<{.E.k...0.PB8.7.^0&P...U.+8..........?v...Z.J......W$....l+.?...&l?.5.._(.e..Qcr=.......S.a........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14963
                  Entropy (8bit):7.987096605057169
                  Encrypted:false
                  SSDEEP:384:aMqE4+A1vEJ9pEYKMiAMnIIWs9yWqPbLXU4app/H:aJE4zvEJ9pFrMIIWUqDLlaLH
                  MD5:A0312181CC70F2CB6BC0A83A7D36BFD3
                  SHA1:0E5EC88DC8DC188FE1DCEC0FEF64FBEDC187D81C
                  SHA-256:1F7CCAE116E4D6899E365A7D82D57EFCD8FC29DD1DBE4AACB6219258EC41F7EB
                  SHA-512:7FCCCC340FF1F42A41210441FDAE1AFC5EC0403469732CBDDBE451FB272AC16C79E7700E0796342654AC58CD23425AAE339F3BC2CABFCD222FACC10432C9AD38
                  Malicious:false
                  Preview:.<!<.L.../....y...-}..*G....NJ..$C../..{...L.....%T0.b.....j%...t.....F.Y..-...2...\1t,..*[K.+..|d.r.ZuOc.|.y.....lC..yKTSe..4........&kp.=-..8;.....a....Z..._M30...q[.u....P....hm.`*...$.#.j.VpB.......(.cM...K...q....3.H=L,...,..[..O._I...(..5:.......zg3.P........{.'T.?.i.@S..b.......`B..(../.#.l......x2%.*.....!.s.g...u...]..g.Q....S..!U.S....Ky:..)[(.S.....8....].S.T...d...+...r..}..O.41u....ua6.p..(.oy..Udi........I..'...|=z.o...,5.......A....,......jJ.HGy....DWC.UNiZBicG...A..kX.h...B...X...Y7..o9..&..}.n..wsDW.t.7.....;..,;a.>.../~.-.|....m`......Cm.x.2i..r.5\.n....T..=..FV$...)y.Q%|..E..-..oA.._. .b...S./..%......O......e..Q..."i...."......3.`{..r.;.Y..d.O.h3K.FD[.~.6.L....5.{..M.+.....Sy.....f. E-OLV..-,e...up..b..f.....<..Y.c.ZD..f.`.Kgg...vVDl..]p.htd.....:\c.)jv. ..*.LE...u..@.B.o...."....D.!>.B....F.u.+@.V.Q..C./X9...=.u.$8........Qg*$..b9CS%`....1..#[M.....D.q.o.....YfO.C.oif....v..._..!3......Y.!..!.h.pde.;...]n..P....7w
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34449
                  Entropy (8bit):7.994616792417918
                  Encrypted:true
                  SSDEEP:768:MPNEefa6VunnyRZI/JbtKYoCyINiEJVX55jgAF79l:MPNEaVunyQ/ACKA5Xx
                  MD5:C417331363522BF264CCD304E711A218
                  SHA1:A039E0DEE6D348CFD6B024DC1AD0416148BA6836
                  SHA-256:8322DB980AEB38AAE995433F953F7E8EC3D51A1FF34B478462361D17457A7A25
                  SHA-512:4AC5C1F461EEC4834188F12B73B1570B7882BFE96192E25B38C6689F65AD4EEA94C88324D38AAC9290115B9EAB0C0A89447AE3D1F57FB94831A28C5E0B7EC3F3
                  Malicious:true
                  Preview:|1..r.... .mc.?..W....9D..5.x............w.;...?n$...zR...ac.(.......qt.).FJ...RC.j...|;.....hn.)J...0......j{...6.8..k......R}../........*.......%...5.n.D2.%[....*..8x_4.....D..S..........:.HQ...*.....v........1.....H[......P..r.H.....G..S:Dh...H....b&...d....yO..q?!J.;(=.$[0...w..Vt=../Z..pe=c....Gzp#.$V.K.."`![.M\.H..:,uf.d..../.."C.gGC.n....E.._.;[.W.K..*.Sa..)..!.|........(.5Q..,6.&.+.`.l.... ...B.s.UQ..i..o6.OT.,.....bTU{.da....'=z.*Q<...%..C...f..K.............6..P....c.....?~..f..4.{.MQp..|...&D...4..,.p<>...w.bR........U...VA..=A..s.....c..r?.....>(..t"..cI).t#.W.G.'..>.....g.1.L.s.../....B...."..b(s.../......:.V........Z.....\.Z..q...=..`.oq.6.u.-;....O}.=..{..!...F.~F...).F./=h=.L}.w)....]...u...x..Z.....2............5...n....].#...........>...}|.......^...:..L\0......p.r.....]1'.d._(V..V.6..D%..S75Gi.'.....Q.j..4.D.......([.....C.t^Y...d.% ...Nqe..$JY......R..(..?......`..*Ne........0....4.....\.Q...n.~p}....$.N...N7..(Q.T...Pw.@.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1499
                  Entropy (8bit):7.839192710127435
                  Encrypted:false
                  SSDEEP:24:ogVKHUN9m/oPOma+KOE1djQZ3FB4Rtv85wPb98FF7Ucy8kAU/XLnr8XjriBKlGt4:9VFmw2mavOE1VQlPclK7KzLnr8XqBUQq
                  MD5:6899B58B10E5DFB2F576B0B1E12F8408
                  SHA1:D4ABF327E4C44737A8CD7FC5B211B350E3269899
                  SHA-256:551E0F261EE2F3ED7A5A5CC17B54AA54922F88E31C39F520E2E7A11B75D4D243
                  SHA-512:ECC4F46A1C3ED2F3784A5E59C699DAB46382E4900BAD71F66C75355E7AFDB11D1E536D6E2CE90D049E2E7B653BA6200A13509D044F9B3A2ED8096D32A3024FB4
                  Malicious:false
                  Preview:0../.ai[.......0..6xU.....2...;*H.&V..Y~.. .ls..ZO.d|..-...TFQ(.....]...]..\5_.....S2d/.W.I.......dYeR...F....W....wU.$..a.>-D.|&.d.i?P..s........A]*.]T.e.^.s..J...2...f{..-.6.*i.D.&..%.!... ..T.F..U.5y|s...B'......d..{..W_.}..t..3.....7CA...y.:E.g.....6..b..._./y.....5...;.wD..@)...7t.0....../ea.V......V..+A...........:"..H.2....Q. .#.a....Gp.........W..(.).tM..yb...[.C.a..<P2`...)L...^P/r'#f_u..o..G..nX.d.99.@.s8..@...a.. .o...LKy7...$+......"..........r.`..".(q.&....3...5..h6.H?..BD/E."..#8.W/.$....k.wP=.\>...\;...2....^...Dt,...O..&....r....A.jx.b'.8k..-...:.."+...2..zz(.N.!.......@.U.zK.!.w3.M.t.B..{..'..7UF.. y|....|M...#...r.......t...@_.jHJ'...SK.r........<.Ir(...].R[]W...P......~$c!.....ep...H...S....z|.oa..l.R...<8.r.A.%........!.f?....i(uhcin#|:..m)..[..W..~.)./.])*`.h.'$.6.=G.e)<...0...-yio.......3TW._..r..Y>.G......u.v....n.&.M..9...>f.!.L..K.:&.....u......<..z....s..b.Z..r....J..vmz.^.0.M'xt3...z..(...e.Q.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1112
                  Entropy (8bit):7.765274942361469
                  Encrypted:false
                  SSDEEP:24:4aQ5u09x4BRSK7IEKg24Xb2Ho1GcVjeBZ0yHoIcM31V3AmQDzmVzBg:bz09ERfIHP4XqHo1NK7THoIcA1V3A1zw
                  MD5:152D5ABCA323AA9686225D110BF72553
                  SHA1:5CF0303224ACAEEFEE1089F8AED22B8FD3C4EEF5
                  SHA-256:4FF2132DE371B4DBF05E864EAE98F672414108B781566CCBD8D0B25E93F5AC79
                  SHA-512:BCE2022AA7C3D60D036E2F14F0B3218C5447CC6EB02E27D77BB868B11B3810A1D98860ECB773F2A8CF784D4581B78B37AFB8F738B4F8D3C9000A960D99C8C186
                  Malicious:false
                  Preview:ZWc.w]..s.=C.k8.@.l..-Rr..<.>...>/[X.S.c?Bud......[...%.0,....cX.W\....ZV.....Rl..R..C...u``Xj....6>Ub?. ....3u.}..{..On..vMt..$..x.j{.........&..jJV.{.....D.q..i}Y.N^..............,....f ......HH.....2..t+..c.ec4<V......lx..[_....T....Sb.....&.....t......N>j..A+.1..l.......c..o...T..e......I..[xO..Ik.4..z....:.{;.c...k.V.g6Y[.....bE..@*.J..].....6.n.'.g......]..\..{C|.4S1g."3..[..}.s{.....I...j.1+..*..^'#Y.e.CS.ev...".g..+....[.XJ .{.We.j..U[...DB.e.5q.+Q^.;.m..?D...f...*.;.....7.L..DrK'M..`.9fj..[..+..B/..*._3..%7..7.c..I=.'..*...,...........O......7...<--z.........n72.+=.I..........-.......E..*./.L...''gH....z..E&..........S.+<Q.od.=.5.xwm..,.]l............{kM.......T........b........;.hBn.....@%..}.j..."..y.O=...>p.!V.+..[...~EA..C....K.^.{d9..`...LX......gh.`.%G.:..#z.)...8......f.k.m.O.&E;`=..._..v...[mY..9b..!C[...*.}....j..X.....t..L!.UB5.~.Y|..Z......RY.....<@.C!...J...!.......Y.#.b.$7.w.:..j..W>..y`U.".C>..Z..\....c(
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):509
                  Entropy (8bit):7.455956397681853
                  Encrypted:false
                  SSDEEP:12:pVaCxk2Ry5CclsT9jgXOFnwruQHBoGnQSToTK:/3xvgXOFnwruQHqSTo
                  MD5:2F2F26E1B29CA36DAF7F902D866A6575
                  SHA1:767F1DC6DEBABAB74282142D567501867AB77DB0
                  SHA-256:82C3D3A862A3AE96506303819C97103F771702F305D04D62697148DF20C3C998
                  SHA-512:4C2F63D86C20BD00D271B90975E1EAA4A83C42EF56E67BFB2A33701761053E18C81C4CE043BD9780B256FA1DA07A67C561558E6816907DF8AE86839B754C7A61
                  Malicious:false
                  Preview:.~X..I2.P..[.\4.*....w.[.:...{..^..8q..`[St.>.....$..f..!.?....8.p|.%Z.J$...B.B......s....m....}[zu.p:.0.R@^..f.{N#.z..B.&|A..(.r.\......9..$.t....h...]fIj....).*1..%.....R.Dw../;..~..P.....[...hL......W..wY..J,...l.....l..y....f...M'@....=.li.l...].f5.0...j?..^.. ..4...4)......{:.s.."q.R=.C/#..8.,xc.G...GiV[]r..Q............Y....Q..w.MdP.Q.,qK.N?..v./.q1..H%...N._8..sq..8..6|?g..T..`.....].......Z.P6...A;.O.B%U..c..F...J-..yS....43..tT....V.-...X........]...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):830
                  Entropy (8bit):7.657310523840153
                  Encrypted:false
                  SSDEEP:24:g2x58alfRX8RoC0vboF8RKrxtgKPWbq2g:16wJX8RuvbS6KdtgjV
                  MD5:15BFBE8C122955CA8F425C088916739F
                  SHA1:4C03A94B9B85B29E2FF30270D8DC9C25D95AF961
                  SHA-256:5C4C7682934FE92750BBFA4059FD4C2243B192E16B3604E3FA0655AC85965D8C
                  SHA-512:51CA263FD25FFB554F9473D1B3116D9261D2A1569FF9902CB0A9B5BE73D874C6FBC5F0A5C6E813BF2A1EB3512A85D7375A5850C99750E30B7A6DC803BEBDCFF8
                  Malicious:false
                  Preview:.|8p..nr.eo...-3..X..eJ+b.)N..7._.}Zs...V.....J...m..........U...m...y.N...9P.V..a..k.7..Y.a..x,a..i.)....]N.8.B-.\...!..*.$8^@A..o..&.m..(.t'.n.E.).....&N.v..... .;.C.Wq[ WN.~8......(V.V8-.V.v`9.......,..f..k.6.....~.....7...%...8..%..r...g{.>......(.....@.<.-.+..+.;!....U5.............d.q..a.vF.....`.*...HG.....K.T.......H...*...y..t..O@H...j.3.2....{..u...a".^...5..T...$Q..=FIT....yK...\....5.$c.(CUr...H................>.'7..l/.......=#.7..2....X<._-.'<.m.'...I%.......)..@......)n.zp..... H.7(~..}.y9E./t.....o.U\.Y:..^...v...C......^.{.a..&p.2q...8....$...D..\..{.X7....^......(^.3.5.(.7..e.$......-.q.`............g..D...`..........^..6,W(.....|..(.;o.O..;F....d......k9A[..........Y.Ol.i.>/.f...}..+[.N.~p.4..Umd#.O..5...d'b...~....E........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):471
                  Entropy (8bit):7.378310808490798
                  Encrypted:false
                  SSDEEP:12:AY5gWHIuz/sIPaTS+Bu8d2dhFvMtm7bYolMy:a8PaTSKl2LFEtk
                  MD5:5CDA0EDD7AF89E22E4070DA2D62B273E
                  SHA1:31D0C19050AF4D38DF5F63ED43BEBC99EFC9FF26
                  SHA-256:89F1C9E1A1195BA5990067F0222F55101F3E8211FAF3A91FDA0A9A14F9300803
                  SHA-512:FFA5FF281AEFC61D106B28D41F24BDABAFDF2836454098A75CE8D5F6AC55061A1DEAFA7D89F507D1328F4095203B5CFF36E1D7B3F2AEB679F4079FFCCECFDAB9
                  Malicious:false
                  Preview:.../.|u.T>&.l_...lK....<...7'>....gd..#~L.l.3ju.W.*..T.+.......#..G.kd..<..R...'..dQ.}.......Q... .9WJ1.7..?r+.gi.....i.?..;J.Q2ux.$.]<a.D;k...b..v...NSv.....;....5;..?.....(....%.............9....lY.N...9./.5(.j.?Z.k.Z...L....9q>.....h.Mt.cra..).wa..B.C....f[..dh.Q..~33R.*.".I..-b...k)X.r..'&i..#.6.....A..z..:.!..b.=.....5.j..K..0....c.. .;..m.8..d7.......H`?.....Ox.vkS..!....'q..7z.. .Ot......"I..T.....k.E'+.........7...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):810
                  Entropy (8bit):7.635016419793831
                  Encrypted:false
                  SSDEEP:24:pIJJaTXy24Fq3aUUTHHRAs5E9U+3n/Zp:qJJc4Y3MbHqU5k/X
                  MD5:C79B77709792B4211278BCACA67F6EDE
                  SHA1:978197F21B7C8ED18FC434966C82A0E4C030F537
                  SHA-256:FD2C2CA1A55F08D050123A8020CFF0540384A5006E54671731F16EC5BA9F2711
                  SHA-512:F44E0A5959697CC42C30F5AC8FC87A8E80E16447AAD5C995E0629B3375434CB477E6B5DF5C3B87482F7713DBB2556B82158C5FAEB0E44C3A2FD387044C36CEDF
                  Malicious:false
                  Preview:.'.u1}t d..)...U.G..&.Y...?B...4......S..T73.q.(v.+.#.x..@T...e.....?:.3.....&. ...4.II......;..I}......K.8...sa.f..kDA(...G..|..{0..>.._...Mt/...Z..5...y.X&.X..#......=...#c....UYmo*.y....f# F....u.D..#...YaJ...m..+..K.S....Ah.i.9.L(...9.......l...?..G`<.....U.....A|.....<cP]...r...3.m.Q..<..^.)..."M:z....'.-$.g7...r.\.......w"..]..,|...i.%....#...- ...2r..X.|..p..S..q..w.S...i.~L....U .y../W..^F.....]l.W......WP.j...Cy._.]t...^H..F=I...mR.u.2....!{.6..w.3.X%...].G.>.7..M.....3.~.....1..I%2./.^.....1.....w..A?k.lr..[Z.W..[.~.b3.q..p..k.......Q..Y.>...Q...z....C...>....f...u."P......%......q...^2..;J?o.L..l.v)...Z.-8.3?.A...NO9...hc...m.*t....7Y.......t.)..{.L..............(.x...^.z..!...h..e..!..I.i......M..'.f9R..e..k..|........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8148
                  Entropy (8bit):7.978198120487564
                  Encrypted:false
                  SSDEEP:192:4wA8wLREEnzSfvv4UvYd52dcguHNom5TNM/8y5aHPr39U:DhwLRGfvv7v8Idcqm5TNM38vC
                  MD5:4132D48585BBA2239A977B014ECED4EE
                  SHA1:148DA08C54A422D3CF5B49DC10F8F423EC10F481
                  SHA-256:645DC7DA2A95DAE8323200C10B59DD54D67EB479D92DD6D3E3AC0389B0A67065
                  SHA-512:2DF9DF6C889D88D49A22559504C47F8B462C79022D906771250D6086E42F82867AA94800342AECFF52A514067A98F31B50021A5C8588478674C038C507CB5814
                  Malicious:false
                  Preview:..|...<#a.f-J.IE.&........<[..o.O..R"..`.p..HC.d.R51u.i.<..?,..hT.:.S...5......7...5._.....Ru.jIj..<.g#l..wo....h...-.......*".5j.....e.hX.B...A.;....#.YoHW...zqm#...........yX......E,(s*.\=xm..!..u..E.O.k..lc.3U....B...S.&.g...3..n.E]..W.J....%T.S..3...}%.(&...1..Bx.oE..)i.w...l..{..7o.-..a]..,.e.U....n..}B...9P".i..\6(..#u..&K..Rx...V.!.=...f7..L..P.)...8FdNJ.k....'...D..G..&*.....|....q.:.~>....:.g.~.......AD...>...../O.;...q...A.?...XLSO.....P...&.t)i.#*w.=...I....s.+qH...3...4.;.g..eh........^..}......V..RF...sE.@J.:D.V......[.6C..oG&T$=T...>.t,.X.t..rI....g..R...|?g..D.A.}..c.2.".w.8....!.>. }]".8[Lr..'..b..}N.Z......rr.o.....;....^(J5....'.D.Ir...5:9.B....T..i[.....u...t.r.2....!...........e(Gf.Y.....vm._qJl....H6.t......+.x.x6.$...2.Z..N..Ji....SVOO...O.8yO.@5.Q.r...|.@....g..,"...A...."G......#iNK.....Q...f.h?p....l.X.....FC..G.b...:_.j.d....3..{..~'..Yc[..p:... i.Zz....._[...i.-.v../.1........9Y.5.fZ.....*.K..3...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3023
                  Entropy (8bit):7.934920595130916
                  Encrypted:false
                  SSDEEP:48:D3GpTkUH2dpGdFWCbD7UWLDFJ+Z3bRtRRuyJwkDRKWCYvRvl3oCL79:iRkUWdSFLbD7U8JJ+tzRRJRDRKwvq0x
                  MD5:5417AFDFF2EF1CB76C242947C094A3F4
                  SHA1:25620146D89989E2919955EC3084A5F22A9B2C3B
                  SHA-256:E303DD785D9AB02A490B64E962B0636946E290FC26171A9C62019984DBEA4B8C
                  SHA-512:82C7ED42CD40C0ED2BC1CEE35F871FD748F08CCB3DD73E88F97A97F0632B731D82EC24F8E087B6CD43DA03E544149731587D29250A82D5EE214E169BB730C5F8
                  Malicious:false
                  Preview:.?.ne......#$k.&.h.AYp..(.....4x.....|....`C..P..i:...z.>.ge5..&|.#_..[.<x..V].~T......9oXC!.= 0...'9..:oP.\;.....mv..C...@C|.......b.h.....n.e@.Qv..X....&...G..p...f>.......j...F...PG.U.._~.Qg..:."..h.Ze\.:C......?...n....<...d.....H....`~.`t.{...@...O........{I.....!.>|L.e...;^)...?....t.G5J...J..I.o}Q!d..A....Bh]...)M.Q=@.?{.:..D..a.).-.......a..:..H ?..A..%....y...6..ct.....I8.'.We.....C...P~....El.....X. $./~F.....=....L..w...h8.7.*SiG...b...P...3...!]9./.,.M....AIj..c....oU.:\.&."{....ii.....:.Q."..... E.........kL...T+`^......)..Go..<;%\.A."g*....:1..C..j0...e3H...S.&v....+.,.}.@.......J......0...gG..zY..R..j...^^.q........e...V...O.`...2|Y..z.>.I...{.<.l.m.....5..#......K. .Af..{O..1.......M$.||.".\F......LV6....:T:i.....G..#.....e2MTu..JR.*:m.M.:......Q...~z'.......(..,......*9..{..|.V(.....uY.`n-.)....{.^G...(yT#a.t9..6.h.._S...a.f..RZ..}g..,^wR..J.....A...4g.s.W.z`Z....*l..C.K)z.m..oi...>.6~J....!..w...ng(1I. .J.F.)U.*j?..s...j..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):986
                  Entropy (8bit):7.747928603403033
                  Encrypted:false
                  SSDEEP:24:UEbzdA9K5aqJt34uK0ohvc7XDHDCbFz6dMs9J:vbzdAo5XT3jKx8HWBz6dT9
                  MD5:710C27E8140397886C04CEB68A78B3CE
                  SHA1:7BD1B14D261D78CCF5C20A4A3CC1EE16A11958AE
                  SHA-256:042DBB32E4A51D54090357CE7AEB16E090A89CF4C06CB28404CE41168821D505
                  SHA-512:8475F7F5F314E9E8E77D31A678A2D5FB63A45BE3375CD5872D9E4A24D7B5201012E43151A4ECE5DE71EB13DF6C9EFDC8D3A72F583C69B68D4F8E55CC504C3161
                  Malicious:false
                  Preview:..I..A.j.b..A.-49.#q?.y.x...b.E..b..B{.@.n......C7.T ......s._..LX..r..G..U+(....(...S.9...h..h...14..7..e,.....e.#.....K.;6n....k...#.X......fT....t.t....{'..# .'WKA.x...g...).+..v...FS.z..s0Fv.E`S.#..k....C.:.U....L.....[2.^..M.tZ..s9.:]..{.[.4..d.a.L..../}}.$*..W..82.?.....zb....9Nb7....8.A..Th.A.4..`...,9y.~]3h..0X..u...I........qY......x.`$+.k.@j'.J.=.....vJI..Ga.2-....q.6.I....h..F..Oi........x.m.9.>.N......}B...E&+......J.......q}.uz..}...os......k.0gc...y\y........./Z:%.}.\..0.......=..'.R...f.T).$......1z..m6Kt...U.y.Y.C.E...#.wk..4....(..Q.t..........)?..hQ..."..[....p4>......51.3.W...j..HKv:.g.i.-ot.L.vn....m.y!,6.....Dt..8B...m;L............EC.....C....|4q.c...1.(.S..Q8I.I.@$jv=e8...S.w.PEV.-......Q>/U....... *.K.....G..nn.&q..N&g.4T.^.>.Y>....z.|....c1WuC....76.o^.."A..t......$..O.....=..C..T.W.lM...{.V]6.[....Z/....V:.......H..*R.v.8...o.y.Q.Xw.v,...I.1AZ...*.o.)..zs...;wo..........:...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1557
                  Entropy (8bit):7.850806498701262
                  Encrypted:false
                  SSDEEP:48:iyucXqTGvlL9i8qs0qLseMBUzZlb9J782o+:CCiILqsTLsexZ19J782o+
                  MD5:0A15151B18C5C8F0491F65B111C85F75
                  SHA1:AEF3EAFC6487AC716E8332665A10EE454314798D
                  SHA-256:D0650D1E63C1117CA772402D7706DBA14BE455334A55FBDA736E774F40EAA310
                  SHA-512:6A999449CD1CC47D3E23B1DF8D7D2F442BD08F9E07D43439018D41E1CB7741C929AA88A34FA5FA09C52407C08C31B80719DD47CC78A1450DED11E2A13DD062AA
                  Malicious:false
                  Preview:..ob...k#..........S....3t..S...2.P..r..c.+.U.....r...6..e.zou.`.uu {x...m.'*.[jR..xm...bo.T..c.....a....y0S6....|e.? ..z.......a..i.,:pQN.Y...s.....H........A\...%.vd...W.RC....)..D...m.....?6........b.......o..&.u.[..|....X.....Pj..2.}.^AY..l.e.p./h.BL".p.....s|..YrL...;..[R].SE..t"........f.W..N..K.h....8.UQP.da..Q..==u.c.p.CY..L....M,.-. ....'...5.]....!|d.)....;u........D...8.n.u.a?(..unvS.....s..{..\...............gC.!...}.T".7g.e..n.@U].2nqv3r..|..1.|.3....L.......[...."....Q^.....laU....+HR.........fB$R..f2.j...A.Y.......,..'.C...).Kq.r..9..m.0....>Ds.....}...rO.=j.,`z|....[...W...@...4TM.zwU..}..,.rz...\.6a.v:.g.;....F......".iH... .;KAt.?.........zp..JflG.I{`l.C.8.sT...C%cN.CB.VEf."O.P.f-....9@G.y%...".....3..},.w...TU-...h.M.m......;..V..+....v....`|t$..w..c...R.M..E..^u..6.(.`D....a...{.&...a..7.D..B.(..S.UB.....c.6.=...W...l.........\8CIr....[..1._g.....z.Y.^d..{.J...5*U...u.d..^.s.o.k.VH.>s]&..$.D.S.-..E.R.m
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):3411
                  Entropy (8bit):7.943331759102708
                  Encrypted:false
                  SSDEEP:96:AwghCxWylc9T4M5bNVHFvGN4Si9l2G7yDbM:+hVpT4KpVbkq
                  MD5:787C96F4ED09BD1342815C644DE4EA12
                  SHA1:C850A937E5E8DE35D97FF576096C1C3A14B4D27D
                  SHA-256:662F00496DB2ECBDD1BB38CC52CEEC6C126827D30A8288DEC33741AECCA1AFE0
                  SHA-512:6A410BB30774F5C565DAB50D03C714C84100D806DF314A48B73042ABFB0068E91DDBB670E3EAD45A2AFAB03F7EF6E6521A9B874C40E5069A14853F0FBF8F3C08
                  Malicious:false
                  Preview:.{..j..kw].w.m.k.d.4).G.T.....$... .....dr..Fw.._~.".7....(|...g..p0...w../..}A....P...M.s:(..2..2.R.O.zu....5.D...h....\Xl..P.....9...W.<......5.6.#...+....c..G..1...;H..|......aKS.H%#...]....e.........../..K......+..\.*.../...(D..[.4..~.....Qy&S...t..|c.O.`..D:v.G..(k....'.%g...A.?0C..;Y......X.C/.....m.@.n.q...J..h8I.T.:.1....\;p..n.aU].^B...@.........<H.=........|.....m...Q"...._zV`i.M.$.E.w...x../..+..5......J...>....q..G...z.[..Gpp.....i......0R...b..;.V....5....F.$.G..Y.-..`...E..pE.....n.2k.x.@..h1ro...+OC.O.........[x..an.+..9.....I.7.+..b_a.a..JMR....w(o...b.T....0.....5n.Vi.Z..\...1.a.t._.."8.*.L%....d.h.Dl.. .g}..b^u..@J....@|...>..=....6D..I.83grB....Xu?.;._.......+nW}|..T.ay%@.....'.qU...b..>.x...F..q...|.f.o.......T(..F..'._.>Vz.l.~..$. .1$t^K!..Hyl.n-...YX.y-..vs4....3.yk+....7..&..!M..s....6.buXr.a.C.hB..(K..2:..7.......a.:UX..k./.bn.)T ..s.z.1..C...2.<.k.r...e7.61.w~..k.....).R..5z=...H..c...v}...a.#.:....=K.L.T....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):6765
                  Entropy (8bit):7.971619603614394
                  Encrypted:false
                  SSDEEP:192:7RqwxZ1BqSFi9uZf6RrkHGj/T4Ak319Y6E:7RnHWSg3Rrkl31a
                  MD5:18F15563CDBE57E50964A65565D3F8FB
                  SHA1:7B00DC48ABF240A6EA85477F8DAEB0D602078498
                  SHA-256:9E3ED62BC2BD8A0512FDEF28C1E9B7F3FCD87FB3F74BD6B49B22331032C61941
                  SHA-512:D45C8C840D8A34ED617675B288C196C19FEFAB1A66E7DCC32630E2F55B74169CD4EF01B658796B23ECE1669D37B4FD3C8A62FB6E06A4A943D2C8C676A791F4D8
                  Malicious:false
                  Preview:....+.........g/..&.sU.oOH.....gQ81YU[M.......6Q...I......7.J..H....D..rL...Yv..%.3.,O.X...w.=.CM.....o...8..;..x]..7.W.-j.......U.*"j..U#Q..5.6;}Zn..g...?..m.G.{.j.w...d...P5S.:..-..;R....c..y........]"...A}.$.M(.g.Kq...1..Jq.r.........vW.... .I....m.I...1......k^\...i.1..v...a...r...a...8....y.<o.}ef..........IV>.?..3....=...u..o.....L...M.T....R..."..4@...<.h...|...{..............|.?O...X)......\z...f..........C.5.........^........c........Q.......6i..wg=.X..}`ov....a.....v.p......S.Oj......S.KF..T@....r..w.Wn.D........vxJg2.'...'&..D.|..z.6].ho=(.a.....4....b......AhZ..F.l.8.k...2WDa#.j.....K..mz=<.C..PL.l......?xS...^.j..$......2.j...U.W..WV..,.i.O....[S../....b.hN......,`#.f.=.?..#/.HZf.@..H.v.0o....I.<.H.g...J8-k.H.P:..5\p^......T...?........k|.O...\*k/ru..>..=.d.qbe.......R.n.K.D......T....-.....t..ad....#%Zp../0I....z..3...v..m.\s.}.aL......Bj<B/sf`s&e.`2.@].La.T.^... .N5.[}}..........o...|.vG.....9.q]...`..em...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1125
                  Entropy (8bit):7.752896747881727
                  Encrypted:false
                  SSDEEP:24:GGD5GmoVHtL66bb4vq8eIp4NHqw7R6IVyuvGmj:Gzx6JS8T4dqwRRyuvG
                  MD5:6C2B01A475F4F4ACA4811A1296DE932C
                  SHA1:FDBB827A70466F17586142F7319EEA434B359C7F
                  SHA-256:B14AC7710E33F059BBC936392F87C9597589BC4A4FCC991A9F4CB9507BAE0166
                  SHA-512:824E557CFA81C3FE0CCD710625EEAE128625F2E36282FE2562BA83C93C1B2B8A3A7FA7C40EC7CEE53AFA80393DC7F7E3DADC6C6A5CE59358A6D21486D5E4900D
                  Malicious:false
                  Preview:u-....R4'T.E...u.o"...q.)|....S.S.q.6....e....w..K....<.....!..a9...q..@...4N.vv..~...b.....h{.].MPP..&..v#.......D.'v....>/...{..to...........O.q6v.. K.....)V...M.W.......,....M.4..E..t...``G#..........h.r?~..%yF5w6...4.io..k6.n.....F.^.[$..H..........7.J.{ ...4.e....eK...._X..(j..eO..].6@....E...._p..&..t....4AO-.-2I..G.h.N.{.nL)...a..J)....!}YV./ .Dr..^$(GEo...z.Z...9V..uB.....G.lR.K..0.jr_\.;....fi...^VU...m9...w...%.{..1....(...t.h6.YJ,.........8....~.....RF...............i..e..w.$<...)Y.;.=.-Hqy..E...\G_.....B]......=....v..?Y.. Exopq....C.!....k.l......I\......}v}..X.xm.Z...q.R.......]....x....H.R29.}....J)h.=...g.H.>.n..>";..lwi.V...........g.....v#..(8Uv1...op.0......\...tD:........;c....:.w.......Y.W@.|.......0..?_jP.]}...o..#....UYM..@.k1r8..W.|...0....[....SEJ.....m.@.'.LQ...]E".jq.`.........n..H.....D/.j..rR...,)|yuf....xf$...52D....V........7....=$S.O.-.....X.v..$c.`=....R\~.{&...c...z.W.@.I..m... .=K..6..F!..Jd.....=.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1130
                  Entropy (8bit):7.802123074090656
                  Encrypted:false
                  SSDEEP:24:nTx06g+aNciwUIntDxpo7fPNNvUkjuUPS7044n:nTr7aNcvBEfV6kjuUPT
                  MD5:2EE1328856557E93CD6C509C55BA6518
                  SHA1:70088A5FAAB099223E56FA7378FB6B60323D843A
                  SHA-256:207F0E0DC6AB47E25A1F88D1367F472686716CA27CBE31DB1685246F9D36B239
                  SHA-512:2643476A4A248063CA6C96A40B11B21063E3579C7CDFA0AE298FF8935F6B29B675AA11B5848097CDFF379773E2DD1B1E0AF16224F29EF7E14A894010962A8947
                  Malicious:false
                  Preview:.Ai...h.T_hK.U..$W).....G.u....B..^..._...2QF...M....:G.mM.Zo.cI.....1l..q...PT........P..G.Y.~)bE.......}q..+.<..5.B.Lb....-nL..xgOr0.ua.........C........,.T.G<..._.....-.1Q$p.KB.f*...........E..h....:4......$..}..^U.d.Q.N...P,......IQ;...6.".g._!..6....l.^.m..\...D.rg.lT...j..Ab.d........|.......mS.g5....d.H....}.....@[..{k4.R.B...Ch6[.4u...TB.\>.MMl.O).;..t]$i...c.....l..U.....O...FA%.GT...A&.z.M......xk..r..."...3+...o..b9a....G..2-...x..P..S$..S.....R.....5*...t... '.HM..voad.!.w.-...h..:.nF..y.zm..{...\Vu..l.H%P...Zd.n.B....S....(.\..,.iw.>...r>7.k......./%.'....:.G...3.kZ...s.J[v!..+f_..] ...9.......G.+n'....D'Xb.....+.7J.s.|.(R.....j...X.!...\..!)..%.M..*)".s;.W.<..E.7...@.....=.<.n..1.;e..X%...'Q.-+.$.8+.S.%s-. "..r...9.}..]::....mI..Cy......pIgw;..FGu..Np?l.-..{.E..q6.Q.:..n#.....t..KHE".,.V1..]wO...\.@......OF...L..c..!_Y.2..k..v1?.... :e..>..4.......V..'.. .G.q.j.?g1O..c..(.0J..^I%..j.).....D........w..b......T.\.-.-_H.B
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):676
                  Entropy (8bit):7.600520878553112
                  Encrypted:false
                  SSDEEP:12:yjQaTjVlZusPhJGWIKJ5i6OFLYZEvbuKHFt8E05+xrlXp2:yDTjss5aA5zOWqDuKHFV/JlX
                  MD5:7CF010723C28B763276C0A71DB92FA01
                  SHA1:D4D8B56E4771BE5F23228829F20C31AF151A785C
                  SHA-256:B47B3A088F5F6FC0A6A86AD20687102A9A3937E43E1A56F666746760173F5616
                  SHA-512:C544780A485DFFE6A1CF07C36563CFD060FE5F722A61BE687608A7C15941CD8FD2E7A8397541BF178B21D0C7B3DE4EF2847A4186DB32ED3DF5C1746D2A6C854D
                  Malicious:false
                  Preview:.._..8.QIN...T]......M5..AP..[>E..7...B....s%.6....Q5#...o.r M...4..=....cf..-.J.M...4.HA...p4....*..z}Q.p.GJ*R..?.&..:h..%....&...o.x|._2........?oSK.7=I\.I......./*.C...2...`..vv.B)}B(........_.F...ef....p.oTO.T..d?UM-...>..4....|.....Z\.%....o.5.X!.>J@.PU<.#5w....W.q.A.p{...oe...8<....>...KQ.A.....:..&i...H5..x..t.7.b.W..0I.0%pMN.'x....(..L...S.N..y.>......S...._lMbp.y+.2.............l...m.@...r.....a.k..^6....d.....(..]".*.G...-S.I'.....C....pQ..B...a......U.<qB..t.%..l.l.H\+m.5.!.;..7.E..u.........,EO\..x.G......n..o{...Ev...>H.nH..............{..s...!.bC.9F..W..y.<..e....4..x..2Gi...iaC@.@9..I...T........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1248
                  Entropy (8bit):7.822714174190794
                  Encrypted:false
                  SSDEEP:24:aEcjxykKqithWj6laVIzksTLu1igGOFNLZSwgaPHkii8Exx0rSO4:7cok3iTWjIaVmksTy1hGmhZRfPbiB6r
                  MD5:045BD8A8D1D9915E1569C3033990B8A9
                  SHA1:AC7913FFA2128726366EEA801682F53415860404
                  SHA-256:D20BB39F880EA70E0AB183415EB54A423DA9DE54EDF9F0894E2FF7857EE86E95
                  SHA-512:78709F983C6334A90494D647A19AA9489C1C89D28C02C57304E214E0F7ABF3DE603398A5FCE79EB7830869E60BA37CE24C15E023D6CBC7D7294E5219565FB4A4
                  Malicious:false
                  Preview:=EM.....Nb...+i&..>.S.%<rf.u..r.Y{.A..........~V.......G...m...6..o~..../.e....4.6..8.9..."4}6l...w..4....[).'.mx.....A...8..v..G. ...E.. ..s...i.$...^...n. ..y.-9U..fq..7]..S..iy>N......(!m..S.Or!..w........EI.3I.{..;.D....xO..#t.........2Z.r../.;.H..Hk.i...r.vt&..F.qH..}Z.NG.w...!Z...1`.St.G.-..*.C6$DL...\.....:.4...N.X..g.%f.'$........x....EJ.....w. .elC..:k.<h0#...2v...^.}....bC.O.......W$>V...E..v.<....-.X.A........M9.Q....4.>..{.@....~..p.~.....$v.tD..TPo...d.M.'.. U..;RS.Y..J9+.......l.o6...C......=+..LQE....:........h[.j..W..E......K..i..,../..B.V....L.h.%.}...".F...O..e.Lc./K..Y..r.....}'.h0...!......^....l......FU>.%..t....C.g.....^3....W.^y0.G......G....X<+...X....'a..R...E.#..U.R...j....)J/l...-....'@....k.$.....D"..k....j1r%#=.........X-..]q.E>)..Hg.~.J.z.../h....h...W.R...y...|Xz%.......g.....an..Q9.......I......z...0Ns.{.....3...9..b.\.!Q3o*..P.5.....<.38^I.Y....p.PL....f.=.........y.^.Kd.'.oNqR.....-...MN...9
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):738
                  Entropy (8bit):7.642700516456444
                  Encrypted:false
                  SSDEEP:12:+9dYZ02dojftlWxgvMMVdTlUZMmzMxZe8u8WucwAOc3k1wrF2/rtXxpjDkA9zh72:TJQvWxGMIdTehnjjuRhc3AwrF2/tx1J0
                  MD5:294C0878D23545C59F339F8313E91B2E
                  SHA1:31461A36EAED68B7FB95EE1C2C7B39B37634551F
                  SHA-256:A332D03DA3A090302E3A61A378BF6A2DC925D5F1BEB8BEE3DF18FD8743BFA3FE
                  SHA-512:34F125B68CAE9E4496926405F66C8CB9DB2DE36207C794052E6CA9CB6A2B0D3350D4BCC04176414A6E7069DB36D6F7E5391BFC9976A65F3DC22FAB29739A2671
                  Malicious:false
                  Preview:.j.P.+S.g.B....c.I..7.J..:......... .T...+'| .T.....{a.W.=..."HU....l..e]\I\..D ..'I......o).....@.4....]"z6.b.......E:3`n..`...xt..M.2...%...0...*.$!..r1.s.e.>..1..W;..-..vx.YJ../H"S.t....R......}..>T.....4=,.\...b9tl......o.V./...B9gD.Y.......CW"..Ct.b.O.E._..{.....^..............HWh....AVF\.$...s..q.P...?..Sv...~A.^]He :;..R.Q...U*...}~..85O..^lz].&.g{.v.P.\.Q.......x=.z..i...0..|".lTX..}l..D$...^.,. .........[.i.z...{...H.o.{..TC..Bk....u.<.q\O@.....R.7...1...3p{..D.{}?..`O...+#..e.V.......(>.`.)...$$D.j.s...S.#.......2....P...].Ns..|...L.2.....I..).F..?...N,....D..=....*8.W..|.n...c.._.=.=.6VTf......Z.7B.......~O...Z.&C#...[2.k..:.Z..j.BE..}.../.U.....h+~.T.K+S............B...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1513
                  Entropy (8bit):7.852568483242269
                  Encrypted:false
                  SSDEEP:24:QvntCGZB0Rk0QyQpW3BCsSggcl2RxyyPnugg2/IAVTFKTM16TXhcMGtiz8yPih0N:yg9dQMRsRxPnAmXVxPCXlDz8yO0
                  MD5:C5C02958C18F86D693309EBBBDFA0AAC
                  SHA1:3826BD3BFC39C37B465864A5229C48E8688D4E29
                  SHA-256:2336C888C5ACA50E34D17B11A1CC195529005C8FB72FAA8C344FF6D17246C7DE
                  SHA-512:AF5833A2B14D34A57B928C703834BF6A3688D160E05E9FDD66D9CBC7DD06E0873D8D73F2E2A7F2B30B3DA7ACF254E19F53E0FF62D2383E3006A10C5648CC25FE
                  Malicious:false
                  Preview:]......../..7...r9].....E...xX...&.7.R_=Fgc..>.{C...Alb.W..<|.>&`.....3%..Y...+...z..x.:m..1..}2.M@;...PJ.....;S.x.....m6....n.*A....4..Q.j.E}....>G6.;..w.zP..!.....$....[..s<z.\..$'....b.H\.{.....b..i.5U.X....,>n.....`..T..`..WWG.....F-...3.a.h*M#..p..L.....=(..6.dJP....Ek.AN./:..eZu.E.G.f...1O../.Q-:....\5...+.......(......Vc....c.>....N.9.Y\..G.P.p.A.....s.'{..K...:..w....z.)...a!....F..B]J...'.t.c..z..........C...K..Z.3.o.Y.....z..i2H..k...T9V.]B.=.8.q.y...,..>n.W*N$D`.q.;8.2.3Z...2.8.Dsu..~...._s....i..#.ha*.Z.m.FYd...pNi.R]:....1&.....n......I=...j6..T.2>....aS.....Y..r...._.p8..=."SM"....\a5U..i0.4...|Pjl..B.Q..egB..r.8.. .E..5 .[I.+'(..w..\...p..."..1..Jc1..].*..R;hI...C......a..Y.zM {.|..Z.........x...v././.......A.v..tT.".!:5K.Qy.[}...i.......ci...R..%......!....I....*..u*..G.5.[..@....f.qr....6.9E...".<ai.%1..H'...._."....MSEU....o.e...@99uWm. ^.H..S8...57Q[ ...aB[35.DkO.....;...X..W.[[..0K.*.....&....A.0..(...M......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):767
                  Entropy (8bit):7.673615671826185
                  Encrypted:false
                  SSDEEP:12:fjeSJR5Bpkj5IHo+tq9Kr1Y3BuoqStEbQ3KjtMo0tFI/2ifCcY8x/YHy:nxKqHIKr1cgStEbAKZzD/2ahI
                  MD5:AD19D1BE607B624EE91333EB0466F085
                  SHA1:413C9B0D3EF9F69E86F585871194C021A47B7A27
                  SHA-256:2CE474660ECBC98C9770CF4CD74698201C8777A0476D52A7733A3830A52F18E4
                  SHA-512:4A9B163B9F7E5AD0DAF2535284BD3C9981739F7C162D7797B7978E38FED9197314B61CB1A288E83B3542D2806561105FBC825BE82D144A69E546555EABBDB986
                  Malicious:false
                  Preview:.x..C...|.2$.....}R...[.f...u...T.]1....;.u.%A.A..9.!...(.f.#...._.5.%..o.{.....:b...?Y.|..5.m...2..i..R..1.L.^.w.C...>.Wf....0rm.V.c.....k=..FCMY....TZ.b..d......s).b9>_.o...m...".L..........%&.G....s!..V..}...v....x...8.r./....G..EC7.d=.P.......w.......^.>...y.h1.N.c....?.Q.*....mX.......%b...5.............=.(\.9D.u.;.I'D4l..k..GnE.R....o.a....2.K.:`]..c..!.......=.1..=.._a..t...N{R~2jC.Z!h..&M.A..(c.QKf.!Q.?.+!b..!e..n7......!..a..j...S.zk6.g...L..0.....+..q...u..5...9..f....[.:..?Cp.T....j.\.B.`gY....l.7.@m....O.6.<..<.kC..-<.j.w.=`9...f.A.I......d.e 9...J.#V.Ua...Na4O..{.........j.%/o.5s>....K.~...U....D...T\..Q2_........H2.._.6[U..F....Y........}.D...aC...i..N.Y:U..4:.d93........_...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1584
                  Entropy (8bit):7.861818768816107
                  Encrypted:false
                  SSDEEP:48:+DeQt2ws68kvVyeD5K/leOfmhKAhIaGP399:+7cz1mE85K/0QmhO399
                  MD5:B9224C3D65C1A8986EEFCBB96F6A740D
                  SHA1:1BFADA657D81C6B2099EDC5B8A8C01F7620C1F54
                  SHA-256:CC67C93A0F0B9C56D20BC240C3DF2D1651EF286C01D81703D5E963FC000161DC
                  SHA-512:84716FDC25695967453FC669C39FAB9DC398080CFF7B4C39BFDB12A62DF2A33D8F44287D2E204FBEBC57A5B7A51042DE7EA607A769429ABDDA131CBC02D7D229
                  Malicious:false
                  Preview:.r.#.08.G..9(2`.r..Y....K).<..U.V.....t{z.^2.x0.7..q...L.-.AB9....&pL.`WQ[.E..!F.d.G....o..G3...B[.?...k....%7...7..s....K.....C_..X..e.]..._.8_............:..L..A..E:p.....Z.K.....5...f.y.YF........oc..:....9..P..{..1A.R...^......I..-Y.[F~X)P...<....4..... X.j .c.-...%7..m.!.3.+..&Hr1f..G......c.\..+.. .f..CL.S!q.E).I+.)..V....7dX..-(.=....#7.p.*..2.....R;..p,..o......x......Y..z.Mfb.wLOl.....c.P$.>..k.fz....ne?.....w^o....0....h.U..N5kp.-..}...C'.1....B....27:...9..Oj...y.......I..l.v`...[......'....$.W..-!..L.y.F.>.o5.X...-XF.....G....L....Q..w1.x&.fN".y...*.......e.$..#g 7.7...8...NN.Fp./......V.L..x.g..>}...z...xn}.)....8..V.....:+j./mV.....v..fn.!IO.H(]......U..X...K>...x..R..@..>.3..........-..p..N....?V../[.. :=.."..{..+.$.....$.........z...1..m.T.g5.@...r>2...mut......_.S.Y.UM....S^l\e.>...6<..)..=.iV&>..G....S%......$..@q.P.....jp..ROa~..R.i;|l.!.k^..;..i..(...c.P.?....J8B.......0.r...IH..W-H..S-.z.Y..wa..). M
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671
                  Entropy (8bit):7.591356073998559
                  Encrypted:false
                  SSDEEP:12:9WOfN9ckb3yhEdgYonnNU6wlSZLJSZy+QHRFcrbhC0Nk3GIehKCwtr8TJa:Me9JbIh9NUFkqy1RYbcn12wtra
                  MD5:31458E6300F8D73C59ABD8BFD3A0346E
                  SHA1:FCB4A6BFBEC6B75DB533350416E2CFC813B8C00B
                  SHA-256:1E2841E5EE35EE232657B2EC6BD1CB1EF23FC988F46F8A87B77631FF5F84C173
                  SHA-512:BDF2835C06DACA8F2646558375A6C8064C8921A2EBFA6D4145FC46232AE7ACDA0328E91617D20D9B453523392EE8CDA196970DA5846ABF66BBF2CA987D0185A0
                  Malicious:false
                  Preview:}.........N.....w.G..s.Q..NB.<...d+..+q[C.A46..a...[H.r^.}..9...-[.....-..t-GE...(+..MW[(6......h.:.....S}MB{..{.6X.9d.Zu.z.xYY.P.%=..q.=.......Y.......3a.._..hoW6.....l9V. ...Ww......N..N.....X.{.gVJ...t#.*.........%.(......p:4..o.x..8...r.s...~..?..>7..CLY..#.&...!.9..?.b....c....C..Q.a..B.+4...l.d....o....Vj..fL.g..[.O.CwQ.t~.s:=_.;.0.Qt.X..t_..(.....\..1.....P{..\..K....}.s...!..E....f...t......h*.1.]........N.ES..`e..o.i.'3...e....$.....>H..G.b1..G`.T.;.y-.6..e.................+0v.O.\...G...p.}.q...f.i.......p.W.....s.q.D.<.?P...H`.pg..........H37.;....I....F...v.I....Hn....6.C6..!...!Z.....Y........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1157
                  Entropy (8bit):7.758740356222406
                  Encrypted:false
                  SSDEEP:24:CB9lElik+hOf7/xfc49AKFtmLboMzw8D0eb2pLmjtWSqAnj:SkT+A7Jfc42UqMMzw8YKSqtz/n
                  MD5:B39C32A0B35EBE165B2176C9CD5278DD
                  SHA1:7FF7924D266510A32507081E854BE8C0DDB9E324
                  SHA-256:EC48378033FC3AE31A8EF654F2F3D77668381955E89210858DD59E0B0878EA86
                  SHA-512:803A7013BFBC4A3C1505934299C0A5DD2EFED1242AA7A435CE72BF01C4FBAD48E52998C04BA15595E811A17025D474C5CACF641D55C8DF5A3C0371DCF6CD3B4A
                  Malicious:false
                  Preview:.2.(E.slK....p.;p.>$...`a..c...W..'.G..M5.`X.n..RZ.)..<m.8..0....O.....n..D..c_.?...S....N5v..M................R.e....F...g.....&q......d.@N<P.`...............:..93#3(.....p.F2.......e.A.vo.MPnD.......Eo.K..lX..../W.RP.o'../.......d....b1.TR..|.x.._.D.^.....MQ&2(..)..x.t=^.)..P...T..w>..'....0......pr...w0#.l}w.3.:.,..(.....|......(.W.G.I....&.I.,.H.)...h..IKawp.X.$.V.C<...7..c.....]Y.OO.o...hb.....;..8.....(+.......:p:.._R.C.|..%.h.C.u*.{0.wi..-.....$.~.ti..C'..e...d....z..s.....t.H...0..\O....Z..m2...L'M5.Z..8.;.B.G..C.......=.r...e.u..np..8....U&hN..q..;.r.C..k...e..4....<..\.....p...r*.l...b[......\.Yn.w.NS.S.E..Q.6_.?.I.2...g.....{.T....(.....Mk.S{?>dC..b8..~..%...aDmu3.ms.K.GJ.!..c...W...Y..b<~. ..X7.....4..%.....=F....X.N...?.t....w)...5s$...$...a.j.....t..T..k...:g...]..st...N...w....%S....n.O.}#....P.gX...*e..G.....w.a.7.{...m^..d.o..4Z..+R....|.w.....u...ZI.x..w2S.D........`.c..]w1Mn.9^. .N.^.J...,.<.....9..!.D..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4494
                  Entropy (8bit):7.956209345869863
                  Encrypted:false
                  SSDEEP:96:QL4T5wLdw8hhbY7FR2vvNRfs9wFy+VL8RPPv:QLc5Ey8h+z2vvNRk9eyM
                  MD5:6E530626A914B11547409636903F8C21
                  SHA1:161DAD751348AE9D6559EAD368E8912121FB2430
                  SHA-256:69198F43E569B75981614619205B3C8E7EF9B4E34BE3DF5112ECC2F1D016A6C3
                  SHA-512:0EAC5426841F42CAC7B1E2959B8EBFF4F8DEA86A9500594B9442A4BDAFD2743002FE2C65756C15198A1414197152841BCFEC2E6391B38D03D75813DFEA2039EF
                  Malicious:false
                  Preview:._.BU.........A...#.L..0E'.."..J..prCU..a.A..rU....L?..K.....@r......`..~...+..O.x....O.....Ja.,O...d.....'.&0..Dx.1.L...r~.e.@$"..7...P..R..=...e.y....vc...$ab..K'...W).]..$.j....R_sKU._0..V..{....^.....D5.....V.Gk. ..R...(6E3..Dj0I..qC.......x..N{.{......m.i}h.{.G..Y..6.....T....p..\1vr<...j...3...P..r..s*v..%1.Y..~2.e..<...d..aC.Q..1....:...~..d...o..T.:c..Xv..f.=.......;.yb....}eg.....^..`...W1.S..:.5.u....E...y_U..[..Aj.'.......+.!.......u(...l./.'.............w..~.c.o8B0.........J..-. ....F..<C(q.P?......0<g}....gS.........4.C.M.,3..FHZ.s.2W..fm9|...r.......-...y8...~Dw..6a5......C.8.Z.90.Z.........W..<.c.!2.P........cRGN...Q..+{.@....uN8.>..B....+...@.m..0z$.t...M..f.{2...p...#..r..)7....3.............S~.g<...{N..7.&....9!.E..$.z......].k..~.......T.|.2..j..!....PMw.."i.j.2+..Q....{..u...V....n...|Y@F.:...H!.p...mb...O..@F.)...7..e.....^..`>x+..... G%;.A.`2.y..}]2Hv..W.1....#.U.EC.3m..f'.M;.2.R.C....zE=..4y...".?.5
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):498
                  Entropy (8bit):7.447635748263588
                  Encrypted:false
                  SSDEEP:6:Mn5er9s9idVn8d+YEmh8iM6hDsbWLCFMr6KdU4qaYlg+FS38hWJspuGxmfTWBXhj:MnO9ln8AubDRC3KIbgB8h0sBUfQWa
                  MD5:932C852ADB642D74C6CFF4215CEA081D
                  SHA1:1E15FC15FBF414C3F34C3407E0F1B6D6448C33D5
                  SHA-256:A4C7825AD2E3051D622A9CB91EB59058FF4B6E70AB2E8E91EFBCAC8903EB4C74
                  SHA-512:DC77CDD754B95AFE95C9682A0156C302B021C1BB6981D98ECC9121333CE6115E46DE31E109E4E50A9ECC9AF309CE9047A11C17D84A10653DA463C98871ECCC24
                  Malicious:false
                  Preview:)......!,....'3..j2.. e.$../.....aR.m...o..............d...hg.5....*Q...$.)N92....Y.r.u6..V|.1..Y..,.z@..q`......6......\.N...._fD$%.U.j?Kt..0.@)..H_:...%.|zrD0fNn(..B.G>f.`..D..,A..f...Tb...5r.Q.3..x...7."%%e.P]......K.........Fc...!.Nc.......`.).&p....4..Z1......2..x.(.M....T@..j.7.~.[&.`>.p..{8Hk......y:..bZ....u....C}z.....{...@#s....t..[wF4...G..\E..Y......7.....)..S..R...........3%./..J...nSR.....v3.!...Z.....UQf.t..kV...Hs...f........R...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):756
                  Entropy (8bit):7.657810417543069
                  Encrypted:false
                  SSDEEP:12:Zsxck6eG1QvrzMKMote79Iu8Ww07nU9+P0bI82Dr9CwqHO0SKlOq5msZ55aAv2my:Z3Fe/vubIRWFQ+g239ly6q5P5lvE22
                  MD5:09756BC1D65964B612B6EBA64E445CA1
                  SHA1:521A5551EAC6482B64E43C05B820BD223CCE4B5B
                  SHA-256:6A0755ADA526BFE2BE1E7E43EE6387DF57CEC807348F79F30FA911F47AB20DA1
                  SHA-512:AE88BC13BF14B12BEBF83565B2131D2DDB4D9DA7A6B21C0A866AFD6261AE84214E4E883D9811C9920ACC323B91AE4F6296CB94110BF0D8448A4EF88518BE4E94
                  Malicious:false
                  Preview:..@..T...`.2....'.....%.\..Z..f;.?.........THk[....Y*v,o!LI..t1(....XA...bm~.O....W..L..3...o.!...t.i.........r....C.}....X.)..D&..,S.MN..-K....C..G>L.(.;^...e^...I<.W...0s....J]c..m.#....L.X[Jc....n-%a.....5......"v...:..4.Q..P.{L...>..1.F.h,.$i9..~.......icB^...._N..9..M... .....J.L.a-..........[..W........e...*j/b....b.f.i.,.......9(..L..&_.....Wb....`{..N../......u....Lv.P..@..vnhZ{.}!..5..........=+9..%.m6.f.............)A... Q.;..i..K.e......K..S%.0#..b.=h.....&...2....+.L..Mw...<....6.).;..Y'..>.s....B.{...._...e...I......&.A.<.............'4q....m.914 ZT..h.I..D~...?.W..W].Vb,OG.6=m.OL...M.u,.q..P...L.....W.ue,Z`T.......S.. ...14...6\..;.t.......>P.d>!......0..j.....V.............T...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):438
                  Entropy (8bit):7.319817470821598
                  Encrypted:false
                  SSDEEP:12:CWzzxD7rwsaJTOcGvafnOkkrQL+4RYV4OA3wx/NvO:CmxD7uJT9GvafLkrQK4RIHAAx
                  MD5:2C74074D4F77019DD0C9ABB21C41DD31
                  SHA1:FA88A314380C201CCA45C844188BC5AE2171F463
                  SHA-256:15A7E56BD170194F9CB755C6887519486D424F4B398105D349E9602D376F20DB
                  SHA-512:4F88718ECFFC27EF9D65C90C549439366B62FF49BD1607EECFA480F028BE7B13D0E4EEB278EC6A2413EBD2BB7C07CE40CBF8109894B5C43C3326A0B8ABDE1584
                  Malicious:false
                  Preview:.B.MM..C..9E.N.8......<.....,<......(.3|`l@.J..e.{e...5...o.N..L.U.T.6.*..i.u...?..R;I..........U............Mp.c.E...go.\...........r......Q.*..N.|...aW.$.....*..I.....c.3.........~....N.....%..bu..[O..o7 ..RQ..}DX"..G..1~.p..%.v.Q..B.I...."kM >..1.k@.q.->`.ny.K_*.q...O.Y:.1uY.....@Q..Gx..O._...<!..5..5.x.. <.{H...f.$4.............a...l."C.6.../.F..]...$...p..W...5..+.r.2._.rI...........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):727
                  Entropy (8bit):7.668041002240283
                  Encrypted:false
                  SSDEEP:12:Yl5OOjc5NfES64BWKg8KOKXqyUviyeXxv1Hsqu9F7ts1mY1MU5Viy:aOMiES6jNjXeRam235Vi
                  MD5:6BE7F2442F56AC33150D239D9FF41F1F
                  SHA1:23519BC1BAEA14F535E4CF18F5464C5CD46651BF
                  SHA-256:ABDE99A3F5B391859B44C3FB321272498ACBFC1CCF7B7F4058A8446BAE96EBDE
                  SHA-512:694D25C404E6955B2AB0DE3978D1E8E491128A16EE5C7BCD914EDC967A2DD583F521CA5F9D27618E7F462AAB4A3A06D066890A1D5FDC25B46D58BD96860F7859
                  Malicious:false
                  Preview:Ex.v..Y.F.?.0/....u.....6:...X.H...?c.;...D..$.. 0.......Ue... ............|.M..U...... '.,y.J.0eM..4.Z.#..0....rRoJQ...1|Ksl...>.&..E'.1.z.4....,u...{.9%...?..E.!tQ.5.6.!.N......YR.G8!=_.!....Z.b.C.>.$4.E%..NsD..2z...D..)...(...4aY..x......&?).DU.nv.o*......n....l.c.......S.^.1..9...B..j%$...:..O4]~...v.9........-z1..z...=.].(b..DB;+9.....{C...b.=jXA.V........"e.![.l/rW...=........ .4..XG.P..'.c.....e.:.....@Zcz...[F2.Nh......0=..._..q...!..9..Yg......t.."....@.@..:..8....(..c.....j.....B.Z7l._/<I.g...G...i..6?...RX.....,....WQ}SS..+cb..._..uP.I..FU/~..t.A<.*..9..O..r-._.*..l..+..L..A......j...7.......s.....R.o.W."..<.3U..p.y.U;..}.H.27.......e.0...............7...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1504
                  Entropy (8bit):7.850136741928439
                  Encrypted:false
                  SSDEEP:24:EQM8Uy/z1iRm3+9cOSnAM0qG+giF0lJOH3vJwYz0cHbE9kebQqfHHx5wwsiiJrpS:BM8UYI3pM0qzgllJOHfrpeJfHx5J3PGm
                  MD5:CAFE14780CD21B25520074E39610A805
                  SHA1:318FE29FE8845956D450884AADF0D194EF4CD6BA
                  SHA-256:6D4DFC632FB5D62E0A09E9488989AC157B8CA236E45627EC67834115BF33E85F
                  SHA-512:EA589CD04253FAECB0F2D72E9DB47DD808BB626659D5D804AB58F53C32956E14F6980D116C27527BAC2491F4D527DEE4FAEFCD9230B7592EDF379511A064B159
                  Malicious:false
                  Preview:....r.f..{.....K.bt..^08m.Us.C.BK.27.....?..\Q.IT.....g.hr>p=.Q; .vg.:.e.O~..J..X..[...f.. ]f..&C@J......W.6..q......v......*s1....T..)..+kP.<.^.!......G..x..Mg.B.,..,-\A...(..,. ...+..q-?-..&<.......e....g....a.o.]%.rTK..r.dx...EI..).I..UL.vx...k>.}E.:D..TR...aV..{D.vG.........f.`.......hsb.M..,_.-.Eed.<..H...../........9...{.....[...5.J...{D.n.0........_........R75........T.5..W.6.K../..P.9]O..W..dt.....o.!..E.....3?#...0FZq@....{...t...{-S.x2..K%O.}.n%...72......R$..h...........PP.&x..j1..z..#p.T..p....T....w.F...U.Eu.~...c...jQZ.?..6.G7.5tT.\..s..._..l.f.6.0..DM..E:..?.6O....S....8.....:.X...).-....(..7?.yz...)..T......A...9t#9'..;&.e}................._.j). .....*..R?.a..FJT{J..3Q...H.......w...[.f..].b..v|Y...jf(......XW....wm.<.......On....P..#X^N..D7..Ss.|..$.O._e...:..VD.)...r@..[..X.......sK...X..A4..N.a..C..v&..[...J...<.....H!.......y|..T..\..5..6..N.wj.A.....%..c..*K....$.........+.^.~.B..2..k'..+|...g.U. ..zO...B.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2662
                  Entropy (8bit):7.917636523832379
                  Encrypted:false
                  SSDEEP:48:HtwzVJ903eN/rmSapgiNqGiwA5hh4INYsEePgYOtrxjH4ha5ioMvkBncFreL:NUm3npgSqG0h4jsEMgXtrxjH4ha5Y8F9
                  MD5:5EA210B2194F0D882CB2EEB9F4C5B4E3
                  SHA1:2E682BE73FAB8779B627C65B0798578050A48835
                  SHA-256:C1BEA7458A6B1EC016DC5CDECBBCCF426E240153E145FEBD38AE7452877CF667
                  SHA-512:2E16737495171C9E8CB53D108451855CD06C33BDFE1030D31DF84EFD6C8A3D67E3D5CC728EFFF5958C6715193F068A6C3EB92157561BBC14E13CDB1A24B89665
                  Malicious:false
                  Preview:...O....R.d....C.].}..?E6......$.r%.<.D.(..`..:..;.:.X..$.....)G.,Z.Ig.....6......6........o...1..+............@.7...Ec. .t.."..U..Q.....0..............3....N.ca...G...4.$.N.......`>...F....O.....?.....m.../N...].O<O`7.yfr6..89..._..iz.t..1...|.3..>.7z....{*.+.....g..P.H%.i.?..X......&g.'.m..W..#.#.F...w...f.... (g...H...1....T3Af&iE.....6..q...1.g.).$/......b.q.c..Ip.:..>.x...S...3.....[..P....j..... ...\......=...B...F._49.=B..L..G.....Z.0x...g.W.....\.......n/....#6`..W...57l#.x.....OL$..4A. ....#.%..,q....A|...rkx.......S.J.3.,.x.jG[...r]...1..}. v...cJgI[.,...b5o.n.]D..m.... ..m.....Yu....O.*...c..#..........4S..x....H.Q....f.Q^....Z5...}~L..B/....`.....9.Gine.....f.oY....Md...lQ.<.)..@.....U.Z.O....g9{&,.G.A...P.[D...{n8'..[..b..[U.j.....`t`q.4.i.t**..v9j/.}.H..$..C..l......*x..nM._...~.e)..9...&.:.e./.X...=...k..|a|.."p..t.&FRn..:|i. ..0.y..H.<.7..6..F..0..B....|...D.S..fj.........Nk...,..SALF...$..@...O...;?Y.0..>`._.a..@h.3.!..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2440
                  Entropy (8bit):7.910220872298014
                  Encrypted:false
                  SSDEEP:48:hP4Zw6JcKkcakVcjJF4qvp5MbHytoTRMtQiuBwq4ZdRt4UyTgDJ9K3Cft8uPd:hQy6JcKDdVcdFL8oC6tUT4/hyj4
                  MD5:7615F5BA44B2A6E41500DA1B96F1ABEE
                  SHA1:779A1285127325DAFA5A309D7156CAE8AADD454B
                  SHA-256:3936FF2D2F8F0A57B9270BC2B5BD4883DC70A9873507F457FCDE11F0565D11B3
                  SHA-512:2E829F7BED259F13EC32C371C4FF99A284B0D1B229E9AC77C8965680ECE06EE1379327C363AAE2E5FF923AF92CE769AAC5206D719C86D282F2FCC16E7BAF866B
                  Malicious:false
                  Preview:!.h;$.....p.|...r.......Epc..-.!.... 9....h/....<MJ..I.;Ru.oI.a.....<..`O......2?..-.!.6.V..pb........o..^......^.gE..T..N".].F].T.{...xCP.r..JL../.....J9."....H,k....M.rvQM....6....D.w{b..x....kBc....(CQd....u. .U(^-.(.......xZl.}.B*......y6n.x........J.&:..L.(-[x.R..G..<..'...?.uL.....``?.. .\..>..48...J.>.3..oh]D....Y...g..5.>....B.a5....2...y4.........$..<K7.f.+.E`Z(.V.:...w.8~.n}...5...QK%._...V....].k:..*....3oA.#c.....S..hr/F..N:F%.s.4.Y.._?6tV...v6.._.../J.-#.....s...9.....k../<.t-.~.....^..7.EZ,e......D......E..;.s.d.J.0r..7.....c......R..e.x..e..D.N0..V{.`......Y......")...K.,^k.4N>V...g,....<....9R.. ......v....gi...L....Jy*...e.........UV..v...5]g.l.C.......h..Qo.t.....s...&...4.)........ Kr....s\....=.L..t.E..oo]...c.Te.F..p.{.&[2...e...s....b.&E...pZ5..Q.nBl*.....=..r..DQ.?"....(v....s.Y;W..~.E.!77,.k..Fb.<.7..#...G..zB....%...ONM.h..M-..A...9:,......6B.B........\..n'.5...a....3..^....1.......o<...7.Y>O.*nm.._....u(..QU.'My.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4986
                  Entropy (8bit):7.9638632836754955
                  Encrypted:false
                  SSDEEP:96:GHtuYQuJ6DwfoNzEjzUEh6xc1PZ4/gFU4CFdVv2mqpSXUUi:GNuYQu3zJIO/4/sUnFdh28X+
                  MD5:2B4D547B0917E788E634E4F16792DAEF
                  SHA1:793FFEF28E996FDDA66A8C2AF16939C64DA7C65E
                  SHA-256:B718D8F167A6DCD9B28FB2F0CDAA502F0EEE2C5B1ED20201A249DEFB33FBDFD4
                  SHA-512:5B82CB140CF77446753C6A0AE17DCEFDDE762492703BCCA69DE8DA411B1CBC5D8F9CA9A5E8ED52DE03E48A3868B5B4C1E915D1D136E473C6C03E61311E35475F
                  Malicious:false
                  Preview:..z....N..};..]......9..T........2x..j..W....M.7.'._ SL[M...'.M.9w..2..r.(E..8...}K.!..y.....N!..P..(..iZM.E...h....3........F3yt...r..U .M.H....f|<.......t...mEj.7...G.D.&Txv....DP.q..e..`O5I.n/..W.`D.Tr..\"."..D...]).mV=7.....y.._.B)...E.;.SBJ...R;fW...MN....5..p;@Lm.g..gt...f./...D..).!....R.u..v.. ...8.Q.....JX....0.2...A..sJ.Vl=...h4.).+.QS.....4&;...M#.>r.bD.b.8-.&.(&:..{O..t.....O...O.g.....X>..D.G..%3..\=.....wd......l...r....y.mv.~._:...sV..jT.G.X.....e........?.J_a.&...H..i...f...... P.e.x..........)"t.......{H.5.ZZ..x=....k.K..+^a.\[.@.F.....-..z...V...G..~.r...O.]0.?.[.2...).;.t=.....43Z\...w.C..P.un...,a.<-..q0 R..O#H..&&y4........'..L........Em..E._.zEb.iuI...z..#.{.<....AUH..`.z.1..d.....{.:q.`5...-G..w_.W.J.X.....5.W8(|.h.&..\.`.x..`.O.u.!./..2.v...0..;b.g..k.}....n...L.....:| "^.=.K..(=....s.Lc...un=.^X1@..O..n..U..].+...tf5.C.....6b.....1..._.d.?.2..B.G.+..P$..0...%.o.w...v...!j.}^. ..w.;h....43%..n!.L...i&..^+;.'`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):783
                  Entropy (8bit):7.661714305154168
                  Encrypted:false
                  SSDEEP:24:6XZ4NlXKgK3JSxe64W04Wy9lYHsdAfDay:uZZgK5SxD+HYUDay
                  MD5:06953E6CB93E1EF9474DFE34C1CDB5AA
                  SHA1:C7F6CA8C1B3143F1BAE84DA549739EDDA1E36BD9
                  SHA-256:41D7ACC44497C252F39F7F875D05320ED9E0F0DBE04AE8454D8539E6AC66AF27
                  SHA-512:C744131EAD928CE83D388F52C1993D3D75F9F78D7574A8C9557428307CA76B19847748B65FD2164B124DC73C2E8101BAC6A238AF2D8174C5FFC49C9674A6C3DE
                  Malicious:false
                  Preview:..K...L.).......c..~.<.:p#t"E...*4C'.#..e...[..:.6q.{..T..A=.....{X2B..$...(V..........~>.F..^j.....)...dvy\......#........O-.X..rd...Hh..m..O.....v9,.N.^....._..C./.'{.+....M.}.G.....<...e.q..5..fr..R...F..K.....h..>..(.<..+0G...+.....]I.......f..'Q....Y...:..glo...k.Eh...9....L..9...v....a.-.@......n....uxB..WV"..X..jW.:....p.(......g.).q.\*+;....X..}I.9R.~S..... .....q@..4b....Sf..5Nz. ..m...H.b*O....U4.ma.......H=...M......r...|.).H....Y..?...@..g,Dk7.xMHf"i..bw....?h.5E.2.Hx.'...D....E..B.=^.^.i..].}.w... q...N...f.v.**..O}..H......r........wZ...0{........zSlv0?#=%.?.....D..2(.q.1..a.GJ......zC:....4c3.{...,h;.~...?.h........L...~..@.....|......o.......,..[G.WX.\..v...n)...4..W?~....&.........H&9.f...]........o...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1535
                  Entropy (8bit):7.852461413520861
                  Encrypted:false
                  SSDEEP:24:utZ/sHgChrdhWhXG1hJgr6cHn1MDBfZHDet6faEEt7KpNIWdFkLDgL/8YRWCvAfv:uzfCd42pcHn+xHwAutZWEO/8i7vACfk9
                  MD5:2E208EF99724C000C4AA6BF5048F9449
                  SHA1:AA2215A9D635591A645556DAAEDBB6A22C82218C
                  SHA-256:539A5CBA92E8575EE6BB177CF3221D7529937D76F41A4FDE5F38673AD270A881
                  SHA-512:666AE75C4934E4BAB9657820D6253D1032462E7F511D81D2EAB70CD66812959F34A419B650107AE940A0343F039CF8B66FCB56287CEB58102175E578B5824A50
                  Malicious:false
                  Preview:...V(!.0..D......u...n<=.r@.6n..L..J..7...y..M..Dr).B..2....0..d..6.R.4........p...Y@6..>vw..j|i.q...}O_.e..J.<SBv.~W..$a4.r1n.&.P.....GD.DF.0s..4..x]....>..Gh....j...Ks..d~j<.1A1.4E..!....P.1.(.!z.O"t.. ....a....]...+.......%.L,b-..fs.QXl.o.{.F.H2.;...Cz..&.....sDe...rf7.r..........{..~......re.'U...Xp..?.=.a.N....kn..1kR....~!.+*],>..R.:\Z.KV...;.L..Kv.P..."R}%-.....:."...M!.mV..'`..-2`.tez.a8...i.CD.Um;..~s....:.}{...{n.e.....q....,...e....#ZV\..~.1."..m.}.PA.|S....*.l.....$.,..M]G.....O.....mlM+W.......h.3s........Ca.t.}_.....$.......qg...p.B....y$h.=T....=.|.x..nJ....C.Fe..|nh.3D..H.! ..?,....gK..r...(._=...EV7.D?w..S.....-u.CP.7.-.F.h..Ke..WV$...^.....~....\.O.R.sd#P?.dE1Q..&6....^.3=..q....*;/.yZ..1'@......2_.G.rE#.5_EL_.f}(.z.3.7*'2....X.B@..F......b../e...m..,.F.2!1mE2.d.:H..Y."T...d+..)F.....M|0..%......o...).....t......O.$..Q....g...F..o.;7...).MC...........`..e0...cQ...L.Ba...2.h.....BG.c^.....\Sa....F..Ye..A.....J.y.6..1.+..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1128
                  Entropy (8bit):7.788189258179823
                  Encrypted:false
                  SSDEEP:24:ZElkU2ypYbtm/5Q4kNjZ0N9oHyWbfTK6lmPwdmsNeU3Y5FTb:ckUobqFk1Z22yW66W8DwUCFT
                  MD5:E094E84BBCC70FC729CC72275451AD75
                  SHA1:09A78310E7A8B876EF78D4F4896B7A92706FA130
                  SHA-256:9781887D6EA178C93EF8CBCB6960006851070EE17596645FC4A705DCBC089CBE
                  SHA-512:9B8B6C8B8FA5E774716AAB47AE1A914076C5D2A34EF29BC7288832A0FB459BEA559EE93D2C28D54FE121358169BD9C2BBCDDB3D26DB2AE8B839976E33EAF6B7C
                  Malicious:false
                  Preview:.......~...........p...q9p.<.........E......s......]....J..."..sU]r{..s<..^.L:x.^_.?|...eH..N....r.B.B-%..?..fi..H#R.......6.;1..OL02.`V.K.....7.F8..G....oo.p.....;...;.... q.&.P..]..a(.......b.g.^.......xk..7.2P;.t.....Y),]"........6.#.R....<.Cn.X.>U..s.L...#..ZSm.G.87:.\4E..?.a.z..U4.....'Jxp...,w..L.yo..!jBtf._.].\)a...rq.M..s...E......+[.^.. .?.....[[..T.\....p,...zB.CB...{..).).:1.s...y[u.....L.r.g...V......<.....].p2y..........U..(i.]d..."..r....]..jhk...T.{.k.;...3.....%.p.. ..tb...>A#..:rx..N.v.7e.-R..Z.U..\.[.v..`.r. $...W.......z....,$C...i.m.&D.G........kEk}}$.^yU\y$&.D.....^s....g.+6:..EY...?.l.Q..:..C..W.[Q%...\..G.K.F.Z.'.....(P.a..o....6..`..s...F..F.x....w..I.....2..S..&8.%O.e..X&.9......=..j.....m..2u..F.v.....z....-.#3\.K..R........<.....iP.%.........~..K.BK_'.[*...6.8/....bq....9.L.4.eVv...i/..h.p.k...7;.7.......M[...3.....'I.=..N...hD......RsPP..a@..K..|..8.V../M..I(..f..S-.O.a.y.4i..d;...3...`MY8.|[.;,.......p^O2.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):668
                  Entropy (8bit):7.541380783933904
                  Encrypted:false
                  SSDEEP:12:6w9tl775uaeBr5tqZWAc990K0hKcf/Za9PtgE4R5pSj0ozU6oOK2RIAV4TFh6:37TeBr5tjARpI5tp4bpSvQ6q3
                  MD5:52652C991C7B8C7F2B8594310CF715C3
                  SHA1:07663B69BAE82293BBB110D2459570A7C6A34017
                  SHA-256:685624015F9823206A0505CB43EC6FB301983B88749AC247FA98514E12E963CF
                  SHA-512:6D9F9554984871DB8C93271FFF0B5D6267394159D37F73D73145FB0103586432A7C02559DFCEF8E1712BFA4F649BB43623C58DE1B1562AB13F2B94895F69E219
                  Malicious:false
                  Preview:#.X.-..+.....-..|.[......Rk..S.0........<s1...b4.<W........._.[.. <.,.....%...\.\.,....|#..N`.......\...F ..Mb.s.;....2...0...Yp.Ll..+..3.....;....B.a..}.O.......M..a.W..y..-....f7j.....K.eE._I.t.<..oR...n....NK...17.....5}w....x...#&.r.....[.......D..9.... ..n.j... ..0N...>....Q....zU ..G..H...A4.....||..V&.%.O.F.z"\.HR.CwA.Q..w......Zh.c.......&&mv.=3.1...I,N\..;....F..D...9D..;.F...\U.h).Zg..iU)9sL...Jq7>J.....>T..`..+.DH.......L......e0SG.y..+.K...g.&V.9N...V..]..5.R..e..]P.....2.7.I.y&.-...#..SS.....n.<.........l.{..3.F...U...z.M.....YKR...........aH.....l[h....KF..X5Lk%..O/.^.f...V"...e..3$.}`....s..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1302
                  Entropy (8bit):7.829281082198293
                  Encrypted:false
                  SSDEEP:24:MSPL4/iqt0ylRYxl/NfmUpzLv34lmphB0kr3Oc8guniWVtZ:pj8RuylixtdmUpv34ehikrD8go
                  MD5:C418AE681327F38494597F552340E998
                  SHA1:F9F1654B7CF64E682B0B5D6A1FCFB16A94C62847
                  SHA-256:D75FC42E5F15C749B06124371CA4BDC401370D2544565013615DE6E060783AEA
                  SHA-512:31E1BEB00108B19114858B36310548AE7208F78CE0BDF94CB1F77E7FE006118BE785098520A51635378162A1E7D22ACE8A00487FCD0D4A50FEB5E7E018B06E05
                  Malicious:false
                  Preview:.5..C.+L....0v%.M.N...E.Qu.Cn@..]|HWW$...9......$....Z'I..D ..... 1.._n6].)....h..........]1. ..#q.e..e.h+Oh.d.....*X)./:...+Ub...K.|...hKE%LGI...c...zr.-...|...r...3..}.......wC...s[.r.....dy....gl..uy.A..s.K<..."1..RL..#.......".....m...........d[...r'.*... y.|.K'...n0.H,E.&..Y.......j.W....G....g8.18R.........k...Sb.\.....2..m.~.h...#o LV....].TJ.Q.....c...A.....oc.U8;...Zk.....8.k.!..3...PCu...i.......A..Qa3..u/..K.I.~...0O:..A.......8..i.<..<.`..........X.D.,.l..1B ....D..>..=.........+.j....j_Kj]...>.T..F....G...&..I.M.......|6...}....(..kP..kwkGSk..u..v.!{..|..[i..s..)....Sk.HaXx....v..o.u.1....r+a.dXA...%!(B.....=ah..S..^G..Hf./~.^I..:.O@.d.}.c.f..$....i.r..1m].N.)..>.Q.....?.D.R.`.-x.}..9.L...T.."L.V....G.a.s.......:...m.o)......z...p.t<..OUv.Q...ebu.4.J.p.....I..HVKru.w.....q...Y-;..H.[......tn......$T..$..^......z....lrx....,)S..=..@$.G.1.....1.^.#..?d..I.yJ''mQ,...qhw}....'...h...=..jl.#?....y.:.M,.....$2b..R..<G./[........f9r.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1590
                  Entropy (8bit):7.866126951937831
                  Encrypted:false
                  SSDEEP:48:5bnm0TyFf4oxTKCA77IF9Q1VdFNvS5M7:8GyFf4Y2CaIgDFX
                  MD5:16A2BEF537103F50F074EA18D090648D
                  SHA1:EB524215FC41B4DAD7C1BFC656D359AFA81C1406
                  SHA-256:13EE11E0720CFE71DF37E3E02D2F72AE6899A9AC4B57F95C24DDE331AFA9BBE7
                  SHA-512:3BD4A47704B40899F9A46F7CEA7306AF0C7DA79EBD2C7FB43E790DF85D46527519E59DABC6B13B42778A9D95C2D2DAC763CC84A47AF5451156D28F555B0C4D34
                  Malicious:false
                  Preview:..^.....W..!`w..gL4......h.P..tasndo.i2.ZpF.k.o....$....[..T..#..........2H....f.Z..,.P....*-.........F...-Dnby... *N.w......8.....;.D"..!...e.....j.$@y.x......V.5...t!wuq.4..../j.I......."<.......->.t.`j.....)r5E...#S..Q..a:...~!.........8c..\.../n..._....i......G..../&.mJz#.".+G...._....l.5:.:..c...Jo.h..4...........'..J.....:.?..D.Q....3...l.%.;.q]...."./......}.R....nRT...%.4%Z.K.m...r.C.3........}2....vY.&.......sp<D{.CL.p['..5.l...>>.*.....=Z>q(._^.]"a..^*.mf..~.C(...>6<57......U..L...Ai.F.*....M.."%n\F.+....|...,...\..adK..]#.I..^s\...Z.L..TYtF......W:N"..w...."v.....6.......#.XxK..(.>....{.M)....?..;.h...........El........A.e.>r.n#. ..3`.I.(...L...e..O......].q7:$.....0....y.(...Q.G...@.w.o....$(...w........\..:..p.v...Q.....x.f.UW..S..Y..)v_.r...k.l....)Y.mtq.>.&..y..H>.p.6........O.......3W..'..@............^.=N..i....J;.wn.....0.<......5....U......J....F.>.j+.e.m_.O?.e2...i...RW@.s..P.9..._z\nML.p~.........mn.....-..VZ
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):699
                  Entropy (8bit):7.628427079724226
                  Encrypted:false
                  SSDEEP:12:TrE9zl0cV9q65L/1LCWIZozWUQ4vzJChA/xpeOM6EwIL1pD0gWlC:TrEpLv5pLCWZG4vlPTedhL
                  MD5:2F351C63341CF45717683524B204BD40
                  SHA1:F477941F00F8449B8752BF4F481890155C7FB4C9
                  SHA-256:004EEC5B9D33E77C6439D355294F6B5491141196ADC90F0597C6DDDDBA4D09C2
                  SHA-512:F1208CF1F1C3AFCDBD6CFFDF088B04BC10FED989BA7855F8F76D771C94E1E8E44FF8574A0BF5E668826AA76DF1A4DCCF28EDCB72B5E2B276DDBC264B70EB41E6
                  Malicious:false
                  Preview:.....|.+..a...1.f....-\Kw..kv....)1P.E`.r(....1X.....,...`..T.........q...q.<N..d..7.....".;.*.v..I..'..D..`N..y..|.~.mi.....Oc..&je@....o@Q[..8...s.,.].z...>;dx.W.u....jN....8/8.......m^w...F.<.aF..t%.E.2.?.2.C....\ .z)2..........nb.._k.'t.....9QmhQ..b!...9.} .D...}.r.....J..-~P.K,.\D..t..P.....K.B.K0c.0...3......]E...bPY*.....~..E.8.9t7.K.E.^wU=a.....9:aJ..@.t..".GO..].f..:UlG.m4...(*.4.g-o..(.}./..I.:...b.L....-..+D.Aom....3.....d.r.....6....8.P+.....2C..^..a,6;.;.['..q..g.D...c_..9R..3..)..O.?S....l......,G.<.v.7.!>........P..Ek.sZ.|...mT...x#D...-.BS....BZd.....Q........{...)..^T....k7r.[9.].P...qZ'6.[o: ......6p.....}.p".........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):937
                  Entropy (8bit):7.71583928591194
                  Encrypted:false
                  SSDEEP:12:MVzSIl115aKDlpTCRUAwlinl03uZD1d1fW7tp2isa7Sk3Os4y6grmufSFmBvspy:MQKJXDCwlgl0uZD17f+/2XqOFSmVFIw
                  MD5:14F76D5990CB00AB8583A7BECB6FD8A1
                  SHA1:83CBAA141C6AE34F1F418920787C1F64A3069E70
                  SHA-256:0CE81F33CC98A06BDE21C0B030CB574E0C01BD43E44D1360138E0F3A50E87879
                  SHA-512:35557E915247DEB14BAF9A869CFCBF66A5DACE3A490FBC88DC5F00FE36E912B38618A19B569A336C327EEA7872C06A9C0C8767446D42C7BC0A1B35A865D62A4F
                  Malicious:false
                  Preview:. Z..T..2..7....Z(..H.....l.l..........J..G......J.L..7.0..P......}..E..H...tC]x.O._..J.m...;l.qbjN..`.m.U...,.y. S.|.d.t...3g...FU........7%\0..W?..}Y/w.(k.&PA.a-C.d....!.}./F$.X.+0.M0..eS.K.w:.......b,...l..e{.dY.2..,K.v.q.F. {..B3..z...$Y`.D..1S..\.........c..6.....+.Oj#..R...-P1....W<i.X.#...SN...6,b.....X..e....+.V.r.N.Z...G.Y..TE..'....LDa..`....mf...GG.........0..K...X.2..dX..al....(.G.a.........2D.i..)Q.,.....H..f{.'`.aF..A.-..*.'.U%..J]/M..P..w.y...w..Z.7...$......l.......S...t..J..7.$|..OA..u..[./<.|v.aU.V.....Q. .,[J..&..Ab8.0h^..hap......0...H,l........2.y..!.Dj.r=#$..t2.1....3`k7.........)N...^...D~g4j}...;.]BV=]M.........5....e*..........{../8_. z._..uA.*1.&T..F..0j.rn...V......&.g...e...:.%..J.<o.Ft.P..o.m.Vt......\G.#..VCs..__....F 3.k4A.di.8!/.0JL.wh..ZW=...^P...W8UP.t.........'.V?....A$d..~......S.<...6.. .F....&I.P.P.4....U..p0|........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15264
                  Entropy (8bit):7.987705921823025
                  Encrypted:false
                  SSDEEP:384:0H+/uQSp6TWjHsud6dJgiZn8CrSfouVebrqBoviFQ2b:0H+/BSATmMuS6MJOebrq6iC2
                  MD5:3C3DC07ADAA90A9B8C00B7A95E200299
                  SHA1:1255AFBE285A66AA7F5796F26472B4A50CFF5064
                  SHA-256:711918F11FDD229D5F4CAA272E2B79F1BC6CEBD6E3DB19B2D5F6F8BF65F2A068
                  SHA-512:95323344C99BD54DE6C30D774A05C73FBC75A2385B20E42CAAFD4A2640CCD7BBED043404133818A0EDD9F8983F694F68465673C2A2BE74DFA2D61BC10DDC5698
                  Malicious:false
                  Preview:...|[.'..L>....S_..Y)....Lc..@.!..B{..nqp.+Ywn..a....]...M.~./....d/Yl.}..?jD.lt.....t$;.....0.....j..N.=;.^....C.,.^.v&.GCme..i.U.......x..c......n...........u5.8.G....|..|SX'.u9.........z..Ch\...!Z/0.h......N].4..R4H&.(;..R^.........l..@p5.C.TU..WP....Nq..-...1.d....]hM..F...K!.....g.P.K.Jj.e.B.E..<.....eQt/...4.-A..>:).....,.[...........yw .y.S.Y...9.-j.g.r3>...u........J.,e-:..4..d.c.v....6Z...2Qt...T.G......52X.....+.3..."c..m.}D......=.V.f.Ar'.q|aks....E.?.e.+>...z.'...l.O...[....Zqm....Q.'...\.u....AP..........tt.B...D..'.Eg.....htJ...Xk...8ed...x}m/.x.wj....~.T....YF...F./..j.Y..et...N;Z.........D.\......<....}..W....J._.wd.Y.......*.Z.].C..J..P.#ft..;x...;.lo5...m...h........g..X...].lF.4w.q.@..d4..pbA"..tu..gls..`.I5..%...g..'.R.........h...{..p.@.JII:<)..r.k....Y....?..A.9..$.Vg....W.#|@.g..]..?%...?......K...}....Z..!......N....q...O.?..#.!A."t).$%.6.......O'..*.k]....FZ.f..g..n...r.L..E......r.....,J...p..ma..j.~\.Q,...~...n.ZW.|
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15412
                  Entropy (8bit):7.98927309892204
                  Encrypted:false
                  SSDEEP:384:EpZuJWPEhjKkYFv2UdPStl2ueDhLk56siRaOcmlFln7X:ECJWMZAv2UdatReDVG6siRPDlDn7X
                  MD5:9EE6A06F3DAF039C9BBFB72FAB17EDD9
                  SHA1:9F3F4878B0CB4A3AF760FD04BCAEB158684F807A
                  SHA-256:3DBEFCECD6F3A575FFD2E6829BC73D8591BFFF5C15F36690622050F47A16CDB0
                  SHA-512:DB50DB6AF679A50F4814C8495F6C0264FA99557AD80673F856E8352DC6647B63DA62B4BAF38CF2ECF6D635CD450A4AD025ACCA2C960CDA9219EA1F176758642E
                  Malicious:false
                  Preview:+ .@...%^...u.....vm3;2+.0..^V8YQ@..7...~..l`.{Z.M5O..B.Qj%K..:......ZG....T....s.uC.O....@P[P'....ai.,...^/.I..p.h...C....,.C.sq^.W..3..6Y..rt.8..b.P!L.]_|. .ak..z[.U....w.-.+9.*Ae...+._...[.w...V.....A.K..*Z<E.1S..%..1k}.!E....0s.z..H.......~M..k..C.l......*.O#..Ap..q.Q.n.u.A...a.~.......!.|t....[...-n....L.g~.}{...K..h..1...W..T ..8..o`:>AH.)[%...1T....;....pd>t.>z..(!.Vy..rPz.. ......3...2.... &!..O=...5.n1..xAZr....(.C. aN._y.j.&[[...r...*.yt....q.q. /.....e.>'2..|.U..q.}p<...(..KH.......E.......m.\1...T.M.d......I.X...:%./h4.z..FNM.Oz{..s....;Wj..W=8..L.].>F...>r.2$.q..I.K....h.'.>.GY...W...s.....|..GG....\.*25....)..|+...M...\. =s.i.=.........[.U0..F..O.......@A...!...4....-*.#Vw4w.o......\.tf....b....UU{..^.O..9...m#.._Y?ev....I.....,...EGZ....('.k..z.3.Du.2@...9x...2U.@.:....?...].x.../.a?.9....K...t.....A.8.]O\5.......,.l..3.f...f)..I=...af.X$..7.......Z.....:...!..Xt..~.I..........E..0..v.....6...._Z.-.)....%..%u. .5wVX{... ;.{.Yk.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1499
                  Entropy (8bit):7.860506131196089
                  Encrypted:false
                  SSDEEP:24:AZAD5HwJR2Z+ZHAvuUmqAWw5SvTq7UfwriAqquEhwBdrOGASsAcE/+3spV3GKUxt:DDBwvldAlmqArywu22R3sAT+EusBmWc9
                  MD5:7DE9854EA953E8BE74A32D7B477B4CD3
                  SHA1:B47864168E4E1C3BD5541487D41AFA63C620A285
                  SHA-256:FCFEBF95DF445996B66F2D522E8C120F96E3F842C3B4AAA383229D2432A02121
                  SHA-512:B9E4B5557557907201B42F048B107E26D250FD54AF7ECDA2B8F2DE640D897337132C6EA5E5862EFB32EEBF11D9B11C7F5DC18984EBBF6A19EDBCD7E697719727
                  Malicious:false
                  Preview:..k.M.I...&.....-....s>1.-...hv.<X..%..^#n....M.K?.'.V.O.e>E..I@m....6Xd....x.L8..k...jgn.1@.....lf...^...2.s..9_.P..0.+I.Zc...K..J29MOF.v..3e.<......ku....v1wZp@.z..hPh.i.X..M.w..q...(.\..<B......L............H..E..RQ..&....q.....1G....j.:\.\{....m.Beg....b_.S...C.f.X..+.o...vt.$.....0....~=.^ad.....l.&/........-..%...9=.6..6f.......OC...H......Y....A...':=.0..'.Bps..b..m.lkT\..r.G..0.7..E.3....Z-d.nAJ$&...".V..^...^Ud..4uYf..g.....P..l....!.3..Q....%3.G<.n....3...=eQt[.s..5...0...'w.+......}w..,...uV.^..6.....J.q.n.>T..jD6..q<:p.S.s.6.".....a(..w.Z.L.^......<...[.S....e.*h&.4`......Qod....x..(...|d......e...!C.5.....r#....`.>....3..@*...+{.......=.Va...&q.B.=....D.S..f....O.\.).OD..v..u..La.#g....Q.F.WP8m9....... o..pd...8.W..)\..........f.+c.`.....FW.......OA.....URb6W.xz4....r.......(...hj...i....H.%3.......[..M...[.Z\.EN...@t...L.8.&...$.Q..O..u0..~..V.z...}..|....`.f)....g..._t3>.nXT...M(.e..J......E...L.+.........S..Tp...4.m{..:{..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1112
                  Entropy (8bit):7.779430145105307
                  Encrypted:false
                  SSDEEP:24:CegHUEX6fan+OA996FFpK43itpVHcXMpxsY0tncQp:81X6ftmhitpNEMpxsY0t
                  MD5:95AA67D57B722AFDE7C7AE64946802C2
                  SHA1:5B419E8F7C6BD1D3942C720C6BC7C6CFE8332B43
                  SHA-256:2CAC127057D9480FF2CAC80A6071A954CAB175789B5AC95680FC908B1F191217
                  SHA-512:76B101D78A120FFC68DDD7035D5E5EF93EC1920B52D0A042941040654E3F3D87C299E842BDDEFC6534E3E59F90D0C2D3B60B9CAA8CC5CEDD11518B0A89464DEB
                  Malicious:false
                  Preview:;x....O.I?..V.}..c...C......v..NS..h....x.....-.....nUVx!..AM.>f..|.K.......V.c..F%......#...Cj....>.....El.e....:.(.!.e/.9<...|=............}...=.\.1.L..cf...P..|...Rp..:U...s~....h.\h.9....~y..K+..P...]..."t-.i..9..._l...y/./p#..&.....L..mV;8...T...cNZ..Um..,...I...A.P........64..>o.".hD*~.W.....!Zx...A.n.f.r.g...[.l...<7.Q..n..c...dh...................,...H("....<../..p..tE)..U..X<..$v..rUp&%./M.W...V..0..Xi@....,qJP...?.^(...%...~K.P':v6.c..z.rKG:JW.m|.}......d.<..=.....qq5t.......rh....D.h........U&...\..7o>.hn.....Lj}...S....u...>.....}.9.K..+..]......{1.K...]\.V_gz.DA...h?..~.l..%..4.....&a....g.z.@........8..q...\s...nU...*.T...\.B.w...G.P....;..u.i2..g..F ..=..J..."..^.H.%.g......?..`...~\.9..[U...1/nV.u..L.P....J.`4....R..7.J{...P9....&l5k!.2..#..\f.0R...h\"..........|...16.Ca..}.A..>_J.8..p.w<w.9.......Pv.h.y.*&DQ:O{..~.,7]|.e8>..x.~Yi...b|.]..k.I.}.3:.U.MA..B.....I..._...v....{w..T..........N.....c?.Z..Z_.Q....,,.%.^.`.5."...6J..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):486
                  Entropy (8bit):7.431495650576915
                  Encrypted:false
                  SSDEEP:12:MwnxcBQPLCF+LUcLOeMBhx7L7P/P7Zj/UGCxUMepW7:XnxkQP+dcyee1L7PH7Zj/6xU4
                  MD5:CBBDC0F5B7B6B31E2EA3C3033F54F73A
                  SHA1:00A4353B84C4417C57E21FA19599874EA80AB7D8
                  SHA-256:83401044C05849178D275BD9F29618E3C08F9027ABB30D1FFBD5CF233E74CF90
                  SHA-512:B98131B4C1B2470FD850CEFB28D99517CA39CBEDDEB52F36A336203212057AFF27E8EC260A9C324A3D7807F3864F964DD8B44D2A423A7F4E93749B38D492BDC5
                  Malicious:false
                  Preview:..^nJ.!....]1.{.2.^...{{..c&...n...f..M$p.."....|.P*_|.t...>.i....aV.8.c."..L.j.Pi..8..RQ<-.*...ti.4..I..}.)N..Ls.D...H...ad...hT.N...2.hXN...|...q..<.P.zt.P.V. ....%S.Qb...<.O..2....v..).3.........,...F...+.n.......9....b..>..a.j....V.y..nK......y.........sE&..`.w..j...b..Hs[..r.E..........Y....&......F[0.._.J..S.5YD..?...dSo.ua@_..a..qd.....f..(JI....&.mt.24p"_.x+.`&,..F........;,..r.}<D.T.+.-.T...........+: .)E.......G../*..-...........F...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):791
                  Entropy (8bit):7.710867088784002
                  Encrypted:false
                  SSDEEP:24:NYu80myF4FgrcwKTV5GIVTKnX9yLcFnKEP:NYuxaF6KrGIFKnXYIl
                  MD5:A5EC5C5C5755CC9AED95FD7457CA05FD
                  SHA1:10C65871157C0077986F5E629DF76B409D3F0D55
                  SHA-256:0A08722BCC4994A664AA5548575CFDCC0EC79C9799C8EBCE95F40016D79C3D60
                  SHA-512:E792795E76397A9CCF760626D788815B42461C3B28497B74E18595DD977B0AF55F36D7B304DF610972B6617DE706B22ADFADC8B384FFB15A25AC9C3FBEDC3A22
                  Malicious:false
                  Preview::...r.wJ..}.w#..`$.Y..|..y...Z..K@.J.2....#..`.CU...HN.2U...b.A..~....'....e{.X.QMF."%&B....V...|..].H..C&.~]...`..G.j...ee.Ht..(\...X...A.q6. iq.P..P...F=..Z.....<.L.{x..K^...B"RC..I......"..p.../........,..W...1U..e...w..,*.e'......w..$.38DAi....".h...ty..\...t3...!.{wNS..T..v.L!.tN..h.5Y.Z..#.s.]..........0=G.B...,(d.....o...+.......p..9t.(.A.Vv.nm. 4uG-"..J{.rc...@+I....|...|.M7/A.bQ~#2*.\_.q5...E.6.3...+..9....6 .'.CS...5..............zk.U.J....b.....8k#.W.....X...P..e.r...u.<$H7R.2.%.LWV.....V..z...%[B;.uW.\..."........w1;.....h..5.....7.."?......G....)C.9Q.Z....dO.....+..E1.........@.[..8y....`.q..i.- ......Wf.%).....H.... .kD..*'.w..........~.//:s>?fX....F..-...q....f....f.l!.Q...7.3..z..........w...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:SysEx File - Apple
                  Category:dropped
                  Size (bytes):500
                  Entropy (8bit):7.36325832763353
                  Encrypted:false
                  SSDEEP:12:yBr2w5mYa+Emo+8zlFA1Z8qWtfR+6HjiTH6:+2KmT+RY4b7wXH0
                  MD5:EC182D5848B9F68C5779CE5D04CA7A2D
                  SHA1:D31F3CB834EE6EEB895FE4AC92994940556F9CBF
                  SHA-256:9A05728AEC75D0C832A9EE585728B5F09C0BD45BA0D53B653C0259787CDFF500
                  SHA-512:947B970C2DA87E1972B47F4CFF04ED19F120E563A3ACE4577E3C9115174678212F0E4ECE717B4AECEB3E869A67824AFF17FA36A1C6DF9D2930E998D75132033C
                  Malicious:false
                  Preview:....F..'.q,....D...<e.!=_.`..Z.*.W....!:..,..L.`.J.p........:.e.I.W.]..g.CS...>..d....{...oT+V.B...3B.....0...h#F.{.2P..)...S.{..l..Q'.v..#2...P.....J....S..fLk..0.....Q.....wr.Ss.y."...r..9.]..4.. ..Vk.z"{...(...N..].X(.........9HE....x.a.....``..i..B...9V$.G....x..{..*.F..J...)y7.m......6Q.'..Y.,...s.$.2.64..iN.............p.'6..gY.._+.8.GZ.\..aB..DZ..K.F..-.....{..0L..{".!T........5p.:.P8R#.....o.}....h.....@......7...l.#..h.a6...........T...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):833
                  Entropy (8bit):7.708782376645631
                  Encrypted:false
                  SSDEEP:12:uPWdavFhq04GPSSpahkiPLpv9VQPs5z8N2UqzSFjxoKN7p50BaknE:AWdadcLerGjDzboFFoK1n0ck
                  MD5:961B98F578EADF5338CF27E1286EA4A8
                  SHA1:BDFFF635A05216C92D76315CC440EF7FF1BAAB97
                  SHA-256:7BF5FB93CB989139B62EB9E55AD419BF9C31AC8DCBA0343CBA067C12FB04F5F4
                  SHA-512:F770906846E8BCFA14B67935ADCCB9D50108CEF00A1755003570720BFE8EB38A90DC51D6ACFFC84D250053A57FC927AAAB2DF4B6F2DF5438C8799856B8EC0A18
                  Malicious:false
                  Preview:.x.Q.\.. ..N.O....W..#]X..M..[.3.i6.%..j.Z...-.`6....|..V.N.|.a.R...c..s....R. ..$......F.."......26.ZP8....MV.k.%J.....!9g.R.Y.. .rp.......vn..2.U....m..k<.._...(7.....m.n...Y......&/..{.h.2'.....<E.q.RaV..P...i...1`Y.........c..m.S~...Lo .....m.]......I...@ET..,tZ.F.>.zd...|$]L.....#.)...+F..)..M(.....o3...iw..i.u.......W....s...9.b...h.E.L..........9r.^.I-.@..5Q.Q.D.h...0JY....]......?7h$.Q.(...Q.3&8$.D...:.=.EB.d.6......B0.e.:....%...MgJ.K..i.bi@...i..A....r.fb.....3[..6..O,..$.sS#v>....`.qC..T/.ZbH.=.l...Z.D@...P.....0x...d...e...&.L|......H.\Q.....H.....^..f.....?...l[...x~@..H.:xY..9........B...........=....].....Zx4.,}M..\c.Yl..<.7$~1@..M.M....)b.....[h+......M/.b.o3..r..}.....*...J..........+.'....v.9$..2h."p..Q".[..-;L@.*6F..&........k...m..B.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7436
                  Entropy (8bit):7.978426790416989
                  Encrypted:false
                  SSDEEP:192:QlpppuY9lUADzO+HlnJFYqCfkaPxB3Wu:Qnj5lUAO+H9JFNQBm
                  MD5:265799F5D458B8A2D9C7DD5EC930E1EF
                  SHA1:76B6FD933DB103DC3DAF8DE88A22B76E795D0A66
                  SHA-256:71BEF41A9B56D3E65D9DD33C49324FB4B62D3E84CB23E4D744EFA303E812F0DA
                  SHA-512:8C3F70E40B78781211E796BA3E1D67A15C9108421AA11342B1E178D56693532DA175C5EFAD944A4A6639D7D0C53DD0DBFD3748D00EF2CE4C36FBF85793B4974E
                  Malicious:false
                  Preview:....Up.~....S.....%.nD.u..l..<.....mT........Pl.QA|CU..k.i.F.&.<.-.,!.....`.TO..%o.....Y..=o..aO..g...q.N.U...Tv`./.{uC...(..u...!...4.Bg#m..t.....*...T:.2.2..}.?6.r..$w...a.....6..\.{....Ii(............N1.6..&.".p.$.;..x..y..<c...:.....M.@..P.....oZ.m4....B...?0.).r..&&>.W.%....%...P.I..hW..=.Ux.h..O]~..b..-.k.r\.W....."&.]........m.+.8....v..,W<..(O.+QJ...{....(.z.|4..E@A....`)$...o.84'=-@...?W[...i(.wc..$...X...c-..q.-$0h..ZrE|.6.8...Ys..^'..^..k....y&,.(..`\\.J.a.O....W5K.Md~c.5!...D..oK...G....zY.oN~l.U..r..O..D|..#..x...l4.`.;..kn..h^)#..[.$.".[)..~H@.p.T..(.......$..&{1c.r..WW.[...Ie.2..>..JAP$.......z....~{D".\.M.W...........G.ao..U.huTN]?H...,_../...jtj.)..W.A...j'....jXqQ.i..Fw.....tv.._..s..$..z..z...!f.N.a.WA3h..j7_......I.z.......Q@.~'@~.f...[#Z4(..$C."...B.<n.......t..U1...X...... ...(.7'.}$..4.<w....."~|..@w*|......F~..6.!7....7a..7{W.._..)(t..~...L.4c.....>......Ux........``..... r`.i..R..~KC..........E...D.S.O...op.dC
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3023
                  Entropy (8bit):7.9257306182308636
                  Encrypted:false
                  SSDEEP:48:EctYdxKZThpMQvEurVGcDdcpiHs33ZBEJ44cIF5Cs4xkRb89qeYxH6dvuPHs5iqo:ECYfKZTrMQvzrEcDCj33ZG/1DCHz9qV/
                  MD5:96A1312941371EFA9AFC6842EE00D323
                  SHA1:3C2DA23C0C9AE1128EED6A96AB86B89EC94D937D
                  SHA-256:CB768B959C896774F5394396519434D1A4ADC7C3634F45391727DC1ED558CC15
                  SHA-512:9AF8084B99E1D73EB373620024F08A3712CA80A9ACECB5DB27B9741007F1969C5734269A17BF2C4019998592F7DCD819F820BED75D55A4E177F716857E487D46
                  Malicious:false
                  Preview:.w....X.....5F..?UY...2..j..~K.+..?..d..(l...Mu..b...P.l....j..j.Es.M..4H].e..jm.G...y..<7..L.x...........&....... .._.....[.T\=a.......~U...#X]..Y..TP..JZJ...j.(..g.......^../R.!Z~..t8YL.3.yw>...s......(S..q/.f....^..._..q..'h..]....|.*#.m.....!.ER&R.9.@..1..fY..a=.iW..A../-..z..0f....<.....)M..\...0E..-...Q.8F......Yq0.^zN.b..<4.Z+Ef....%.~..p...J...<.;..3!.7......^.S|..T...t..L..Y.Q.Q.>.._..`S....V.v\......).v.... Z..t......b.DBU.X....vm...H...v%_L......=.(H.....!K..v........t+.(.>.[.M$...kK.`....)U...`?...f. C..2tx..m.k{.R+......&.......S..R]. M.g............*.J.1....Z8....O.4....-...2v.!.3G].M*...&..6...,o.R.P.P.A<..#..#..x.N%..^...G...t"m.s......msHzn.}.....,...V.W..- ..|...]9..{.."[..y2..&j.{..<p[@`l...d...!VT.(... _.../...`..z\-.Z.$.....S..#f?L.d....j...x0.....#P..j.7S."..,e.../...0...=.I....x33.vV.-cn.`fXK..U..l...<....%...a,3./...}..2..4...V1U_...c.F......>O..fP.%..........ir..Dq^Naw........0.8..9....m..Z.Y..;....5O.....T.A
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):986
                  Entropy (8bit):7.7475056784193415
                  Encrypted:false
                  SSDEEP:24:AazHavUGO//LyDE+N1cgos5MmFPYnkeYJM:ovs3GDE+N1c8LveYJ
                  MD5:8935BA5875681F52235F9CF7455BB14F
                  SHA1:2CAC24FC7E36EDB961DBCC930250EC37B63E0CDC
                  SHA-256:519D809C8B623B00494242ECE4CE52D8232F77425DC92AC538266A6570243B46
                  SHA-512:FF83DBCA15577DE1B3377DC4797B9345C33B433B647A6CE3F33F8D467DB6FED86B042BA18DD30BF2D13DB550145C75320AEF0572DA8A7F233F1917AF42399781
                  Malicious:false
                  Preview:-v.+C,......2..s!@1~[C0.)...U.f.... .X.e...>.g...)p....(.g..b ..Boq.q0C"...t..n....J.Fz.....!<..H8GNW...Y..K8...c.s.o..B.Sv......o.....f .M...'..:.....0.(h.w."gI@c.*_.I.L.&.....#T..h.."..b.tg..#.....a..d..H.k{......A..L.b&.i..y..C..ov[.!.......s3...........8Y,tU..xM.g....Xg[mV.v@d.A.4...X.k.k<...gy...GM...9./@.L%'...Q...'7..W.P].W.AE..Sb-.m.etY..|...m......O{..QR..L.}*.....X%......Q...#5..i..!.I*.b.P.'.K|.;...{`)c.&.i.....(...L.6.%{.....8...)3>..&b04..I........d.,.....S[.'TF.s.....o..e..{........6O..v4. .:dd......$R......}..*..<=A.V.6....]. .J9=J..!.jo..!t.-.|X..j.e?Qk.F\i...+..7...|I.......(...L...5K....E(.%..."......r;...}.._\...yY...4...l....,.}%.\..3.{.X....#........?...#.A..(./..W......u.d].A....Y...3.~.,...... ..m.jM..@..d.O..._...M.E.k....../..f...n.d./........R.vYF .6AM.....bQ.....v.S...{L.........4...+..b\;y...Z0S.\4.M:...........=._&..../..p.=hg......Z.7.d$K...e.....h.X.._...........:...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1557
                  Entropy (8bit):7.852234763259219
                  Encrypted:false
                  SSDEEP:48:j0MgbvK9fWrN91eSRJE8NQWJeDItcpT+0:vwvK9fWrN9e8CWJe8CT
                  MD5:865C9D3B7AFF3CEC3A0A03812634D1E6
                  SHA1:6BADA3C27AC50186FF2B7C08796EDD8387F5890E
                  SHA-256:5A8A85450A860C52719551B67A586B3F8ABAB152D62A5A544A2B428D045E27E3
                  SHA-512:FCF39C6627EAB1B7715C5465CBEC02A7B1DB155368D7DCCEDCAE71A30B36F1015A370308B50F829BFDF1E221371E21EC274D1EE235E088ED85BE4E5043177BC6
                  Malicious:false
                  Preview:..R>.\t<-..a.(....h...s2i.7.. ?_.yA.......h?.@.Z;.=.........Vt=...#.<..|..%....4Z..W"...s.GK.=...a....s..Z_L.....T+..........m....9W.I.P.|.......x..X.*j......~x..H..5..&..I.$....a.h....+...2..PU..^\...?NAP0..^../I..j..6,k..]9N.O.}>0d2.[..Q2n..+:t.N.......o...(n*.-.(e..j..O.1z..(z....O...~...J..ks8e;9.+.A.4.._p+.'.O5.K.w[.M.'.^P..4..0...n...a,.\..^..].4.. r..u...Zg..........:.o1.....D._V^...g.i.o..I...-E...6i.s.:..$.'.(..%T.......]T.....d.T.M.&d.D.k..{uW,......sT.y...Bd.X.RB.B...)v..s.^hWv.8..?v......U.N...};....... ........8KR...+.a5...u...:..!.5D`.l......J....Lb.#.....U.JW../..../.(...B?4.......D./.[.B...)T..VS.....wj..Z............?.1|../rv0F.c....9S.....0..`.}.j.4)cV..r.J..xj..q....$H.WlT...?q.nM.;...]i.=.`.....8+`Z%....V.a.0l...6..%..f~..(..D..&..........?.. ..)zh......Mx..E.c*../...Z..7:b ..Q.OGh...=.*.w..V...\.......xwT7g..f."....R..l...WP...@..+}.{/gp..O.4p.q!].7frkT......1.1...h.OG9.[(>.[c...k....<l.v
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3411
                  Entropy (8bit):7.941894977355122
                  Encrypted:false
                  SSDEEP:48:mi8JViOGR16RmAudpQwez18MwxQ1wU/e6zNqONvFL66ChYgW3bY233kNSY/iSXVl:iI16wphe8MwxiwU2gNVB6bhtW0UKSYF
                  MD5:1FA1A2892DEDE18CBA819548328FCD12
                  SHA1:9A01C2F764995AECDA510F7DED64ED77A95CAA46
                  SHA-256:370B43741621B5A4C53772A801C97365453FFADD522642246C635390B74680C0
                  SHA-512:5188CBEE09341165B8391404DB242B1EB5F5868B5BA8AB716F1799B8AFF08D93F414357FE0E591A987D2D364508B69423E50194045012E3AD81177D8BF60FBF3
                  Malicious:false
                  Preview:.....q`/Q,/.Br..j.Ff.li....[.....#..N..K...Ji....[..^.1.."r....$...W>Y....u....9....~2..)O.c.(cE......G......V..........L..Sr-`...1W.O...)9..X..T#...%..;.!.8....hq...&ZKG47....5~.....".w$...o..q..ZG.q'=.U.?[k...q[..B......%r...(...w.r(,..E..#/...G..L.....w.HnIu..-.L_XGo..7..O. .-..L.......IH......}.-o...Y.Ld-[F:0....t.*.....v?.h.V.M.G.W.....L....x.....&..B.(J..9r.B0.8............m.|.F...<._.....cy.if..%y.w1O.T........W...i.8/...,.Y...........T......B..`.......&....*...+G|t'].&i;.u.............~cR....7.NG ...y..*......-..nD7.O..=K\..<......m...#|*.Z.V..7.....Z0.Z..N#....N9.C"..w.]......F......yB...KO..F.t...3'.....$Pc,...`.......D..v..|.h.......Dr-O|.;.a....Q...{.a`.n).6.(L...g...j.8.C...o...>.b..?.....p...R..U.ADd...3!7....+Nx.........K_.c@.d.`e.<;...\oO.B.....)..@}.^w.....2..WLGgCW.;..1.0........bN.......Ogv.V.. ...Z....*NI.ds...e.Z.c.;..|F........${t...A.[......Bv..f.....T...Y=g..0.....^.P..&..T..{0..;.._Z..0ka..c.$..c.p.....&.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):6728
                  Entropy (8bit):7.973887682513085
                  Encrypted:false
                  SSDEEP:192:rfOiGI6gv5tYJy7D5/jBR8S2TckjdDEGQZ:rlTJN/mTc8da
                  MD5:49D2E7D7775F452FE96C6C570891B57E
                  SHA1:66572F571DCC3133D24B19A21E87DD53B211306D
                  SHA-256:35D003DA0770BE13E9ECFF6FEF150113B109E828B113DAF3587C91B9756FAA78
                  SHA-512:190C4ECD8D43A2460B7768FBCB29194C2AFAAE5A3C4A8AE4638FDBCA6F4201E934AD4BF70E1974697020006C120DEBC93A738CC56A3CB7EB124F19A924A533AD
                  Malicious:false
                  Preview:.,a~..1.ju.....BO ...=..%..J... ..v.Z..D.[g..:...\.&..L.......I............Z.u..'{..8.&... V..s.....f...&....?.....>.@.....+.FbJ.U..z.6........=:J....E.Wf.&...........'...T.......t.J.......%.T...u19+...4....^w...W..CZ.[H.gn#...cB.....^^.jp!...P..=.!].....:....`@.gh..z!d..,*..j}....Y...x..t...*.........Z......8..CyBl#DbO../.~.. ,.Dvw.='.......X.f5.|.V...8CA..P..,.)....^..o....&~.2i...5.L.+Qkk.BK.m6V.........km%. v..,....a.._m..2....c..c.$..Rl.L..c..*.r4.g...ez%a!~c.r.....JK.%........W..9.6.+.k5..w.r../B.6..VA#.Cl>n.Sp#.j.y]X.S......>.PW....n....4h.C(.X5...M.n..1..~....&R...<..u.+.. ~..Z.EA../.....E...x :._..i...F0.....M.D.@\.H..f....,.f.Z...?T..>E..[..k5w..6'/...F7`... .Y..3.r3..p-.U..^...K...Q..Es..tQ..C.!0G.dAy.9R...G'~....x.t.y..6...q.TW=.8*{.yo..`3...,....I....v-....S<...O..G ..;.`.{.m....'........8.0W..q.i..z.5c....>.............)....0,.tx.o........[._+..I...~z.....|..Ddp......\....~.......A..O.D..6..CU^L}...!,....8s)..a..7i.an.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1394
                  Entropy (8bit):7.816834005366602
                  Encrypted:false
                  SSDEEP:24:wm+Rvkh/Bk0FKVxAPUCeTbeAd0h2otDycScU47lEQtWNAZ92zP4xx/m299uLRv4C:h++hzEAPUCeveth2ODyc7ZdWY92zam26
                  MD5:EDEBF2D13C37FB8F1A6197BD1CEA4CD7
                  SHA1:5E7597C63C233BCDB3E69DFCB42E43E8FC3FBE15
                  SHA-256:704B5A0DEA3A4105603CF773C85EB93D8982FE3CA7B678CEC2B50C15494AB3EC
                  SHA-512:665C4AC0A2DACED6360E7EFAAE2A066ECD4CD1F91C57F8F9B083FF87100714A5A338936DFF9460915CD6ADDF2EB08644944F0EBA03AE1D1BB60A1D7EFA62EDA0
                  Malicious:false
                  Preview:.....E.zP.>..M.\O)eqMl....u.[....M."..&W.<.QH.....W...[..Jmpb...^+..Ic...v.qArp..-7f.K.m]..I=..lR..3B..Uj.Z..M.t...t.'..v..tjG#....<.......l./.alSl'.......m.@..0.K.%?...c.N....ro..J"a.J.nH...zLs/.@...P.._.N. ...V.4. .b..`..R?lS.P.....u.EbL1..6H;qy...f..l..u'".o.......y..c.ip..%.@n'..2.1v1;.~.N..}o.[......-.:.|..b...........A.#.f.V..p.8..Jh.o..wR......g+...`x1.....Kvz.JX..j.#.....].b$..u....%......f.....+..}..R.Yp.[n......f}..*..*dT....xnW.....Q...R..U....4../).t..I.v...-........m...............$4..5.d<....A..].i.-.7-.G~../s ..[.s.@........B5L.f.p...K.V+.3.n(..Y.L.;......VA.?.X..Y1..p..........Rt.%.....F......).k..&....g......0..&O..[........9.......:"i.t.[....9.&..%P.P....p.....e.?.?.n....p.E.7.B1..x6.m.7..AU..n.P...#.L./...#.o.j{...x..YK)......{.w.0.D#0x.dl.K...4...H5X....JG...)..!..-W...}-.......+ga.vKU..{(.7}Z..A....py...;....0....8.O...Urd...........@..('......M.D./>....\.b3......}._.K.o...%...|'..Y.....t+{Q.o2^..M...~...$o.d...e
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1149
                  Entropy (8bit):7.785647682958873
                  Encrypted:false
                  SSDEEP:24:OVg1KtlVeHMaEM3uemusYj3KpRr6qTxkwe:MlQseoYj3Kv6cxd
                  MD5:82C0000195B823F71FDAE28A3BFA08FA
                  SHA1:9C56B75E82E5BA35E24D583E83A749579AE3D6F8
                  SHA-256:78F0D6D60A596152A6EA833830A0E157099F440847EE5B8E5B9FF04B2206FE20
                  SHA-512:1A46A38114F6DAA6EF1D4BD57D5F8DB198A1D5DED1678C663C7A7B1DA3A1FBF6789D3F02776B0AAFABFBABD8EC4A7DF3A6702F37D2239723C13ACF2C8CC4464C
                  Malicious:false
                  Preview:.H.[.....k".eDp.j.IP....S.9I..z...~e....-..n....D=...q1..r.:..x..].3)FK.....!5.F..(<.(...`.]3*..."...l.....LdS......}.B/.p........;..f..Y....W.!...-)s...f.....x......I.....=rQPQ.LW.^z.R.0.^..........p.........r&~.n.h....\H.4 ...suv...W.<|./u=.e.\....c)]%^<..Ts.(.'R....R1J.*..<.P$E...C.'[H....D...0v...!.......p...]E.7(._.1....i.....z...q..r..NH.............c...Z}q=.*.k...PF..B...&..Z 1-f.m.".(*.;.[+.b..e....6,z.o......av J:^|....<.S.qz....pG.B..f...A..e#U....e.1 3.{..\.!'~..r.I.J..R.[<...W#.....5.E.dz..<....Q?....B!K.}...s....9V4...^2$..Y>...<.<".s...X.0........%.4.....r...J+..}.........X<XR..... Y|.`L..........lNo..@2.w..F.M.&.p..c.....,......S.)./-3o`...n.1*-...[.{...2.;...Mk?...-.&......w.[.TU..3...:.....{j.......1.-Q...e......g....=.........:CY..c:Y......w.q......T...Z....S.S.q.~m9^E..2..^..o..F.>.\f.~>fQY.....L........?H.f..|["..4.VC.S..1...i..c......0.X....Ubt..N%W..>...:..(..O......Q....."|..p........L+.iE!<.bn..a...b...M..d.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):676
                  Entropy (8bit):7.65267195787177
                  Encrypted:false
                  SSDEEP:12:yyCYVVnN4KtFm9JyVg1EfeS0lBmBU6lDxzzA88Y88l7S7QIuEDML:oUH6ryVCER0lBJUxHj8YEi
                  MD5:56B04DC3B7D8B61A74CC01DF4003B5BC
                  SHA1:D99CB49AB7CCCE568BF266A0EA551B3474E7E806
                  SHA-256:0E731832C050D8065230DEC8B90E2E6F50850F95E4F1423BAF5E9A542380F076
                  SHA-512:8C9659E95B8DD6C2C7C73E91D6DFCC9EFB240AB7525184FCD2F7A5E494EF2C5B92F513C331CFF00DD2BEC6BAD6EC23273E0B3FDD7E20A7F9701681CB1AE45991
                  Malicious:false
                  Preview:.....>.u...BKX.......(.,.c;hj.r..5...+yt..BO..@1.'...D|.....GQ........#..|2.`.D. .,}.o.6|*.X......p..Rl-9..HG.fl.........o.u\B.o}.O.T..W.?.N..U].M..,*..%1.#z.3...I...[_......n...vL AF....:..#iE......d...m.].@..<}?e4q.0J..<5....c;V.a#..2.#4..$k...|G5....Jdo...]..g.8.,O2-H.....[.y"..d..$...9.m.PwO.....{U.....(l.Jb...d..3.. ....+......./..n.,Kc._s...][ij2q.3.)...I...P......b.....Z;$..FOuE..c.I..X..].....`r.y."sA....G..rl......v........~`..*....K.=c6..m~Z/[4mY~.R@.CB......r..%....>dVCc#.]......US...?....d.::m5..Z8.P.e........,.{bss).F....o.R.8..........".m...I{N .F........}U..T.X.r.$..m=..W.>h.{B..I..m'.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1248
                  Entropy (8bit):7.794165020421656
                  Encrypted:false
                  SSDEEP:24:U3Pgl58uqp+JcJ1AQ47qqYbrGzr/lLw/qYSLGrGjaQl9jfxFnwXPEZuJ9vCYF41d:Uu58bEa4SslLWSbb+PE4Z4g
                  MD5:496884BFE03E0DAD25E6E96F85691F47
                  SHA1:CD08D0B73FF3E61AB7D53CF2013975F97C08334C
                  SHA-256:C930D25740B42E60DB3CC6E5449B69DA217A8F4F3B36242F1E601000151AF8BE
                  SHA-512:91CBC6ABFD8F2AE9506A4D2476CC93096B420748C1A5BE6DF5FD7BB36A5D865D5B9A384407F3B9E10D7B93D90EA105D038C78F98781922BCAD693A0ABF8A0320
                  Malicious:false
                  Preview:.>^,..+...EL~.......vX .h......'7O:.! ./...YUF...9..J.9.,D....R.....T .g.af.1V?.......z.....].cH3..rE..v.3.{y.....{.....`.J...>...d.......j..R4.C.".G.s-?..c|..2v].Oy{..f%0.. G.."...[Z..Xb...v...(..JY..M...w+.@]... ;kr~WJk.!"....S.....9@w.f.:....Q.}@.r..l.d.._3......f..lW...Wz3{...U.....s.p.XQm....`.z..DN....Z...0B..ow.~|`ni....3}x2R.......xJ.t.....U..X%.....c..0.E...Q..!.X....P./....S."..k2..me.....Ovd..7.<k.(.:..u?...y.]C...c....N.4..T.......<...>O....A.^.n..r...WL..._s...!...e5..^.1.<.z.'..p.NM..p....B..F...q..FN.x.....)...'.7...;.V.....M.j...Z0<...g..z..b..K.....(B^....-nm..".m.i..J;..U.{>8...d..f.h..n[e....#[....?.b.J.JG.po.G.G.Z.W...4....0."QG.@.. p..Sl..@vG4...E._Z4....(.........C!..0Q...Q...+h..t.!w.s..e....k.YR.k..{2..(.nf..S.&.*...u...a.6.a^.^..X;..........-....Y..{.......y.....gp..@...v...egM=.U.y..}.F...].O>..p[....2..A.e.S.-.E9.VB.....f..{.{..NR).p.Iv.R..V.V..J..lGt+z"q.E..x)SpE.....^..5.?l.?....b..x....a.h.[.......r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):738
                  Entropy (8bit):7.679123316873642
                  Encrypted:false
                  SSDEEP:12:OGstBgRXODNvlc0M/KPfT+3YGFfhq3bsADlN5REzLaXm4kNS4Cqxl5f5kVdcM:OGsteR6NvO0m4r+IWfM3b/vRE/T4kNmk
                  MD5:504C706059BD93C7BCB89A5DADDF040A
                  SHA1:117A6E21EDE1AB38F2C7F9072D201850BFDF7530
                  SHA-256:2ABF4949B755375F7C3D5E2531BB0C9E566B14BA2B858AD88AF7FBE6850F5721
                  SHA-512:7A2471827A582106FFD2B3187A6DE14B09073EF24260D9798AFC95749207C94BBB3074C2ED7D10CF6CD1762FA7299FBB7B33652FABC561F3DB2AAB97499D8835
                  Malicious:false
                  Preview:r]...\...I..>R..7_}V;)\.+.bC.9}.J..N..,.(j..\...".1.Z.....x........}.F..$.k..NMI.d..[..E*.|P.,...gl&...s.n..U...J...%g.e..X...G......MZe......j*...N&.o......8.l1.Kq......A.(...Ah.+.....O..:..E...BU.(.:..$..7....Y._.W...*M .[`L....U/C7.^ .%.i..+Qw.o........_.rN.o...~..A.*.W-3C!.P...N..NX.l.........?1Lr.g...O..mf.....V.Gx.Qx...k.c.-..^..b.sJ9..`..b.2.....8....>u.+)j.x....q-8p.......7Y.s!/ro.....w..u#..W....!.=..I....).'_=..Z..a..g[ .b...Q-&6.u..=d....zp:.M..a..!....f.v....R}.......eyh>.:........ 1...`.c!...c.K... ...1[....|=w......E./,.k#.{..L.1.OW..n.Y....1-..Z9...`..cV....r..;...?.i.(T.!.......ZU...B.......X....Ma..u!...w.Jh._.........>)...,...d.).;7R&.n...?.9........B...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1513
                  Entropy (8bit):7.843198937048652
                  Encrypted:false
                  SSDEEP:24:2Kqiqjt2m4C5J2lxEGdCj8rdHOrMfAWIJ7g+h5y9Qx/x+rOi9d91bjJVUNpp3v3/:2KqP2ZC5J2lxvdC0Kh6+zy9Y/wrOAqhV
                  MD5:0B4D3D7E6968DECF1B3D2F63DE912DA3
                  SHA1:6811DDD0B331E39E85CEEE76309293223174BF43
                  SHA-256:63758ECBB8692BA24985BB2CA5EC335E893CBB07C4E53AA86664C4EB56B3647B
                  SHA-512:2E06649B6EC0E6F40912E8EB3E4FE4CC3651FEA816C3F4E3C32BBEFDC3E05B38EA5F8E4F77954AB6DA741381355303EDF84F23F03DB07D00744DFAD1EEEC0E05
                  Malicious:false
                  Preview:...\E.G...J/.w9.H....J..M....Ro...h..#.'.?..DFK;.e..7..3P...G.x..........9.;.....<...[.!;.&.Y\....KV?...P..>..uJXh.....a....>+$..(s.|j,.m.P]5/.x...e.$F....S..+.Q.o.h..>.O.5.j....D?4 ..lj*..Dz.9ga............X}.H..s.!..l.....x-.e.+..z.L.......MKla..l.J..m......dH..*N..YP............\...!y].....o.Xs...6....$..FK.;....40hg.]..0..Z0.>.U.......g.k?q.C}..o..W..@.)....y...A.&..%.S.v."I....C...8QD.....;..bQLB..!"?...&R#.....oB$)...x.VYz....6j..A<...#.G;.Y ..u..$....|*...y..)..Y..~.zT).<..9bd.4Y.;...vb....I..$.f...[..Z..#a.=...a.......W.e....n......?.....f...;).C..'...gMU..I.\........J`.......R.ZPH...H.c.\..'.._k.s.o...".f.%....`.^h...>.nC..;.8.I....$.@.8...n.i[Q;.T.."..gp.vk...Zn..8y$ m:."@'."..@....... zi...G.}..".)./.<...... .I_....L.?M.>..5......q|.K.'.5m+K........5...j.S.g..s/T...1. 8gI.Re.O.|.....'_...hF.e.....D.w.....j.....T.{.9.X.}&-T...9..L223.e.X.x&..el.Z.a..p..I.C.`.*4u.K.1...*.c.&L+....9..k..B.}.z..~s..z;I.6....y.^q...U...,....&7.D./.Lko$4.#
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):767
                  Entropy (8bit):7.615599787953223
                  Encrypted:false
                  SSDEEP:12:1x1/HC4lSIm//3UW8lptFWT0tIpx3yp+dKqcre/C5KoATI9MT5PatTitNsVUvlyJ:1x1fC/F6tcrxE+fWH5KUkZa0tL9yOS
                  MD5:B6390E98BC0A46C6A6BD73F7DDFFB8BF
                  SHA1:7F3C3BB97DAB2F036BFE27393396009FD47530AD
                  SHA-256:B59232A90EB7001DE44FDDAD37D5E43834EC87A677B3DD67685CF09AC86C1C4E
                  SHA-512:F4FF50034394734AF5B6D5C16054821E9EA36A27CF92CA25E5896A88C69BEA6327E4FF30C8D026D9ECB0AF8AA641EC2720012150CD36CA9882934F95D8169194
                  Malicious:false
                  Preview:.T..I......z=.i..9..+.P.w:.T]..>.u.....R.e]..<]3........ _..nM.^...|R.WV.V..S.a..74h.fd...H..n......*.).V"...)u[.O....8j."./..A|?..j.+..X0..Pcy....]9.&..8....|....v3U...W....[S.....@..(.8..fXd=a..C..K.sT.8]....i...:.'i.8j.r6.:.U6;..gT. J...p..w...?..y.#..3.hHR...4.O..J..Z...`.bx..V.`..Lb..L...vM..K},g.r.E...TNO.Oj..E..v.'...|..n.|...|&...c.Q.yE.zm)...c.....0.....8y3....) y8.O .af....%'ao..|O`H?4.....")ROC~.\(......K.'..@".USh.....P5....Q(mk. .I.Ma.U.R..n...L....y..N&9Y.g.p..t=-...!.'.M...G=.._f.fG./wzl@s...X.Q>.r.k.0-.....(...qQn..iz].<.v......pL....c.]3a.*......2.]l.+...uB.2.k.nw.&p=@..-.......N..H.1\*.......c.l..j0..@......b']...._.........X.T....JJ.C.K..C...T......d,.e...'.7...O...@..U...H........._...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1584
                  Entropy (8bit):7.859314601410618
                  Encrypted:false
                  SSDEEP:48:0b0/mbg+fVQK6G4FBta7Mwg/6PGITglQ:0b0Qg8QK6G4w7Bg/aVT1
                  MD5:0077543CA29C965239B8A93B1578C187
                  SHA1:450AE78985E1357F63016A1F50E723CEF2607C7F
                  SHA-256:3CE075E79EE6E44612C6385244B267AAEA53E5E871B0AB4BDD7948D017CE89B6
                  SHA-512:100DE5D7932778872E58A0290CD0BE8EC25F09E072ADC37482A9C30B2E22E1FEE8DF74307F6B07E2314C46F9C75D53C989E57395A3E9DE7A614F8A59CED8E580
                  Malicious:false
                  Preview:`.>&.......8.u..D.hum.UQ.....l.,.G.;....z.%.E...0..c.....A.y)..(......{/..<.8~.:G...N.&.|..r...R......I.U....P.=...g.2..T.."..e..(....f.j./...E;?.......Z.l....i0>a....w......:..Y......X..K.....L...A..5z.......=.h..I?.. .h..f...fY.....W..u....Q.....%...JV.[..:.....jd1!....v.i.|..Q........{..,6..d_.~..\QA..b...^.u..;..E.B"t.".m....f...z..V<#r#.SI..ED).x.......}...=k....5..8.B.5.o{._.d.?.8.Y...Z.(W...~.....ZbV....._b..N...D8U.K..I.GW.. .....e.f^.......L.....z;8Z4....R.h.HN..L.r..HNG>..N../...c.SL.Z..~...5.tB.)...=.mc.+.D..-jL...3 ....|..r...X...n)1....4.".,..7>...h.).....ASGD.g..(........6 _za)A..+.n...vwZ...;......rh.. ..W....#$................^N....|.~.......i..L.xh...u....9K.#.._...7...\q.gX.A.ou....1c..i......Z.*......./......lG....=Vdq|"n.g>......o?.)..'...*Q..E...$/......^..(.&6/.q.JuE.g..k1X@U...q2Bi....P.].<E.P|..HE..KrbO[oN#./..K,.1SS..ycK...}....._..'...2gy.`*&:E.nQm.|N..R.n].t..|...%'..nT...tj"..mtF#...#.w.2:....:F...H...9...x8<.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671
                  Entropy (8bit):7.60910668358958
                  Encrypted:false
                  SSDEEP:12:RjSuons4Ycj0TQkb5vDKfK+ED0IwEI8MIh2Ij/dYo9F2pUrpMdoAXk:IuF4fgTxlvDuK+EI88IxYo9md
                  MD5:A918CCF8A384296C57F02174FA6322B4
                  SHA1:23C5D0DE83F837A4B7DAAB5394CC287E4F2302F4
                  SHA-256:6928B69FE7045E6707A357864D216C4A48E4A17912F2F5309A00921FCDBAA12E
                  SHA-512:7D9E3BB9D1C55AA348F2002E309BCE4ACB632FD194333E14B28135661CA3EE8E3530922713090DEF2FF08A2DDE64BB9B8292E5EFAC2FEF9E73F244238C9547C5
                  Malicious:false
                  Preview:.z..-..y.c.I.jm`.t.......}.Z..&/./ .\..&.....!.[Nl~..|..R.......oE.....F.X..)g...^Y.N*.6...U.a....N..F ,e..d....iK&.....>.....y.Fp/.....A..4.i.B.......... .^{..).=.y.U...<......9....\3n...u.J`.....,....r.......h5.|...7.8..CA?.N...h.W.m.....a.......[LK.r.:..tu_...)..nPG.......W.H"...a....B.>l...j7..~.l..(@5v5.SI....]%d?....]O.,..I.T...)._...x.v.."....!Y1.....'*k.....;WX5.%9....Pha.............82l..#...o....l..u.a.#...;.L...}.1dK.D...(.u...k.=O.Q.......c.z).I..'...y./.M.Q..6..."...k.......y....ty..:.u.....$. ..5IcJ.T.F!L..7.....j.]...Ix.......He.........C.a&.f:.gZn.;]ve'..:...x1e...5_..[.v^.E./,.".2a........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1157
                  Entropy (8bit):7.8105897433550355
                  Encrypted:false
                  SSDEEP:24:UxlupHrAFg+cyQreX2Wiqp7iiwjYQs66s1Fwk89Lf1X1:U7Gk1cyo+2WNvwq60f1X1
                  MD5:F3566153878786053163EDEB04364D4E
                  SHA1:2C1D0020F5B2D1EF47F06CCCC0B95D60439BD94C
                  SHA-256:3CB85691B07430C9EBF7B36589CE99AE660DFE5D5F01A0E70854D573E0BDBB38
                  SHA-512:035B0F91F79C881155052E2B84AB0F6C7FFC6611C7821995D7A87E6E59ED33B7DC85DB89A96DB78A400B7D3B1DF75D25082444AEAD2D2DD8BF30C078F6829129
                  Malicious:false
                  Preview:.....W=gX.n...fzO....'-.......$F9.u.C...a(#...........F.i..%....).W...HaK...C...*.c.@.Ot.T...g.B......4.|.l.........}.I.......G..M=...mrc..rSB,..ML?!....%'S.fqp.y...].i;N..f."....._....:U...D.%.0A.F..\/....PF.T....z.6.xWBh...W...-]......H..#...z..=......g.....zY.,.J...Q.a......i..........r..I...9..."...w....|--a....f.m~.Q#........:..;..j.x.,..3.Y.&....|.o.......).$.....cB.J.]......w..Q!n.MT.;...z..O. *Jj..>2.B.u....#:.....3...P...&Xj!|....3.~.4.;.+3....2.j...^.u.b;..e.....h...9!...4M0v~..QV.........`..5.......-].R..qW..."V".zx.....W-.'..+w.WZKC[?...).a.../=.q..]...nf&G....[....;y....rH............1.X.......2.:...x..%K.(..y.Ml..B...U..e..s.,..Tv{...|1..$..@.r..Y.....v..)S._g#.a.t>1.9......U..PFn+8.b..Kg..6?...71.W]...|...?y....z......mF..U...b...!..~...m..S...+..........Hmhm.......j2...n...~..<..q.r:bH..V/...nY..~..e......e-.6..H..}.;.?.....H...88.-....th.c...-.i%W..3...+c.)Asl....[n{.....d....c....t..V.8...W....>..\4o
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4494
                  Entropy (8bit):7.959032179031652
                  Encrypted:false
                  SSDEEP:96:MAqngtitS2UmjWA+0V7OPMapFOZFX3Sdqmfg+B:QngtYScIm7OP7OZFHSIu/
                  MD5:161AE1A63E34AFA8903A56E2C4D6C600
                  SHA1:BC55D6C295AD8D75C57F9AF9F6257B6761BC6975
                  SHA-256:EC76DAA812BA952A2580ED6F8EE57045B1389C3BBB5312D5344037F3B6A2A8F5
                  SHA-512:3600980C7006E8B92E28CEF2E8233DE4B3C420CFD80D83D2844E83FDB0AC9FDFE77E896740E3D1C70C0AE9EA15EB9C78C227E191A1F7664C2C84D71CC3E743F8
                  Malicious:false
                  Preview:...>U+....Yp@1......bw6.1....!TD.D.,.a.+.!).m.|.d...(...}...(....rcl.....50....rJ.5..t...9...D...H.......=.HE(..6.j5..2r.7..i...A....0.....f~o....V.......qL...J....d8....T.....!4T..C....-.Ai.geY.....n......v.T>..:....x...V:.x.d@..k...&.Z..e?c..&.]..m.GwK.,..4l..y.~..S..I.....D.e....{...7.%,..%...&.%DC.-qaG|......-..'.:.u.kQ..4N-w...8....V...E.#Z..z...D..IWD&..`t.#[...-qM.`AS....HWA..e...n..gj....._......Ns.i...w..."*1G.IS..~|d.w..r/....N..a...%c.....A}..d.L..UI.h....X....z=_..+......S...:.k.....<.gR.FF.....M.*@.x.."....8J.N.@.!......;...^....0.\I........?..8-.9..K....n.\.?.....R..]e%.[.4?bd[.3V.........X.k...J.......v.-....+....m5>-....;.k...L....)m.D. ),..Q........Y........(...z5T..........N..PD9....Po..i..b.Q..F.).o....0KvH.[*.M...j..?..j.?.p.......J..<.Py.....NT.!.>W.avR....(.}rw..Tm...o.WA...*..y.OQ.6..P...]%..Z...[.NM...I.y!........$....qq.......9.p}...sMh....jr..+D.....d........w>....f.UUB.yfhP.OG^.m?..l..]V
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):36148
                  Entropy (8bit):7.995539406916731
                  Encrypted:true
                  SSDEEP:768:zj3AFaq6BpxHx4ml9k8NyGm5zdr4tvM4OxQZ8HyL2nQ04/:zjwFaq6J9+nd42HmiHyaQH/
                  MD5:DCCBA6C1C8D8080DCAABC2F86EA627D0
                  SHA1:2B0B9ECF1DF8A7215D7CC63268E008146C314B8B
                  SHA-256:5AE0FB1C7DBF5C44A11274A5E07F5D24D4B3C1C2A00ED549299819E0CAD071E2
                  SHA-512:2E5733311CEE2DBD6D82B303E1F658CE7BC02C6FF5DD529354A7570700D0C55B0634A0161DD493F900188B56A80C423E557E6BADDB90B927E2BCE36A1772E372
                  Malicious:true
                  Preview:1.c.7.v...tj.f........%........5.4..".....3).u..'.OM,..I.-..lU.#....1`..@.o.:l..D...FI....b.y.&FC.....7.....b.}M..`$.axX............T...P ...m]k..].K.+.L......y%@1/.,<...].........,..t.....:pY....o ....`.._@jZM.b....b4..@..qU..q.S....4*..BK-.y.S@V{..X.....7.l..l..<..F2.\.cy...G]C......I\js.....n.WSa.....j .....w)K..?.y. ........j.Q.%.p.^...........^vw..t.).:.z...}..f6...i..m.....6... .C.........8..........$..np%.WN...a\.&..CF...-......(..j....ce.l. .%.....~r&...2.^.\E.1y...@......-.XX*P..k.`%.i...-b@{...@.KV<.z./.{.p...ciNX.r.L%.a.d.2.'u...n).G.\m....I.....!..H... .r .O.g..8..2.8&|.x..Bx.A.pC.,3..k....=..t.U.*....|.-..P..?...g..HD..{,......\mT%.W.7.......Q.A_..K...V(...rH:[C.c...Fw..\S.......n.r;.".<X*ND._~w.....t...^.b.4....!9....U.......+P...L?\.U@v^Y..SDg+V...:...h2....}.=.8~0.NH.V.3.5x..=.4@DE.<V.-.....$......?..._#:.,vsY...F....Ig.G.s.=....I.t..G.......-Y....r...`t..VU.Y."....F..8.".E6....6X.|.....G.....w...tM.e4%.]. ....@g...+]....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34558
                  Entropy (8bit):7.994684091973814
                  Encrypted:true
                  SSDEEP:768:seEFgMD7X4Fd4/ehwZITvFGpG1OLtRRYyZkS3l9NKZ9sKUD:SFgeXzG0CIpaOLzuyrNKZ9Lq
                  MD5:F857F886F67D1274DC979E6ED904147E
                  SHA1:AA8BF2215947784142CEB7AF6443D34FCA974E7F
                  SHA-256:0DF1A1C24656FF94624B7C8B4DC15C83BDD05A63DF316FB0308BCCBA5BF7F5D4
                  SHA-512:0E44EA795A14A267901380D869990B4ACA33CD2285206157217339121CC322D7A47890EF2AB89D3DCDE90364EF8DA50431DF5A5C0C85F3B277345A1221A753EC
                  Malicious:true
                  Preview:a......i.Z.....70....m...1..E...B.pO...-]v.zIj.M....q....C....I...c.'......{..4...M.KK.b.Q5......lJ....-y.S..r.+.W.VZ./..a.#.>.8.........AP....LtTU)q.X.....k.c8.R.M.....f...>.......Bf....2.X+...+V..`....M.o.g8.M?2.a...3g..C.K..)Xb.[.D.....B...i.&K-..XK..Jn.i..W0(..Rw.....n....r3.q.euHrD...{v....s...Z...[^......U.Y.... .1.....R...J..u.4k........4$.Lm..2..&.OqQ6l......cDBY..)y....8...0{....Q.a...s..p.......{...T.7[..9..#Z.TN5..!.e/....H2.:...:.#...jXIA...~.......B.~/.k..L&.V...^.........C.......^.VW&*d..7.3.B...X4.&.Sf.....(.'.g....e... ..IZ.R.....A....1.E]YGK...U.?....Q.Xl.].[....-.{k..Mha\.7Y.]O....Vn..\Z...TwW4.t.1....p..EP.F........v.........E..X....=....`T7.-...J..=.W.......C4.....Lls..c.;yF..~...f..&pM...&.]....T...].F..~.. ......qa........,....x....;..rrD...zn.1...<..=A.|..E_.._..v..`.%...a...!..3...I&...y....c.........T..E....@..;.i...^...cW....m........|...\Tr.f...S...t{z{..^.]abk..O.q -...ht]3..,.R.....&..L.LOn;..+Y$.....}r......~..Y
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):31573
                  Entropy (8bit):7.994510112028759
                  Encrypted:true
                  SSDEEP:384:xfThShT283jLaAY12MBSlrGesSTcOXypsNVeppHy6A44FTMg/Q6XTZblV9a4oSip:BNShT28VzqTUypeQLiTrQ4lV9arSZ4
                  MD5:AE0CD86A0871C7C77EB7BFB7B3E5F767
                  SHA1:12F533572268957AFCB86E452606248F5F56C3A0
                  SHA-256:E56D9B0C8FB1964272832E1A4622FB006EBD107E5A81273B8E1E623D74CFDC2F
                  SHA-512:0CC4268F981306BA40A2F9C40AB913343483F7F0B9426FB58C69D1B3DA573145D77B252A1BCDE148F0FFF38C575716D0EA7F6CF74C45E4CE82E8459BFA1BCB7B
                  Malicious:true
                  Preview:W..M..`.)./....gt....|v$N........OA.@.f....<E..*..Jf..T.X...$..jX....@x....`{u..Mf.t.....(...&2..!.-.h.+..W>z.."..;D.(4J*p2....Q...Bs....W}.w......K.)....{[P...*6.....z..V.f.&.).....f...Q...V..Y.yI..X.X`....@..aC0..a.6.....!.^..^...F..6..^.....9/a..4%.UE..........y...-o...D._f.Zf.$.9..r.]..G9Lj..Q.j...@\..8J..J.....&...@...0....HR.|. {&.P......@.^......-...ij0...i..tA2zO(.d.......&i..6F..N..5.......`....B.......R.W.. .CL.,HK..R(f'............p..mt*.....UP<..:W:...5..=6.9:1.Fj..u.".e..e.3S.wX...9......../..@.VH.2.....wf....K.............V....................;....#....@,..+s....J.K../.`....#b.'..S...h........0...........m..).....S._.....2.N..\..o.6..2...........r.=Jf .d...*]8.n..#..........I7J...............XC..@K.n...e..-.C.)......]....I...8`...G.c....W.....c..v....K$...).Z|.......G. .[...y... 4.L..sU.J..m.'.t..k,.(y...g..-F....d.L+)._..k..}Sq.H..j....<......I:l .R.f....._x.........<..cEP....{..o..9_9..)D......f.G.]Nl.b.Cf.$..T.swXA....x.2..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):37474
                  Entropy (8bit):7.994390165867786
                  Encrypted:true
                  SSDEEP:768:gjK2FwOV0uNYIcijRqRy1AJolIls4+EwoR64QRONdjI60:gjFw6zmIcidR1i5s4g264tdc60
                  MD5:CFB09610291CDEC7F12BA13962F7D04C
                  SHA1:F4EB39CD83DBD0ED701F7E5A8DF932CEC1FC873A
                  SHA-256:6BA30316CE4353A92E7A6B0333D8F3F5CD1759359804C85DE30AD1EDE078712E
                  SHA-512:43102AF8D17B77EF1B948B9C35883761C2592E3AAC30CB4E8D0A8087580AED3E46F3B6BFA60D4BF2BC840FADB8C23A8B8E0A15A65E0DDA2C21AAEF843C5A49D8
                  Malicious:true
                  Preview:.+z8..9..`.....X......e.W.R...6."..3.YnE<..i7.<3...v.."....r......#j..G=..r...9>....3.......w[I........K2....u.2C.#..c..<~.^.fWr.........+..V.2.M.$..*c...0!k...M..I....H...R......#,.B...'N.f61.2.T.l.{..B..3......'X..J.aM.B$!..v..'ET...Zl.3v..%.=.9...U.I6..S...gV.....th....K...o...^ni...._....3K.X...m$.1v..-...M...$..-q..^.....Qc9.2^..5:...M%O.-AG6$...'.J..pz.-ee..2*../..@.y7h..G......1...)..}.C.....?.......%.m.PA..p...G..(.....fy..C36.SNi.v.q.,v/..B.{/s.O....mfM....X3..1....7.]#....c".........)..........dD.M.4,K...:...m{...,.1.?.."p..'?...T/7..j.X..).|y.[.h.g.E.>_...V....../.X..hx=2.8.s.%rQ.xq....*&3.8Y.F..u...B....q.....u `......4.EcATT8..nU?R`v....e.*+.K.<..Y...f.f_Q...g..8l..2;.#...#...oz..;Gm..>){5.O<....].....c ...B..<UV.vI....r......lp8...#.9.d.......t.......N..d10 ?..F...1.!&.F.N..x;.I.......[].C..*..D&..jr.z...4..'|..*.&......(. .(D...V.....}.6>..t0..0v.RV@c:..0.t........."&L8...4K7.....&..@..?...4c"...a......n.1A.Du..Zw..|........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30863
                  Entropy (8bit):7.994125287125021
                  Encrypted:true
                  SSDEEP:768:S5/aZx4N81SlM8LZCElcW7z6svhTkLIuzy:aN81Sai8A/6svRkn
                  MD5:4CFFC11404950DF84446378839DB5615
                  SHA1:8BA8D126A9405B6D53268004A230A87483DA47E9
                  SHA-256:7B33935D62CCD4AC26870D7E360B008436030A8366D952BDF8B849B2BB1D481C
                  SHA-512:631300F0B099E096CC75EDB434E53CE3D82D7C515BF90ECAD3559FF12C45396BEF7F1B77A1B46B03605C34FF8FBC83E0C2CC565AD83512851AE7603CCEE58B24
                  Malicious:true
                  Preview:.o.4.38...u.z7E..+...mf..k.m!H}.....H0..,9.rY@]r....L..R..H..O.y..no...a(...=.i...8.....H..u..E...]..%..gQ.j$~i.Pv.G..r_#j3o...YmSL<...)..k..)."..n.W..y.d...V. w..........7Q.,./..C./.K.S.^...(...@S~...m......v..x.)..P..i4...D.{3.....$t<...9.%.t......#o.^.nS..:....Jn..(.....,.."r.g.b.;...c...U2..........r......W".P..#j.u..*m......*W.h.!&k_..*7.:...L......r.C4.....]....v@.%Y.d...h..S.e....Wo.|..v...9.z./._.*V...q.5M.>.fb8.-..U\L..S7...].3.n..4.%...2`h....W......V$.sK\..7....!iz..'..)..1...1..^.:...7.....?w.......M.|l.J.D..m.s..{.K.;b.......7i......).[..t..80..s...+KY...|.l...X....}.\.,..L.EE.-.....C.d'.)..h..X{]..m.:g..m...........TWi9~.VH'q.bZ..N3..:...\..(...]d3]_..?0.hKs........?..U..S..z.ZB....r..8.3..J`.-..|.-..e..ED..5B*HU"V\ ....Y..y|D.c....P.`.`....}:........! ..N..J.058#6H...,\4.h.......;...n..dnr|.+-.`..0mos.-.rQ..-gB'....;6..:..Im4...`...Y...Q.t..,....].m...".[.........>L%...9;\.8...<.`..........XK.i.5v&H%...H....Ts......#M%-..|"....B.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):983
                  Entropy (8bit):7.7111446324254205
                  Encrypted:false
                  SSDEEP:24:hUBq3mqbaviLHm4WP9Fr5fSUXAU4u1fI2eF0s9mP5AUER:oq3FbaCHm35fvdIBUB
                  MD5:3AECC9070123CCFCAD94CC0F7181BC2D
                  SHA1:0B940A8B9EC622E606F000C0CF4EA72692A0DF42
                  SHA-256:BEEADAAC1FD7091DF6D9D24961B6D1A018FA28D22F1FE827E7F02C7C5878A361
                  SHA-512:D8B460CD78D20ED40DD30143185E3A11DAF28869844CBCD4B4513D4606011340D22EE2DBCFFE6D3AB0351E4F8AB265EA07DA437FBCA54543E3ED8DFF358DA2F3
                  Malicious:false
                  Preview:....U..RB.I..^.GY)...1@.. Id..v..T.7.KM-....a./p.........,H..+.41\=0...hBz....U...xb.X6._&.....a..8......e}I...f.@0.......\..>Gj...:%...W...T#w.......:.....B\/2!.e...y1....P*a..0....*M.0.........B.L..pEJ..X..H..O^+.P\..u.....Q.0....-.I..".._(z_&.*...Z5%X.......!..~.X..' !.(......{r.:..~.q..X.Q..\..B.F.....;.gtx!_F.O.l..y.....G.....-8.u..eJ../g).T....I/..N..p.._y....l.;VI>...i..i...il..j..7s]S.f.J.m-M.B6`&.?...T\3]..kp.6....k!{M.p...I.q..Q....0.C..-..\/........n.7.1....{......e....g)..*./....h5.5.T.i.0.l..9.....-....x......J.....Z}MD..g..op...>.V.._....[...B....I.).[...Ww.,%..~.,....**.`...w.E..R..7E.}..~"...=..s.`.U...O......EL@..i.F.R.^7....{...)a...[....g...v.o25.'r~.c.W..>.NZ...B;.~2Fn.%5..../....b..!..?...nd..!7.........q..>.kM9.P..A....L............l....J...$Q3...+M.7.D..n2....Q..D........:YKE:.Y../J[.>Sz.hdD.v.hM..q..Qd}7..........-/.m....B......$.0....*3..%.4.....eH*.T\..EPM...R............7...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30863
                  Entropy (8bit):7.994601165341054
                  Encrypted:true
                  SSDEEP:768:wDQJuZM9qE0h5PezY/WI1U+9/T78pSAENqmpj:wl7E0KzY/V9/QSAiqSj
                  MD5:77D2AFC867D5496C4D06EC5579DFAB86
                  SHA1:4E98D44BBB1E1BC062AEB2EC76C75D91E93DC6CB
                  SHA-256:267D1F0D085741F0FDC532490F67D303B405BC4B5F9C2A8CA55C9349C43B1B50
                  SHA-512:A4220B4EA752D0197FB24EEFCF8CF03F70488C981B8436BBB5600FE7368E7E1182039C3595D478A273AE37AC6D3F9AAAB3CE67ED66D4734F2A24F120F17626DE
                  Malicious:true
                  Preview:.......l.,.=..A.XzoR..P.u.).6....../.....Z`..E....+....*.%oS.....).Q...6@.i.$.'..{....>T_......4X..ez.....:..u.Y.%4....a...BqW#...U$..f*r_..^....X..zQ...zX..<0n.......x.'.]*..x..x.. $.)......OXs..=...d...RG..a!j..V.)E.h"..._c.i..}...^G.....0.d.K..2...G.y..".a....g(..;g`..vL.1.@T..........X.....{f.g..v{..|.C....+C.D.V..U.ot.."Ao..x.i...?..\.eA.5..q..G.w.\.qDt.f....c<...=p>..leU(.TJ...^.$l.9T.z....q...E..0XA..t`<*.!.5...1...4.V..2*.."......@....v..n1.D..eJl ....-fT.*.Q.A2..E~.).....w4.P/.v...)5....^5.a....H.R..*.7..t......&..h...K8...{......0.*.;..-O.s..)3....W.'".`{x&?._j..-~....q......TLQ./.r.w(....C.X.!.'..Dv..jM.W.~.....2....'.......B#)*..k|Vm....&3M.j....HmFR[xc.7.~g".03....'J.e).qpt..+X.-.........-....e....Dr..c..D..~Zc.r.o.1.&...%2..l....E.rB...N....L...P..0....2..Qj.U....t.{1..M.u.ev..N...sV)......K..!5...A.~.e.N?...[{...e.D~...\.Y.F..{...G.c..K.4. ......W...k.*.[h..H.%C.b..za.......u.B!D.....g..Y...x]l...U0z.`..&..)yq..#.n.I.M)...B.IU6..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):36300
                  Entropy (8bit):7.99483654522738
                  Encrypted:true
                  SSDEEP:768:Bv5sKNAVfrIEZaaY5hgAwChyHpC1Kktak9BGGLOZ5gLEUFzUUsdRcvJ:BvTNEfr/ZaaYvx3SC1KkTGGsWf6UsDcx
                  MD5:EEABAAF54318B78BF5FDB4B5BD877024
                  SHA1:C2B5A3DC40036E30E7ACC19286B7FA0840A40ADE
                  SHA-256:602D8AA1B380BC11DD0AACAA261316C529D6253839F1118F9C65B0E82A7BF62D
                  SHA-512:7696BB5643BEE47B5BAEF7B27631B30B2025C16F8A1E91C6BE5AB75D2978784D3503C6D05A05C113336201E4E5C0ED5A291113ED7B7E68AF47FDB3DCE2EDC71D
                  Malicious:true
                  Preview:....}.....T.Z.....+..R..k....7Y....+.....L....vQ.O.......S...-w..Z..W...(5}S.61...E.......A.~..z)!.VZ....Q.@dW.Y.R.W}L7.;Y..E".%....j...?...F..D....M....92~.+..Ap..R;.8..\.x...J....2...5..U.E;.,_.<"....|.d..(mzZ...u..5=...1)..lP.].B.FrD!N.=.e.....2...).yG.<..\w..g.l%.is#.Y.^C4....G....-...R].3X....X..:..d.UX....4>..$..J.?..o..t.w.....W..'@...1gg..5:z39...+b..'....Z9N....j.'.,.;.......`...;......B...o..h..*9.....[J]......9..5..|.).,..0|..e.)t...I..d.Q......ht.>N.LB..>T...QC..../.....3..}..^._...6%...Xv..t.5. D0.rf...I...u.Q....J:...u.i;r.`.6J......Y..Y...z.1..1.p!.\.7D......b.....}h.......y...#p`vW...rcE5....,dL..VuC,.F./w=...V!.U.}8B(h.dC....l..0.5....;.. ...../F........9.}..f...L.D."!t....i.g.;.f@..`.O\...n....XI<[.../bZ.sG".U....!..7.Gf.y.pR.......'..lXBC?.9.....=...$..w....1..x.k..4 D..?.]ge@..[...&R..........]...}j..dc...%.7.C.5.K[W.....[.g`.,kY..X....?..sTL.>.[..a..7)..J..KA ..I...B.V.3o"uR.-...r..xw..C.^8l.z..T.&....2S.......o....fR^-
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34442
                  Entropy (8bit):7.995079871849525
                  Encrypted:true
                  SSDEEP:768:keCGUgtJoQoflCcsFOb61Hxt9sh7OAth2A/SV:k3gULhb61Rt9sH/2J
                  MD5:2B152BF19D16BFE0C1C0436B0FB6E8A3
                  SHA1:2CA1FF6654F79E1E1E9C22FF826EE4DB16CA0606
                  SHA-256:9369A34380402A60936CAE75018DF9464D63E9D1A59DABCC4ABB9C45D909E99D
                  SHA-512:0E2E1BCD0A18083B5153BB82E6653B20B935C2063E2E88130BD40D3C19A14FA58D68D2912CCBF6B64A2FCFD2165A12FFCF884A1FD6F06C88766A42C011A2DC5C
                  Malicious:true
                  Preview:.n..7.ZVe....x.$...cGE..m.m.......F.w..M..r<\.....X=.,./G..{.6m.TwNd.....&0&....s..k.$...2....E.XE.O.....3........Fm..@...aDL....V.".NX.L^B}f...!1..[..d...f......`.x1.^.D.y.XY.....M...\.{.Jt...+dY...G....QVIDX5......]o....W.B.&M...v.%... ....i....M.X.#V:.n.R..`!.../...of.t.b.cu3..W].P/.78..;*......{..BK...>.o>..`=.4...4m~.P...;.T.............9..NZ..../...^.dH.._R...A..==..!.O#........&*..@..4........!...z.M..M....OD.~j.....Ut3..8...9........H......H....c...g......O.E.a.Y..=.@.T..J...'. ~m......*... .?(...;.:}."...80.o.)"i...9s.....B@\...G@.$Q.MkH'7)...y.8c.K....Mq&.z...!z.$.....<D.H.c../....:\.....O.#`..R.a...,."M.x...~...,x....c..y?.e.....XC.)x.sS^.*.q.t...*..........!.eyk...b..-2.....D..p.&..aD...N.4.q...y\%..Q5td+....oP[./.5JM...........S.)...S.p..nh.h{7.l..U.4"....g.....c.j..x.;....[.....I..r....e...tw/.;9.CR..9~8xiVF0...%K..|..;.).;u1t.\...=..}$gF...ST.u...%W..W.t.G....L......HDJ...Q.&...M...d.r.)....z....1."...<..l.uQ[.Dw.2(*..P..C=...]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35405
                  Entropy (8bit):7.994227200664412
                  Encrypted:true
                  SSDEEP:768:94XIZh75CNoGdUPNCOtpU3tpWktQWf5vCtopq9Wqo8K5Ioil:hj7MN/OE3qGCqpc7Zoil
                  MD5:881FC7CDD38BCBDE706551ABDABDCA9D
                  SHA1:6A9551D4136DE1E0B3635F4D2A57B24B1B6FB2A8
                  SHA-256:033B074FEB183633F21700B7399C7E2185B49B225571D4033D626C08C310237F
                  SHA-512:BACBF57B3435F4B5905B9BA50257677F8D0AE2BD8E2FB2AC107CFACD0619890E1A95064BF966E9AF272644483B9A9B4C178BBF165EAEF88FBB902F51E390BFF3
                  Malicious:true
                  Preview:.DO.9oa..`._..Kn.7..l..TY;P+..7m.%.Q....vj..k...:..![{yL".....GR.fL..;sg.........#...z.F....p.,....d.U_f...s.(m}....c..d....}\l.w...*(/.[.\.|z>.<..r).#.+.Z[..nl.MyQ.Y.....g.#B.... .L.k....o..f....0...........]..j.J...mkx.....ccJo.............07;..z.J.{@..V.>NUo.3WL..YGw.\N...3.......t...%....L...!9.....\I."...... .L...'.C....u.<..u.+.A./..;/....iW.H......"x..<V..y%J..Tq.^.rXJ`...,%....#Z.9y.....Db....c^.N6.c.;5..t.FN.Av..\3.. ..|.|......)F..N{...U.$S..$v..X.1D__......z.e...fi.E.Y..[..}..d..}..j.pH..kf.1..}..z./(.....J.T.g.L5xwv......;....*..LI.[.V.,.......>&H..p..y.G.@.?.m..w....,N...i...r...t....)F.a..Y...O_..O...p....E........KHI$..e..;.[.u..J......2.nHP.......>...N]...'.M.C....D.-...?..u...X..M.PZ.{......Ac..G.....f2..t......l_..{.._..M...~.@|.:..=.Ve.t8.E>......]V&...n"O:......../.2w.o..6../.,..GM...LS.7.Q.].B.u.Y..5..4.....A.Z......dr....{.VMS..i.Ey_.5..|..R..R.)....c...M}t..W.........nz.v-../...sC.+].If.......2dh.~....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):37345
                  Entropy (8bit):7.995967169451554
                  Encrypted:true
                  SSDEEP:768:QM9A/QgCa3HB0JC6sZuMg4WWl8epmmn0RCa1kpjgvSGiJGa33dnZ2xp:QMSYgC+HB006sAMg4WWlzn0RCltTGiXW
                  MD5:DD10F9990F5AA0E04DA62655D0ACD4BF
                  SHA1:4A13F211AF28C639461123611FCC9B2A708AC4DD
                  SHA-256:414DE1693CCB6E382DA1713B75662AECA4D099C733CFDE373E7FA6BA4A3FBA4A
                  SHA-512:7692FFEA312FC401DB7F18FF782BE1FCAF36B6E5F0B5632BCBBBE2B737804C434D37F10F8D24E704279180D754258E19A87F9750B119563D45C0ABD62F835183
                  Malicious:true
                  Preview:..%.....X".=..:2....emU...U.$./M.o..Q4u5....3G..7.h.W...|...Gm.]...81...F1...:8...h<..&.......67..dS.Q.W....9>.6..'..S..=?.`...8.....Hb..0.q)E%.26.e(...;......I]6.J%3.g.+.C..m.s...U.Y....po.g.O.)>..b.NK$n..*.....U..n...g..k..I..C..eZ..).%..f#9*2...X.....z.d...I......k._.1p\..n.&..os'..k..BG..6..}...Y.h..eS.b.J.U[.!..........oc;....-.kl...*..1E9...0b..zh..4.w5.}..,...v...>[.....U..v.L..j.Z.5.......n~Y.).s.v..T..8I._0.%..@....5>&F. .e.7....U.....ll.|..O..wWku.u.sw.36...T...(..w.D...1..&..a...F9.q.I.@.w.E@...X...x...+...e.S[4.,.S6D._ej.;O.H.....:.p......V3_.3.d.. ..S"....oh..d..dG....6.."`<..y{......n6..Au.1|z/.QL....@...b..]W..tC[.50.....qX.)&f...g$...4]Y.Nq<..V....7..R......\...U]v-...........eg..7.[.>,G..;......I....h...HXo..M.4~1.athy..1.......2..V~.."..,.Wp..YN^w.tg.L,w.=..7.wT.y...?.....O..QY.....36....wM .O;y).n.^8.@Hx;}.9V..c^...'...~g%.CZ!....v..[..@o.#./}..u...U!..z*t.W'YQ%D..4Jm~.Fo....#O.........T<"_Y...8..........|...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):37345
                  Entropy (8bit):7.994271937111554
                  Encrypted:true
                  SSDEEP:768:sKAIBHo7EnfRVy96tHIDaQjCf+rJvfbLvjWa296oMiS0CSgikAZWGqi3TGbm4jes:RL4EneCoGQDrJvf3vpDo7SX447
                  MD5:B1D9FAC21F52AE37E5F1FA2FAF108A8C
                  SHA1:8FFBB0B6DDB441315BD62F1DE0EEF4BC71CC736D
                  SHA-256:34157DB7B3E2D3E42262950932566192A6D31193121BBE2BD57371BF239ED623
                  SHA-512:AF6A94787AB720AB24F9D671084336B9D13BA9B1E815A5CD5693275CE277176BDA243C7F62ADEA55D833BF2F7BB181880D568706CCC50F7AF8E8BC04532991C6
                  Malicious:true
                  Preview:k.#!.............d.#K*.K.|.tn......S..{V.z. -....]n..........7.1.Q.1.....1.m......"k>.."..f,.3.......mW.S.......,..&oc.#3............].7.R.. .N.|].q...$..#..%.^.=.$)J...z....h...5.JK0+9..<.N.7....O.Z.b!|M.m.. M.iC.5........D.!?8.F`Db...}.1.k`......-F#..}p.,'dD...X.=P...}......%......qIM.fS.,A.M...9..pC...5-p..C... pZ..x^_.......u.....y.S.?0.....L..VO..ava...f;.Z\._..%R.0.r)[..c?..G.E..........5....Vn.\...<.k...O-G...q..<P.v.@.u..P.W.".D.....7.}....}Kqu&.qQ*....C.F....P.r.$8..~.v<.0%.c.CP.|.7..kH..F.#....)..Z...kF...........@.Ry.+I..3.6...}......e......@.w.$.!a.......k..j.0.H..Qq`.fxK.o......S...?b...:._.....6.....gH......a..d...["....R........ .b=w..$....5..Y#D...7.(.-....$..).<H....:...M...........hBp.j....j..4.._......lNB....y.."..D...w.....xb;...6;5..P..9......F..yA....Q..wp..o..}.....v.$#..ln.P..K......TD........+..'rN..Uv.......kR1.,..YD9..*$E5/....Z.8H.{..........APJ.r...........GPb..2...1%.......6r`..riWy.........0.z%yk.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33720
                  Entropy (8bit):7.994612743993396
                  Encrypted:true
                  SSDEEP:768:hWkIHVjDSEMoe+Ql1oKlZ5kxS4u6j3jBSbxqP+rY4UH8QsPO8gmld6GnWzG:hTIHVjDUoe+yyy6BAxqPyzyOO8Fld6uW
                  MD5:B9381C4FD071AB5C124F17CC45CA0F8A
                  SHA1:501086EDFFD2CE4C38048B360C528FB524EF9420
                  SHA-256:70C78F8BC2E23C643EB719E9F2E62532546150E82158E4FFB46BA537D33910BA
                  SHA-512:7F5FF4ADE0808705CC59E8922336E47624BE65301053B1887D63C66EB02B07090D0C8A14B333B241D1D8405D55A3E41E1E5C8323CEA9ED07E3B937C148C48076
                  Malicious:true
                  Preview:pE.....<\.c....U.b.{#.So!..D...&...E...5.yJ....s.C..........X....U.-j...S.....2.7%..I..xx..(.$.1u....."!..."+..'..`2A.K{.uj.\..F0.h.y89.4......@k.....SzC..........?%.V.M.f.p$..l......"+.9`0b".M..=.Z(.X....Oj......@.yD.H.r.|3.\.N.9%.kO.YE...@...Z....W..3.(.,~...HM.......;.o..B.....kz...{.1;f=)Gue.MP>Qo.7...9?.n....|..KQc..'N....6.<...(_.Z....N..[g...s...z.:...2.9..<........}^.MQ.....C.m.....)?C..?.......G....j1.tw.1:..[6.._.d-.N..!ME.z}Zq...;.._....B.........D&..d.b<8..D.c{f...F-H......X.D.<J..h.-....Nv M..Z..).R.Fd.B.m.-.<V.tUG......._R..0.U....A...93e.B.....X..n.o..?W..a.....C...v..-.sF.{<:..k_..l...q...'.P..s.|..j..).}..l....3.d..)..<0=N..C..K.....kU4.G..n..1..<U.L..Ar.y....b,.Y..]8.T+_...^.u.h...w.d...?._<S.m.....1..... ...lD.....(mW.....Ul.[.pL.0.U_.@.9+@.X..x`..;..|.o..&.=0..lf6...[.}F..yoT..R..K0Q...)f..:I...I:..H...c3...R....9.`.`....cb..*bHF...ex.W..*}...K....J..~n..{.X..@.$:<.d.AWK....}.Z....f2Jnn..1..x....(....%....T.f.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):37509
                  Entropy (8bit):7.994678338631123
                  Encrypted:true
                  SSDEEP:768:M/GHlt+OtLQPmB0zlIH6KgowTxJkJ8tUjJkmvATwymGRcPO6X7kHhpUW:qGFtvuuBdH3QJtUVJ/yvqTYB
                  MD5:32F38D070199C4883570BB4047851C9C
                  SHA1:BD6C6677BE07E87EF0E79585BB881A55459A2B37
                  SHA-256:5DEC173E481F338F544A77214D0AE895C5CBF42CC71D5969B87FAF3118FC26E3
                  SHA-512:C3ADF99FB53483460EE156AF7D8397385804D8A687DA2195228C9BD44138DBA374B48DF6D35C1E6857FC21375A55C432627510D6B7735F7D745E21319FE043C6
                  Malicious:true
                  Preview:.F9..... D.... .nv...k.z....wV=............'......v{.E ..U..........T<.3m...?.........G.V.S.[C.{.,..z.........5...-...yf7C.F<.z|W...A.'.=-.....[E.._r;...O,....Q..^.h.7y.J.....h..aSNSC"n.q."..T...AE..S4.......<.r.Z....b...y.e+[0_..}.Q..z.H.U..\i...G.W...c..hqN.[`..L*ktaq.T...X..h ....0..&.NJ..O.'..j....;...k..H.F3.......+?".z....s?....*.f..$.V5T;A}.Gj..<.3..cH....w..mg i&.V..N!..7..0Q...>.g.N/>...<@b.e"..o@.H...`.uy.9.v....Tm.f...r..OfN..G..4j)...j.....T...x-....c.:"5......ra..*.............Pq.)q...l.p.m./$Z......7.....p.!..c.8C....[.%.-...OJ.......O.%V.H.....Y.<.V..}.{....\.x...F....C.z...46.?s.....{.D..".....7..(Y.....*.......rI..Z&tn.#9v.Yj...B...>.....9.FS..Jf.vk.0*,.2X...e.8.YB..W._Y.U"~..{![.+../X......$..:B&.....&.!|......9.U0U....@..EO.j..Q...^.>..j21.x9..&.E.[...{Ks<.*[.8%o....5D=..y...]..A2?....K.2..r....JT..?....T@@!.......^....".....@.....DD...mvZ.1\.|..If.]j-Kq........Ew{..Yg....NT.r....Lg.w".|D..._...\@..V..G..6....^..&..3X..!A.pl|.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33892
                  Entropy (8bit):7.994872118065089
                  Encrypted:true
                  SSDEEP:768:5Rlqu+5yIE2nO4zHeUee0jNUot4SnAvM1ZUPLjd7E8C2YgLJ:5RlqXyIO4xdc6ot4SAKi97GULJ
                  MD5:21E60B30C6CF154B36A31CAEF91B43FF
                  SHA1:7B4FA16A4C399C415C648E90E8A85700229F2F9E
                  SHA-256:0CDABFD410EE1C3934EF1055986B342D71B66C926A927B4460379A4C0371D183
                  SHA-512:238130D7275C5A2FDC489DB43F614E7C50974D961AA9A319AB106615071454BF991AA99F16A44D23C43E4AB6A82EA65AA06A2B9ABA216F93FDAF8A8103FA42DC
                  Malicious:true
                  Preview:J..:.R:.8%.U."..=KO....Z......m.....4.b...YmV..{X~_..y.r1!........'...H....c...'Ck;M.(.H%..nL..O.2.....w`.`..#Q...U........m3....ja...`J..b........8m.OV...R7..e.!.c5..k..6.o.3.w}....#.c......X..:Of.Y..L&.vF.0k....G.....m9].G@.3.....L..VY6...m7...e.....F...C......c...Su..:rx...C-!...m....)...,AQ. ..+......?<+.[.Q.P..$.N...%..e.H.7.D...%~.,..Ru....f.....[p..."KP.'5o$.!..x.Y.....+.u....C.p#C.......g..*..-:Y.8..{.A...d).O...^Q*.....O....x................t..1Jh...<......X\.x./b.........&S.9....!.......4.P:../....25......9{N.7-F1I.N.+K.b.*... 85.=T.l....n..-..[J.}.x.5.% ..M'.E.p.E...L.[....9ar.A.Z?..t*..'Bi.w.#......k7.q...8.Q.......8}L..*..........C..N....%#.....SN....t....&....f.........[.....Q.T]..L".)..q<p....;...Q...O..Rs.=...:.b...T..!.........*.....yu...f.....8.Zk...,.+~~........%R..9wNtck.........hk:$N.......!......<.:...u..../.....Yrz....D.U.....v.8.dv`.f6.lYJ.....t...x-..........QftWy...>{.k.,DZ.S....Bm.........XXF......p..m.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):42063
                  Entropy (8bit):7.995495130318187
                  Encrypted:true
                  SSDEEP:768:qOgmlm0n+j7GO/73SS53nxSeUAxWz0Sp3IQYZRvudDNXmj5nIC7EOXG4FAKZccI/:qOgy8DXxSeUAgz0SqlRvudBXG5PQqG4O
                  MD5:2874C1FB4E4AAF5680B665F0D47A1421
                  SHA1:F38AE84DB2CBF41C3010C270598225AE11B8975C
                  SHA-256:61766329036CC78157D0CFA5C27C5E5AA3B059D1A9021DB18AAAACA40607D523
                  SHA-512:D9EDAEDAD9F032F2B18981119E4DFE4755175773A63D3378002E1F9CA10AB12CDDDA0CF3253937754DA44B544DF50D4AFA5C1C408DE1725158A53931306AF205
                  Malicious:true
                  Preview:...>4...W.......h......l..._}$5I'Kd(..Yz/Z.;;...0.....&.h2o.....%q.q;...5......W.).S..&.@./..1^mau}......p.KW.ni.....8..|..].<l..^.....#j..>..t....Jk......m.zu.f..52...h.d...6.G...f;%.;U.:{r...B....P....;]......r.T..+.R.t...:..H.....'..[?..K.K.n...X6o.-.8D...e.Jd.R...P..........y>..t...tJ?....2_.'En.D.(.d.a..+.kE...)..V$....f.*.V.f.Q.$......r6.8N3wP.......S.f0ub...0........h...V..sF.........#.{.%G.m....-....D.......~r.:T...."`G.E...B..."..TjnC.{j.[...!.".C\mu..|d..b.j.....:.U..3k.*d......?............x...C7..S2..,.......U....8n.-..5|...n.7.Z2F...j....k..mI....Y......H......g'...c....lm..g....\"x...ZH."...x......./Hc.L...%..P.Z...&..y.X.3...%.p.MO...I.....7C(^...>..B\.G.}...r.<i.aj...e._j.%i....R..=.Lo.CC..s.j.......e.l.V.i'a...U(....E:.......{6O8*...u...M{.1..P3.{...|.O...x.[...k.+....A..8U..U.1.khx.2VR@.[@z.}.X^.....a........N..9.6>.v..G@EK.n..... A.~...(F...p..%..'..B.&..:.Y&.H.x?.J./u1.#D......]9.mz..I..."9~d.6.M>...O...gE
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):37068
                  Entropy (8bit):7.995056949507187
                  Encrypted:true
                  SSDEEP:768:vcfNmWhZJJ4qS0QrozPhdtbaDqOkrFeIJTES+bdO:kAWhZT4qSgzPLZTrFeMo
                  MD5:F74DA1BEE4E779AD9EAE234C3CC6D12A
                  SHA1:772003E858DBFA51C6BAEA5B477AEB0DB1C586DA
                  SHA-256:0401D0677B6EE61B04B7CF5C70BB4AB6EF25B432CAD469887621194E8AA690E5
                  SHA-512:D2D4DE3CEA3EA880E8008EBD5B4A09A65CD5E56950899274197A85A93ABFFA321BC63A5ABE6F4000A2EC634873E05FE556239768A67D212735605E2454E27DA8
                  Malicious:true
                  Preview:...X.......l,.....h.e..@.....d..,...8t..li...&...%.6Ks].VQ.kJ..]y.......7.8.+..X...{!.....Z..>.....CZ....Y..(.1 .m..}....eG.g.jh.$.W..K.0.......1.."....J.N.YM}...f._...Nb..ui..Q."a.-..8W....u..S...S."@...{[V0...#.ZE..De.j.....7.i......Uo84... .+............u..m.0a..z.X....._.....}.-..=-..x..+.o...=.n......U..e7.-..F...D........C...;..D...gD....F.....A.$..LV.P..Nm..R..~.B.....2..3.{...&.*_../7.^p-....]....u...C...?r......"...D...`^.|(.......#....8a. ).mn..x...u...../?[...5T6x.....BW...'>......~[....F...|.d..{.+....S..j.&..N.......6....}.\T..)...s..e.".&..{[~.3...{.......6..l..1.!og...P..u....kK..20.....C3.)...o.....I).iS...7i....G..6P..E..g..33..K..%?._...W:..a.|.[Kv..Z8.l}.-...../...{.\pzB..-?.a.*Y}.e{....z.....G....V.K..x..*jX....mB...gv...s.I.5..n.P..P....H.R$...B..l...Q<hX#.UeT4=.NJ...A.......a...........c.H..O.b.&.....(.(...Fg....iz7T.......N.{../#..<u.G=....z.[...)".yu).!.....)k...0.c_iw%']T....C.^..I..A.............!X..m..7..4..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32230
                  Entropy (8bit):7.994456618239734
                  Encrypted:true
                  SSDEEP:768:lPqeAz/We6V0gxn3vNuU8vcyVuVpsXVt69XOaFU2m1Rz:lP5Yue6V7/4zcRV2XVWbUXz
                  MD5:9EF9E9A7B53A1191B92714E6906AC444
                  SHA1:06FFFF1A7B59366930DEF61B00A43A37FC7D1445
                  SHA-256:DC9B8A7DC231AB02C2B0E17803F3934237DDCF4B00D5DA6D28371347E83AAE5F
                  SHA-512:22BD6E34F8C8E7E11D24101D7F2A76ABF343FD78C4DE2BF4BE3A3CEA9A69DEC3E5606013193415286A9E953345417EB33C04BCE22A0B4DB21E6CE9D42398239B
                  Malicious:true
                  Preview:...oc<|.G..r.........xd.O.,..%.7...%.....g.|...9+.eD.k6.5a}..bv..}.......1.Z@~o/..sL1m!..\|3.f.......Z..j......64.....?.e..K..0....\..$.+h.s.....|.hJ....8.[.x|.]-.J.#..GlQ#..A.....M...&GH..R.f..#fy..H3........9..8.V./..&.~..n.......Cz..l.>g..-U-...\.[I....9...n:xM|?.F..g..{W_V.i,..]2?..`|.v...1...{\._s-!...~[Z.t[h..nsb.E...#.J..4.!1&.=:.A..ne!....d.-u.?..h.O..........W=........j.....r....$.....S.&.\..Q..g...........A5.&".~..4Ls.b.8.'..I.xL.H.\..^.26b0.....{.}.J.=5..Z....4.8.\...-...vt..B......s.c....e..E...}v.M...EbtN..+_5).;}....GH......)3..:...Z...g..>..|....9V$..*..t.'<Z..V....D........I..?......3.....L.R&D$.,n.c...Y...4.. ~........w.X..yXo....UC..>...".6c.'.w..`.........(i~....{..!'..E...AKL...P.U.....e...4.. ..2k.)..Ph..N:.RY.,'@.0q.$.[.f......*.%r.d/X......!..^.@...k.E...q...T.T>..<._.s`x.J...N"....av..7...13.,..-....'..F..............G..<...]........fl.......[..A'.t.....H..Y.W.......i[G|@*.g....}.v9...D...UfFQ....X.1....|..u..!..Y..b...ofm
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35261
                  Entropy (8bit):7.994033293022851
                  Encrypted:true
                  SSDEEP:768:G4Cm5aEPguhoHuXM2l248xIz7b9MkEIuwfAv7iACqsKG:GK57ouhoOXr8G7bpEyfgRYK
                  MD5:6A07338380D24D06027FE4CF52E096DD
                  SHA1:18CBC312EEB6AA3445147FAE1B71896B08BFDE0D
                  SHA-256:DB821EF4A3193E8596177AE52776B29F23E404117A5214FBBC037FD1161236D5
                  SHA-512:259BE9EEAF0E40088A211B5C889EFE8F2C08C4CE2C9A5107B6B6C303A8CA8309237C9C7D529F9361C47F6AD34E512C8F8E85D41ABDCD182AA64C344D3B4E2D66
                  Malicious:true
                  Preview:CT36.,..}....}........$\h+.s........s..YP.w:^`..ZW4.J..L[..*.......C.'.s8H.F...D.;;...p.g.E.em.|._f|..v.......:....IT...*..(....k....`....C........#..f..m.&..?...K.5....$j@.1]%......5.....^.../V.V<....Q.....6.(Y%..`M....4.......Q.K.d....7...9.(./.7.i.Y......e.c.KY...)j;.U..8..5...c@......Tq....1.z..^.n.e.C..hb..+..X.....".%3.1NV....|'...l..E...h .iV}.q.c...x'...o.,_......3.IQ..._...l)..;.7...@.G.0|.?....TG.......~h.t...W.>.....1xP.B..c..DD...>...Y....9......_.}...p....;..=$.....3...=......H.7...w......9..........uUq.Y...*}....X..J.7..[J.c..T.....C..K.W0....\P{..mNK...W.1..OfP..5r...c.&Zx.......N.4.m^..t..s7}..(8b/...drE.+....jd#..Qju..HW.j..B.v..\...,<b.6.....jF..q...~...}.y.I..h.C...z..>...$..-..C.....P........w........{$/.J.....b.%]....I^..E.W...{$<,% ......BFy..+.........5....q..U....@.M...s. 6.#k.3I._4....,8..Uiy.....}....o.........E%.......1..U.u...v.....7^.....G..5?._.Cn . ....GT....;...?O..U.&.*t2I.......4..=............^.dx3.i..L..y
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35516
                  Entropy (8bit):7.994968598748032
                  Encrypted:true
                  SSDEEP:768:EjOY43F5aABDaykmNC9LMuLAb736zaAS7qYzviKDj8vZBOl:RYyYamx/1fAn36zaAWzKKDIvK
                  MD5:2F11BDEC274BB8B398F7C2CEA9AFD083
                  SHA1:EF42706BD8702521D776488A38450F6852812CC0
                  SHA-256:AC38DCFFEF47301B54F87C1C64BFD78CAE2E8C5AA7B6955F81F09DC4BCDB6F9D
                  SHA-512:903D3C7DD5A0149AD5F0B5C5E2E7DC147325C91E949821C36D06A15A5DAA27274E00E1B821CC2D405E6A48D89F394253FD4D01367582773132495E335A9F26DE
                  Malicious:true
                  Preview:.g..T....(J.u..E.]....;fx.z.)...4.....I. .......1Y5&.".p+<Zn).=....o.Z....D$..fl.q..X<...QQ.6........U....E..0.w3...I.u..=....}.........{l...$)?..&.M..p:.h..).'.W.nP.&-...>.a.`.-K...@0..~4..9vA.9.j6...:..f.........u.........6.VTC...J....I.2.eVko.7.c..M.'..ky}Tz.N'.J.Q,..a.t....^.u..8..F.;.s_V..3..Mx.s........}..4MF!.Cv..M..fL.....g...n.o."..h.W...1!.=.u+....7.w.q.#J.........>.b'..:....E.7..k..m.N..q.L...B.dYF...........ZX..PG..?..a.k.|...).......3....km..`Y.......g...K.....?S.{.V!......i..tw.QS\.8.........hAz......`...-\.....y...`..&z^,_.k.y.IY..*.t.@...Y.QCe.J...(S..q...o...[.H.J.iR.......SA.md.....n?._Zk..VG..q...3..Q.....(..B.{-....VC;u...._.....K........N_A._G.gQ..fx.zcT..[....q...V...tq.CC..Z..r.0.WUM...cc.P..}@o..'...d3.SS...d.Z.V7.<|.y.,.X...&?.<g..Hw.M.0._.y~E.....Z..m.$...<54..u..J...J.._tg..Nl5/.#.....p. gQ...U...[.#......'.7.y.t<CT..*......8...c...+a6..*...li.-.^.c~8]w..b!....6........=.s.. .y..RR=...ntw.Q.f.........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35065
                  Entropy (8bit):7.994700253915265
                  Encrypted:true
                  SSDEEP:768:njImXFkDLo59ZkaMsFBQCnsIsjQ4qqmtoB:jIS0o59ZkaFBZ314q7
                  MD5:431F7D7F08AD8B09B5EC7E73936DBCD2
                  SHA1:17AFC3301B693ED68D504E766833CDB485B7C51F
                  SHA-256:1D208DFD79AD56E4B02A2B934CBA6C096EFFC586C67EA8528C51C9E592CE02E4
                  SHA-512:2E9D55F45608D0B482FF417925756FB2C50F88B650080A5E4EEBEB65780AAE92874B4B5CFB5A91D794465E824D4F7693E3777128C5E8E9B6876C9C5CC2D16538
                  Malicious:true
                  Preview:........5L!-...>.*c......GU;..X>.1.gW.pR..''....K.5..r...M8.aS.11wD..YKk...^4.,{.Y.-.....Xz.....[...C....r.I......).c..1T.?*T......v")SW.....3.M.....Z...."'....-.f.....[.V...Q%.xQJ..O.(..T.G>Z;...mb..)..Y\.[....e5....SlnvT4-...-vlA......u....9.o.Z......k).>..i....GOPA...d.._..3........J$......1.}[.+..g..psvz.&Z.m~.=.n...;'$>..[5H.tEX.]a...7.U#f......z@~b$v....'9.@....zW.k..}db..X.G.......*.i.g(.....Z....._h....,..$.L.)..... Q.#.P.4a.y<......j:.uG.....ya~.....7.=.NHYf....u..W......g....Jk..=._.Z...h.-....H}+......o.J....L.#.....:...,i......@y.....{7ly...Z.+.....N)....o[G.U....6<.%J.............\.._ v.j].w...d......P._l.iH..e...n?.[#..E'v1v.....&..f...*>..U.M...*e.uzz....UEX.xH..c.S.x...(...*....4.....4..[....]z.I.Fa..hl]G..0s...t.......Ui..\>GS..-s.......y.K. ...Q/.t....W.F.>..:...!=.e.Q.c..Q.;.C.....(..4O.........VEu..B*\...=..I..e......1.D.a.^.W...7.I....I.....Z..&..zE.....W........V1.....M..^..Ej...If.X?.`..7.3..0{.@.9b.m...Y....6&.|.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):36536
                  Entropy (8bit):7.995175523957675
                  Encrypted:true
                  SSDEEP:768:Y/CGJ+4YmQjpmXJGKHP4/MlKIXSrp5euZvncQVasawHZhtf:YViDAJJsmIp5euZewLN
                  MD5:C97317F0F25FCC265E385EE477B83680
                  SHA1:6EC8B39609C91BF7EC26B76E39BDA8A0EF676FC1
                  SHA-256:D61B2A48FE7D2640CFE6ECF5602E2A2AB8EB46B59937BAB54AB332BC9B09956C
                  SHA-512:DC21DC0F1CF1E044B9958A182161EBC8D43235E8C6F32F64D721AF4A06F90F2314716B088D4771F5E1839DC701855F9A6F3581203B5CCC5374C75DDB4D443951
                  Malicious:true
                  Preview:1.......=.9.r......+..5.....k..slB.on=%,:.r..#...../..SXuaR..B.#w>...............6.....0..."U~..Oa...@..j..BW.H.A..o.......\.....*H..6.....->(.O%r'.m....].\...[.U[5VG...9..q#..'.#..q..].r..J;VV[CE.].I...!..m|ts.A.../.(f`..ph.D2...;.L..s...c;...[...7..x.)...O.+...;....{..in.*.sj....s... yY...2..Gs)....R..p...Sg:..L..Rd.(..\..6.Rrh.....VS?....\..L..J.......w......{3`..E.....R}.3..x...2.S..V..8.[M.....\p7^N.2.3}.N...dP..Ad..c..2..7Z.^.....h.e7.Bv.....aC.k..-.1....HH.V..wy...F....o..../.).nK.Q.,.MW.t.L"...3.2S.......{...$....9...B.m..3..+........c1.E.R^K....\)..Z]]f9Q?...-.........<.nT......).%.[..............A....6.=@.N..$WK.I.{..t...y....PE.R.%..4.p.!!?.KH=..#...Z7.w.....-.E.g.2p.+.Lv=.}\g.=......}..j/.2.Bmx[...5.S;..g....S.z..iI.......xq...o.dC..............Q8T..$.8C..`pa.*.w.C......K#.D.F.uF.<&.........V.".9a(......&....'W..........."..?.f.li.1D...+H.....u....2|o.Mg..NJFY....Dd.........Z.fEK..PF.V.+.....*..9-@..$.Gn.n...3wx
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30881
                  Entropy (8bit):7.994670002650147
                  Encrypted:true
                  SSDEEP:768:1KCWCToeUhtiZLcwxvgSdJEDbPDK0bckW6hB9YFQ9dOyiHH:1KgHUhkxvgUEhctkBKFjT
                  MD5:24538D4EEA47459C4F4B6CF139D6A94F
                  SHA1:3056D79F57C455DDACE80516D1F28F738D20C2D3
                  SHA-256:59EBE5171687EFFEA6DC2E588A8B03F11C84068CC5767BB5B659823619A84A10
                  SHA-512:B84CD47A7BE9E8D979A380F42414E197A30C5AEAC56894C6A4E17C32D915BE3499DB88260C753D8AEB3BD3800AA11FCF384B392FD248A0EC038F04F48CF6922A
                  Malicious:true
                  Preview:T%.d.W.D..kX./..a."......M4...%]UH&k#.|..........1n..r..w....A..G......n_........s........fw.....u34HPf..>..,....._...}hQ.e.M..'\.a_.?.U...HS.....bW|.V............K..3......e..(....n....%.....5\.\.S.N....Uc...6...}.:L..K........;..[..sc.$..w................OOD4".rO=.poSb...!.A....".Qz$...w...TJ+....X..EP...},..3rB..Aa..........o.....+.B...5h..v.\4...iMA_.:......l.m..N.{..:...~.r...H@.=RW....N./@j..Nk......S..-..ps..NX....h..\.../*.......f..|...p..-.....~G._.z..P........$!.d.Ep..*.,(B..9.3........@O......b....'..\....S...%..K........'F.T7.8A.A.6....&N..D.`.....S'"..)X....r..4.+.Rh.2.H0.g.....=..m#..P.._m...G6.@.^rb.)..........O.8f]....D.)%...?.vz.j.X(.....w.6..|^q.t.@...Q...).......8......+......F........}.Q..q..k.P.J.i..oytSi.....Mi8<X...m..,.|$9p4...).<.Is........R.*........Sp.Wi..Kf.%......S.]Mt.XE~.9.SF.......4J...K.A..~...O..U..Jjq...S....LK.#.....^,.......U......_....^..0.0.n.Z\...5........f...'%l.6...&..>..,l...n..:e.l..R...1..".5c..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):52508
                  Entropy (8bit):7.996218804596554
                  Encrypted:true
                  SSDEEP:1536:XcZPDt16L+5Zqt5I93SmpoC2g8sTCb6xINR9IT:Xct0Kej31tuNx4R9IT
                  MD5:30ED963A1D139E3942B586CA5ECCE5F9
                  SHA1:7E61EF7AB1D7351110BA98A392183EAE857F7210
                  SHA-256:29181E8FF2A8A6A1FC676FD149B268516EB61D546B0A9AF553F838DAEE99C4FB
                  SHA-512:0100A710F8FD54B3D8A638694C6483E969548E1149B7FFD00AD7A60F9F6FB5AC5BC8D3794C8E5CDD18058D6CE085B546F8A67CE5C2035F1F27E3030CBF911E49
                  Malicious:true
                  Preview:b...I9...'V.M[.to...E.......!.<..'..W!....CM\'..'R..."{q......>3.....`5.E2.........,.....z...T.).A..q.AB..F,...p<.JY...'G..B.1F..I.(T1.n~5b.eQtM.[...R,d.......{S.~...N1Q..t.Z..r.z.|gr@).........[rY......epO`e..'.......t..D..R..E`^,[fO...}.M.U....?.......UA;.UT.._.s..I.a+6S=...-.'a....~.T.......*..c..P^.v...XS..l.N..L...0d#.c...."..N..`h.E$.b..#..O.../...........X..h_..?......J)S.{.+.,..}u.ng.*........?..w.".|J_.......v...CY.[k......*%,..z...}pGLc;5Pm-....(.. ...C.......oO...Z...1..=..1..H..iFE^......O|a.y...y..W..A\.X..$......9>.........M=5....`CC...#..6....XT..........!...o?CT....T!.......".MeN.b...x...T ..F..{....m.....j|G.... ..Dc?8.i...Z.....@4MZ.&......{.)..C..D...H_%N|.....).=.`...26E.g............P.S.w.O".?.\Az.......6.U....ydcp..W......<T3..w.,v....*>o.$.LR}..T..K....@..7.C..a..u..$.....2.).F.))9..{.....Z..v.j.!$.t....jL.o.."6d....~.z..5....VP....o.M..:...$x.....6.`m\..:&......z..\eA.}W.m....M..5N..........;.._E$'.0..,.....&.s."G.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35311
                  Entropy (8bit):7.994253779779276
                  Encrypted:true
                  SSDEEP:768:FSX8aBZp1RM4aaYbpXxkcLKlQ5doeiZxaLi7KB7dCSe:FQ8ySdhDLKW5WwLi+Pn
                  MD5:86C62BFBF93301C4DE7123B842E1F780
                  SHA1:B1331051FC3576E266BD03676141B2D3A0BC5BE7
                  SHA-256:D7073FAF0D1943DCF52246A001FF278C8B1F6A3445323394A4373E0CB0E2167F
                  SHA-512:189E13B6215E4A99E6310E83A0B056A40EBB8695A9F12EF7146CA956F7A49AB10CAC3ED836372B40476C6B8789E9010BA6464C207F8B06CAB35CA78FBF1BEA19
                  Malicious:true
                  Preview:..8...a.4.R+,qC..$.e,...xKM......Tt...3&u.L......5.$..}Q..<%..r .q...W.+..x..?@G.......jf.}.i...}V.p$bA.SA%:...5.A}.a...-w..>&....9.s.......0O4.N.Oz0..z.....6..j._[E..e=.L.....qW4xe8.z...Y.@..`u*...2.H..QpR.#{...}%.#...]...\....nxMKS..v.kt%X3.(..Ry.-(".Q.p0..r.........@R{*-?..;.B...S...K..t.GIy...s....&.(.e....g(Pe8.?.K..0..6...T.;8.......p%.....c ..>fN.........."...<.N..o...d0*m.9.}......c...,<,....sv....n...O?.y.c.8....C}.G....@..u..i+.8.z.......*..TmC.O.x.jq.=.[.L..G........YV..:6...~....g..:MH.jf...JBO.0.e.V-..?....\zM...A...}a..........dc. ...In.!^.....z.K.+t.,C.t......R..H.`.?#......M".v3..........Nk..}b.xC...1 m...A1.0.Y%3rd.^..gz4X...9P..1..Q.+.........y?....V..KV'.....W\.[.a/.7....Sg.B=.K.X..#5.[..;...*.....8....&....G..h.P..g.b.-...S.[.%..................>.:.9Q...9...j..R.R.._/.!..(_;..H.V....h....-6..y..:,'..@..........E.&P.....z....2...Bx._.X:.....<.p@yvu1..b.........!.....#.Y..^mE...l....`.w...15..:JvH....dX.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33821
                  Entropy (8bit):7.99368370703919
                  Encrypted:true
                  SSDEEP:768:0BZ3/s/DNv9nU8BWB25spRTXoYA2Svf05zauJLdjlUMM82u3927NWKI:65Ov9NWBEsnTX62of0VLdjubBuE5W3
                  MD5:C8CA1E46FD0E7BFE2A3B9135854CB9EF
                  SHA1:EB001406D93711B8F46FB67494E8D526FAEBA9F4
                  SHA-256:A51554BB3053450D7D5351661DB40EAA848BF68627AADBD2A7710C4EBF6C673D
                  SHA-512:450A2E1B2E7704C4368D1D2399761ED67ADD20579F3C1A5BCFEA32FB5972B3577F98E1CCC447AE084F4CC9418B4B99F228A4A5A13FCE49A9D061A48290C8C613
                  Malicious:true
                  Preview:a..G*.0..........S.....=....=...q<......N.X$IU....<..".IQQ..@...O#i...}...+.v..D.f.7....{u4.d...".....Al...T.*.......~~.....z.yPK..}..i{...?".S.l../..\....v....Z^........@..brU..?..d... .....i82.j....<.ix.Q ZME.......4.....y%....cO..}.....c.C.....f......]i.F..C....m...LK...&..~TN...dJ....?.)......b2.=...XYc.z. ..S.{..Lv...f'...)b....8....}V%....6..!.L......r.=P.s..a..k.(...2...9g....... .$#A..b..nq.d.>8{+g%".C....M...px....{#'..`...n.#S.g...eR.....4;O..3..r.=..BUL.F.dW.0........l..)....De:.."..T.Z.)..8".f.,..h.].R!..E... ..P.|8...U..'.D..-...k.S.-...Z_...-...:.::.6..!......&.?..m...(.....[#Wy.q"...\V.....X..H.m...k.~..m....W..._R...4h....A-yh}@.|.....z.n..^.....]#^!..\......6.B..*.B..E...67......\.......E..2...H...}`.(L...n..fV^v.Pf......f...K.$..6........xQ}...,+TN.`..Q.2..R..]]...~.Eu..c.s$m._..GCq...84{Gu.]ZR..%.I...6?..D.qu..u..j].,....T5....#`.MH5.6.i;<..t..M./..D.r..9<h.A.9S...ag;.I.a.....5....\....H..'...O=_Ez..S.L1.?..z..0...C
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32658
                  Entropy (8bit):7.994116815589175
                  Encrypted:true
                  SSDEEP:768:FEgcEABczFP8644QELpSkgy/omf2SvE26qLcHJIeXGa:FEgcJGzFP14g8U1f2SM3qcLXGa
                  MD5:E607F41DD5CEB0FAECD2558A36C2CDCE
                  SHA1:F8177C3711AB21F1D175286D6101C6CBF2ECFEDC
                  SHA-256:50CD07CFD5BAD41A8FA4A26A835B61AB271725B12D377A8802EEC8A12C25AB16
                  SHA-512:CDB4CBEE953EEC09B919F6EE136840F0BB4DDDC07E4048608C558F8361ABBD634AAAA2F79237290407593169DFD4C73C22449F3552198AD023AF9D660450299E
                  Malicious:true
                  Preview:y......}E...?8Dz...-M.\.Em...A.X..1.|..dD.E.*.d..........c...u<..OX\.....~.....$....G.:....8c..09O....y8.Yz#8W..M..^.vkL.z q.!.....[.!..q......";/2._..T...Qqf../.......vI."X.;...x..rtU.6.h$.....;.......-..T`u......5.3.2...\.k......9.q..*7S...z...a..-....{...A.:.Q..Z...2v.I.%.V.!...7+..oQ.f`.n.._2.gv.y|#........\..p1.E...P._vcC...5T.Z...de{....;../..C...m&..z#X..9k#..N....\..s.~.G`.l<W...GJ.p....p...G...M_.....E.So....Tl...........zp!..O'F...F0.-D.U.sQN.....ID.r2S..[....l.u..n.=v.<.(]Bu,+."..f...9......l...7...C..aV.g....G.S........p+l ..!uIsv.b.8%mr.....|..(.lq*.V].z.v.Y.D.]my,...p_N.4... ?;u...^A.........w......4R..f.[n...:.c.......@.&.{.*..Z'.zz}..@W.-...I~...G.:....i.`W..Q.....C.........`....|u..5.g...*.x.g. K.r..JC..G.@..U.j.W....I.<.L...*.|..^.. ....3.9H..&..|7.}......U#I..0.(.5Z..:<:......w.. @.....'^......".....*.Jj..o|u2..&..zi-`t.O.Dqq..U..UM\T.....j_o.z.t...b<.N....Q.q...........;og7.....fQ....N...I.QV...g.p.8.b...b...,{..6>.H<.]A.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35415
                  Entropy (8bit):7.995056779767886
                  Encrypted:true
                  SSDEEP:768:9JYcZuDJ8EMT/2uJT5CuYGZlxMv0iNn2Oj1GEMhLTGNtM:818EML2uqu6v0PO0hhfGs
                  MD5:523D3BFA7EDF0126A13B9181C1F925E6
                  SHA1:02B5652090AD80DEE3DE2CA4C093FBAB0F133256
                  SHA-256:36238028378CC883BE7EBF7CE9382A91F8A94B2EC2B43F54E265F5098F4FB4DE
                  SHA-512:7912829F0C7ED774B9A25D52123220CC53F302859228E24D43F50554AB98BC81CDA3611F62B0ABBDC4389315303C73C91FECEA7EAD1D47DA51BCBF40562873F1
                  Malicious:true
                  Preview:...MxA]....A....B.K./2.3H.r.@...KZ........9_^BY.(.!.C....E..x..6...<.^.../.....+O.%....x1."....XB.K.pj.O.28.|.y`{..Kk..G...=.k.l=$.=!1e7.......V...2...e....m....!g..4.{..oo.X..'.g.E.nH.AR.......cFS...*..M...VU.W..!..Z....x.5..]X.....J._#..h.).p@.9.E....VR....:..+...VE.Z3H...b!...y*..8I._\..8....:...q.k...>.A.&..>..=%.... yA...x...8td...XH...(.* ..A.oQ5gg..`v.S..k..v8j.8x... m*.1.o..W.:..V..[K.w..+(..{O..hUI{..%..L..O.6..Bk.>.b..C.,B.D.u....2n"..%.$YW.*p.....Cs..Xk1......Z.M.......|o.&..-i.;.B"AGKpfE...7PySy.q}..#|..:].]@Q%.;..&[e..8........9(...M..t.3....R..t..0kZ!..<.=..u.^......r_7.=q.J.&.U....E./~!...1.b..1{2...D.7.?....q.$..M.fwu.J..uHc.3..il.....G..Y....W<........1m.<..u..".-k>.I...-...^E;.&....tN..b.m..7..:N.r....g..78..........N4E...=.P........V.:fW...h..m.gw..g.!...0.v...y....[{..>l>w.UB.!^^q.C.2;...p........Id.I.*.e..h.;...O6z..G@..<#.+..W..~d.....b=.4.[........^KEvd.<.......6-u....InS.A.(...B,E..5..!Z..vK...V.V.....O .V3:6..L.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1364
                  Entropy (8bit):7.831013823780384
                  Encrypted:false
                  SSDEEP:24:K9FSEbB87DIErqaoM4WD1AYl+qoaOB9kuMjY6BicB7utUpZvjnIyo:aFcHtqlBWDeqoVIYdg7usZvb
                  MD5:F78450CF9051D850F9B3E437FF0D9FAA
                  SHA1:35169167972567C0F9E2583C832D8464876E749E
                  SHA-256:098A6B7285AD75D1E74683CF0BB26078CDC65318673C5CE0D93CF9A2AD0CEED5
                  SHA-512:71182E87968CB4432228AF671A23EB83828DB49166F74843B22FFE2E009ACAB1423D2E607EB1C8C29CA8610FE1D85D753C4F273D824326F95C6FF92BB826A521
                  Malicious:false
                  Preview:.K.r...b........3.e.b..K..[9...3.:|..L7,. .+|4-i..Z.j..'eC..X...>.d..&..9.A.L....W.M?........yF....j0..a.p....6C...d.p...~...7.U...u.G......W...Q.q....[....*&X.....dw4{...H......~/I.$gO......<g.........8"...z.F.....&1R....n....{b..S..i.b.|.@.h..$F...v...T.K`..rL.h..8..(,2i71HP...zW)+....k.V..OB.....1... .x._..-A[m.. ..[...L....B$JK`{._...:N/........y.'.S.....Tx...aRxZ..J....]).WnsGRRQ.:f.X..qC...E..["...4.).X....C...........i.w...........I.......3...M....0X..9.A.....:n`p.=./>^(.{Q...t..g,.[..m.rAj....}1r.g3..K..}t........#5...............8^h..$....."I.|...[..%.Q....IEX".c....;.GO..`d.=..4.....f..yB.W9j~..........855M../....g.j..wm..}......$..A......'R..s.z.l...g}........7Q.|.m3.t&...a....j....E....*.....L..5".~..0..P..Q.f.....0.......h...v..&.a,...U..|...LU.]....o=.S.1...7M7..?PD.....)..v.P\$...M..zu.T)k+4V.w.y^h....9q.|V..L..(./CP..{.+YX ...3...Kp..u......'y....M....O... [S....y.d.ij.....U......E.P.{t..m)\.hc..S...y...2....}
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):53367
                  Entropy (8bit):7.996023749669309
                  Encrypted:true
                  SSDEEP:768:1fjUONTX5p1c0Uq9mtlwu9zTNmyexXHjnUFhaZvMFic4G5NGGXuSninoHSH:5TXaW9mlwAzQtTn5RMFvWSniX
                  MD5:CF78B6436C80241A23CCBEAA0231AF59
                  SHA1:B72498BB4437F241DB5775FCD3C61CD3527A368D
                  SHA-256:3AAA16F8E43F24C4F0BFB90B72E6ED0178DCF98A75C2C0893E96E4B794D195B2
                  SHA-512:6E0BA26EEC88DF27AC0CAED4C9E0CD512BBA5F07F4AACDCACEA95B26EFE2F6A668FBB6AEF665D7D789DF3AAD00DF1CE866CFC6E5263617F6411697D1D7EC7D08
                  Malicious:true
                  Preview:......{.JZBRi@.U..../..Y.0.`...=....H...U..v.\m..U.o....)!F..P0..oW..^...eN...O.Pu.S!..W...HU..?..C...m..U...#.....g......+.....l9..;......V........0>.U......GP..U.p.[.6.=.y-.8_..,.......]..r.!.p.Q.h8.....j5.&..$..,.....{..Q+A.l.=I.;.a.X>.&..R|v.up.R.as......zF:..q...qk};Y..z..H...x....w..+..j....=?.C..Z.....lv........dG....b.VI%.......P.z.......x&..n..........o..RR..p.`.k..@...s.....B.K.....M..& 0....>.'.2.3..&.BG.?....$Hd..2...........}s.w...5....._m.........6..).....I..!....~/..b..q.i..~].]......yu..f.A...H=.X.Q.:...B..}..0..8..%?y......;...qn.....+....L..._..@.s..Y......n.|....vmC..g...M..W...e.;.w}../...#..Y~.Op.`.1e..M.xn.(.......^K...I.E..g..nt.x.q...#..x5UZ.H.^.>.]`...g[a..c..Qq..-...?t^.....Iz./.....IO.I.I.q.8.!.w..R..x..:...Y...Ot....oh.kt........[#u.A1R.(..z]......py....<I.Xo:I....X.u.1..<.d.].....]ZJ..d....=7..P...@.GZ)........>....y../&..Z....k...v..f......dc.[!....9.?m.~...0Z7..m..cNtT:T....F...l.g6.u....Ye......F..}
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30842
                  Entropy (8bit):7.993511273493775
                  Encrypted:true
                  SSDEEP:768:zKc3UDpXyrISb2LxhYfBWxWRAek6/zUWQOnMEB+ej:mrjSb2Lxssek1W7Uej
                  MD5:DFDBF1D0AEBD6F49D608DF47FAA29A0C
                  SHA1:8371BC214D55DB652FA99D315F7CE888B4071456
                  SHA-256:C7CC955099D1EEC8F394A8ED877BC275ECE9658804400AB2D56CCB1D5F01C595
                  SHA-512:E6D2220C2DEE99E069F42FE07216D321AC417880DA6E55A27EF77D6B2E3B0759D5B962D595B1CE19F03796FA8AAFA5F7FB3E219DF7C9BE7956C03DBAF09A805E
                  Malicious:true
                  Preview:lB]^D!...5...F+.W...|..h+|<.........V.9i..Ps...x....0..^N...>.#...IP...^`..E..S.p...D......a...R.kI;(..J..XJ.C.%.b...d...>\"t.X5i........5...Hr..(.Ko.^;.....b.Cj.A>}..l...W......3....<.xT...}_...j.B.....3....).)]...w.K{...e.e...9Q=.._.......@.;A....s..~@y..K.k+.I....(}.<!W.P...."...z.r'2#.Kc<...@.^\..~wI..e..........C..n)..V.....^.;.E.a...J...#{{..........5.1=...Sy].B..2%O.B.$c...\".`V.E.....:aj..9P..."SO..\....#.E.V.1.5...a%..wdT.....S-..._..-.C..,tn......P.. cB..}.....}.-["c.....Y...[..e:7v.$@...!.E...<..w...... ...r0OW..@...].8...H.s.!._b~....K#uu.!E.kU....&f........-x.8.`..(R.g~'......N.*.<.%2{/.}..6.G....j..D..2'9a..=]...)ZRV}.r..:SI.6..]. .8....+4.~..l.e...d4...z.I..6....#....2f!.z.......MoB..Bd.D.....*"3.......O.k|.Y.e.~..|T.oH6&..p.^;. ....]<.W..+.....,j...%....7n..|..u.`&....h.T.....".R.C..........x.Z.O...:...G.V.O....,l..v]Qy..st..6,4.._..A.lG.gB}....$V..49t..a...$Ly..[.......f....V_.!.^.....lT.<.>.G..d..J.2U.u....8.7R......T
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30762
                  Entropy (8bit):7.993143697739105
                  Encrypted:true
                  SSDEEP:768:Xpo6lGe8fSKKK2M+PQ+Pk159MV2CLq98830g:Zo6lG7JExPkq26q97kg
                  MD5:B9432F9238EA02CC9241A425D3C06DB3
                  SHA1:60187836BD7906923D9B4C58CB37503F79DC8917
                  SHA-256:EAEA7D7FCB3A9CAC2A3B38025144BAC5A006F305EBF8929D6AF6416FF05388A9
                  SHA-512:82038694B0941669F1382DB120D0E3EB446611514560064F19C53376745875021522895E518009D017F8933713DE8DEF6797DB185E338EF9AD5685C2D74FB0D6
                  Malicious:true
                  Preview:.tx...3.H4*.. ...*....gf..^..wM4T/.ba..n.8.[..w>.R.W..E......j.?..KA..L..}hJ`Qf..H...|0..!.1...h....=:......8.Hk............]g..-....H..j.I<.}...N......*,+....1.Z.gy].I..1......~C.Uj.0..7`..../...xw.....0....LS%.PS./.a......3V.~../9...vY=0s.._...JE....n.$...Kq....K...P.:..d.....(.l....h.....b.......q..ru.. ..=....._.6..`b.........t....D..j~.H...t.9.#.D..*F.hf..!..w....s..ZK..*..4.$....`..jb....Xz.H..".zi.4.:C.8.z<....v..N7.].n.{.....P....8...Z}S.....c..L......a.*.k..^.^St.Y.P..n../..`.H.....Q.[..b..V..l..QE9..NO3...2zn.j....H....8..D.. aw..N...;..$...dJ.Qs"..n."....HCv...........~Ab.]..kx...[z....h.o..Fi.q....v-.SS..5l.c._..;.!3c:H......mhY...H${.'P....f...d.4.Yz...f..1.....'3-_^%PZ...E..B..4.....pM.X.gf..T..>.u...._T....>d.J.^.....nt..B_-;\....O...mM...=9....o.......DA.`*..{.F^p..Y...V..C..._G-..+?.....OU. P....=.-Q.V....X].l.0..M0...w....L.....MRr...V....I.(.|.q..I..U.&8;.n..l.%.DZ.q..m4j.U...&.T.........=....l..$Q..y.Qz".
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):823830
                  Entropy (8bit):7.999790775929622
                  Encrypted:true
                  SSDEEP:24576:pbL+gWcxHZJXfVeeFZoM4lnJsWEf7/aIdbEUz8U2eF:F+srXdeezon/lUI3eF
                  MD5:B543301E404A4B5044A36CACD259C4C8
                  SHA1:6017B3DFF28EAFB5CEBBD4454ED286567C9F99EF
                  SHA-256:EDEEA069515FD972CBE819282EBE80E181A2A43F9AC3438E044D79D7F9EC4BAC
                  SHA-512:0DBFBEA8AF4AEC7CA3ECF771FCF9227F9BA84C8BF6711AA60746335BE61FC1031B24D499702ACD568A3E53FF1094810AD4FDE76FFF27FC582185A961F29D4D75
                  Malicious:true
                  Preview:u.].|J.,Q4.0..(xhMl(...@....P)&.By@...O...!3.Mu....,&.B(...>..MG..8NV.h.....(.j}.O.{.G.RL...o.'.v.$.8_..d...p...8..e.R.K....mL.....8s.Z....y.....(.a..pcx.m%VklE.rs~...{...(.o..U.j..;...gf.......qc^M_.A.........*...... .,.A@.0.t.1[m.a%.di.i.Z. ......?".i.}..w....~.v..JDYL..{..{o7.q:.`W..$..,^.5..`.x<.&f..ix.i...R............x.)nl\.+x..wJ,.o....%......k.'.......A3.":.$...s.~e.,.......^...$.a..T....V........)...T.....`.~/.oN......^.....8.s.!...z-&|&.#I.........?.^u..O.S....U..{JB.....O]...................1..k..z?.. `=,D.0.Y.:..[......;.z~..t.D.3._..B...o../...w\.h;......bxz..\...c.p.8.d....n.|..Wn.I...Y.`K..p L..$....+za..].-...,.O7.lH......Kg.y..s..F.N.f.M..V.S.>..A.......QN.......$...&Y.......\..&t.m...q._..Tl..Y..t..".c...O..b.._`--.k..k^.?<W.y.+.F:..a.l.{(\.P,t....r.xu..0(#.?.....Tg.G0.|.w....,...=X...DV.'...D...IHU..6....h`)F`.G....SUA(. ..x..M..^*..u..4q...z..hC.C.7...y..t...2.a......R.,@...gX......v...r.;H]C..-u`..4k...M..bs...@%..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:PGP Secret Sub-key -
                  Category:dropped
                  Size (bytes):65274
                  Entropy (8bit):7.997430412130514
                  Encrypted:true
                  SSDEEP:1536:UJ7BIATG/CrKM1iqpKbzIRnm9UQc0SEFw4+OrvWt/7HD:UbHTSCrKM1p4bERFd0LV+Oyt/7j
                  MD5:AB6B5B1B4071B1FEB655D453748C89D8
                  SHA1:8B77E258F741A0B05CD3BBDC1182F5744AFB2AA9
                  SHA-256:16D909AA576E1D986A01316DA0B4DA9FC4CF1B7CC888D821E44131A0373A7335
                  SHA-512:F4F570262CC491D706F2ECD9BD035B756F175759C1B3192D16DCD0DBE08E81E0034ADF3E97BD9FF9D72B651C28BCC9E3358315A8D29B41D341403B0A9657CBE0
                  Malicious:true
                  Preview:.v.<4.G.o@'9[....E....[f...R.C.mQ.tIs.....\...@.._.({..4..~.0D.. )...To......?T...g.W.R...6'd!...>."6.)W>....mS.3,>{..|..FL.{...........2.x.......=.<.....L<.....0]r..#l.c.~.J;..!.3`.K.`....9....|1.i....e..$.....1H..T...Lh...'W.N...E.M.m.4b?T....Kh%'.H...y.p)..=.3zuy.z..f.KQ.............+y....(#...;.e......=.i--.g..ERC..-sr."..U..:.s..Z.G.F......d......<.a.Zg..a... .?....XW%...3..rS...C...w(..hr...U...>.....*.a..K.........x3ym.y[..T.....>..!."e.-.%...lv../....Z.F-{g.......2.W~......~..$..`[.w>...A..@.a.F...h.#..(ry.5CD.96.}=.q.b...8+A.5......|.N>.#.oX9.xX.L.)eT.(.3...k.|W..8.6r...By,.z..I.........j.r.......uJ..P.?jrFc.g..:....L..$2..-..6..v......?%.B.W....b)...!.t....h..p.E....9..F..-..S.A.W...K....R36.&ekT.....1" .cZM!...>.^r..j.;.A....J....z(...u..&4..b} 3...=...k..~.C7..."...E..s.#l.Z.v.Jy[.~...i..d...x<....70N.....6...........e..{yVp.$j.\.GRD) ....w.pO9.=..C.....u.m..f.#......G.Ju..O7.)..6../...}..Gb....9=_..z....n.....)a....~.Ib.2.gU.4...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):962
                  Entropy (8bit):7.72968461820919
                  Encrypted:false
                  SSDEEP:24:mHcaMybPc0SADqXRUBXdhBpUGX6x5MNT+J/3HkHr:tybPFF2X+ZBpUGXu5MNv
                  MD5:5A9B6F3958F31D8570C2149C59DE8994
                  SHA1:69A7BEE5FCBCF74F1A76A2DF9D05F53E04B1AB69
                  SHA-256:6B0CE5CF1E6D31C983BACBECD9FD152E4AE68A90DE74E5A19DEF0B32A3168BAF
                  SHA-512:5E7D8CD3051D259A1586E9FE48ABD19579030D1AF94A2EB98F3D49E567CB2F93D188807087252EC06AD87E2F2B850EB0B002A0580296C9A455935C68ECBF3BEC
                  Malicious:false
                  Preview:..W....d...=1/.b....V.....=/....7..:N..v.Vf..L.*....,...q...>...Td.o...-.t.SF.....Xk...2.h....W..9.n......3..+u..Fj.CYUI..2?.3_.........g..*.Sn...2.Fq.s.wnS.[.H&.....6...4.Rl.S.hQ..k.,.b!....{1...=...p.<.2...Fj#..."...*d9tM[..ms...!..n.W.M..;y..z...'.>.fr@..B.Z,..5..Zq.!9.=..4..|...p.s..5...VKi6Y...T.....C....5...V...zr'."...j.\.2@.r..|,*A....V..$ ........w."g.x.v..Y1@.v..d#.../d.]W.)U.H,.r...?..S=T.o..r.=b5.P...Qp.z...O...i...1...........e..Q..8.E.......OI....t!.=7....x...Z.......|?z.E...c?.|.Y..7.V..Z.<.$..C|.>MJ./..#.2.Y.....@_[..].._.Ef.0Q..v.........u...F..q.7.......o.XuY...gg.n...T..Y7.... fi91.q...Jt.?.....oF.~a.QW.........M@U.8.C|x......<...K.........kd...2-6.........U.........h......Gh...".Ug-..AD..s4...._....5...-..{l.........Q..N...t....|%......4.b..7)....Ds.....=B..~.p(\.s&......q..A..H......g..........uk#".......67JX.......?{e.7....q..P... .>...@....\.M..6.?.y.Tj.........."...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):13077
                  Entropy (8bit):7.984224083593798
                  Encrypted:false
                  SSDEEP:192:tT6Be7xsX88fkTfEQU22TVTgIxJrx/HajfWgM0QKjhHRczjg1ZkP5VRipEufLT7:HytEU5jxtxfAWgAmhxlZkmEGT
                  MD5:1C53995AE42F6A5F64090E8328635F23
                  SHA1:8E20B3D82E0921E52165B53FAE207DD549A9685E
                  SHA-256:C21F80150DD441640D308CF215EC80D557107E47628B5302ECF20DCCDFCD5147
                  SHA-512:11575CC0D5B08C0D02FDD683422FD077D702BEB4F8908B83B2BC38BB9F75444C66115A5A842E29BF6776C8D2F9E9B27C0F4E2DD4CC36692CF049EF978A53D6D3
                  Malicious:false
                  Preview:...6cj....r...M.9\..b...E[....2.^.......!.A..:XJTk,.Q+!.\.P..L...V@w"....3..(.J.......!9.d....+.[..Z../.z..S\.n.iJiy.,..;..Y1..}...wG.^..m....\.P`.<.%rE.....b..>.B..y.o....).....3:.........Z.k*;(...f....Z.".;....`.......I.h..iN..Q..1"Y+.........'....'..I.$u.h.VT..,..[...8..*...!;i._..4...s...8..T...Rv...J.. ..T....A,.m..*&..w.d$.c.?Z...W......]...n.!a.M}...T...P(.Q...9g+_..r..R.../.,.w..tM....R.....\.Dp.pO.n.p....B.#..(...Y..\.t..w.I...umf..y$iG;.?q`.F..._.I.U...t....'or.....<...l".\...9j\..i..}f?...n%.......&=Nk.....r.qF....|..c.M....N..:..AN[..d.....L.Nc..).".G..`z3..*..j@~._.7..z.v...e.oc...*.]...k.\.....b.0.2...O.Q....._;.$.TS...g.a..RAr}..g.J}....u&c|}...!7..e.+l.i........K......\...U..D.;.w.....f......dI.o.b.H..A.'iC..Tj.m..7...)..p=..6 .Z.. .6m<..I.Y-..\..U.8.h.+q.5[i*.B..z(..1..........y}..,O.Y.....S.U...A....~......i.Od.L>=i..kfS....S....<E4...j..Q.....[..1.s..aKV..h..b..W~2..>...N.....L.....Zf.x.j:.O.2...r.[r....Qb...N.0.f..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1476
                  Entropy (8bit):7.855409896394512
                  Encrypted:false
                  SSDEEP:24:Ub17FodDTFwrr+V0RCfZRxukiLYRHjcmrFt1jWqCiYVn9heRN1r0G1XEb9:Wsgr+V0Ro4kiMlgI71Qn9he31AG10b9
                  MD5:B7BF5348F8AFD90F75BE23EBF255F742
                  SHA1:1EF5D72F5EAA668EF4BB54F523FB8334148CE2BB
                  SHA-256:FF72B830433110E2CC53E93DD0494A5BCBAEBADBE9B8C19A83C3702FD1EE712A
                  SHA-512:BFA2AA1ED47E0DC5CB4843B9A557C7B8542B348EB6E642DEC095F83E6432C36E8F5B548689F751123B43D087A87D50E4FC3F026A58767B2A5477273C14B0979A
                  Malicious:false
                  Preview:x.C.....T.Ww*..}....R.\Z.E.2.......5!....v......s..u...=.cie-_...h.s..)(.....#E:.....;Z.......).1#T`..w....d...{,..\.....\.....I).....*..a d.@..--}K.....Q.....A...C...?T...`...t.iT..x......@....P....R ..uC;0j7+1.....}w......0.4U.au.E..E.y......s{..3.....%.............g.b...,....Gj...G.R'...|...G,=b..|........d....Y|!...QB.?....0...sAs.r.....:.Jo..&.].....#...x.z..9@..f.dS..e=..h......]..U.V.f.0"(.T..c.N....=..i.9.4...<....>.d...{..x.-...E.0s.....oe..)Cf..l...^po0..BN.'....^..%3[.mq.. .-j9.Y.hr.2..........J..^.) 2d.vx.k.L.U..Kl^..e.vgsz..SM..-...+....mX.N.~@.>.f.....k.a.../.m.|.R.t=..7.).JJ.zh...6O..z..<%.....6...W.A.uV.cr....FL3......@..2......v....;U..1...J:^=D...4.".V...SQ.^0b.].[Y..._.Nb.....\.1....8.~7N.l?.(U^..M.e(...i=!...x.Q..Z9pC.l.l..d.f....,W..<.....;...S..i.J..S.7...QR....dWL..&v.\JR...ZgDA<..R......L../F@L...]....@P.....&n..d....`..."..3.0.....L6....!#.`X/.'...U.qR.:.K..o......LQp70.....M.E=...q..w....I... .6d.:U.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2457
                  Entropy (8bit):7.918880875534245
                  Encrypted:false
                  SSDEEP:48:kwX9WlBB/qXDFIfFc3gF17bM1k+STOg18zL2Ka0i+2JxCHSbjcP:dG/qXDac3grbM1k+SDC2B0i7xCHSbI
                  MD5:80450C0C98ABC0530493B7BFFBDF05F8
                  SHA1:122BEFD5C6FC3E868FEB7E435C05E22316AAFBFF
                  SHA-256:66F85DC6C02D227D912932F852B83B67232EED834E362EB9561493E74B52BC59
                  SHA-512:A81CF5877A2AFB994E86A34261E550189DD33AE4DFBF7BB9DE2D7273E2F777ED038F586FEBC3094E620C0339C84C2E5DD7AB0CC66F804996BBB7F75EDCD43EA5
                  Malicious:false
                  Preview:..u...n..s...Y.a....G..XF.M.{.A....*...(.#.Q:..<7...aP....I.m....E....C..M.iy.c.x.....y..|.^~....%._Sn.....~..H.-+....e-..*^...+.......L2..&j...E.6x..r$.._p.m.W...n.1.?..A@C..NMk...8..,.tB.......!pT.b.o..~.+....F.'_.QV..)s.-...]%|P.. u..=......*...qZ.$....)..6.D....h.w....!s....e..8L.[.N..0..y.S..P3.@(.#.........P....~...c......cn....EUZ..O.t.(..im}./d..U..\..Sb...O.^.g.f."..oz.....|X..\m..@.\h......Q..cT.7...k.(..G...`.'2..hW0....=.,3i.{y.......|nc7,.1......X.....'....DBu3.:....I..m.z......#.!w..c.y.yXY.w.R..7@.a}...#.VG..q..>.......{.#...O..u.B..,.c.e.'oh}.'.*O.]..og.)..F.a. ..1..Vp.j..m...E....*...d'....B.....G......3."Z.......;.YgC......cs*P....R.w.....Q....B.l.).....#..[.<../z'...5...0\..\.Q&"n..'j!.#...)1A.ajMnN..a..3.tD%..g.4-R.4.[............6..'../I.J.4....i...Z...>e~.Q5O......N.....dm.UV.V.&..q.D.(@....c]...H!=}..%.......H..a.....d\L; e......co....~5.}h..zD...b..|J..b....z.z....D"[f&..N....w.0[ML....h /..,.-^..!.eA\>.,.z7.......r....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2489
                  Entropy (8bit):7.90917975459852
                  Encrypted:false
                  SSDEEP:48:QyCZ/Fks9c9Wwr/FPSo/Hm7dJgt+L/sLXZKNxOhp2ipsep6c:QDZ9v9c9WQ/5SKHiJg4EYxOhsKxs
                  MD5:C45E94B0D01FED6E1FEC569A6BD7BBDA
                  SHA1:07C1F41F33F4EE9D5600FB3B47BF50EA71C03DB7
                  SHA-256:84591DD178874E6EAAE63E7B06FC59192F2AE0EF6EF31E70DF2FF61937888CA1
                  SHA-512:094575B379D1BD9E7D4BDF7F38A11FE3AB9EF7220CF096F20AB48708B0835983B283D6702A1CBCA75B904555CFFD6A9A180F39FA55F9EA10981A3138E332ED02
                  Malicious:false
                  Preview:..k..8......n}..%...Cj.N.."..qZp.....gO..&...$.<.w.H...L.8.4o...Z....o^......7`c.....I....}....G&....U.MR...L.g..) ..!z]....|.T.,..q!......0.....F;.8-`..<.Ef........PS..w.#!...Q.....z..Z.p.R..8............-..5m.Q........).9.#+].J..'...e]#.7Z.K>....Z,z.u...0..KL...)p...]...D..:~.....-<..D.Q.Z4t&4.sM...v.u....Se...3..8h...U2Ap.?.tg.S...Y.q.....; MaF.I..."....&.....$./.c..m.7.{u....U..08.we.c2.[.'...7..5`.gn..h*..pW..g.S..{..._j...E.G..Vk^6(..e....."..|.4.d.H`IC..?j..Jo+N.....xBv..(.z..w.....T.f.5..G.J..A.b.H.\B.o....FE...Yz.q..Q......K.....!..a\...?..0.%`.Us......}53).].~W..p+..nt..7.pR.!.........!O|...,...e...}b&.]....1Z.A-J..FY..Lfha..7..8.@.8...e3.r..~.T....q..i3..mj.(...l.xG.....V...>=k.aX..MZ.Z?.^.JU....Vv..;.A..X.o...|.G....a.. ..I......lM.Z..h...y.+...K.<>...l.xN*..9*...=..uQ(:......W.x....@.@.H.eKi..........P..:k.r.kXt}.t[{.....%.p.j...F......Iu....\.Dz+)..x...i.....m...'.89.G.1...Y.b.(D.p.t.o..L...s.amF....5.........z..(U.Ck..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2404
                  Entropy (8bit):7.915944711258965
                  Encrypted:false
                  SSDEEP:48:uysQ7QZC15nz3UeUvuPo0kQF2tX6pAlmpmIiygtZ74f0:uFzC15nz3j1kQF2tqqopmdhDcM
                  MD5:8E2AC6401CD4939EA6D9C590B8B05003
                  SHA1:A7D5FCC97A0B615B3DE718C04C64CF72E5125EF3
                  SHA-256:C40114F71BBE003A38C14FB96F5B389262C6575FA4F42197098B1B1FF3A7C33C
                  SHA-512:3CBC363E177B2F54A51119CA74E21DF7A1EC9A2680603B952E3D85ADD55959DFE6F510114375C28D189C26F99FA087428BD2B0A4B7D0642480178417BC132D8B
                  Malicious:false
                  Preview:w...M..I......0..?Z?U...d.62r#..I..u.[-..=l.9.*.7...T..o......rV..d.}.m.......g.r....+.{q.QA.wh.U."A}n.Z.B.....KoCe..`...z._..!...d.U^.e...c....C.W....o..%x..c.c...dW.....y..B0.....[..1Y.._....;..._....Gy.......Y..OEM&....t.n..e....\......{.....?.U[qp`Y.i...<j@..b.~[.H.....;..\...VC..V.%.I.T..>.J ......*....G.D..H'@i.0...X1].Kf. ....u..B.e..bd0.d..@.g.b.._.-...j-..p.p....tX.KD..S..h.=N{.5q\.b.72../.P{.fH.P.^/.$.iF)...QM.'..s...}.(..K....E.]P....@.?mS.CF.l.....C.$......s5T....^x...B..G...$.:Ru.8K.g...H....l..TBv........N.....B&...{.T.~...#..9i..w.A..J......sU.7....p....G..*.M.0gf...U.F.L.....#.pb...B.x..1#!.G....;...H{.."4?....p..H.&X..Q....4......:*..S.ap......../&..UE....L.f.~:..Um.&.{.~J....m.O....U[....Q.&.s.....G.w#.@.5.G ..~......<..6....&jXl.6....m..\.....p:E7.E1.A..(..Ep.J.W^..c..O..^.v@[......s...5.N...;.2..q..:8B.R(u.a.!....Sd..P...._.Hau.L\...`y._.uQ...p..r.....0.....4.2...G......<..V:...>`.s<E.B.../<.*.yJ8..c.{.....j...lA..q.7.+...Q..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2509
                  Entropy (8bit):7.904877868174458
                  Encrypted:false
                  SSDEEP:48:n1LQD5H/cTWxyGt7eRCWV1xMByIKA0jB2JlT45MDVL0lqxMvMik:n1L+5HUixyE7eRR1xMUIKvjB2JlT3VLS
                  MD5:24294871A0265132DE1BB0F8274B0B4B
                  SHA1:F061F1CC23F38E99B54194D5E5ABC5AB917AAFCC
                  SHA-256:873458820010577C09C484EFF6EC3FDDCA440FD033ECE7238D7D1E6E785F03F1
                  SHA-512:1BA8B21AD50719DAD92559EB3D7A8A72E22F61B4CFAFB4DF959543857926201E95A8198275B49885EDE1573CB23FC3BE9DA3E6C87EC29B1B314B4DE96BC07A3D
                  Malicious:false
                  Preview:w.....=.~AO........y....di..Z...c9.kTL$...wsNM.N. mR.y....VGm"..&.....4.c_..."..U`u<....-CU....y1p.T\/cPB...EN.*.^..'....C..(x7.O.%....Wgo`.4s...-.....S..S.y..E....1&#.E....&......p_..j./.%j.Y.....p.k..H.=3.].....DIwFt.j.P.>.R..-n\,........P..<..5.6....>(.B..4..1.....@H.d.9..2kox...M...<..I6.......L+...X1O.$..?..F.X.]..o........G.m.....u.(.n/...}.9....v..-..*...v...;..!.......Y...F/.......^.....s.uS........#.h.....=BU...s..7#6,B.]....K...i....`T... ..ja...,....s....+BY....E...U_,w<Fi.+.(p8_.!.....1oB.Qc....y.C.ew...}.!I...w..I..Lm..wXr.?G!\.......^7v.2i7.....^..$.{Q.Y..w..J.3T`.......u..P(.......X.]...=J...wox...<.A.#>...P.9l.........?..`j....r<.M...p..4.......d...a..K.-.p.QFD.".\..lm./....x.q.8..v..Y.|]&........N.JQ...a...h...fA....~...g.c4]...t.&.=...0Y.S9/......]..`rh..Y&~EW<<8.lP+].....8..e......*....A.}.......13...Um.*W.|...=c..|.m.|..0.A(yav\.. ..g.r.d.rk<..7@.U8.......v....*.IC..?...?..X.0..?..FDE......3.....G..iDv.....(..f.."..bn..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2349
                  Entropy (8bit):7.907593255455008
                  Encrypted:false
                  SSDEEP:48:/dJGrd7xz1s6vuz2ZKg5Poc6+XgsdJ4nLyx07dAU5tRWc:/TGR7xxs6vuzc5h6+Qs9nwWc
                  MD5:6E2E214D741CB37FE80DB37F613810C8
                  SHA1:C58DBF3AC6CF9BC559AE15FE91087699F36A37B2
                  SHA-256:5CF756114AB61B6AF0620B3ED82BC03AF1FD4E73AEAD31A87ACA0C3D6DC73D70
                  SHA-512:003D2D62B814BD07DCED81CD8A12C4084FD57DD4F80AE818719B7CE108E28A4D6571F0F0331B7245DD62109B0DBCAB55AD9FB7ED6071C5D389EA6FC4CE9B8F2B
                  Malicious:false
                  Preview:5./....".m.t/._4..D...O...>..".)...q...r....y.`........&(*.m0.+U........B.K..8.p.....{6.....\.;T.F.....A......V.F.].9.}5.-_(>@i>..|...B.YU...BS..$..^......k8Bgh.1y.d&V9.....@....)....................................l....N.I..s[..'.].....E.7......u.f.......h.;.4..p.>s_...2.x..\V.Z..R....,${..Ub.%&....W.XN;..XB..mk.s.#I?...lB..u.UgodZ{.u..\..r(;W......m.o..Fu.f<.<.&. .?E...;..1......9.$S.^.\.....}..^.F..I.S|.;.W..../.CO..~m9@%K$....t...D.T.56..)*?.Af.X..|....y.=.J.(.Q.k..Ih........A@Z.-......t.Nv}..m..GA.x\fz.\tU.R...C.*:.4l1..P.m.X.......{f/.[@.].........Z7..J7.<...QS........?. R.V79(E.k-r............W..^U..1<.@'.T.Yq2;.L.....I...e.......V..?YM.....=...e7.T.. ]...{.l.T.1.8v1.p.= .?..5=.A..Q(Hk6>n_G.h6..%*..}.....-...r.z.,'..Fw.dj.(..b..Q?....|....._T7;.}..BC....0...+..3;$/.)..ab....Y.#u........fM-rl...x...}...K.T...........0.....}q..W...)~........T5_.q..C...N~){......bB.#W8....+.!...'.^.....+.....[M.\.#1...W6.L..U....'.b....Z.......0.X
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1476
                  Entropy (8bit):7.850111079343744
                  Encrypted:false
                  SSDEEP:24:yQsRNTzuigHcVu23Le3jpGUmIcewNM9SRJZtc+uawPKlH2t589F4GFvYCibp2X:yRhwJgLYlctM9STAN89rAZbi
                  MD5:2E980E1863B7CF0CA8BE1DBF2C81A408
                  SHA1:34BFFB462B6A0F8838F644C6BD8A44C59A6D6E63
                  SHA-256:D9C6D09F5D18316A4C865EB4F1ECEB6BAB16C99798CB3705BEB572337020E8B3
                  SHA-512:95C0098430326D813B05D651B7E4E0BF1164BEECD8EE2A7AE1A8D8EAC637DEAAA857610FD76E07E4480B0D18F3FA188629401BEAB275390B6D2CC36FEE3E8B51
                  Malicious:false
                  Preview:.x.\.t~NL....2|.:"..l.P..=C.wK.........v..cV.....t.~......P.m.x.w/....`.{a.L..5.......?.;%...D..n.;..E.....E..i....B]=\.l...N/2..".t.'S{t"2A..gN.R^i.LN...B..e.(...>.<.....?o..Z.oS+s.....mBp....a..D..[....i.2..7.........W.uB...;.....&.[+VH..3+.:....|p.a......M.W.....:.c.c.....1.Z..)...D...-+.y.e...K....:.7.l.u..CZ2.....^.....I7v....tK..I.z..b........m...H.-.rJ.....9..&]..%.......a..#..h.S.l.1D.Y9.91yq.<.f..j,.P~.~..J-.i.!$ke{..[...rc.......c.gr..bq.[1........&G...}.Y..%.k........(...2..x...S7....)\...Pz.....V{..S^_.....#r.*..9...%..ogI....9y...A.'%T.]Gx.....B..........x.mOD....6s.M.V......Z.U&.v.z.)...>..*...."..s,'....o.X..825.......f+9.F..dg.._.0TR..cf9q.&.;.-..]...:......o.@.D....../ ..J.C.I....x...AV.M...?.}....j....i..}(.F....;(..$K.. U,....r...j.....&gY.....p.............O.\j$N*.2.r.%...g.U......OX..K..]1d.......~.u=..CU.p..N(%.....S<....Z...m|'0d........c....:.J.......=E.C.....e.yX..m.....^(:.b..5.c.KI... ..8s....!O7Z....X..v-...kk.A
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2349
                  Entropy (8bit):7.908636982800165
                  Encrypted:false
                  SSDEEP:48:MqFP89sMCsC1U3lLSh+0rg/JalPnGkteRdeuAxEGom0PDCcLCD:MqFP84sC1UhSTg/8lfXkeNToV7e
                  MD5:E50DCEE911E49B786ED231AEC59A1071
                  SHA1:8B5063B89C92DF6C0D1EF097561E34B035232D71
                  SHA-256:0E2BDF893CE3265EA8C1CD81335981EE276C53B28CD9856E1BAA42EF8BAD13E4
                  SHA-512:23417881492DB3D6BD580BCBBF2D3D60950FDFB681CA9D175B7EECAF01874BEE8338FC98097E2F0DD85056FBE143020A3B37191C8D932F83E95DFB235A79274E
                  Malicious:false
                  Preview:NL.u^q....{...R@G..Y.L.t..h...aA....V...A&....P..p.._...e.^......6`4H.d..e[v...d.a....i...q.AZ.Qm].!..+......).J..U...mX..B...y..ctQ.....i...p...x 8y.N....j.G....../.,.h..1\..V..c....F.gR...e....:/......Q..bK..;<f.M..f.U..y.JK..t!.Pg......."5.UN-5T....0.....1...r.E..E....U...3b.1`..@#Sy........\T...z....8....R.....k...^..I.. .i"..^c.rAnX.=_M...zz...............}:.t.}@(..w`;s....Fp....].0.|.z..;A.."..Jv...,%y....../.....bL..5.../<......A.}..H.;...KC.....q.h./yH..K1..y..^.......W...#..S.d..]...1.....^.A.h8C^.#..o....f...".m.,.t..-..q..B.g.%f0YSV\. =...X...)..&Z\3U..K...G..k.x+.g3x....kc........b^..L.R.em.pQ[...8..h.`..mq... v0)KP....9kG}.9.w.a..tn!.kIaQu.0..n.....Zr'...\.2.v.....-.....C..).V.+..P...\l............Z..0a....4V....:..\...w.o...C..t!3<..=.K..q*V.d$.&.O.G3\4....~37.8I..;.q...l......*J-7...L......t.)[.........Q....O.t...B.......6.sc=.R.._...g...............wwg.4.#.......{..c.....~^;...a".d}..,ji.r..B5.p.7j..(.{.kSL...:....B.m<j.'.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2507
                  Entropy (8bit):7.928945585970909
                  Encrypted:false
                  SSDEEP:48:aKaUrVR2fRdHgsostjKFn5KMXCryXo1zynGFzIfzO97N7FPMNmAEcBoea/:aKzT6MstjknUMyGX4ynGUzO97N7FWmAC
                  MD5:B6CFC13EE630883FA06E0940CA0C9EFC
                  SHA1:71895F1228CBB429931836E7E1CB2CD81DDE7E55
                  SHA-256:868E9174E4F1AC06B78E87D69D2469C405D893659328D66F6C93C383EADB68E8
                  SHA-512:05DDE7314B09B2D90EE9583CDD441C8CC1C36C359DD8462627AB810735FD29B22D5AF35E733F0D97445B776D3CE42E36BADEDC5AC6AE2A18F4F4E1F9A0A639C7
                  Malicious:false
                  Preview:.TZ...d..$.a..Q.5.S.l ..s2i\gB.e=]...o......u]D._.O^....yI{..m.CA...58..US.....if....,....g.?..4...........W..\..u...=MmP.......J.r_T....3.:+..*.............f.......+..ny.,....p.TU|g....v.mq.h.&......T.Q2...V.(. .:...k..`.u..u"..|7..>r.Wg.r.(......y|...........d..4p...m-.Q...4.5&.....;._...d.s.t.'1..W..K..C...Lp.0.9.9.XF...A..'.1c._ ...Q\...,.Ly{....^Z.rHo4..+6...h...._...R.>h....S.o_....$H..q).o.i.....)...... y.].#2...l.. Mt&.[#].W.+=."...-.k...N.40`g.dk}.g..".5..v...Mvy..G.Xw.0.....YF..].$...d....g..a...X..o...`....|..V.F2J...........X.:.Ok..TP..>..Z#..|9..s....rc.7.]...=.8..[e.J-..0np_.Sc....=yjo.....}."$...h..n."......&..|....?.C:......q..%S%..{.......>...Lo!.$W.u....t.S....!....B.b.f..d...A..p?...s......v.J.0....0".x.YN.a_Q..H ^."...u!...H...TH...'f48....o.......T..t....?.|..I.. C....}b2k......(u.H*..=y.S*..........<...ay.|.^vV2.B@..8J...Za ....Zq..-.9.f..]<.7...M..&kl.]a.$ ..7.../(.M..n..fJ.b.,._.e.7..~...G7.:.....S..&.n.S(
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2393
                  Entropy (8bit):7.903010420124403
                  Encrypted:false
                  SSDEEP:48:qEe5GcCHuLhvGN5Fjaiap2K/BvAXbv41xqWRGT967yiH:tAGcCXzQiaYAvAE3qv9K
                  MD5:8E2CF86C4252B33AD0238B6C63C57720
                  SHA1:24ACAC5FAA538FD181E11C43905EE11D6BE70A59
                  SHA-256:A87B3F409C7FD006E2710FBFD72CACA4C9C66BABDBA290A2D9C237F894910EF0
                  SHA-512:3698E0D5CD7C2D33D8A07668FF8550D5070B757C0237A6068765609C9E8C07CE52E33C4D82DDF737C37BC9BED8D61197C014DAF2618F9EAF914337BAA099C972
                  Malicious:false
                  Preview:..^q.Kd....!.Z!.....r..Yj..f.kR..)Lt......~.."F'"?C..K;....%.d...e2..u.!..............P........g<....+......9.e..........c.R.X1#..A.v.7...Y..j.R.y.....+..%|m. _9...eI........]......R....0<W........N..H...u.V..."...2....T...4...jl..F.t.t#..".#.\....P.=...eW.?....)..X.K...._.!Py......e.E!D..H..=...B...>.t..c_.D....#.%...~X...v.D.9.v..B7./..6.......A....n....D0.[..b......+...r..h.\...6..(E..*........D.17X.#Zf...p.).........Ekz...j..Wt......G..._#...E,.#.......2.~.G.k..R.Gw8a..x.S.pD.....f.9.....~....K.p....5.N.*y...Wn.SD..n.y.......f.....]#.g...K..=......{}.A.%....K./...3.d.o...I:..r..F@0o..a.z.4.=Q...;Y..\o.F`=.I.a;V.h.-C.....v.YM.\..{..?...Ba..(=..'5..D'.(M]....(.`s..-.Z.n.X.F[....u. .\.......q...-u7,f."...M.'@.B~.. ..CF.D..~d..n../)%....$.....$.tg..t..Z...d......L......[..?R....j.z6V9.x.5....y..N....%.j..|..?..Y.Y......w.^..q}..n.e%f...v..;....].../Y......jJ...C...}......\.,r}7.9.K{...,$P...e.~.#..{*.^*ZUs...S6G!...B^.5....5.n..}....qB.]...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):2420
                  Entropy (8bit):7.910694072788531
                  Encrypted:false
                  SSDEEP:48:6CFozYmk/MkSMSWojiRgl7qBIyNwTgtTqi0Q7q62cZxBtbhn8SuNqx6D:6CF1KfMSIRgleBt+gNqi0j6HbJxC
                  MD5:76D9E495A3301575DA104463E44746B7
                  SHA1:699D0F3C770ABFFD6C65A0EDE2B5AA104EDD047E
                  SHA-256:DD51B2C2570D8E5C50FCA39177BE0FEDD1256CB6474B2A3317B1EEABB354F91D
                  SHA-512:90FBF07F248472489DD947B68065B507C26EC0ECC930B9AE7647249BCF63F192EE89EE57421083FC251228E8EE96FB6C56266C255A419849E6BB4488EC21E213
                  Malicious:false
                  Preview:.HD....e_w..,q-.dx.."..T..;...J_...q .b...H.a.l4....P.U.b...SY.#t..Yz+xV.,...`.Y..^m.f.w.!N....#.8i(....D.Q.}N.]S8R...>..Y...^......BI36Q...t..S]=Qws..]........gH...`..7.y.m@{...>.[.O\....F.^Y.;*vgS......R.,zw...q?".gMp7.$6.\.....'p........9....\. ..`.4..TB..H)X..,A.Z6_<.R%...<.......m.+..h%......O..)1W.....A..G7.L......z..E):..*...=.;.....d'...........w."......;.....4.....|..vQ.r.....Y!....G....j.U...4....L..y.q...?...4.o.M8L.#.r.k..b....48..i..../.d.......Q..}...ox._.......%; .>k.h.$-..?e.p..Y....h.<..<"1$a:....NBc..J......o<..:..:..f.,dg.=.s.m.[=.....k....cX.."..@a.......z1A...<.|.(..Q.,fhw-.+,^...vM<...Q.......hz.un.."A.3.^...&]..J..`<...s...<..P......L..d.R.z....;g.=..x.v^M.p"WJM?q.4..c..6&2...~,y..S....Q.G?..k.....Ja..{.l.."`..Z.._L.!j'...,.......PS+....`...&._V.T..4...;...r.8r.A......0.;...4.Y. 0.1.."...g..~..$.....4...3.*........U.5..PHKi.B...`aK.f.Wb.O..o.w.?.N..y..b.Qe!./2.....R.^|..M.h.3/".......`)..RV+.?jW.........!`.6
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2600
                  Entropy (8bit):7.9092733634591585
                  Encrypted:false
                  SSDEEP:48:0vyxAcUzPj6RS+u6yBtVUpCF78l5A/gKXJ57fMmTzsbiNI:lxAnTj6264tVUpv5A/gKZ57fMmnsbG
                  MD5:0BE065C2765249147DD2A6B5ACA9CDB1
                  SHA1:3AAD7A750EA8BF19AABEC440AF915B1E500FC8B5
                  SHA-256:6D8B199EE03E92936F98E50AC267DC33B72F2D923408E305F5AECF2037B3E730
                  SHA-512:E160E834BDC335BC707D4A9800C9A5683C680EC53CAEB9E3AFE0BBCBB09DDAF805CD500F65F2FF39B51974BC830419AD865BBF6C0E4D3B616692F2960D666CED
                  Malicious:false
                  Preview:\..k......>.M{%9.........Z.9.p.E$...._...T....7>QX.f.xy.#.E^{.a^A)p.klNr.C22|K|h/T.L.a..V...^..{@: .^H....z..B.^.N$..*....u>.l\..a).W.&[./7..3.......$.gb3..F.<zr....KG....kB..YD%....9..........Z.E.-l...A...Xz.h..PLX..m...r}.p..C.z.'<..V..../.R.a.}cb.c.......~a.......jh.J2Y..l|.'a..(...w)..j.....*.pl.0e....2M.$.0....{..^\..C.wo.mz.8.4:.t.^..g...R...._..<........i..,....$...........\H2*.....gz....wN0'0.c.....S...@.....]{..|....@.W..k....=.~ v+@.N.....b.b...T8......,-.9l..<_.'.{.e..|.%_J..](.@|e...]!k..^......f..O.x{....U..+|...*.a.....V.....C..V\8}....f..XG..E.;.!y...4.f..O.na..^~CA.[..7.'!Y.fs/i..,.mUf%~...qaX..]....6.(....P.O.tF.nQ....R..X...DE....g..jy..b\+.....-...h\..........x..n'.]..Zw]...1.;.g"...`..Q2...X.<ML'N .x..u.b.....h...S....[.a..d.I[...H.Gf.........[....bW.....RR..\s...F..).]I.'D:.Z..z...}.2\...l....h...@....ANP....5..>.F%..i..=...M4..#!..9.q.....+.=.U..6.....Gsp'....U[g.q.j..'.6=\*...I.I....v...0(Q4....*.....-F......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2600
                  Entropy (8bit):7.915930212188561
                  Encrypted:false
                  SSDEEP:48:Qyh5Vsd+VLI8DqkF1OieT0v0tovPsRn16iZfBkrXGBqhKwXQ:z5WQfWkFoE0+vPsR1PfBk7uBwX
                  MD5:618BEE651D4DF53A048AB30E8148DA85
                  SHA1:86F6E78AC1CCB71ED8F7352B0014DCCF6D6B513D
                  SHA-256:4D6F77FF938AEE4BADE1F3FAF5905D94BE253DB8E9CB62038A63C3EEB4CC9B74
                  SHA-512:55C9392C69221291DCEE25B5A682037B358559B7655CDC24EB0A38A0D4D9491CC513122DC857B1CF7B0E987EC027C2A562AFC74B9CCF47025C6F9113B5D21A97
                  Malicious:false
                  Preview:.nla....>.o.Z|.2.P.Z..H~...L....;v.u.qX:......+..m!....=..F.._j ..G.......6.2.....)G{.5.!M..+.R.(.\..\.&./..7R..;.>~..h...J......iR.s..N..r.5.?..3N..5.I..HW..Q8..z.7...'.sVCF....~m..>..+...&..U..{S/...,R...!..CI.,.M.nvJ.`./..|.Z.....)....Y2.Y.g.H~..Q...t.8....0../l...,)......x....Q:........K.6|.....8O...8Pw....St..'...n.....P...{.ENk..S...*...hy..?........IL....W...l..yxB.zI.{FK9=.%}..W.9..0....^......i.....*sS.......Q.j...2..X...x.lScB......`JZ.on.%..C....GQ.F..j.q..*..e{L=./..H.. .Y..i......3.....!..+ .)..?.$.....O.A.u.........:....n...cU2i...V.#..S.?..P_...3..............%......,...+.B`z.i.U.y...S......7...."..@.`>.QK......Z. .Y..#..C;.~Wk...../....4. ....B.w....A.r...*iX..B..,.....p..l.R..@...f......D.k.^.....^a......e.5...O...`YX..O........S.........v.....!.B..(y|.#:..5....@@.......*...ZM....';.X..y..lL.mo..2....;..W.a..gM+BW......L/i..I.U...Wi..<. L..O...BtVEW..ACF.!).EQ.........+.O.]....b.&.<(P^WQ.?.FK.... .s{o-N..iy...O...t.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1476
                  Entropy (8bit):7.82963047514884
                  Encrypted:false
                  SSDEEP:24:2PUI4ThrKXRLKFGCtQIgbgI6yJTa0RMLwHkHXZFEqTvlDGJ0dsmbMCdSNp2qfUzG:2MI4Th+BLqUbiy9Rpk3ZFEqT96yssMCe
                  MD5:B249D206CEDD36032DDF006AD53A087E
                  SHA1:BC24B6D825B69C719218389519725C4F8D2236E4
                  SHA-256:6BCA677707ACE632E3175A0EBED6092D3C79A00ABF08583B90226624B14EB7CB
                  SHA-512:0280A7918B01DD189EF5E21865DE4E0E91CF26B2CB99E7E638BE0424D5D9945A9989171ADA69C2259BF7C09CA46E9F00D6B7E9848F8DF50BA6EC589D4C31D484
                  Malicious:false
                  Preview:+?.T.r..e.m..ok....#..].`Z...XC.../U.......w......|..l.u..P...%H..{....u.B..6....UW.Z.Jw.z.|p;=.=.[.Y#_z...Zcq.1)...OD..]..Q%...4........[g.... ms..R.C.../..xm...Y>..q...}9...5#.x...Fg..'$....D........0.R.....+...#..g.=...[x.|.@?..'..'.5...@.....I..~X..[..n.."........ .>.5G...:7d.{.3..s.BC...*.0....(./E.J.].]b.#;..........f{"f).*J.....N^.n.Q.......>..D.SF.%.....`N.......r.q.B.;a..8.~}..>#..{..G....%...j..iI9p....7..pwK.D...%0..Xsyh.J.Y..].v.......y.`!..]...Z.3h.'8...C......_......"I.I.|n.S}..@..M.e.. ..,.ya..<......1.V........~.......x...}D.2J....HP.jm.DY6.Zl..A..>D...9(...:_.:....)o.Q.,......}...*....PH.....5..j..E..EK;}./..72`q.....lKr..:@.f.....*....5Gl>.u..-c.>@.1'.....>3;q...vy.R......H../9....0....>..g.@.....>...>~2....G"Dv......2TU.....?.f...|M.'.v...e.......1../..5C.<W..dYn{....a.9..<.....w....)k.........O..".....N.#....^....d..=<...^..Id..I..w.K.a..bs.*..O.t.........E..;..R.B.-..w4.....@.Qda.r....W..S.X..5tR.75
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2457
                  Entropy (8bit):7.906069981414911
                  Encrypted:false
                  SSDEEP:48:zNhISvVsFIoyg0Kt0+V/A/g0tfejWJKy7aIiq2gooimbWil9ogHpWKUiQ:zBvVsqXg020G/AjMKJBfiq2gNNPogJ/
                  MD5:04338333671861B8D2BA14BB31ECFD23
                  SHA1:DCC533E6ADDE18BF2F3C0E2F071BC9271C49FEE0
                  SHA-256:355100821C7D3DEF0FDB98FFD27590BCB693D54F9F227937F6AB05A7E5FC4CDA
                  SHA-512:1E9B55E452D62777C95500A968BC626F8046B731DB40CC1435C8809F509C6FAF2631A6945FDFCD1C8C057AAFDDEBABEA86D3586D6FA460D30A77E54016504159
                  Malicious:false
                  Preview:..w..%.../..Lm...~.........4@"X.._aA.J.......=...Q.v.T....)...4....f.4......jY."N...L..:.A>...Q>...{f..J.h..-Z...2t....$H....j...Bm.v...c.....?..z.\..Gv..)...U..;.0"...Q..%..j..j:....u..o>....M.W....M...I...h..`..^...)...#............}x.......D....y..qJ.,d,a.b...&....8%...3J..;.4X..0.m../O.!.c..]...sS.>....Q.v1...E_.y..(.z.D._l....O.B.....7...).......15..V.!&.....'...M..b....._..ZF..`.......3..EAM.4C.).?....@.g.%...o.$..b.....`.u....p$.s ...`.~.........q.;.H...6#...t.,*....N...r..A.D...~.....|......$i{.....|.'.d..G.g.........o...q.h?...+.(]|..v.Y...@.l......!...=.Z......W.p2..E....}.c.{&=.?iV.3...C.q...P...R..T..[.......A(_.o........@....B.?......"*o....!P._...G.2n..V........."..G_.i/"..7...4.<.)hs..8.R.-n#..*...\..VX.!...!.......^...W./.f..u....qw.M....V......%. ^..l..&.g..I...'AAq.F...I.R8Nd....A....%N.l.us7^. ..i.v_.fp...@.{R.zw<.)E]..*...S2.*ud..D...)...?.g...i...t..(+..y..c.[.G.Q_.99.;.h.........(r..g.k./..e..LO.=.......;.O...&
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2604
                  Entropy (8bit):7.9171936758249615
                  Encrypted:false
                  SSDEEP:48:Z5D5658nzP696yhdOKHfShrWkOPd0b+3WNdLDf/CERDshz3HDbgS55HL:Z5t65ym3CWFPdj3chf/CERmfgS
                  MD5:952863F3787D817EE11C6430065689F7
                  SHA1:7FF20E123628B7CEDDCF0644AE71524A6364ED17
                  SHA-256:AC33B08DAE1C54A45788B472FBBF4838C2EA012A1801A15FD50CC13966334B4E
                  SHA-512:35605475CE6908B0FFED0E335E35C9044C91847EC819EC559E1D3E7333232F30F8B330557EB39CDED9006DD3B69B3C752D6B7751C2F5C496A4875BBB223E64A0
                  Malicious:false
                  Preview:..L....._5l...A.N...7j......y..<....E..L..2z.F..r...6c..2.B..0.l.e#..)o....6cL..4j-...}`...u..V.s..iy...|..2.a{Y....~..R.P...-..e.....?qz ........2z..'.."..<Y.............U....u...`Eq...Ps... ..$xBk......,.>o&&...?O....n.<..(.....].(..^ohw.%...[".........2.#`I...j.....s....Au...[j.0.N$..R...Y.....?........r..j.g..,...+..g+..>....9"nK...g...9...<`f...YM..?..._..e.... .C..P..(.....Q.....v..[.5XC=...2......8.T&...U./..:*vy..h2..O.....8..!.m_.7.4.......~...wn...].U.T.t.K.I..<d....&..R....GH...c...I.Yq..<..M+p..1:E....6...<.......u3.._...IR.1.7..=.\.d.T...s.X.2..F!...f,.....].hP.q........6TA..K.z..%4^...:.cs8..-........;.u...k.....?|.*....BY.=.....r.P.....HW..6...Z..........K...............H_..s......#.1V..4 ......u....AL-.+..U_.....lLY.7...R..Z...c...KD/s..h.9Z..."...._..0{.\.A...z.N...Y~....Yi..2Ln.h..K%8..$.-=....z..q.8=....|%.],.......F.3>.(..R>....:.3s~.......RU..j....d.....K.C...jT."d}e.|.Y.Q...x.j2..Z..+..[U.6.W..z.._..R.&.I.pzC.K&.m......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2442
                  Entropy (8bit):7.9095222132156895
                  Encrypted:false
                  SSDEEP:48:kWRAy09XhwAq0A+w1M9Wlzyt62XfejEf/C06p3jX39iK/Azj3FN:kWR3+xrq0IOI2X2Y37mTNHOj
                  MD5:D45512F4FF73F461132ACE0BF6626794
                  SHA1:69CDC08D0DB02015806652580DA02AF2D6AFAF3E
                  SHA-256:EEBB732577354899295DD83F9CA7A3D3915A141D7BF76B8A2A89E360ECCE967E
                  SHA-512:A39DEF8FB43FA8793197C86E8A0E434892B57BE830A8CCCBAF6B0BE6270022EECAE1B71D7A927C29CA10DCC0BF13F7B0FE5B32F15F8B5AF810E703DE803E23E3
                  Malicious:false
                  Preview:.;P.....-.QVE.`p.9....(.^.$sq$.....y.*..I..)G.Y.7)...M.oQZ.+.`..O;...-j..n}>.q&{dwO.0wn..P.5f..U.}%7.......u.B>;..dtW.T@..7...A...k. ..:...$y...r_D.4.ld..M;y.y.It.a"&( ...`.@....y,.....O<....b.^.f.u.P..<...........a5+^.b).Y....|../...x@5..o.... .i.]f.x 1.....Nl........[.6O..y8..-.'gD......2......._o.`.........z.6aLsd.M..L(..#.D..%.:b...t9...+.gX.4..g.k........uQg.|..o..A..Rz[[..kLuL.o?9.9......&.k.vE..].i.M=P..2.>\{.)-..w.@._.....ly ..r.......-..h...4..0..fX.O$..@....C......}$...%z.F]....Y8.~..:.~,Y.p.......AV......S..gD.<_._;'.......]..Y..~.....5.T..E..;...t.^._..{...E.'e.}.......`..^.f8.*J..g.....m....b.g..VG.|.w.Ut..u..........)..v.b.p.p....e6.hM.s..."*...+`b81#....m.`B.......-.s.I.:...3...Z..h..jE).J.......>.1.......s..W[KU$EZJ.z.c|O..3.i.y.=.z........`9...*mD.zZIm.u....2$...Mx>...$..?...H.d.Y..#.......S.,....d(.e.`..4.....(4...k......I~YVL..\.....SJ.i...Z...\...S`N.8.p....T........6..St.\.(Y...Y}3).........' ...BZiN.Da..K.......f.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2618
                  Entropy (8bit):7.901587106878147
                  Encrypted:false
                  SSDEEP:48:/F/va4dTBK1yc9qa5h/jksxJeA1jkdcFbfJwe7w+2/poN9vRNDY97hMfOPpWEtNT:/FqQWogxksxJt1jkOBR7moNjNDY9QO3Z
                  MD5:1A3AA58C2BDCFBF64D83372A31CC0B7F
                  SHA1:AAE7280436B3254FB52DDDE8A7717126982F25D6
                  SHA-256:C3043B1BBD3537A52658FC88D45138B0256E66ABFF29D13330A1F95171DA2E57
                  SHA-512:28CCBB08BA5BCBDC09889E0A77DF6F3E2C41162BEFE2071B91F0A5E741824A245908CA92E552023DAEAFDDE06934C615C62A22323EAD10242109A0C1553D40D4
                  Malicious:false
                  Preview:w.zR..h.Fs)...g.ee...a~r.v.6...<...r0..<v...p.pp.X.I,..q....I&...D'..._......$a.O..n..o...P..^,...W8A..}?.}dkh...8.R.T..Y.P.+...y.>..s'....F..V........v.`X.t...=zP..u...[.......#.~..M.....G.iI#..=.d..|.^......)../S.(I5.\SU..q......@F...5U&.i"..*r..:7G^.2..H.{!M.N.R...).G2_.......0.>."...P.vnh0x.O.#.......$.T..j..UD..6Q.j.4.;...B.$o...36.#.Uh$...#u?.8L.Q.......:5.../l.....sNW..,..HlA...^L(.#V....7cM~..r}....",.R........<6..`8.Z6.J-f"A..c!.e`[.>.I.g..S.[.^..Q*..:...uA..{X...<~,.l....[...?B.X.uq[6.3.....OK.~.?^......bw..^.eR......*\.........K.zZZ.a...C..>jU..B.....H!=$......^5..=....*[.W.\.p..Q8....A..l.R.B.#.g........CE.].!O.I.v...d{..#..'O.c.p.c.H...I......8.....c.+.<.1..bl%...>..a.......q.pK.....K_..#..4 G.....z9)'...F.._...z...#)E..f.$$..\.x.^'...r..U....... .+.5AYy+....|.....^H.R.X...e..F...+......~?.3[..M.z..Ung....w.>@J..w.dj....<.....$..h..I...G..sa..I..yT..h ..T~..&...E.#ml..7D..:S...>..ON.s........#.g..C.:.t.I.k....T.;.!].
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2466
                  Entropy (8bit):7.916427828388642
                  Encrypted:false
                  SSDEEP:48:AUmVwZzU093kuK8EWPHbkdpoxcL8ecsNGsPHyyl537AK6tnyXjQN/Ui:Adq5zmv8rP7k8OLFcsNGsPSyv7AQz
                  MD5:AE611DEB80116B215FBF5220E4AF8BE3
                  SHA1:F4E7440908E090E9D6A76ECD002CA309DDDAD4E2
                  SHA-256:74AD5863CD05925CBCC6EF0C22E04A8F62ADE5D9CF4DE8E13ABB45E4F8AC0034
                  SHA-512:CE2607AF51FB04CE15755F368023BF3CCF0C70E5CDE97B56186EA040A5780A60A59D439E6453E35AA973F572BCEB2CD23E3E436AD1F30C4AACE483DA3A51B713
                  Malicious:false
                  Preview:_..%y.9.(n_...E.$.m_..T...&S..... .<(%6....p..t..(..m_...ufw....nl4...,c.....l.'u....p..Sqh}*FC./o..-eP....B..D%...Q..ua.Fg.CJK....A%j]5.....G.k.37...k6 .........Rj.C....N.07.j.U'K.."......gp..8.\..;...>......!8.."0....... .........-i...x.J.t.K..Cx....as..2.~.3.}......~fDjoo.D-....J..w.....6.......o.E.%Qx...m.:.....a.......d.:.W..;..6v\.ba.....-.....(~.O'9...Z.("o.k{.U.....?..w..v...e[....K.S..../.,.....Zr}.../.3....y[..a...k.d`pf.....];"CE.......?B...F.m...!v.4..)n~....T.nfA.Z.N4.;.a;....'.Sa.~.k...!L..p.......{)...Hy.-h...>6.+...~*+[..l$..........f....=..3...O.ji.A.?M.b....m....N..S.:>.x...Vu...B.L,1.....+....I`6*F..'.j....S.W.u/S..Pg.:{.6..&..2 ..J^...].a.Z99nv..h.l...2p..x.......T..'<.)./.5.@.4..#....h.85.%..l-+.u;VW....3\..B......@.N.F............V......-./j.dN.dG....P.....8OM.l.....A.+......RS...|-......k..T.<.i@....X.._.;5AI..b..z.=.CA...Q.X../.w?{....Z1....4U..A+......Pu...Nq_H+"U..5...';R..+..G.(.w..`)...w.!2....7*.5...1&.z....R....R....)MJwd
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2347
                  Entropy (8bit):7.901646136328683
                  Encrypted:false
                  SSDEEP:48:LqR6WqmXCruRVUtSPvJgF55S0famCrIiLjVXj2W2Isc3DSamL5j:LqPRRuQPv+FvS8CrIiLSIs
                  MD5:DAFE8F4C8CB204DD7E778377424D28F9
                  SHA1:332589559A25CA3639FFE7895CFBE357D0D6C0F5
                  SHA-256:7A963DAE07288C3F04B5D869EB8A0BB4FDED354B5950784EEA06504B2CB60803
                  SHA-512:37F6FEB40F3D6C89D8A22D85BCB6E1F3C90C72C09F54A63C17979BE00296A0F2BADDB04ECE9F8490BF81B938D8541F0D696397F146453601929543200867D0BA
                  Malicious:false
                  Preview:...G..@......^...K.5s3"P.......0..~.7l.l..D.......g.Q....(..i|<.........)....o...}.5(..03Ln...w..q.......+:..M.O`6'.Go5..."1.'.r.(.#..{T=DLP6.p.. .......1(......y.{w.w.O..M=J....H....DA,...'.P.~..`R..}1..I.D.v~........m......"..e.Q\..Q...fj.WHR...K..S.U..x.Ks......h.....F/...ci8...>!.v..kP...B."...?.W..6\`CF:..;...Z....4m.O..&../..GFc.B...3Kc9.j.....-..{.&...L .y...0..z....m....1.`.......!.#e...^2.iHc#Dvd....#?.-&..v,.".Ii.....'e..m..a...o.c...GW..>..ei.O. ..X..p..3.....!QN..~"..(z8.<h.K.U..D.....S......P..!.. ...]........$6...zW.C...aa.....59....i..7.@..5.u...I>j.a.g...e.6hf....V.n..OeW..n.n2<.~..k,...@.{...W..k...sK...s:.o....u.......1.....C..TVV...6Q....@RbZMQ.M...D.t.N$...VP5.1....oT....?.I..&XJ.M.8.F..k..d........0......6..$..(...8..|.8..7.9.u...kM..p.7.5..-....G.W.~3.K...*.R.N^.b....'..@.._.%...T..r.Xf.+..rv.f..`.ME.)...%..).....4..5...7..|.Y`...;Z.....PJ.p..lQh/..Y3..}.oxJ<...5.|....J........YQ.B..Y..W.=..ZK..._
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2385
                  Entropy (8bit):7.891612297437776
                  Encrypted:false
                  SSDEEP:48:kz7jhCIhWj4P0BMWcw74y2C2XZg0aIp2OSYo8xNw49Oz8sbgp7XA:kz7jSj4XWcw8fTxSf8zNZ8QQ
                  MD5:7DB5ED2678F38B97C4C28060B79B6632
                  SHA1:4A8F345D46DCECD6549ADDD1D2F2BB77D13D5CE1
                  SHA-256:3C2D4BDAD320A5AE2EF995D296549692336550F413B5F3D650CA68CFE9F9FFC7
                  SHA-512:6304A864FDE138EFA45581F0FFDFE85016C2FA5F0E75FE433189A503B05BF9975F5750F74247A20B22A3D9EBE5862953AC5D9413ACA5685F0E73AE88FDFAEB73
                  Malicious:false
                  Preview:..0.D...dT..+.%.x.Ao..*.gT.Y..=...&.=..2.\9..,Q..V.4.4cc.E...o$.e.c..w....z.T$.....M#.N.-....|.<D..U_(.....XE..W{k.+;.j!/..H-..SQ..j.qU...OvbN.{N...8{.......E....r..S.+..~..-.\L}O...W....f=D....x.>PJ..w{.....Vf.H......`pdrU,.F/.Z. ..x.\.<i9.B..."?..8L#f..6..*.....:..m.K...Nn.Bi.....0u.@.&.W.p..Y....a\..E...uXW.....cN...:..R. D||...Im.3+..=.e.....1...c|..|.a.............fr._.....rX.9....s.D.3..L...../M..pWW.c...sp.j..6.,.}..'..)$.5m~i.....%....hQN.K?;.J...2...]..g...U....{7..n..S...........r.RTh.=<[..v.R..<.M.....* Ij/J..l..e..Xu....r..!p,...A_#w......}.Sv.2.........-...^...u.....D../.dfsO.W....S..FX....Z..{J{.....e~PvW..k......Y@...8......2.\....|./.O.Q.3c.....cr...P..ru..`..L.;....i.+WC}%E.2.Z...h..@.(;L].....9s....u.P..../...t./...6.W.W.rP'm..SP.. ...wSN....V.).b.=...j..~..P.Dh......%..kC^L...=...........8..9.j+............a...........t.....`.X.F ...&f.. ..Q..T..i8xQ...|J.!b@.!nL....~b..Q@.~..?.cE.$.. ..z&~-Z..U........r.#.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2486
                  Entropy (8bit):7.911329598919194
                  Encrypted:false
                  SSDEEP:48:x42JVQHWSw6Oolc0qemh73B4bA/29nLCccgyMMkzzy48SQcbJiW:i2JYtw2Q3B4U/EnL4ktu4DJP
                  MD5:156CB4B2FA41E96159A4EFAF48D78D40
                  SHA1:90371DF4C61C30CEB00B96D816DCA1446842D03E
                  SHA-256:F0E75FE01EDB5E0734D0099AAFDE7B669ACEBE6E28ADB28DC67BBFB382B5FECA
                  SHA-512:D99D8441A3684599A3631656513451962F06278BF58859DAE2FD40B0BF948895417C07BEA1052789B3B2DDBDAAFB10458E4E5D6C4B225B266D2DBA2CF6B26F62
                  Malicious:false
                  Preview:.....&;.....l...VC.....X..}..O._.....2.b.O.ud.6F..._J..E^.v..:p..%L.....z>..48.Q..n..y..ij...Zt...kG/...6.?...D...F..6........y_.r..h...k..9....@t..%.....*.U7..P.Q......9.....^.P........oo_*-!..x..@....<<..J..$0.~8....7l...F....s..G..|.aS.{. F.g...e......u....k.F.L..ZV....iWn./.|F.L.E...BI...D....tS.)..0}..aJ......t...B.I.4F....x.i ..A<..R.C.4r8}{....`.._S.Kgw.ZX.T8j.13.....8w..#G.x...O...d.mg1x...n-..gb....1...&L.+.0.&..R....LM.f..T.4.]A.w...X.6.Q..I. *Cx......']......;.....g.aV.6.8.....*Kmr.........k.K.A0...)..+J:#~.k~B......=T<.......3.e.+....*.A.....^x..w......1f.*.i9.R.U.B.....l+.,.?..........=.|.:.B:(....9.Y.......b./;.g.L...&.-l.....Z^@<............`..{..3.D.7..b.....,ku..7MA..Y.....T....?.;.N.X..w.}....Y.K..n'........]....w.6.r..w\..&..oQy*O...xn7....o..k..c...x.#I..G..Z...u7.....ic..N<p.s..0z..W.T... '3D\*H$b......... ...=D.....O+.]Y..e.u.`....'.Z.N..[...}........`.J.."..........h..p..C<a.,..?.]J.../.I...m.6..]......i....}..l.....h.[..w;.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2426
                  Entropy (8bit):7.907287618163441
                  Encrypted:false
                  SSDEEP:48:srzNUhyVjxaLoN/HE1zsqJawWTK5gmsvA30OSjz7sTkTOg:Q+hUNNdOTT5gbAEOSbsTkr
                  MD5:B4937F2C379654A439F90BEEC22043A2
                  SHA1:005534366A1FF7401F37468C0CA1015A4C15AE72
                  SHA-256:115F7F16EDAAFDD372263814FB33DE8BF5C2B2B3F0F50F2107EDCBA44FD3B619
                  SHA-512:5CAC9A0836421E8BFDA2E887F813BEB74BEEBF33B560F9B420F9CE9F4FFBFA7AC2F58015686BC59495FF1D794DC4886213C00DA5138BEE4C7536ABCE611C7E14
                  Malicious:false
                  Preview:....r.J...z...y.k?j....F..^..TMG4>...V...H$ #.7qY..5..[..`......n..{".........z_X...=.....O#.x>.Y3...uF.e.:....BQ.7...6..Vl.&-+z.......~...5..d..K;.....u.(R..&_..>`UJ.#...l#.C..4b..r......J....r.'...:<C...47.%}..|..A>...O-y...@.{..jY.....N...r..>.n..@|$P.W.D.j..pN....Ahz...s!......$..j.......jl$.iF....d...~.FD.H.U..EZ.....L&{<JII..e.1O....&.>.Y*T...g..5v.N...S'.V..LCTH.?.+.#.Y.o.......i...RU..yO$h......t.....E..Mh..A.S4F.[.P.hKOv..S..5]..$..Ez.....K..'...........q_.QO..u/.gW6.S.oVq.L..t.KS...*...s.[......0...E.xt......2.(A...........Z.&.....zvS<b.?o..L...":...5!....z..OD..kM.Q..2w.....}U...#.I.o.R{<}.%........Bp..<W5^_....%|.\;v...}....4O.`w.p....\...{O1s..oN..$..>..q3.fQ..by..:..?.JM}.~f...a....../zh.kX....^..!.....KK.|[..'.....h.......G.?2..Sr..\>...?...*&.kz3+.gH.a*.?k...].2........Y..V..a.k..0.m...B~.R:.:.....p....Re...v/0..:~..I..... Z..[.......Yy&]oe.40.....AG...t9X.....).N...kU.K..TY....ED0...c......4...%n.m....>.0V.h...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2544
                  Entropy (8bit):7.912231796720363
                  Encrypted:false
                  SSDEEP:48:J5CkNQ9QX6tzjFVk49XuBrxHhUrvZahXvhXmlqNhVJ8gRk93/XYPN58:XpNQ96+M49XuBNH+rvZahfF+qNjJ8VYg
                  MD5:9C51538542B01F4FBDB1F40A20CFAC78
                  SHA1:78902A4FB40085B01BD4C2C4D0C60ABC751959B0
                  SHA-256:8EFB4E7D09B836D3D66F4913A3578323CC3469047A805AA2E1C5E422B4DCF669
                  SHA-512:7C4A2040E703C11C228830F4BA3746864C544FCD4EB4486D56C3DF4237208E625568081245542BB2BD7E135D3FF949BD4C89B020EF70E12B5934914F0A7E4DE5
                  Malicious:false
                  Preview:z..,..y.R....Z=..P..;..VB.0^u..4..M._..^......p...F.....7H.b...r1...RU.eiX..@....W...6.mO~..W...R^....~ot|'.).wh..W.Y1..l..+P|..|.:...FX..<M.....<6...M.a.R..."...9#Sg1.Q.GZ.cf..<.2.J.I.....,v..........J...L_...r..D,..*5.J.Q.#x.$...:.....0G..iC...*....<........&..\.X.).3.n..h.^..g.!.`...9.c...X........!.i.E..~K...&.....$.U...F%..R..|i^|....f7...<?..s..:.8..J.......~,E..0s.L.!3X(d.l...A(...X....D.....w.i.Jqb..J1..Y......c.+?$.6_7F.G...).3...op)...:..U.........'(.!E.(..f@.qs..~U..WW3.;^8.U..L..7.`;..7...0t4..HE..:..{..xI.j.. ;.N).-.{=.M#i6.q.1.c..oN....R.d'..1.....H....K..[...PK9.V.VX..QoYx.ggY..4....f..k..v.~.~a|....{....)R.a...q..Q.n%.~U.l.s`.V.I.3....6.1.R.].U...x....a7....M......g..."......./.......oiY..R.X.fU..N.b?PJk......4...,...x\......Y...S..g-..o|j..$-.Us.pY%.....l..........?..B.)Y..;'.[.......K."?<...(...Gn..0....$+.j.1...l.,9[.E.6...t.\a;|....../.....n....D{.$..w.@!.b.Q..~..Q.......;..k1....#.....W.....a.2..b...m.......@Q.Q.$
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2349
                  Entropy (8bit):7.9100441273499404
                  Encrypted:false
                  SSDEEP:48:EppdehnvwtCu4BvMhCyDRoj1I1xDonObkLgiSvxdc:Epp4vu74tMDRoj1IzDIsPiSp+
                  MD5:ECAA550B7B44FE04BD9306CA221E47AB
                  SHA1:2442EB60929C8A5D8F418CEF3AAE7DADEA96EB9D
                  SHA-256:842A78373C0EA1D7FFA9CBA34A968475594D1E8AC71A542402CB340C9C3AFB61
                  SHA-512:06634D37F0482EE9B68B8D3A7399BD164A1C64B0C469537048D7A568736FC6B2DB08C0AD5E15E1196A39930351AD365776B9979342BE2FA073B03AA552F2BD3B
                  Malicious:false
                  Preview:.....2...8L_";2.b..p..>.F.F.%g.....M.../4..3.>.g#..Yr.#.......\.vMkB....{ys.k..C.T..-......`._.Y.~....>>b.7w.3y.`..O\...9.e~S..?.#....hS...1.m[^K.j|..H{V......x0.7=....\......7<.I.l.."+1.....?1..;..3...M.o.Sq...u....I..a.).m..=S<,..i."....4..O.R3.......uzn.....]....E..G..X*..9=.......hx...M/l.....wzp..3.G..|.\...e.VA...qS..A'...+A.j\...m........j..1.u....,......_.4.U..-..5...k..c......`....c...........I.t.h#......./..3..?./.UT...)...V.!..i..`.......H....\...'-sy.B......%G#. ..A.lF.o.8.W.O.E.Kw...$.d..]tq....4dK.M.b....3.P.Zm....2...d.......F............I..Z|z.m....@.*..b.....U..?.........g...'.%.4..:..{o@LD..~....p.\.n/....cm.N...WF.|.p.G...FE....k."_....E..T.."...@}4......f<....$....5a#.....g/..g..x..D...K..c..o..r....._E.>......J.W..0......3*..W.G!.._-.(...X.t\...J.*....g>..By.pf...E.%>..AO....Tr_...Y..p.....Bi..[CV.y.,_....h.r..../..`.W.....q#.....C..i..1.(.p.I.R...y.R.-.1./..g..K../. j.....B.2v>tc...f.6.IN\.]._s..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2952
                  Entropy (8bit):7.930082192938736
                  Encrypted:false
                  SSDEEP:48:6GmAdHFVfQVjimC2PbsyeVTGBdQd6C1amG8zATV5nmdhLryYNOnHvxQanQImtT:6GmwF1QRimzsye5AYR8X8zi5mjLGYNO0
                  MD5:402C490ACE993598246770BB0840677C
                  SHA1:DB7A6DF4847001C875BEEDB5E01ADEC08338C521
                  SHA-256:71F95A2012F3B08ED7DD265778084E7F2DAE6850D71B5865CD3BF1BB754DED81
                  SHA-512:60C12FB55C32F48A72F893F025E45D8261AAEA977CA398EF1E6DAC1706CFB9CF0568C0911CC3EF8403B00C3454C36CD9FABF696F272FB62CB76522926D80109D
                  Malicious:false
                  Preview:......."FT..7...@."..qN.v....1.]..dp.....g..\|.]4..f.}RW..CR..p:.c<Z..k0......2E..b....S...L.e@;Cr..c....Q.<l....../..P..O...\.;....$..L.4.s3.{u.M.t.td...l.{.})..!..q.&..-Hzwq?.C. /.E....5..-b....-r..6D.Q.....L......~.O...e3.).)l.).pY..K.$'.1)j....8......S........;...m.X".4.....x^`[.*j...'P....`.v.!...Q...!.?C..Jw...X...?.3..O.k...!N.0...w...>..+2S..)mL=o.....2....SS.-_!8.d..TSH........E*..(.]..|..uCd......f...Cc....6.EJ{ke.....k.w.....W..+..DhU..=.rw..K9...mcd..L.(......ZSw+U..Z(.}.V..y8.^...q.S#.._z...`N..........(...s.....YF?::..7.d.9.JXx.6.D..,!.k.t......7........~..^.2l.CP;(..g.L.'./......x.P.....O.... ..u.........*A....Dd....Is....<........H.r.........j....[.5.UI.o..).{....:...6....ZQ1....gKp....J.../di..s..I..p.&.}.....9+.y|.>.a..:..".!....y.p.......o_1.D..".....@G.k.*b.5......a..4..,..."|.H8.4P....+5S.PI43l.....3a..f.a[...(0.b...U......4.*<.P...'...=.}t..-.._?....J...hv..J!Z0C...c......_...Nf4ZG.t.t._N..@..,......w.....<...mj
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2563
                  Entropy (8bit):7.917419884874812
                  Encrypted:false
                  SSDEEP:48:cBxOrTu8Ijr+kdgYKRVwDPXmtVIjrBgqijf/1RIoM9qFxgONdrmbU:jTsjr1dgPwr4kWXr7xgONdSb
                  MD5:CD4E8E8C41FD61C2AA04F08515D9D075
                  SHA1:D0AE96F2882BD1935A43055166F90B407E6FAB3D
                  SHA-256:8DC65C7F6C07203F3C542648E24CB7C003F17A654864A8064CF1A737B08BFA4C
                  SHA-512:E2E99B3130FE1C42790AAA03C7956879B264B28F04DEFD9EA9C07E220376EE2D91AC29DF7B43DC604F42E38F78D28610C7E3FE88F6CFEE0FBF49EE86952C4EBA
                  Malicious:false
                  Preview:.G.....*N..2\9S.;..#.._...A...jB.^?...!....\....]g....]..1..n....a1.......*....4....A'./.......;7....y.Z.]...N......O.....j.]k..M....A0...\.X~...r.f.^.d.0.JP.........~.4.*Kz.....i.z..UD.Z...g.m|...,QX..'.%+.M.+DT.a.f..G!_.......3.35...3.ov..>...G....P.\,I...&.F.D[7.o.x.;!.vS+.$;2.:.(...i.4...[..uL..B..l..k....I.f..o.i.q..?.d...$L..!.:D..*.1.,[.......k.G.m.36zq.T!..K.....|X..".6fJ<..{Y.h/..XYov&..!.p..%.A..$...."z.,.\.....~.2A.0./.....v..s...{...M8.}.2....~...W....=..p..\.R.k....|b)P..s.cT.C.....%.F..>.x.7..p...'p.Ra]QoV:)kd.U....b:......o."..T...8.lM9../..DGZ....<..e.....1K..q......Z.M'....w...RH.y.....w...Q..Wj..r.es..N.h.;O...l.^..F.l...<.66......*ZF.. I..&......T39...|....oB.w...+......]...=.dKz.,^....HI.>.Z*.`. 9. 8.../3..p...v.l.y..pl.n.q...Y.. b.~B.....Q.....I....O.v.=N..B..?3..3.-...e.(h.(.R.D.U.....1&.NLG..UB..x.....AaA..fy.Qc.h.r..]C ..D.D.V&.D/...d....(.[s...!..v..*o..dL(}.;.U#a...Y{+.)O....z..LH...........J..c....DD....H.Z....fH
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2405
                  Entropy (8bit):7.903713425513148
                  Encrypted:false
                  SSDEEP:48:CCsRt/Q1fCPpH4irj6yeRa2lWDdrxT6IdX7mAnmUYX3:X1ZZa2ebT6rwxYn
                  MD5:82425566AB91A2DAE385F04372CCC4B9
                  SHA1:6AADB28D033DE7DA9653107AFF5D6C4BA8A54D1F
                  SHA-256:F53AC1051539D70B859732EC295095D3D7B93D4E24059C91E27E5C37FF897082
                  SHA-512:94BDC4CB4D49DED1D65E6123E3CE7EE5C6607B7A03552056BF8D72A1D0422748B5113CF436A1CF895A8715C0110821127618BA821C7971830C39E68F3E3E784F
                  Malicious:false
                  Preview:o.n......F.4.sP{..1.).R.&.....].|w}wK..V...\.P.h).s..v...-e.......=..u....F.U..-&..xx.+...{...U.zq.5.Y.Em+.......z/.B.....ci.A..^E...K ...f.....f....(.4.N..V..N...i(k...{.....H...`......-.].S~.p...u.s&...JF.$......(.4I........!....kW.W...&.$].4N....J4..a..+J.3.."B.hEl..?.dh%._..^......7B.~,..jr........'.s.h}.&h.oq......~..s.N.<nXlxD.8..d`P...(.CaLpJP.<..Y.o.....WN. N.p+.d,k.....Y....rg"...3..E.+.....G....QU...h...7xy!..m.".vX.....w.R..g.Sq...Gv[.UZ.d..1..1..VJ.22..?.V..CO.F........=.$....y...t...B......T.]"..eF..,"....z:..jx.'...%Pn..p....=.)....0cE........*.Kz.K.=.~.....o.1..^ .m..p.!.Iy....Q..\........s.|.l..L.:..;.%...Zt.X.G.C.NR.am.k.#..v...0P.W........&T.^.=..Q...^...6.s.Y..f..<R..x.n.}.....%....FRA.J..04-..L6L...a..tv.b..F..*.X...X..!...p..`..U.......UC..7.....H..O...$u....}>....aY.*....4A..e.3/..zV)....v...^...da....W...]...?.....g.!y~_..tXK.W....J....\pJp...(.l.R9.2.".|..7....4.;.*B...y.${..36..p.K.(...?>7......B.....x..'.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1476
                  Entropy (8bit):7.839967326624048
                  Encrypted:false
                  SSDEEP:24:lcDw5qrrl26/y8x8i45vf/2DGEQ1Y2bnjqfigZ7KFrY1nQlS2hssvKi+:KTnlp38is/27Q1VbjqQ+nmfhbT+
                  MD5:985318E1F034DE669317B7B18BC9486F
                  SHA1:DD0ADAC91A633FA4CB54DC0773AD2449D394B085
                  SHA-256:313CCE249CE05C1A9829AA9DD2F8D84111EA2ABB881A7AB2A4BDFC0CBD648F74
                  SHA-512:A6959FD494FD8DB6C6FD4BBD9E6BBF8845181BE3119B263A0D38FD4E8094045F7D1AE92BD7F62080A05A5C42260D92BCD1848D52DE86AC04A35127B1BD1F563E
                  Malicious:false
                  Preview:..@.P......v.`?..........C".#o...].~..8.b.,..y......I.../@8.,.b...z.....z..B..........+..<.......EL.E.../......{.vr.t.....D.w..ZI..?...oR.Ao.Kc4yh.[.'.1.G.%#.!..a..U.=..X#..F....<9..9KH...F....@.....4..>..F(..Y.....]l..=a.l.....{...X.}......5H...wN|H>.U.........r.J...m.|.F(_l.xL.`...}.....T...s...K4...g..t.:......$....W..(k._%..{..P.y..<...w*I.v......1...7j3.Q..1.1nQ....Y..~...e..>..yp.;...u.X.,(. <rI..."#....[...K.(YB.$....6.....X_..k+.q..?..-.G.L...H....8K...{fj.c|...M....$54<k....a..(.C+...@._V*b.D....tQ.Ph..P..m...Py+GEv]..y.Y..v.>$]..a8.+..wd.'QjK..x...l....5=%.%...~.+%.\....6..8h.].|..........0.R..A....,..aI]#..|8...^R..5N.k..Qe...ni.Q..v...T.V..*...R.U...z..GQ..7..7.K...S....".Q`..Y.r.....3..LC...s....92#Q.ST..I.._.E.~..Q/.P%..\w.!e$.a%.B.t.}.H:.....A?.%..M...u.0.e.....q9.d0J..T@V..A...^V..T>.0.$..E......8.TK........GO.D..[..y...N.`.hm.{W..*.j_..M.\C,.e.z..?.....\.....P......z.3.EX.Aa..o.nN....z.y34@zW..*.C.3.j;j..,T.fL.1o;......7o.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2391
                  Entropy (8bit):7.916825323410114
                  Encrypted:false
                  SSDEEP:48:TQRXK1ibPLENo3GsbHg2TVDBAEGUE6ZNr+X4bHsFplCaDr1Y:TQRXpTENo3GsbAwVDBAEGB6ZNr+BPggr
                  MD5:ED1B16EE0C1E61D7A75891B2866A7B45
                  SHA1:AEF9030294BC857E000117499627A3A61D4F4835
                  SHA-256:1148D0D9EC165788EC5CDD50AEFD2A9798F87DDFA38764ECFC0953BF1F9AB85C
                  SHA-512:8E898D7E02008C0BD1096B65F678CDBC363110539C1F2E1D1DD704258453B0C6233507EE40C32DC6A5935AEDA239D955F8816769B7778992DEA51B73355A23E8
                  Malicious:false
                  Preview:.....?q.I<.`...6..{..3pa.9..%.&dI.2Z.L..Nxw.%.....)....+..h.c$Z`L...J....nj.yM.ki...`....6...*./..\..m8...-Ef.........~e2......)$b.?........Pj..,.a.e..0+..$...C).$..Z....7..F.Jr>.<L+...p..>..}s....-.....\~.k....<......=...%.6.7..0...d8.]._.4.I......*NV.....B.=...Oj.0..'R.{ .......C.M.<<.pS.u...J.!...N"...C...O.+P.h.j*.q.V..<.........Kz3$.m...s..G....8.L..N..0^Oh........T.9.8.C/........x.7b.f[..@.+}Q...E].-2.i....1.&=+._4zQ...yg...50{.X;.Z...g.V>y.......rt.....`=.:G..r7.).=..;.Z.S.....>..a.......SC......l5.w',p...?-z|$OU.1(_-.Y1.#p..@5CZn...Q..#..i.LM.Ho.U...1"m./..j....f.h=.H.l..6....ZArA8t...m)F._.i(..6.]r,$...g..^S:.V;eL9V>=0'......>[..k....Z..{Qq.T.tjA....N......>9..<A.? }$......TPQ..+......#.Y.x.b.9...`F.[.5<..W1.-........U.y.{v./WU..W.=x...=..f.........M|.>&...........[}.....p..._b~..A.MQe..y..@.gtl....9..;}%..@v..)..n...U....!.%.a.2<...?._..!^..b..=...2.*ms.wC...o..B..C..e.e".R.T..H.......+........V..,....`{.QT....S...p
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2402
                  Entropy (8bit):7.9054440221643745
                  Encrypted:false
                  SSDEEP:48:7vP5ygv1ppXRkPVrNkhILIDhkEHD96xGFb55WtZuAph1VRJ:LBv1paNxcDhz8xGV5QKIrR
                  MD5:1DFAD355E069454701F07B577BFBBCA3
                  SHA1:715FDE235B2BCB78F2EA6DE74AFC0A74ECD12BF3
                  SHA-256:2E5B84B95538975DC06017A2D85A07E45792C6F488C6C6C6BABE10A48F677D59
                  SHA-512:4CAEB640B69521237C64ECA116F2CF8EC8175E3A6C9122C1ABD45901159EEC57170E1A8F640949001637EF742F7FF7091A6373FFD26221FE90635C2008938284
                  Malicious:false
                  Preview:".....M..."..x.kRA.c.x.".,.9.?'.(O|g}..r.n!./.C).-Q.n..kc.&.!..U.. ....P....uwm.r..Y".9...b..!4....{xOaNx......QKm..t ..)....Y.&X:cgQi..}..H.qM......Z..e#i..@Df.d.=~.h.ji@<V...`...td.n..(.=N1$..'.?c14p.,C.uW.=.=......=sF.%...C^^_q.ORa....0.&....Uf#.c'..#X.R......l.p..bC.."L#.c;... 6...28d..6l.>X.1A.....b~....r]Hk.....:..;|.E........h..q......7....>.)R.....H.y....c.7*g.Xyf...1@.M.6.^_..'.R..].G...8<8..'..r.8?.t....X...{a7.=`'p.p....s_N0.I....`....Qe...'..._Ab..J&.5.%....:.......>.<..$T.!.........].T.<.E...Z.....2..D...}?..)-..#|d..d{...q.....*`:......iD.?.`....`2.A..a.".u.SLj...I..S...X..#.5.|2..hH...x..,..w-.c~U&k..9...6G...`.&|..W..+{....,v"..c....Z!z...j...f..5....D...'..{M.g..X....p.=u..QT....S.."......H....=T..S...V....t.....;q...D...;..(".'...?..t.....R....mK.B...b.:.q..h;...7..:.H.dLc...g....Z..........I..U...k.^..L...n........X.........-.!...f...h..%vC(...K<.W..9H.$...@b<....R(X...3).a.b..?./,v....)*x..q...f..D.g......r.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1375
                  Entropy (8bit):7.847925897367989
                  Encrypted:false
                  SSDEEP:24:kCik5FQoVEwUhJHwVvVHs9LtlYOm8o+TlSbsMHi/nb51w/Wv/eNlwktRn6/OJKSu:1Hx6XvQ8tlYOm8JQbsAiD51NvutRn6m4
                  MD5:60DB25917EFB31B7BE2BF9A580F1310B
                  SHA1:00396DE28B9D88B6FCFA7A3ACFD3728D0C739A1C
                  SHA-256:D4BA4DBEA06DE0BD392CE062812A678C9AAB96B7ACA2C1364DEC280A3AC6DD6C
                  SHA-512:CEFBFFA560FD85892E42D0FB809A73311BFF67F2F647F7A115C86C65B14F0E136CD44210716E593B6E828AB24FBE0CCB20A6F614E0EEC4BA05D4DC1461B5FFB5
                  Malicious:false
                  Preview:...W%#.=......83....OQ.o..P.......}7.....p..#.....A;......5.u.)<...E.^...z/.0]..f.%K.*+.O.s.{.g.C;.P.q.Y.g#._q...-6.K.=..... .9y.J..Dp...5...E.=.\..o.SpU..}.J...k..]> ...Q...c2....i.TY...3<X4.......JXs......... .wH..)Z...C.MA..".......Gf.......l...X..$.=O.W2k.........a*?...N..<..:.K>.xG .,U..b....:*.....'.9.oe.=@C.. ...f..9h{....6[.N)...BJ..k...D..t.9.H.].E..b...X.R&.]..w.W...E+..".......2...QUiB..}J.....y...:........j.i......H3M.b.p.{y.Z .r...4`..L.<'E)% ..c..<w...@L..~...V..fd.....{.J...S...7.........J..[..K3.M.i..l..g5..zH..btO3.i.UK..{..ES.Y.7...N$>.2`..-o...`.~..6....W|.@..~t...(.x.......:<..`.KT...d.1R.d........Z....+..l...L-k....ew./;.V*....1.s....\.L3Y.-.RWnL%K..............,.~O.Q.Q&..Q....y.+`.)2....2......(....1.),-......3. ^.O...p.$..SA.t.*.....9..X..K...}._.9F\.V..l..aI.X77.{....`..gQr..8k.../....C...V......9.&....S<.X....;EF.@!@.0..$..?>.{.6..g...u:/-u.4.n.b....O....}u........4......SP.$..F.aI>.~..R1..i~\O..U.^n..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2961
                  Entropy (8bit):7.9271862016787455
                  Encrypted:false
                  SSDEEP:48:iJfaos+ofoBdNxKDpf1NAD92wExe6iy5HbLCP+t/dJPLMUf:wioRKoBtKDpf1NEAwgbuPY/k+
                  MD5:B8402C1576B5F284D8D313BAE3090729
                  SHA1:B5D07AC1E40EE9A611F1D5FEAF0C9F372EC4D78A
                  SHA-256:1E702CAE179E060FF1295A8F68A61ABE669FD94CA0E92367F19BB5ADA3BD1106
                  SHA-512:5E018F872E16B1E17FBD81739B3D7C3B873668587D832AD9A01874D3FB406BEDF745545AF66C4A59DC85C63B10D644867E5B59697A2BB6B792265EB7D3EBF14D
                  Malicious:false
                  Preview:.^@..A.f(.~Oi..2../y.d.J..+.....!'..(...y........Ij..7.G.....i..9Q..{Q....f..!. K.....KY..y.....sw..?.6..c.Lu....@..Se{].L.c.lN.5.'.'..G.....'...'{.......E$..<.=.......%.4.w7.......i.p........AP.f...v..,*........P..j..:z.2...X.....g.r.zv.........(..@..@G.VKs+.AX.Q.'...)0...9...............X...f.....{.[[j..P......nPG.......x3...p...Q`.W.2../.."{N^.....i..kk.1..R.a._G[k.[.A@.'.+..[H.V..t.....Pg.u...ur0.g...bo...]....w.f...3.b(.c..6I..|u(..%....tI..I...q......9...;.QMY.<..}n.8.......g.l.Y.N:$in ......*..m+....V.I.S.d..`..&..Z..qc..%4......CE.......f2...a.x{........A.-......K3..l...=.....%....\...;?" .;../..i%.........Y....e.2.=..AqI...+}j.PM^.......=l.l.......%.i........>\M...G.%..e. D.'.V4,.|.+...J(...4_K..{7..g..L..'M"ZCx.?.G...d....F.~..X8.u.G.J.+.-.1.m./4.#..2.^...2...._K...........~......X.v.a]..$...u..e.P......R4...,1.s-[..L..P.D....bX..w....L..>...u].bv.1..DY..]+....1..%!T......!.^..T..l@,.Q..b.S.;.7.HM.....}.a......(KSM.;2l.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2296
                  Entropy (8bit):7.9086254617583815
                  Encrypted:false
                  SSDEEP:48:MB7UQI07x19wiJ0Hx0+DmPRDyaFcGZGTo+hAjPjFW+dkBf1UyzQy6dV:MB7Unv5HxHDoRDyaCToEGBW+kBNU8QyC
                  MD5:9ECEE28FABD6F4475D301DD0F541DD1D
                  SHA1:63A18B475104838EFD2394CB797E276FB3391222
                  SHA-256:317620911B1E36B8ECA7E94A7A9A113C4AA451629835FDEE58AAB6DA76DBEB03
                  SHA-512:142C1575B670B94B8769A39946CDFE0F67DC5CDE35C1BD1A975F4645342A8B9BB1152A425F19C34B0596526ACFAE242BB1CFC351F6FB92A77687992BE6D03589
                  Malicious:false
                  Preview::..>..j[.._k.tT.V.:......{,~f.P:f -E.&.E..J...^)z..[B....f"x..lo..5..1:9..v..c...r.a.M~.!&..........?D*a*...HI.....:P.2(..6..[..va.A.L.US./.k..,l..Q.*SQ.Jn..7LZfH.....o...e....7... .[.U..<.*=..8...22$vP.R..K......s.(.2a.A.@%c.Q..#J>.!.:L.kCc0{.....K.]....'....*...".....*.D..t}^q..K....".l.h.9}....3...y\....5.8...D..(k.&.*...y...../.+....D...EK.~.+.}P..U.=u.5..D.f...M......j...,.<$.....t..-.&...|.`... ^.X...99....<..2.5.1........;.7d. ....k.A.$,tsN.1....RIuq.W....v0.~t.....,...x..T....B)...U..k.\%.ehsS>.z..I....d2....C.....Ew...$e.|0;.zH+.;..2.......R..C....Bw.L....Z.R9.5).EK.e.0&}....pE~.o!....y.8bW[..up..,..i..4".*}~VJ...Z...3.J..@.o`G..)W.K....T.c?.o.."..M.$m....0..@m.`..J.....~.4o&v...}.......tG...."..5....si.....AMLY....*.w.s....B.G!.-Vjk..0_.2...X.}.6L......<.xQ..B..k..*s.2.~.C..j..)p..W.G...H.j...W..~=.`...T5U.a..E$?.n9.&..._..m..)... .W.*rx.%`]Q.<....MSM.......su..........Y..-^8..Z...mf%8.Yg'......9.\./...*.....t6.2..!W
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM, 0x8C-variant)
                  Category:dropped
                  Size (bytes):2317
                  Entropy (8bit):7.902332182021753
                  Encrypted:false
                  SSDEEP:48:4HeSVA4oR8dfQop8Mkg0eYlQO5e/Lhp9RTuJ:4Hj6bidffD4eqNYtp9dU
                  MD5:CB8598F5554CE12BDB3E53D6EB8C2A41
                  SHA1:47AF2018476DC30E14E85ADE9D6955608B4ACBB8
                  SHA-256:01E0B963C7A708511BC8CCD2F2E3A47FF13CA2617768CF929F9FAD4875F0906A
                  SHA-512:00BB267F6826A6B246DEAA737411FBF83D1C347256D1B0F8DC17804D5FAEBCD1D7746DC260B7BF60558FBD17661869B7CFE60A850F87A9DEE386FD96F317C26C
                  Malicious:false
                  Preview:./....4e..Q.....XP..;.....#M..Wz..*.....c.8\.......zr........SA.`.."..K.......GR...J....CX..(f......3~....l.8.%.....[4...dY#...+..tX......\?..Y.M.6Xs.'.......[..q8I.....4.S..I.......]S5.'HT...G.y..+Jrr_Y..V.X? .....%...U.%...D.L.G 4..x.hr$..W.?..v.7V.....2...o../.._G.........*4.NH'1....&9.\...lFB..;...e..I....J..d.:..L6.......|,T.... .yvK..y..c.^hy..y^..@.# ^`i.;........[B..........yU#i.K.\su..E.Pq...X...k.!...R.l...CM]uq.y......X.$..?,Wl.Z..i.Z.G...6F.....J.M..g....U..-B...0'0...C].m.y...Y_9......(.e.JM/6..P;..>8.....]...D|ia$E.I...Y.-..bQ...Y...\.......7u.c0....z..........}...K^..lb..fDS5j.S5.0....w...Y...x%`.vf......r.k....S..B....*.8....oav...re..x9.t_.r.....].....m.F9.........c..c;>w.........@..Y5.M...t.S..V.a?:@3...{1..q./...w.....<.7.y..=....cItZ>.]u....1.3.P..I...3\..oB.....T........"..K||4...0.om.{.E..0.aM.u...s..KS"%t.U.....N....V%.#......c.....;.."q..Jl..{.......i.}..$..]].`...rNB.a.....X....G.)Uug.......6..E..FF....m..!.q..&...0G.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):382440
                  Entropy (8bit):7.999522369641396
                  Encrypted:true
                  SSDEEP:6144:ALpuQNIGiKz5q+scKfvzsG765iYT6lXhsqF3vieb0SDfJLgGjRfG99xxJI:guwIq5q1cQvAGuV+lX6qF3rgSDfJnF69
                  MD5:3280E381461934BFFDC31A231C1259B5
                  SHA1:429EAFC3A7A2BF1229BB2B0780209F6BD913FF05
                  SHA-256:9F82C53A356BE12D12A2CA787073CEE9FB0A3DB3E00C7FBE43FF0FC330B0F2F7
                  SHA-512:CA32A1FA8B533E7707BF4B873B7CB5A6D9FE430CF30EA78AB837FB8B0D2426AFB6B769CC941B805F2C67E948AF2214CF0BC289EF6FC1801D922302BB83D20E7F
                  Malicious:true
                  Preview:...e.....}@...K]d?.9.........Eh.......s...W......q..p...t?K4Hna{....n.}.R.. U..T..i`.....l2.............`G.....Z........!^L....!gJ...c..W.......<.&(;.......7#H.,{.'...9...........;.3.Q.........N.o.6..?..X\..Z.^'9!....IO.y.t.h.T.U...r.b.Ma%r)}...@...||...H".*..7s..S...:...ig..qb....D..u...H..qe.4.....a..V..S<..I...:.[j..f(...;@.=n.`.K...3*Tl.p...^,tt;=_&....1JB...^U....o..K..+.I....z~.....c.+....N.w%.G..-7?.W.-.....-d..Fv0o.r....>.rG-..e....q\h.t.a.z..|.r...+w..k..`"...U...B..0...nz3.n.s...4-.az.....-...t.3p$...V..`.*.q.D........q......n....<....R.R/.f..xw.-._h1.S.?.At.?.. ..<..MZ...,SC@.i=8s....b..j.@......3.y....p..J.L...k.2`..........e...Z.#...0g.....FM..`....E..u.F.=..'.<.:$..*............G.o.](...D....S.........r../n.H.*.........z....P"...n...8y..{.....&T^H.i..B..UT.Qf..$.R..%..w}kt.9..y.3.rN.....>.E.....(..'|...Y......'.....B..:................p.0.3..{.?q..._.{.=.5...0I}.+...w.,J...6...R....[[@..Q....P.Z.C...(.Ey'`.)-bD x...v.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2882
                  Entropy (8bit):7.925736991590982
                  Encrypted:false
                  SSDEEP:48:TM8Gk6Ng0EHKl3BAWt/kFgFYGGBx6RlDrMz8TcN5er/oDFaYrMjGnxuVjhz1:TMI6C5qBCsU2rW6XDZ4NYr/wFaYYjw4R
                  MD5:ED1211E74AF70FEA9FC23E3049400C9B
                  SHA1:FE3B40D1A79ED6826134935FBD9F79953075E818
                  SHA-256:A18FF259C83A3A37C12E946320DCCF52829A1711C5C1D5C3761EDF1025F454EC
                  SHA-512:31AEF80290C61249274A8C9F0234D9B97E4173EFB27C1E4F0553D61E98C892AF0878E0C55A4085ECDF38156AEBAD684FDDDCF85728193D7D5822F7B16775130F
                  Malicious:false
                  Preview:mn.@E.8qeu."f.........p-M-.h.W......e...?.P..Ev#...s.G./?K>V.......U}<-.>O....c5p.U... .o....K*...)./r%S.3.u.........Nb..U.IC...8.M..............n.."..'..ig..tn(zL..4..j5....@....j...O....H..]...Kw.4.S..f.....*.-.G....6.So?...[.e..!H].Mh.d.O...V....Dw..a]`.....7:J"f)...w........,.B.v.n..9.,MW.........K.............f(...e..5=.!..u...N\?...;..8Z..v..!....... T.....C.Zz..68..q=...b.......;...uY...;...(PT....;..R...)..x.M..../..~....,...j.....C.f...A.........d.p..x.H..P...L.w.5ZTT...=.^.DNgG..../+..1Y.7..a-~....@&:&...RM.c..@...Lqo...h@u...2..l=d>q.......h!.M...h.3.>.K.).3:..&C.y....g.w.0.;f.A..*^&..G.:2.........u.X......'.;.l.j@ep.i..U..a.o....07~23\l3..l.u...t]...W.c...Z.R.9.8..A./$..T........v%.p.6e..Wj.C..V...@M(......'Z.....[.u=}.4....%N.W....\...JsI......,....0...E.{(5...l:=@..?.|..6.{...a.........S.s.&%##.?\...L.......V|.$.H=.2..j..`.u.p..@5..2......j.........V...)...l .4.Y+O..^...W.S..l. `...V.K<..|.._...0......%....w.O..!..8.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):962
                  Entropy (8bit):7.735188881245371
                  Encrypted:false
                  SSDEEP:24:F55uBGlk91ru8lqv9N/R2z1He+jVOU8MC2dtU:zUB7jKNRCBVwkd
                  MD5:DC681673811D7CD5417CB088B40991C7
                  SHA1:25DD5EED01F9F520FBC1994232EA156666AB9405
                  SHA-256:E3A906E03E57E83F3F6B64363FF8155F2A7C187E9A8BC8248B339AA7CF3886B5
                  SHA-512:727023BD140C864AC37F0A81CF92C12C0BB6CADA52611B64B6136164BB157AA176F6B13754D6AF6EE99AA9253067CC3A3C340187A622A53E5620B160F0717CF5
                  Malicious:false
                  Preview:Vf._...b3...=...#T..Z...X..p.!%nd..?Kd7...v....1.'..........x..-...f...X....X.X=W~............@Ht.[.:......C.....|}...H3.K..>7L.5..`.....FV.).sv<kJ@.Px.o......~....... .8..'..:.6...^.....L>Z!W+...C..5...<.t...H;.e..."0.]ny...Z[...u...#*.G...p..=....A.K.....O.3.;4A...T.......$...?.K..<.G}...!..a.-...Z.~...k..b..I0y1..R.....h....E@.}...dI.F/?.......b........@.VP.(..I.*......bIE......f./"..Y......|.>m{.....h..x.vX..^\...We....8..c.G..B..m7&.L.s..b...a....a...E#.URU.o..s.L."._`.........'..y|.a.@.G.....e.:..._..VPV)...NW#4....B=...m....&.C..f.o.....R........8b|..8..JM.1....E.....gP.44h.g(_..i[I*..<@A..1......G...8"{...d.3. .O:....;{.N..#..h.......!.&......n.o.Q.....+..&H[.......a[.........J.z...k.}jYbm...J.w....D..IM..[)xV.<$u..r......h|.QN......j..#.f......H6..x.M.(.n=$.H...Nj......:.L.;....-.&....,).W!T-.C3".......D.._#BE.9K....k.1.&J3...]..Q.*.S...lX.RZ...KS..?q......o........"...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35973
                  Entropy (8bit):7.994728721785413
                  Encrypted:true
                  SSDEEP:768:sdBUnjnqtl6XlzEEMxr7J9K1fbgaGnLv0duaOpST/hTnDOALeaqlk:Y2njklaDMxrdufvGnLcdvOUlTnKLq
                  MD5:D638F0EC2F38D0009AB7FCD1ACD581C9
                  SHA1:0CCDFF7C91AD66DC908C6D6B5D4D4C8DBB6F473A
                  SHA-256:AE4FF26F15CE99588904E338B9EC84D6B195730A4BB81602713DADFF6250D5DE
                  SHA-512:88BF520AE1F9196FEF8F6B810A2589F152191EAC706C86EF4229CF5C074C132072E2BBBDB2B260AC17BD6213D3E9B4D727F807475B22CD6345347DBEBA636F82
                  Malicious:true
                  Preview:&...Z.G.a`.F.O...K.*..-.E..a... ~"..Ky.....R].|..N..zC.w..6._.0.F....\.r..Z_'.^.U..../.......<.E...IE.p...+]....U.G.IJ.......\l.B...@j1..[BI...z.B...F.c[.......r5.U..b..'...a..C~xK...=.0.......A.D.A.O..........p.fI......o.....RL..vE.......~...c.7kz.*.O..!."K....4....^...)......t}m..../F.../h..l.f...u..[..s.H.s..9.U..~...3..A...Vr..m:._....j.......e..?.qY.......$...f._..`),x.....7LQ..zE...#..0o...[4X.!.B.....?B1..z....9...~.D<..X/h.....vA....:...q....|...$...t+...!...X..x..\..o....e........{YM.@....s...U..v.yMB(....z4...]j.R...~...)..L}....."...T...d.^.8..&...Z..$..5<L*.........;.dx....D....F......PEU.\..2Dph..5v.gQ.d.5..r..>...]...p....].|.P%..f...n.c.z.V.s..s....K............c....../.l2%....W..H\EH{....>.g...u.....n&X..f.7.GL..'.OB..$...HR..7.?.:E....9..%b.7.g.p.6.$...(..U..]..L.m.0zj.,.Ga..*]l....;.F....G...8............\..#../f]...a.o..$..{.@cd.D..Nq|.|P..3.g..~...v...Q.f.j..]..^..I....9^.;.6g+...\.......&_.W<..i....B..6.`.....hm..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1068
                  Entropy (8bit):7.772435203647367
                  Encrypted:false
                  SSDEEP:24:9fhFDXpxAkWqQUBGbd2EjTuCCS7tsZyPW9pfaZS:9A3qNBGbdaCCSk1jC
                  MD5:602738E476B171EE320832CC9F59A8CC
                  SHA1:172913F3C9CC734E94486FD7871AD340D3B0EA5C
                  SHA-256:BE4ED957368394E945C7B251F6B21D13F72C935FD609218931227377732F932B
                  SHA-512:3533D1E66CEBFF52A4422B81963B8128C0D2F828FE074D61A523F3552AB08F06778AC2FCD5CF4C93F53CA07B02082553C8373B83D74A48C522C7341AE9450480
                  Malicious:false
                  Preview:.sWG..Ny.s....6|).u4. ..d!.$.D... +...X.0.[...|..gi.P..}.9u.%}:;.q..5....A....&.s-8\`.....T..F....D.f..I....W.0..q........U>......|..Vq ..M.@..M....U.....ex/.z@....g...3..w.P..Lv...Pz{..ns...\.W.r....(.G'......j...`X,.......)..X....r.Gm.l..&...OG...q:...)..............WEE..e.u.w...C.=kt.P.m..L.,.U.T...4z.....u.vv.x.. ..MI2h....l..F.U.....@...P.f~.....=9"B.0Uq.q.......w.....4#.(.x.<\..Gn.. $}^......_......k.c.G...S.C]v.X*.....$>..7..SF.a/.Ds...0..6ri.q...._.o......$..X..z....^(..IS.8+.T..K...?c.bTQ?.z"w8^.....k%D#.?m..#...6......v.e..`Xx..$.m....m..g[.d...A*u...J.N...6.Qr~..`....'^7.=jE^.`^......7.E.XQ^.R.$/_......G>6.F...x.V...B...ug.x0.f.I....4.g.D.B!....M...{..2.~mi.zs....:`.....1q....qq..(...O.5.....c.rX$X~......Mk.TE.....M.nw+.rV.....zV.b..}.:.L<|.K..Y.#...s=R.LXJ..!....",.....A.M...}.O...g......R9G9..3S.=G..B"m*9=...2..f....]..i!6B...B|...k.J.9..<I$.d..b;...Y...*.w....Nv..[.............dJ...H..l[........G.^0........E...._..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1353
                  Entropy (8bit):7.821465590640367
                  Encrypted:false
                  SSDEEP:24:PVNjEb7T/7Dximgq08sK3kv0eWN+niHw1JBqC9QWpk6YsuaLSt8W9a:PzELTDAmSK3VeWNJHeTHKYkBaL
                  MD5:1DD1699580D90A132FDFFFF581F6C48A
                  SHA1:9375E91DD7B5E4501829ACCE6C7C790A79B2AB1F
                  SHA-256:27FE5D9F697977ADAD359C3E97C567428EDCF6FE52C6A25D7B61A1B9A63C4069
                  SHA-512:97DA96AB26A6751CFE1E84B835B7D629AB8050841D7E453A0EB393A010265CDEFBD57C3299C90B1E28A262F652156B70EE9DE3F107DA281C080566E5BFD8CF14
                  Malicious:false
                  Preview:.6.......p.k...UR..+.8......&_......6...q.Y..vr.*..K.9..T..........1!G!....]....7..R**.T.vg.@H..3.?/..dqQ.u...6.\G..(..T......:)o.E.UT.E.h..A..p'....k......7x.$....W?>;YY....-...@.~...d..PL>b...6}.Z.Qq.|..l....~C?tkW...[.<.."..cx..j..i.W........x.....Q......F^<..[.......M1]..r.hl8.}5....P....7.4[.b.\..fn...0..:............Q..3t.>0.%...}....e.".Xo.....i.....F$8.).B.........s.Y.".",#*.'...._A.].j.`ntJ;.bqL.#.k....um.w...9...e... .h..U..+.@..88.}zF.n..........~~.Plyd.L..2....Xo......?...p5)..jLX#...'....p.0....;.....k...oF.G.s.fn."K=..B>...n..z=.p0..>.<:.... U.&..?.2.O1w..... .h~.K-.+..:]..*...*..8;b...'..1j.9.*x.p...d8<.S..C....O.2..m.B<u.XKl...0^7......q.15...;.l.2...q.aH./.?P.._....$U[.L...bu......;.E..`!.K.K-R...........S.....iX.<....#.'.KvYt~.....`.....sz.Zc<h..K.>.$|s..Iz.FD. ......Jv....n{["........JV(^}.....l......G*V....~...H.D..S)..........\.Xx.EVk..P.&..*..$...w.-'....t.....l8\.....R.3...+yW...S.occ.._i^4...H;y..@P....%.c.q..-..?(..e1r..{..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1350
                  Entropy (8bit):7.8309953635556555
                  Encrypted:false
                  SSDEEP:24:LRNbkTPtZuz8uvqC3cep/WiivS7AZNLx8xQIdb/3khRpDrAROcZwC:L0xmLcep/Bi6ax2QCj0hRJrAROci
                  MD5:D1A02980639597CDE6402AADCFF19A5B
                  SHA1:C9E8FD72F630F4A2533A8BC3629E6D419656BAC3
                  SHA-256:B487D0DBA01D7547F423133B644D8E653B2C27781397F7FF8FAA67A90F59AFE8
                  SHA-512:F275F982495B53A549F44D2CC8D819C1E4D55DACA7B17C9575515EA4BD7CB537F01583FB4348B2BAE06E4237AFC55AC46CE851CDC5CB4258E7C4D3D4F26A5018
                  Malicious:false
                  Preview:.K...K.R}....1..."j.....(...b7..3aL.P#....>9K....r...'.P..W..OA..B6.t.}.7...0.$^....E.L.v..hiUH..m....V.B/..R...........}.e.{E.i..b.YjM"....[..BN../.'....{#z.%..x..+...:^5.s:.........WV..F`.V...d._*B..I..../..o.k.~&..Kx/...X.....Y..f..d..C.:......A.....*f......Rc.y..F_6...L..,W.x.".K...T1...M..8..s).......2a........3.......9.hFPq..M..[kV.j}...1 U.;..P...o.`1...+!..K9.h.g...dW....v....(...%Z.r.(.}<|N..I.j.......[.<..P@.#.H..:..t..7G?)<!H.G...4..I....+M&O.&.\^.oB..2X..v..{.kzY......~={_....}.<.b.*/..?T...SBM%m.....D.....x.!#H.&.?I.iV._..z..a>.2...e:.[M..OEK|.;..@#.CX):..... +T.i.c.9p ............[#*D...6.l....h..../}G...^..*.t.?.v.n....3....q.5.+..."N..hR...d.1..{.w.Y...g..}.2....he.E<...w.,.%.-\2.N..a...@...U.}V.i.I.!..V...7....O....x.H.....#...J(UW..X..tc_e}.LC...m.6c.Rw..z(.8a..$`..Q..t.Q."..q.....):..>...8.a$\.<......U_...PEm.1.Z...PI..E.Mo.8Yvn....ATQ..^0Q.&.._...D.b.........U.;...H,...k.h..|zJ.^.'.<.Z1Y.Z4}A....f.H~L.5./..."b
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1731
                  Entropy (8bit):7.874266077881066
                  Encrypted:false
                  SSDEEP:48:nK4zWKRDpQMnG/4WFjHADIqrwqsbgs8S3:nKOWKPQKW4WVNq6gsZ3
                  MD5:40498BBFE87B056A5D2A604F06FCD311
                  SHA1:1E155B341A373D1D498459B1969FCFB3546D7AC6
                  SHA-256:F371702A74281D527780902B737DAC309077F8E09AC281790B3814133487E652
                  SHA-512:4C95FDDBB56F10934ACB9060F4379889546FE3AB3117BC588150935C5A7F237587F889EB95FEEB39E8095D488A54206BD073B90E715D94CF27F6DC42FCFA51AA
                  Malicious:false
                  Preview:..z.#..J.%.y..H.,.6..(.M.x.Q..=...{..S..7/...(......O/zSL6Oh.H.K..b....d...[|.$.....M.....^.I..3....G..~............B.E].6.$h.-k9&.....?7.y.....(..e..OF.a..yzc.x|r..U]'...~k{G..A.8..`......!%..X...Z..3!.H.9......(l.r....R...&G.FZa|!.....#..P..z..C...D.8.\......sow...cf...f...2d......C..bF@..Q=.0..B-...Q...s..jzT....h.O..b.t.lz..6.-.j..W..G.d..[...8.Q..U.......g... t.n K.z3M.D0..D9${.h...*....X...i.8..=....*J,.u....1{)......Q...sf1..6hZk....:}7.zw_B.Z.....t)....>YQ.1...M8..,E....`...........{.h^......|!..6. ..:=.S.J41.....w.<..y...ak..X.I....T..Ts..(....Y...1.I.m ."...x.I..Tq...H.S...g.z......Z'..lo5.Q.YT`....7...e\...O......(~v./.]....C..+..*..1z..#T..F.r`..75.#..V.\.T..t+..>... .:.[]...Y..W.+a.c.K?Y..x\.=W... .3".,.....b..t;.....L.d.v..-...5B.L*S&ssq..}..Y...$..f..}.M{H.........(.F.."7..|..Huy...FK.C.v.....t fT....J...)..........b.%..O.1...M.!..%..]Rv(.I^.5.b.....<.....QU....."Y.H.5V.....I..O..4...W|..c.q .*.."..J.;..........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1728
                  Entropy (8bit):7.8792301913028835
                  Encrypted:false
                  SSDEEP:48:Igw3Wzz7wC1FlA4TJ7weqK5rnStBam3Q:wWndLA4S09
                  MD5:D93B4089A2C03FDEF8DE829219C9C9E7
                  SHA1:3B5A9853D20BB5244ACBDB82C32F339063ED248F
                  SHA-256:D929D2EDBD036C568F0EC9A494FD23DAB8B825A89DB4616965DD729A243C710E
                  SHA-512:754F987CC3EAFBE8500FE3B8F6D4D465A8F4F04B8C8391A62786ECA7366418C521902288BA6BABA51CF4EFA4F9412E9C35E6ADAAE99B957B9E59B46A92B3AE44
                  Malicious:false
                  Preview:?&...T..a.V......!.lQ(....=.V...~t69......0.Q.E;.....e.g....C.j...&.Y.i...`..hqy.rs`3-...RG&......A%9@T..bZ.......sj.c..B....O}.y..E......q.f.cn...p..%P...'..h.:.....1.$P..T.u.4.!:.wJZ.>D.s/...s..@."|..w{.Sg.v5s|..."......E...o.].....T...!u....r...c',..8Z..t...........m..a.r1.;a". e....Q..8/.....DW.f....9*.H.fL.........h.q....g*.\....4...B.6.Fc.Y|<...1).FS.f.A..i.-.5..t.E2_y.j3wo..........E..N.v..0>.+Eo..%.?...%.......N...2..d...z>].....CdX.Z]'.K.sMeu+....!. .-.....^..6J..O..kb...]M~.^..[q..>.@.Z-2./......s.f.?.H...;D-.<..y...B..2.e.P...yw.-%.\e.h...>.[...6.....3.N..T.J..d.7...`xp.P.;.....G. ...;....-..{.4.P.u..+....k.s........f#...M.... ^P....m..mZg..H{.7....x..!.12D.#S6..).J.'n8..W....1....x.+*1.....;.fh>..TCpa..{...9.;N..&E.U....y.....`..B.-e...xe....L"n!....C........E.=O...72.....A...`.#..hn..k0..xj:...J.r..u*.P...|.].)..-.Y..[....W...t.#..;..Z.s...%...b.SF...f'..1..>S....S..=.O-XWS<X|."..L.yG...$..w...9....h...1.l..n...s...@.A
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1095
                  Entropy (8bit):7.773236787107812
                  Encrypted:false
                  SSDEEP:24:4mUc6qS/VMBRWWrzDBpcMc/29nVdnS0bivWfUma6Y8kGpjnA:bUcCoLztpc27iSUmaIkGpjA
                  MD5:0077DC7183C37C8C9DFA1E74CBF46AAA
                  SHA1:32784D6ECB491D03F806AFF5D0C4D4904E4A1E86
                  SHA-256:5307959C7BF0EA4A24755814CA5A273CFB386F3235873523D64493FD02D9BFE1
                  SHA-512:B5F3B864D5313EE09B2BC1EB1B5E557E146761ACA2711E3A18D3B195E63B8E38AF0C14E3B3B15DE5D00F0BFBA0B159EE30EE2609E090CB155EAA7877A005BEE2
                  Malicious:false
                  Preview:h.|._y.1...:...c~..~.....op.T^..[.i.i]hw.;...e..t..\.h..h.vO.?|...s./.!F&P.....R..w. ..3Y./.>..Vj....0.v...5.=.....Sd..8./..3w.)_.s.u.m.4...P..C|...+1[%W.%....JF..R.v.O..wb.B..k.7...%..._.......~[_/}`...B5.#@@`e..i{...\.Uq.z........y...4d|..5.....K>N"...O.J...`.$.7z...3..?.2+eG.:...[Q..CQV.<..f8..J..8.pe.~.Z.L.a..K..13c.y6.V.K.@.....'..........3.R.or...T..2........&O>....E..-T...p;.+.....)......C../.v,.te..%.Q.J..B..{-^.8..%....c....#..7iO..v`....W......I.6.t.Y..R;q..8:.X....LK.p..-.......q.w......yHR;p..)....s.B....Vtc^.|.rUP.ta!.l$...G....~.............]...*.=.\q.ly`....u..b.......8.U~h.nk..8..q....c.dy-....2.m..b.j...%..|.....a..&.M.p4.8h9..M~.za...U...T.h...(.,+x.|p..9.qKaz...8...:...j.G...h"..m.g&4 ...l......Y....If2...5Q...04.Y5.........8.f..U5.8.(..V...n..b/.CL..$...?O.I....aM.%..AL.b....&yk".t...bUU..........g+..g.i....z.o.........`.c...W......Tb.7\3/h.fC.5..&Dz.....Z_.I.......&u....%J.....^.,..;..E...D..x.c../;.*....../.....P..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):650
                  Entropy (8bit):7.58245708421621
                  Encrypted:false
                  SSDEEP:12:v3Z2aihxOzbSynaxYGv32m1xoIWXYr9AhehdWAwknD:fZ2Ny2YGv3nGzoZAhRpu
                  MD5:3890D6FFDDEC6DDBEB5958DF0BEB1FA6
                  SHA1:A5191AE30B4DF24148AB7A27FA810193F0A72837
                  SHA-256:DE839C5E86FE0AF6132E9C306C2DE43D58E839F607093A0DB16F59B6E4F93189
                  SHA-512:7FB933DDDDF6935A77B5A334782085E880575E5762211E689070A55A00FD52D95CC583BD6E6AE9286D45982B6465A7570810122C9082776B8CB39E19F576B807
                  Malicious:false
                  Preview:...$t4.....i..CE...n.j..J7.].....E.?dK.}......8.T...P)sg...`.ZP&...T.[~..+...1,....x.r.....s..'.f@.....w..O."vC......E...q..(.[....7..a.0..-.Mb.../4C.o+.WQ..C...w.6.p^u......k.S....s\.?-.P..kv. .].x~.I..V.jC...R...8N..D.$E.$k..P....3..vp.....m... .B .#..g;.=...I.c^.F......W..5...O...5.`....tx......-Ewn.@3.1......w.:q.,..l....0..=....q...g..8.....a..3.....C.......\b8..Qj~......g..:..e..^KI..2..o[4....*..9T......k.4...|*^...0...B.i.Du.(.<D...ps.].........Pfx..z.._L.(Ux;.UB.].-.`....}..~"....5..........t.....MD{.3.$....R...B8C........u............5...... ....W()e.;....=........gV`..@.*........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1550
                  Entropy (8bit):7.838414002823017
                  Encrypted:false
                  SSDEEP:24:iIqAn3ROxnucbvqflcfkDCQvBxeM92wIIuKjDcZIJiicWDZ4ruI5ylpr1eI8:BgxnDqdcCCGeM9RVjDcabDZ6aE
                  MD5:A8298772D09294B569B7BF334AE48277
                  SHA1:44B885A8A00CB70994D551E80376AA3792B09202
                  SHA-256:09930E741BFECA4D5FA2BF4048AD347B8456D5DE8C51930DD4F5CCB73E2A26FF
                  SHA-512:41B87F947794E53B0ECD9D3F7F57142B93076A13771D335C6C4F32FE1AC787099E448043E004A0EE2822C9BFB184C2CA3820BFEB1C434CFEF5314B3A6130E905
                  Malicious:false
                  Preview:'{..{...W!.7+.Yu...7..S.. !.,%.....$.<R.....t.B.]..~..@.TQ...g..KL...G0..z.\....^.....!...]............ &]s......L...x...j..y...,..[.......b?.y.u......0.Q.n..s.?....q(j.P~.G.?.C0...-....<....i.....O..o...._..A..b>...... .^...f..cr>z..c......Q..`....F8v.U..../...A..HC...q...........=.r.wk.OS..F..K...O...Bq...'.v.....Jx.....Y.@....dX.^ru.t.[;.s%..Co.[jb....+....Y..[..........(..kY].]....$C..[......o....QR....Ur...z.|..y=.."R..rk2......}.....a.<.....P5D...~.x.......\R*'...yb.^60..w.5...?~Q..|....0]..w...G ...iV...n..1!rZ3'...a.'.v....8.Y...c...."Y.w...y.Qt.....!{..t..j...Y...jq.(....gl...8sU.LE..a.n.....w........9.|x..W9...Q.`..:q....A........h.qC.).G..e?.L..q.T..[.V!.I.9.C.o.P.k~s.e.Z.k...Ea.A/...Py)<S...#.....i..`?!J...$.5.....,...v..?..rLeT/FoA.@L`b}.1..H....&d...2....-.;.A....=8^&U......op.K.).......q.(........^.H.h=A..e3.=.$.._.......Y.pXp..h....6..a.......{...f...(...{...hKUy.F...a...t>....7.M^5B..#..2[j..xR....Y$..f..U. ..^t+i
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1550
                  Entropy (8bit):7.840595381246026
                  Encrypted:false
                  SSDEEP:48:sDeh0s+2kySoHtqR6g+wRNJhxpCoF48v:sah0slfRURC24s
                  MD5:29B739581C4E3AC74792EB4DF6DBDE3E
                  SHA1:CD9CEB2CB4C7B6FF5BD741530210F2EF6968BC08
                  SHA-256:D84D3AC2992D685D27F11B025B994E1FA9D9303F1A55E698AB3C41FB4731A607
                  SHA-512:2A15C3F66F9A78DB144B67D5262F3B92092C8A0905095ADA7C8A6060103D66452E663EEA00C4DAD4919C46D6F4E1E38D5069F82D1E43CBEFE33734E067A613B7
                  Malicious:false
                  Preview:<..-..*.::E.b >....(]57..O...[...l.]n......u.'+Nf.....B..Vj.o..x.@v.....9.p.~..v....xP..K....u.tC!......8)AKX61......^.`..............E6C.=.....Y....{k..y.H..6..*...ki...5..1.O'.g.B..S...)g6En...u...._.^S.&....).a...S.r._.T.Z..N....64..bW..z9t^..3.....$...c....=.W..7...3.v.2.....s.s0=7.../.....k..}.^F.{....j}Z.NR=....s%N..N.....;.g.F...pk.....A..ujg..+.]..I.M.5uR_.}Z"O..P.Z.xC..HA.#....2.f.M9.6.m.;Y.;]I.)..<..[...ZU[#.|.......9.+g........{.U...E...<.5....|.lQ[...C....qd.U.i.....|.FL*u....m..8..W.io.....9..)..........2....W.q(....n.D....8QcJ.l..l.vv.......r..<#.....Jvgu..N....."T.....-]....B.L...].|..tp.#g...;.\..l...W.o.......3oQ..Bd.+`{.IjD5......M...X.TqV.:._.>.. .q,.)^..D$..X1.....[7.o....(}.\...!..T.[.j}...&....5_10x.nj......<MZ5Sm.."....4e...L.&.rF. P#G.. .....YP\.F.x.:@.A..T.....9!*....[..>...{^....U.(.*........I..y.m..a2....|.............Y.U.[.~Oy.7M...<..X.-q..)].*.izP.K.Y...].).]Z..7*.K.4?J.>*.".m....oHS-?...8.V?d.6G..29.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):329
                  Entropy (8bit):7.10315274103425
                  Encrypted:false
                  SSDEEP:6:B6vysvF9HD8jISwt6cCRz5UEGT9iCAb6YFOAmlXUc9hcPTjOpE:cZzIjIjCFHG9FIJYrtURPME
                  MD5:652CA5ACABD139014DDF4E81FFC21C72
                  SHA1:5B143197E7D31CF7B393827A23B604FAA4DFC35F
                  SHA-256:2E6EBA5EFA2163204EE8165D911E2193FD4E6E1EC3EB4904F95FF1BD76C12A3B
                  SHA-512:CEC9D8BD5D2B77667E6CA1BAC16A6DA93EB4413DD167DA1EBE10BA854BEBAEE01BD71B6B40EF7EAD62AF1EBC1F2FFCD4C2381F8AB80D793BE79F900FE494E4E3
                  Malicious:false
                  Preview:....h.-...x..|.]L..<........|.9#uJ.......\.u.Vooe.._..u.R..1Zd)..*...:...[.%..m_.so.............z..)...#..8T...u2(h.Vu4..[.......P.q.,.A.a/.Y..Z..;.%..<.....w5.O;Vd}K.XA=.M..g.q~OC|3..m[.W.$...J.NGd...y..E.k...>a..jr.0>1.........A.....ai...k....D.....l..Q...{.../.I.....m..4)..............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9110
                  Entropy (8bit):7.976291588628652
                  Encrypted:false
                  SSDEEP:192:/myU9ShlkfCmY+HlhXtMxZVCLtBxg68q/niZHv9BA/sOXRhaLxwglh046:/ysh6Km3hc67q3uniZHv9O/sOXROasx
                  MD5:F2476344C6EB1E6AE5173E87C94E9116
                  SHA1:2CC5D757F58E5ECDCE740750AF58B4BC13A480D7
                  SHA-256:729F5669BDE76E86C89FBCF9A55292924B2DC4A0030D7C2EE7B90673E16D6305
                  SHA-512:D4F5D46F95B113FA98C6C4D0DED63AFCC9156678F0A1B36F1D2FB55BB485157DAE9E8179B02E8667AB9CDB651430DC58982AC94E5A856750F5205F9E9F4EF350
                  Malicious:false
                  Preview:.W.....g.r...PxO......Rn.Mv..&..l.$.<5...f...o..*......?i.j.&\.f2.....Y......jx...I...p,.u.].=.j.=..S...1..o.Ju.....GAY......^...|+.............&..aD.`8....y.....*1{.c]}....r-.......s-..x.,_.v'......B..XfGR.34.q....c..*\Q.AVx.r.'..U..e......8.c\..i...G.'U/....1=.Q&...V..p.j.v.XE.f..)Hd...l.G..'.].=. ox..mT..E..x...S.h..@./.w.tT.'.[.Z2...YO.......;"...R....mGu.%.\.z.u.[.s-.N...@..3.x..zK......+..A. jmy.x.....w.{k.NM....&)(.i_4...A...Kwy.].=...X.?%.6.....3.[...{..;.....0%.&.g\e.[.G.".^.'..JhR..N..:.g^.br.0A.....;....-*.TZy=V...R."...m...V..{...W.W..CK...-....".s]_.Z.<......+.Z....p8....r.q.zD..b1..Q.NTIj...LxD...@m .>=[tb...J.<J..c0ua.)QU..V... .......?...g87....M^..i4.$....l83.b..M...0..!...aVw...MT.+#.f'..N5O..9...s........)...........+.%.#....}....d6'..D.."n..6..y..H.[.-..0.d2......cA..}g/|CS..U..w.s.DA...6..F.....@.M8'..+...|........9?.c......^.[.RU....q.j.Z:K.........k..iI.*...|Z...Hacp.M8..N....}.....8..G.).y.....A..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):18937
                  Entropy (8bit):7.991017476370911
                  Encrypted:true
                  SSDEEP:384:0bhxPuhanBEd1ERsT3GVyR0ybLhuN4AqNIOF0+nbY25:0dxPFE6BlmNPiOlbYm
                  MD5:9288445EC2B082B8D16DA6A0C139D58A
                  SHA1:C47AB8385E7AFB7FA0935D3DC2EAB85432BFBFD2
                  SHA-256:44A00B3D4B704AA264536A299E37B39732F81347E1BD47D1BC05CA9895E91F74
                  SHA-512:7C7603EDD585118EE87470C24F9E86F7DC45D6CBAA7A324F7F79BD708F18B220646216F04DCB79675AC955C577A8E01F2C5B6A8E5DDC123712BF69698744B180
                  Malicious:true
                  Preview::.t..........^...xvjz.4.tz.N......X..w.0.v.q.......,....|=.p]!.U...3....l[..Q... .d......h...gyfk. o........(....{.B..3...F.j...B............G..J...-5.2a..z.0.$....w..8..{N...jb..........!..X.!...pH.....|."..~...f.;.y".s.9QY.o.*.`0.$..75.....ls.yV.U.g^.W.+*...........E%....Q.w6.64.5.N.b.J.2....6...z..4...g..#.UqJD.......y*...&h*..i.c%.M....J=.o.S.......k'{..,.h.....j........l/.........!S.e....eq.=i....u........0I.QJ...b.Gs.....j.`.'..h...jye.....m....%..{....r.H.<.d....j...."..u.u~..PK....p5.R...{.C.R..9,.<..Hd&.j+t%...Z.....g}#)V..\...a..x.m.H_CYX'<.5.".....Yn;..[x+U.;..!.Ku...j..inK.....}Op.-.i..qq.0.(...H:):..Ej.(.S.x.{.......^.....A<..T.K....r^.7o.'x.c&.B.\n...y2.<..:Q.....'`R]..n......X...R....1.Uu.2X.I^.i...'D.....K.%N.A.....JY/.iQ.Vg.g....g..K..n`...Z..LjP<....l...k.K._...?...5Y$.8...7.b.7u..3.:g...om...Y.Y.....Y..E.W.;..u...]..Vb..W.S.eU...D.a5....:wqa,V,g..E..gk_dy.K..G]z..5. .?..d...".`..a..|.....f.\@..q..3Z$B..}22,
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9343
                  Entropy (8bit):7.980573236736151
                  Encrypted:false
                  SSDEEP:192:rziHKTkvdHFk0Wv24RsTbunw7yoNIDTh9kCzzdz/iM3/myaZPk:r5TcD4RBw7DITz/nmyMP
                  MD5:7831C378D1CD73BD9DFF2DED3873B4CA
                  SHA1:F2C9D250FEC160C6A831E9590AA77624C63A6AE7
                  SHA-256:EF7B11B266A41474C696B86C136910E3FEDDF750078610B0D1459C90887A8EBE
                  SHA-512:26E02DB5EEC0AD15A0D429A1C3DD7DB543005398BC7F217708F8E639324832FE6625217D935F4DB045927158D4874AFA13F489287EEE385B2AD6E95EA72DC979
                  Malicious:false
                  Preview:Z....`-.............y(.P.x{.(.K5L..m.....n....@@..E.(...~.yS...5....k...G..7$...,......g$.._........J..a..IY.<..!.l#..p....d..i..:>...$...y.......!c9.....A..2%.T..@'T..b.A.....jFe.[$.;..n..1.Z.....6I.......=z.n.Y..W..&..).....=8.uo..3.........7.GhyG..;..{........}.D..5<.2J6....j.../.....0.l..h.._..g. U....V.M.C..u.O.v.`..b.....v.&3.."...I..K<.....`....<....KI...S.g......~...f.].`K...M..4.Z.zOU......56Y.sk..z..O.L.....Q...j..s..v..S..;...b.K{..e..<..|..-...9R..4R...H.C.y.....}.....8n.-.'....%.:.{.2uoF....9C..o..l.....z..\.tP.......E...S.M7.......Qu.Th.)..S..'....&.?....D....48K.....X......a-V....*.e....5..I^....R.-..\.A.].....\...w..#`.][.s.q.....}'l?..(#.........f.^s."..6:v .y..O.Yk'..4...4..J.`r.%9..l[..e.i}.....cX.K......u...8...]._..&L~...\K.....p..:S..Ak..`..r;....(...$..=#..F.8.Mr.....m_8...>...j........Z.\Q.n>.....UUG14y.<..sR..........EC._WY..a..;1.`P.....h..bd....ph...Z.U.....\2.=o.....W.w......e..j...K.|..h...#........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):19396
                  Entropy (8bit):7.990049038908773
                  Encrypted:true
                  SSDEEP:384://lQSLag2+3JiSZW46fihxCpKCX3CVaBfDZsQTGGRU+jEmZ6gk:9Lag2iJtZqfiipKU3CVaBflNT9RTEQpk
                  MD5:5D459CCB6095F05A6D65BD23B724B095
                  SHA1:BA8BE88ACDE40825ACBBB8F3F614A647126BBFAB
                  SHA-256:9BB43F068B31CC175E2B34DFE3CCAAEBFE671DBA9885BAB8A0788D15D35A381E
                  SHA-512:0FD737F0AB79410844846F080F41E3F659DB52AB6248640B0FAF1A62B48C35B1873FF5CBF995F927734696D3D05855BE03A63CC47F52C27B1E44AC10D1314A81
                  Malicious:true
                  Preview:.....fy.c......".....!..4.Sl9.........U.k.v.n......*.. ;..7....-Xi.B.+%.......}E...b...)....<|....<....e....K.U:.e$.i.SpO..(9Y.....6..i.n.....)).x^}GPb.;..y.....,..).+$)...y-&..v..9...o]..H].._..._HH;..^...:...^....*.n.5.<".5..."..Yh.7..VP.*..x../..x...x..C:G9.b..'..B.MD2..S...S.)......O...p.KD.....+............"......'.*....J...v........f..EJ].t..^. ............{.....;.j..Ay..I...f`...'..jyg...>....<..[.^'J.KE~.6L.[.....o...B....0Q.;c..a.K...gF-0.Z...q.r........).>..3_....._e=[.Y.d.c...{..M.YA.k94.U.{.J.9...3b..PSx3SiF.+.33...a.EV../..YE.x.u..'C...l.....q;X..%.VQK&.....W.fm.n..e..s@.Z..3nS.d......H.fQ,.......~..l...H.qa...1Z5...68L..u..$#......0.d.j6....U...i.M.t....T........(.z...K]....D3.......k.8\.he}.?..W$.~R.........9.m..l/.Z"r.O..[...dw...)J....i.G...h...;.....Z.b.....?.Z..3."....`.r@XQ..{Q.t.fi...<.tS@...y3.......P.l..Zo....L.H."....&x.....4..4`...).7R.?.p.._..,..j]..}.jZ...7!..|...L..)U.k&n.Pt.....p....f......]C....`h0.R.E+.q.~
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):649
                  Entropy (8bit):7.586669818943258
                  Encrypted:false
                  SSDEEP:12:9JNayGCIhPYs7aUycSftrya7zqgLaVOXM4Tjp0I8ToB3xHC:nNayGCed7aUyRVrTvLakp0ZkB9
                  MD5:3DCEC56B456249C197E1441418CC334F
                  SHA1:580673DFABC98F1D24421B4671081CFE40C4D50F
                  SHA-256:50870867687140F32896948DC86C82F4BBB8CD2986135703675FBB90826DC33A
                  SHA-512:E13340DBF3BE16590805CA9DF7F613EE14846F786D48E9BDE8CB531FF6B363C3C3558EBD505AA1CA0FF09A28718AA42780BDE7AEBAF4EE34B33EFA8D1116790B
                  Malicious:false
                  Preview:BF..a.@..F6.....R.........kW.0....#*.v.>.#.|m...d.o.~.q........=:.<.|..lp..0;.1..v.xD..vqNL^[Fv.i}.9.../.8i.k.&...2.6..J.@uRQ..SH8XFd.D7.ZjQ>..J.wY........^.+..F^XtB..M..O..Fl.D.R.......4...T...2#..?.......U2....P...Z........;...[...b..a..R44H.:@.L...D./..["..4..`.$fO%.X,.6.A.jSj.V...}w..SKzJi.#......._..v.....4.tI.J.Nr.L.*.D.v.YE..5...fmH...+./@xwL.`{;H4.....-fb.....D.)-....-.C..V4.7r...."l....:L....=.Y...k1...Iq].....#G.B*...3Qo..-..;a.N..U..Y..*.!.5..p(J.-..Pw.<.....{p..a.|wx.t.`....a._.p.*y^x..4..3T..J..1.B.........}.....nR.......*.)f_ag.s.......6.....`0.J.....!J;.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):971
                  Entropy (8bit):7.745640011044853
                  Encrypted:false
                  SSDEEP:24:PLKsLWrLvJ/SCerYML0o5KYQbc+sC0PRTg6i196Qh:jVGRo/K3bSCSZ5i1cQh
                  MD5:1A5C94688215A16F099C2EE442078479
                  SHA1:45D62930D7DFE63D67F20E749107E63183A4E27E
                  SHA-256:AF93CF2E443E00C6B2AA58B1F8A2DBA8678D5D6896DAEF3D0058054414133A76
                  SHA-512:D26ED98288D27966CC8E380E39878550214AA5E2882D0E2852A2AFBAAC5E8967AA9A039D41D994D7DC9C55C70DBB11A97195BD5E213F6F9641BF2573FAFF52EF
                  Malicious:false
                  Preview:.'.k..Y+A.../..S...... T.V1e.H.U..lD.:....Y.........:.A...._.9......7@f.0...h j..........Z...).9.u1D...... N...C......1..e..P..`"..x..'....8(?..9&.....J.....6......d.X...\..)r3..n..i...K..m.p....Y..q.....=V5.......w,...."/.....H...............*XKz...LigE$a$...pS.v..V7....~.k.=4uo..c..J..y.......c....t...z..eF7..M...}s.OeS..0.T(d!.-[w.Q....mY..I.x....dD.%..x.2j..r6..U...9eDs$...|.V.Zn...Ui..../..dD.....=..,.....p..[...X..5.b....S....W......]...........^.&.)..{c...3.....w.+'M.|C....!...a.A..8.N=..;.......fb..C..vI;...|..J.F..T..-X..{.hp..#..mqg.I....xN..........."bj.!6.c...@&.../..jNS.B.c+.:.....F.,.VT.....V..f<.-..........z..x.Z.1...:..r.R.V..$.$.qQ.A...81v....?%....g. ..y.}..V...O..*.L..;kkQ.oYG....v-a....Xu. q.k!rsu...a.....K..e{1.o"F.....4P...wu.~]....J.........t....H.....tKK....7...4...}.K.....@..[....5;..H.L.;^.DR.a.C.k+.......'.<.....:.q....~.A...*...j..&....T.,H.n.....Y.p.{.6.........+...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5358
                  Entropy (8bit):7.9558108087913535
                  Encrypted:false
                  SSDEEP:96:fShHzT0Oj4qTYcO74X+ZVc8gmBFFDT0YXKfzJDKaRuI5Eq:fc/aqTHO0875DTTMDKaRNE
                  MD5:83367AB919FA1FDE05AD325089EFCA1A
                  SHA1:1F270D153BD952B625FCD68FFEC966336BB1A838
                  SHA-256:F810E1A5602E9710F4CF7F2DB4D0C656F9BD8A1CA39690A6CA32337EACA0992E
                  SHA-512:43250130083D19DD8B6E8F65AB6E4043EECDD19DCFA57147F3224E0A41DADFE00C6EF0CEBBD736D5ECD05F17F40A85678B7114B61902B563BB3B28474C323F7E
                  Malicious:false
                  Preview:.!.nwS^......e.w5m5..'tc.U{.....z.......... .f....d.r=.g.D..P...l]...p....3.E..7R.........L-...s..I.s.p....p.^k."=\...q/!.........{...|..W|.n.... .T.Y.]k...hP...AO.D. ...s.-..I6.S.tv.....R.....RjE."d.?.._.....s..A.8.:fY.i.5....%U.:R-.m....(<0.b.%..M...5...)I.R....7p..T.#...:.W..!..P..O..d..#x.......13...~.........G.kpP..M.C..}...y..f.)..t<...i....M..5I...I`i...j..V.$.cAhpm.@....<&A....@...3....@...9..Q.....0.8...x.+.....4.4*>.....;.......%^..].9..U....RPE.|.0..V./gt&......x...KO...|.C..!....[..T_.U..9.-*.Y...1.x\.Q.0....)E(....`v....X..-*[]1.\..*.q.]..d.....z`...X[.K.H[u.C..<.".... q..G.x.^.]e...}......dC~Yr=i..L..g..N^..^.I..Q..h]._..StX....H.G.@V.I.|X{_O..0...c...7...$.....g.?z.....k....7..+`Ws..Dl..*......?....lQ<)P..#.h........h~....z..5<..9p`..u#...9.^T.[.gZ....Od0..i`......R.....m.v..k....hV.+,.@...I...k..J...`u.......U7.;|H f..E,4.m9......Ty...<6qX.'j.|....i.f?.O'l..,..7.X...y.7}.0..?Xc?.a9'...C.<i......C";.X0O<..EW$..$)]........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):12200
                  Entropy (8bit):7.983005053064666
                  Encrypted:false
                  SSDEEP:192:aT//WRI3zXbPVWKRIwasBoyc/g4xQOp2ACjeapa/114/+ePFl/FZgvVvwg8X:aT/nzXbPVIvf/ZxQOp25etD+R2vVvw
                  MD5:FED2C894338FD04DD6CFA45C3A1A8EFD
                  SHA1:1749223746922C5F0A4E97D0370CEE902E37B81D
                  SHA-256:E3A0EEBC4E0F2F39AC9DB671DEE68F264B7B49BDC8262B5A87150DCB7D83E7B8
                  SHA-512:C3436F51D72A22817183AE82CBD8FBC0733F24377A41DFC01C299DC3B15723F92D910D92365FCE0FCC82C1B9AE43BD0D78CE2C6A51C38D13C4E8687866898D71
                  Malicious:false
                  Preview:b..).&...2.....7.....O......Q.rx*U.o.(.....K..aZ.. ..._...n.@.4.....8cw.^..h.%..w,d..|r..v.$Fa.(,8F5..2eTM....E....-R......f.....?bE,.........L.g.._.'.....M..-4.g.S.VC_.Ati>+>952....A....\w.>,...N.|.....8....]. tTn.e,d.i;...z.q....gWz..[./d............l.gQe.\>$0....'.9...y5...8.2~.?.w..W!3.Jw-F*dS\B&.};..Y.=..VtSd..E.-t.@.9..~."[.;..%Y.._P.N.....S.\(=yD.&.......R..E.a/.....AG,....w.*........!..x...X..=..p....|.F.1.*..nw......l..Sp...!.....;8.4LE..jk.....8e.OPx...) "Y....`,b.....v~.z.../..l.p...........P"`....y.\.d.?W..U ..BY}....{......s....\.-.r.WF..z.M....5e.4\l.9.oA.-:......n2..(.}........0.*T...e:..[..yU ,..k.(.......;*..{....,..{..Q0..../.B.\.....p....'....hE...B7N./..|o*..{.d.5Eoa...H8..*..'a.y.w.P......M...jv........a.l3.\"......lC,.O..R.....T.....V......."U ..2.0?..e5.y.U..#...+2h(.fM).t.<...A...W.#.i..X.C^..rd.B.H.q%.B.(l.@|l.S..9.R8..f......<.'uU.U...........M..,.v..........U...R.......i.vM~a..+q.U....dNe .Z..J...A.E.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2522
                  Entropy (8bit):7.911650012846097
                  Encrypted:false
                  SSDEEP:48:VWzdrqZu/tFq7MBoHRlCwYtCY1VlNb8J3eq01LGOQmeG2MzME8dyKAk:VwrVFq77zdOCYzlNAJ/Oj26ME8YX
                  MD5:CABF623945A7B85FD3E9F2FCFFB04A44
                  SHA1:DE906BE0E36533064C56F553166B2DD7DCEF411D
                  SHA-256:89509DAA7FEF897F3E861D2B472EFBE7C78BC552F9CA0C186C342FB8B821CAD6
                  SHA-512:7B0976E2A2F22C3E624523FE9519C04F4B10DA066FCCF09A384F7587C0970A62CBC9823DA4D63CC6144644236DCA1354D5B4CA0445A6DDCC6A2BB060B7CD6D78
                  Malicious:false
                  Preview:.::...@<..5..........tk.&...Ux..1!y^..e.>;#]...FEo4*...+..E.(.......G... ..R\..5.=.Lt!./.Y....N.1Z.*...E.....3R[..l.[....<..2.N>.l"z.B.. .f1..}..L..\...O.;:.(.......$.0./<o..4Z...Bk#~n....-.......A.2.L..G.x....@.i#...Z.,..N3GM...C..........I..........P.a.m.....7.M......"'S../.k..?....$y._@..5..G.XL4F.h.......h..j.....qb....?.k>-.$V...E.oQ.T..$.......`.bFYg}.Q..s@..?.(......./..p..u..{..*.#...9$.`[.1_.x.MYV...xg..v1>...y<. .+!....P.X.{..L...*r.Z..7.d}T~.5.7b.............m4;../y...+.4$.hi(&D.1..Wl8FV.q...D|....0..<1.Q.6...Eh.$.D.8.q&....Q(..s...O.F.....yzt ..3...[..I...6.....c..yT...211t....-!......q.I..o.P..Y..?:s...&>..`].d.n.Q..9D.{t...M[".,S*..`.K..mYQ(...}u.......La.&.&...%S.......z.G.^t..>:...t^5.:.k.mk.6.!!.$.G6.}s..J..O..7..(Q.n0.....].......g.{k0...Kr.s..q...Im.:..[..P..$~:../H,..}.Kfd.1.-sf-..1.~......o.h*. .qr.S.....l..}.g..#.V.....+?.....).6.....v..y...Z[.h....m.....aO`W...<.f..."..?...x...Y..W..h. .b..4.D.*.}.....w.>...mt..2.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:PGP Secret Sub-key -
                  Category:dropped
                  Size (bytes):356
                  Entropy (8bit):7.138115603816998
                  Encrypted:false
                  SSDEEP:6:fTWxwGTzGHn+nBE5Fmmd/3RuZE9lrLePpqlOIVss3wxdJ7LkWylZ:fTFGumBE5FR3RuZE9lrlOOs/dBkZZ
                  MD5:B84F13DF9326D16CFACF77A394AD9FCF
                  SHA1:D56C57D741AA08412BA1F20B27DBB842BE321737
                  SHA-256:027D34C6BCD90FA0F6E41FE7DDACA71369F15B80AB6DBFAEBC9C29A46B862525
                  SHA-512:1C287E79FFF3BF4CAD445BFAED1644CAF7CF2C8C15AE75C7F035269AFEEC5D26BA079BFB057F104301BD2B6E6099F8CAB3A08AEDD632723B29CF1491E6DC1294
                  Malicious:false
                  Preview:........."o...?.Ef}.&D@....7..>.RS.k].2o..}.Y...x.L...T...q.O.#T..a.7D.2..%...>^A5.E,.8........9...uw..H.P...8.w.H_Z...Zc.r...k!*...pm.8....|....h%.Mk.SB.4P.k..mk.....@.}.B%....Y.K ..X.t.Z$.f.D...@..;.!....)l.\k..MR.X.xH.......c)...&.i{.;.....R..........N=AR{y3Y........h..FH..B..r.W./.>...&..,9#.....(...s........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5141
                  Entropy (8bit):7.9631870758834165
                  Encrypted:false
                  SSDEEP:96:xIm2BoCps6k6qejX0xnAIC8b0LDMaewztoUT8KfisD4taY9N/:O7o76pFjkFCXLDOG8Mis0ta+/
                  MD5:3F460B08B4030B335D5D696B79024F03
                  SHA1:10449F40F5A3172DA5A1F08DC355F34B95660E01
                  SHA-256:7B98CC66BA8A6B2AF5FF2985F0DA6BC230016FE62D0F1079937FBDD65CEBEA48
                  SHA-512:60AFBECCFEC1E75A5C53B61A07449FD75748F40AE2751D1EDDFEC5CE632EAF59A79CEDAB09E5482860383025410E3B355C0F09BEA2B0C8BF6AD1B61F66771EAA
                  Malicious:false
                  Preview:...d.b.."..|N...Cm=.1...=..[5..Y.F.AU.~._O..*.Z/*.W.c$.)...4uT%....t...U.G..n..gM..9..U.].@.......>..52.)...*..w...$n......J.M.C8..(R.....{c....6Q.r....f.q......+....l.....2.(HvK...........E....R.AK...y.........C......;...5..lT..G@..W..%.....'....[3c..rC/..j..ML..a..*.ZMOm......O.p,.+....n9..O.209G5pH.=.f.......@..6~.. %...tt#.#....|...-rG..J.....-...HS..c.]c...~.l!.'...-.tBp..kk.B.;..Uba.i..(..B...`n...(D..,.....h...9.^e.m....K S.......%X..k...~k4...Z.Wx~.d..=gR.8....."V\........v...mtQcI]..g-8h..g......X.skl.....{..-.............|.F..0...I~....'....[.t.%......S.H...4P...f....j.w...q..D....8a.9.]k.}.k.?e.....Z........~}d..&9Gk._*.#!....5-BsA.b......UQ..9_.c-Jx8.gE'A.P#D....)+G......._..tC...y.W(1.7"(l.K...f|.............U*..i..y.I.I.J ..@...8..=.@6.C4+."...GA...c.We.x.:.*.'K...~..s[u.$n.u.....QU...,O!..x......(..^z.........%....Z.43krA...|..G.......M.6IN..B..}W..<w*....:.2.....".....?H..t.An..(..qn_~U....l...0..135...6..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):847
                  Entropy (8bit):7.676102708432684
                  Encrypted:false
                  SSDEEP:24:R/FPNa/vJKzGgOiA/MQ3MvPiPqPkILLQt5p3h:R/ZM5AGgqUgGrPtopR
                  MD5:D5A1CD7C69E6641289CC4EF943A8A82C
                  SHA1:17A7A7C3562AB9C0865FA46B06B49FBA1CAD01A7
                  SHA-256:ADBC92AE733F95F256C9BB7E55F0D13A72057DFB9ED71211A123D88591C18521
                  SHA-512:0A70C150588398D1B537CCF6772DF83AFE5E6652B45F5BEC2F76F17346DFA9C1E59203804C7830318AED40590F96B92308202C588ED690E58BC0ADDB2F7E76F1
                  Malicious:false
                  Preview:6..,.:..\...L...nI.,...e...X1s...B.......".y.:2..T...G;\.E..).m..... <.'^..........^..1...I.f.8(....LV/.< |.*....F.8s3.....WT.x/...<\...../...u.3.U>.|.....~......._!.e..vX...#.....&.4...H....J.i6.;/T..~....ni{C?.;.R.....Pj?+....{:.3Wy..2...>....?.XP../......g..P.c....?.uC.[..U..'.dj......[.j+.4..h.;0..JJ...Mv..N......dK..^.Rj.SL.IF:J.DB*..T.|R..m....!U..&...3...KCW.XM...4..G.W......=K....)0$0......B`?..Z&......j.C.. .6e....:h....,......V....Q&..?.o..^..Y....^:m.tye)....v.....b%.:.{.m..Td...Q..1.lm..Z+.h......4N..V...:c.;.......v......l..\.0.+....w^.d... ..tM.9;M;T!.<.s..:?...H./ar*..&C..%....P...&....b..LR......!.Nj..el.r..Od.s.(W.H...`.........`S....F..^..%Q5.jpa.]r..0b`......=y.<...Y^.:.6....[....U<taZ.........g..8A...".V.......@...^w<5.l..>[.i#....y..Q.]......^.X........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5661728
                  Entropy (8bit):7.999969990989484
                  Encrypted:true
                  SSDEEP:98304:1YELPLK05kzy5+XU6kuCXIYTK6eUOqHq+arwXYQ8m7DW32AdP5v4QFqG6NZ1pmGo:2ELOJzSB6FxYO6NoQr7+Lv4E8zpROJqW
                  MD5:6E38BDA112A8966C46D15640A8D76C89
                  SHA1:D5E73B02373B7CE3E64012AE82AA9BF6643DAD13
                  SHA-256:5A94751208C47077B5E4DD60270C92518953F6D36F0271E36DF543D1E9ED3801
                  SHA-512:BF7A232611EE09E447838739E043037E1AFCEC66F38A89614266A1A79B68EB9469B305DFCCF3AF3C8998341563C8CDFB2C6B5ADF506327188C678059F7EBEA3A
                  Malicious:true
                  Preview:.......F\.7HT.....@..a.....F>WC.1.^.r{[.!.pM..:..jL....d..L!.gi.m..a.l..\...k|..l.`....P=h..S.C.W.^.F..R......_j.....]LT;V.n.....)...7`..8.M..?.?..Q\.u.+.....&..j3...g.c.....c..s.6..CMX@.psBZ.2..f&!...W.$.^L...".6n.7..L...5..)."....QT...Vtgr.n*..V.....~.VJ.'..'.k,..x.ye.......X..5b...6=Y\.%..^}=....]..|.......X.........Z......(.0..J......T<..=....IU!.,E...R......tC.P.....Y.....o.'.\s,dDl.-.TL.........H!.Ao.....H..5p:...H.pZ.F.=tc..n..U ...~.-...0....#....~....V....]I?...E.......k.vJ.Gq....P...g+d...L.d..r.q.L...@u<...gY..I...&..~..+...5.x ...6.u...%.',...O.=.)]?...../....-.........]...R.p....y.9M...-..F...5f.v..s(.h..'`.....n.X2..9.'.7...=.f..^.d....o[<.[......J/.,YK.....@.H..:..^...?....R.;.`..J...g^R........q....5..|.;nyZ..Ns........'.C)Q.............u....]Ve.,..2j........g......u.c&.N.K.Y7..k..A.~.R.?...P.9..4xC.p...:..ww....O\....qB..;.A.. d.r...Ff.X..\.Yo.$..'...>......Bg.F......-.S.......]ne.R<..z6.w..._..J..h7..e.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):11513
                  Entropy (8bit):7.979554780185153
                  Encrypted:false
                  SSDEEP:192:izu9aHcw8DwSrVh3kqnXY7QLuFCOKriAi7EZbRAbinFlXKbDGK8VLDXrNS:izuMcwIwa3kqGQLppriAkE1qbinFlXKR
                  MD5:51E41F60F846A4902E0DE922EB973EAF
                  SHA1:837BDCA1A6139D3ABCBADC0889E9BF464D63E914
                  SHA-256:ABBEDAC83E58191D2D0C107EA54481A3EE22846FE823BC705F9CE3B458115CA7
                  SHA-512:8A2C2E2F360CCE1A2DD4C3C9DB1FBF488600B447CDBE186D182AD5613E73A281A870EA2EB949BFD8381108BB79F0396E8F16E72D45BF8410ED4FF2775823EF0F
                  Malicious:false
                  Preview:..7.....8.\..,H...5..n....h."..K.=W....S...n..f..n.38...w.aG...nCL.'...+.dxz.pE&O........ .c..uCS..$m........H.n..W..J..*.U.,Q<.Cu.......Y\..":..c...H|.....`...8e....=.<...iC.3;.o...1....v.89\...>%.:?..8tf.J.....9Vgk....L......&Q..o.....Dh.E..j.\......K.28.....1....v.....x4....S....-...RI]...O..........w.......`.<m.(.X....n]...}.~..^...q.I....&.T.g.o...zg..QRE.Zn....WA.*(..Lh........>a.].".21......../g..HR...[.....=....v........vk...B..c....2/r....f@N.....6A...8..V...... .......l....|K.....ab8...u..7.!.C.?....6A...7...#.....h..)..V....P..;.....(.8....C...i.C..<v.W.U.......#.....H.`y.;P..?.........&.4.f[....[QpH8.g'y..I...@m......./+...V.>v.9-...=V.S.. r.R........`..^.#....s#...5.B|IPW?.q.:..:.6....R.n<.'...R-E..Kaa....5.i._..n.........%_T..r$6$....r.BA......S...&..2.M..\g..k.jr..*..s.K...A%5.:.V.bi.^WsE..%..;...n...u.I[..s'.....t.N..a..Y..T,..6....k..X?..&Y.VQyPgb.!...~.>6.....^l..\..c._9O.a...>.......=..K"4...,.....o...l.N,"
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:SysEx File - Fujitsu
                  Category:dropped
                  Size (bytes):858
                  Entropy (8bit):7.713061578285532
                  Encrypted:false
                  SSDEEP:24:izTB0SAuc76hWKbjFfXQBsQvk0XQhBdcfdz:u0SAuc76hWCZgBsQvkGQHdch
                  MD5:6A034FCBCBCF485092B41E7C8FFC1CA2
                  SHA1:48D2721AAF67A19F5DF97FDB38593F6862841236
                  SHA-256:D1A06673F8155075EB5A809A7427DA6F172616EF6A1E3A79CBF7F9923E32A382
                  SHA-512:91962478676DE38227F23C1DE5DA2F1758971C668A86173D3ABF8B6DDB890CC939988F53B73BD74A006D683A0DDA1B633D9A58719F6C7F0CC332C03E0D05F8D7
                  Malicious:false
                  Preview:.Ka.....BQ..w......t..8u..[.}.....<2?.....r...N../.*n...d..}.6........<.R.cG.dd5`Ko........n...M.S5..v.Hb%'.....>.u.>.#..P..&5..c...H4..>:iB.rI.H.....t.......5Y.]8Ft.......o.Lc..hg....0.6.........b..t...a.Q.F......">..4..@.UT{....zCZC.n...z..\..+?...D..v.q.......;.w..%..*c..S.ZL.y.j.X...8 \qo..n..k......*..W.R8I5vG.I...%......>.|..?.5...q.d..A...{....x...g]5...Q=...k...a........$.ajzUC..l......l.....+.K....^..9....H.e.!.....,#..]..(U...By..X*.a....."tAt<Y...k_(...0.T.Xh.L."...r.d.. h\..M.8.@.S.../.]U... ..g......0>.(=..i...)m:R.g..'..h....G.m.n.....d.>;.$Rb.h..Z.....ts.zJ.....%...9.:..^jx.....od.&n.#9E..3{c.\..&Y..A...)......|J.8.C....2Z....X.ag.pY(..-.4hh......`B.8.a.j.....G..n..\.\..me..3..........~...-JY......n.+3.-.HnT.8U.........7+...~y1....!....D.8n........P..v.=1.....wg..!t.W<..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):857
                  Entropy (8bit):7.700222080462529
                  Encrypted:false
                  SSDEEP:24:HKXSSlBF6jZV4MsxtlHUXOHj0BBTug2AGBoY:qC2ED4MsjNgsjc9uvAyo
                  MD5:C120A8C7A891FF6CC6B6FEE4CB8F1FA9
                  SHA1:B1DD53E95BEA3476968BF925E36D25C067106AE6
                  SHA-256:D110711921D7530F88C1E355DD69260EE1E64AF26187EE3ED9E7D0202147403E
                  SHA-512:C4948168A606693BF11DE2CEA1F8EDF9B4EA14250A9F8B3FE7DCB6838CB32CD5C232D08B6C82167305989B4D62369C276D2545B13AEDBC479F7288156136E581
                  Malicious:false
                  Preview:+..G.V. .....Znc.....s.;wr.3.....N../......4.f2.. ..7>........4....OR.......-.;ZJ..........N.....y.K.....T.."b..q...........[..6Lit...#....!...Od..N...Y....Sq..tfK[u...Ui.=.K..n......J.[..e...6....3G...M..7.-66.O....Z*....hSC.!..a+........,..E.X.\o.....~....g...U..6..i......./.....F.....;#S.k).L..l.~..&. r.{....f.CA.............}v|_.`......X........a..Y...2...G.....r..<g.......r.....S..]...e......>.sRU..>..x......3.HW..kV)~......c....LBW2.f.y..?>....#..!....x.K....Do0.d...IC...8.[P...........~..l..$V.D.x]dP......nt.G....v.{....H".y......n.f..<..LYD..=>U#..2..z....EC.....r.,u....D01.,m..bj..w]..CI.H;..X-.n..L,.=......"^.Ny...`..cU..%..S..k...=giY.Ags....E..$.....A.9...&Y...].......o...[M.Y)...b.i..Ez.vf.X..........w....{.4....9.....@T....%D9}...:..........cH..9..V........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):854
                  Entropy (8bit):7.722214405679312
                  Encrypted:false
                  SSDEEP:24:rIEY4NLevupfIxfnQjJJX3eoY35XDoh0:r7Y4NLevupQnQjSpT
                  MD5:9AF50F190A1FBBDB6062E482B94D0BF6
                  SHA1:3B9945096E4FDF2769C57354DD9D39024972A980
                  SHA-256:1F75D0866A3A33F82BEDD5DB53EC8EF2BE8FD8FB82F73956EF682BE2F115B274
                  SHA-512:ABA9D8E3BA7F6B34EA3ECDD2EBC66F1ADE97225F3E7D2FA6B27117593E66EE6571A6DD8E44E6EFAC54CC37AEF35660EBE9CD6A79C7A3BCEB61CACCB9DE8953EE
                  Malicious:false
                  Preview:.c...B_.H...5z..7.^.......df.$l.^.~k.!..^H.{8K.b8P5;.x.=..{..tAn2.i.....F....,......T.@..}.....D-..z.0..VQJ^X(..Y.* 2..{.:. ...B..s.D-......A..5.<..C..j...g...>a.C@..........q.O....~....m|D...L...n..6..,U..?."......?.$..C...v..|So....:s.>......m..U...o.'..../Q...<.l..~..C.]6...F..!. .)...)...{.u..}.....&f....$........t...7...tj..yyy.....;.m...S.. .>.VF. .C...hz.W...>...%...."a.a..o..Y..j..`...sZ../.L]fE..#...3.m?S.H.9.].V..I...$.d..h..7...Cx.,K..;....s^{.......~1...I..D...Nn./T........b|...=>...&Y....pBJ...s`4....A..1.6...F|V1..W.P..;3?.n..|.$.H.?8..D".....?....d$.xd[.O...[9-.KT........J.L*-9.7.j.1^a.w.\...wWi...H.P:.*..ON..U......%#.k..Ic...'...e.i.{..@..X..M.2.>.))....L.Hz]....h.T.G...P..-.|$..~U5.....N.L...............\...E(.....D......+.v2+3.g.WP:{..N.=".du....(.V........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):854
                  Entropy (8bit):7.667200942154607
                  Encrypted:false
                  SSDEEP:12:ccsiEzrVNTijBFbWvEVeaivFChf4jTvmDF2HF6irfzkaEOwNDHQo8lfZOc:u9z5JijjbW8kaHmvmC6izzh9sknw
                  MD5:7646C58E1BC99B55FB3E1F52709E95D2
                  SHA1:F03E7B277C9DA36A0AC1E4A78A327F7ACC84C829
                  SHA-256:A3B1AED833D4B45E286E685B6B4280FB74383685A8B28294C65DB3E25C9CCCF9
                  SHA-512:6628D1B4C4D507F7D6D1DBC86BC6C2A57D3C357E45BF87AB2BF410426AC76AC9DC74A5F2F4642BB80C31FDC3762F7529084448696FE83DDA260928B86B0AEE5B
                  Malicious:false
                  Preview:n!...y..ul%...|T.r.-.s..ba:.u.w..:.P..C...[..jEIa....I..j.W=.o.zc'pz.t.0./..k.A......ju...4..[cH.1.._.q.Xw....s`@;'..I`.*$..=i....).@..6U.CN.H...=&......p$..)w..5.h[.H.KJ,..Gw%.E. .8E......|.H^#.<?........dC1E. ......D....y.......+..v.a9-..G..v..f>B<....7..PI..........4:H.....V~.....u.Y|...Oq............k...g..^.....@_..<-......I.DJ..\...J.[......v.{.5V...=..&...3...v.X.y..e^Bn..e.%..m...{b(Yx...efE%...,m.?.iJ.cY+!.|.r..K....zT..N`~u.m-].+!qV|........../..I!....q.|..........Y{_J0.......a..H..@...o.........../ED.Y..w.M...W....+d...W.P....>....l../OG........gG......:..u.v/w+.1#...).ac!|....yr+Z.y..=.a..g.....~.S.E.6...?..hx.@RHNP5.....9M.......n....<....u.t.s.TMMJ..DA..^.{......<....K.G..D..mS.........zW...r.._...l....qf.mL.o.GUIB...8..sc-:..o.=......o........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1550
                  Entropy (8bit):7.842361617009852
                  Encrypted:false
                  SSDEEP:24:hIMaiP7UTiGeFrYzH175bOe6+nj6UcU7PmRACBziKu0FP4tp:KMPDjYzV7Ycnj6lcmRLliyFP
                  MD5:32108D338DFDDA9BDEBA6D6D0F6FFD25
                  SHA1:5F7148D8E50AF948D634FA8635DF18B5BB98C51B
                  SHA-256:5BADB193C3438E1508A572FF4300AC15E859D6AF041A4F5A426678D19AA1315C
                  SHA-512:687690A6F9C97B084518AFD464EADF4D9BCDBB1A1816AAE45A5D1A653DB7C4CE802F64CF71299ED78C5DBED384A07DFAC42BAD2C581744759024A4C38E156ACE
                  Malicious:false
                  Preview:.^...l.o.^5....S.....<Y.K..V..N|.....>.xe..q.D..^.....$.%.>20..../CO....p...[..|....D.B.1}....b5L<V.0..f.c...'.\.m.N..Ex.[?E..Ft....l.r]....w....Ck.J..E....} .cG.^u..../`....h...w...C.3]t*lG._..!.)....9c.q.Y..m|.Fo.% .....^..Z....@..g[7H.^c...w./....e.1....L.R.U.O...........?h..qC*od.;..#./u...E..v]..w6..}B?.^S.*.n....Z...6O4.C.F.X.~/...c.............lg.F..8}.*.Z.y..Y.......Q.0.|V.SfZm{..\m....Q.D+i..3...y6z......N~.c.a...0.qB.....rvzD~.$_.6.1+I....a...#.........NE..Q..W.....b...).`...(}^,._E..7..6z...V$.U.S4@..*.+.L.c...._....0\..we..V...C^...I.`..AXJ...,.v.....p....S.}}...'Y.c.......q..qB..rN....u.....YN.Z.......AT]....g.C6...Wr.<.C..U....0.....~LM.H....}@..'..U.....E.qh..&.....0.<..<.$..I...h)...o...3/.....ipQ.W..I.<g!..z..Z.,g.OjG.9..E.....V.....A.+.e..t...gdyq.p.R{~............)^..v..6.r.......ul2.&.....p,...o...!Og.K..>l...D.@.z..&.M.".d..S!....-.Zo...N.0...'.e<..F....Z.E..\..7.0.......C...z&.F.n)..2.U.T...........cUG3i.d..9..V..T~
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1550
                  Entropy (8bit):7.853875916555771
                  Encrypted:false
                  SSDEEP:24:iwuX/ycGbrtxZX1erAEhlQSocHPYfPsyiCo7lP8VD4XMl2B5vHP1l6w:iw1brD7KAEh1vJzRSh8L/P
                  MD5:51C2A003B60FE276A05408A790A8A1D7
                  SHA1:99561794807B026A10952947636C52465496D6AA
                  SHA-256:CB2958CAB7D7AFF2FE5D1F496B18D311F3B71AC7ED7F5FB850EFFD5D58DF40B8
                  SHA-512:1396B812EF0DEB70D1E81A08775E793A78637B9D125898CABB426DBC96BB411DD3C01FCA9C0F384732A874D834D6EA2E083E73FF15996D1C3D2CA1583384B963
                  Malicious:false
                  Preview:M....F....}Ob{..+o.A..l.....*{..?.1...Kl@..}....H...a..........t..m?..D.$.f...]$-n../bK$...e.OC...7......d..y......;D5:.....>.gr...:.,K...X.v<x2.x..z.\u..z4.p.....K...l.....TM.)..}H....w.] [.;l...\Fx.$ ...~7.._.g....#.../)..g.v..L....+.<.bJR..^.`.+9.D.'.6.;L^.H...q.x.......;....1.d..n+..O....r0....s@W.<B.....p.;...A....^.v:|jU....r..`m....t....w....y.`UY.;.......l..Vq..jN.o-.*G.r.R.. ...U..k.(.Z...e.3..2p.[.J...e.0.6...5LI..0.nR..z4..4..;..-v2...D...,D)...:...d.....#.|.=.@..J....9..7.eX.1O.Jx...&..^..,iou$...O....F&l..nS.k.....j..;...p.nSAI..A......o.|......E.E.kT.?..}+..l...dc... .O#k..|V.Vwn..8.[."...@........Q9^....H.Rw.$...Z.,.`P[V...n~..g...............]..1KF.....|=;B.M.....8.A..>.}n.R.DY..V..#.'.\...!,.o.d...M.}.Z{..K..A.H....].._.M.....%../...Z[.6..K..r...B...8...m...zg....\.p.h.>....C.4.i..Wh...#......F..<..od....]..v]....u..x.~..ja.a@.`....l.0.?<h.,....+I..@9...Do....#Z..,..woi<..]G..!.R.k..\.5.9a...W.;...s..C.b.8..mp
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1068
                  Entropy (8bit):7.75814438235167
                  Encrypted:false
                  SSDEEP:24:Ev8hgGKNzF6MM837dKy3w+E2U48FP28soZyd+3oHuXscA:EEgx6MJ3R3WZXBdZXXscA
                  MD5:8141C3F108A2D0BF79B3AD1C8993DEEC
                  SHA1:9F88AB9FA92DAF602AEA41E3BC352F9087E675D9
                  SHA-256:994D98773E59D06D60EED7340E02304B152B3FA9F61FF1DC01D9D097BBBEA79F
                  SHA-512:9115DF828C9B94186420D6101F2F06ECAA1BF1FA9B99DEBAD98C2EDA07B3B5CF21D01F31017C3AA33C6302655EDF2144E22DFA522FE5E4871EE3D02008249DD4
                  Malicious:false
                  Preview:6.d.1.n..[..0.>.F.=....q[...<.^u....f...D...B..k-....P.$...n....f..kqA.]y..>...E.4...........L...Y.19....A...../.F&&y.......:..........C...dg.q...MxT+..O._D.O.d{X>Z..r...T..i.$.=J...)....v.w...[....K.].V....1.c..W.....J.}%=...s........[.R.m......%Y,50...9[....)...FI.g...r..d.T.^....FZ..7r.l[...,iG.....^..|..D.u......B..'s....{..~.....qs.:.,'.......1P..fdG.$.........Bz....5-.) \....1gF=F) .Q[.8.. W...1M..IZj..|.....1I.K%....i...Q..S.}p.....\.?..A.!z....E.4..Z~...o.kf.0........h,....^&....r.Y..../....f.3. .6...NNiG..AUe(.J.Y..9u.........=&2.....m......%`...P..7..I.Q......F...Z.>2....*..{.6`^].[l..z.)..%.?..wh..../.....*...........Y.I..d.M6...W...0....d...H<....."0..k.k+.H%...L.'6.3$....I>.C./..`W.KR...N.te.g.X.}.<.M.:C.C.PK.D..]`h0w.4...sx.|{j.aQ+.......;:.,.mf.KYh.........e_.s..|..P.s@.....r.....AJj'.j3.@..A..Q..A...U......C.....IMP.DV...C....O.3..pg B....&.z.r...1,.....cA.{..&.....)4.....%.Z...h..[I............t1.....<..3..0..f.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1353
                  Entropy (8bit):7.826296540872852
                  Encrypted:false
                  SSDEEP:24:UBQfZLqln7g+ustg7QEWc0PzvdoA9lN3rmX/6tVMPPK4snvBT93aDrjlzj1inxGn:0eLqqhh7bWcUhJF7VSPPonvExj1ixGo0
                  MD5:9F80673BEED1F53F321C8D16D677CC6C
                  SHA1:D957DC47A74B081AD2794F7B528418961099D34B
                  SHA-256:4FAFBF829175F25D1110475A8D6CB2D832CA24AEA6C14AFDE8B8772F41364A7D
                  SHA-512:4D29B643A021B26EF0EB65CB233CE0B66DFA1CB0DDE2EE0D01CA53C6171E0ACF810D6AA0CFACBE47DF8CCC67FDAF243F547FF0ED98D9B81375920474823B9447
                  Malicious:false
                  Preview:....1|f<..H"..q..i5.{g.6.my.>......A*....J..].TX....f.9].<n|.j.5...:....k.w..F]Vi*C.._...7|Q^\'..0&..-P..fM..ZN.1...ZNL.-..7mks...".yk..79.R...H....#Ri]..E....^.pF.L.....&...Y....-w A.}..-e..t.......S.....B*.'y#..Z..^..].{B..\a.n.&...........n... .^b..H.%.<bo..k.......+......S..]...0.~8..;...vzt...X..s..K2C.<Jo..Ht.8+....0.G..A.T..gkw..21~W..V[.`l1Dg.?...8Q..d.L.EH....d.....U....l.....zER........,.....I...<L.M..lO.p.F.j]35...u.....E.....n....%.NgIr..[0l.a\....2.?..G}P............eO......V5..gE..'.5.~!..p......y.JT...0...`.s....].2b..A.......p(^...x.;.m......j..I.C3...o....E.ljH...i5\:.c.oxn..l..F..o.cY.............&....W..{..vZ.-.)~rF.~...82B.y.l..%....HGQ...1.?.8....i...!.........k...)......4.)O?..g..<.p.M.M....Z.. S6..\...N.S<....0{.!O.)..1=7..m...d..T7.)...YN.93..Q......r.d.gN.....Z.u.......K*:.+....{..F.Z......)k...j+..`3=||..7.1[.|./.@G^"..du..uN...kguB...J.....<....a.iq9.h..w>.h..+.#....*.3[,\._S..w..&Vx..O.g).kxH.g.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1350
                  Entropy (8bit):7.827494680529653
                  Encrypted:false
                  SSDEEP:24:H37XwCuLkQ9YYxexDSZUGt15oO7FYByMTD5OKnvBBVaOnv8zaULgv7wu7andEu+R:HLXwCuLk2YMmGGO2ys5OKtnkzPoE3nRo
                  MD5:9BE7EA4796AAA61A26B00CA88FD199F0
                  SHA1:E8C8E6B9D1EB02F04BA9B7E811D529E4D052548B
                  SHA-256:DF4B7A85E9D91950FBE9BA8DBF72B8595BEAA4F8025A31672AE791A81D366BC7
                  SHA-512:898EF43E5CC2CE63B86DA33DC8C48871899EEE61629E6715785C129775660031D2587E5625B4D6CBFE125A8EDBDAB2AD6D29033386B8C80626E18B706293E3E5
                  Malicious:false
                  Preview:E5E?z...L........g.R...@....=FG..,..R7j2..e.Q.V...A]z.(.....E`.?.*n]..t...*=....z%<....a.^.'....6P...Vc4.7..e...z}..vYRp}u...L^.=....l.......y..[..c.P(M.....>.IK._...'........'.|...f....H...E...a."@.%..i.b..X.....O......5.R..G.......NVM.!..w.....,*8..3k.TA...\./..".%.....2.#Ov..z..f...u..5]"X. 7.;/A3].VPu...jpR5.8.....tn.....M{.3~.."........,Kq?.0..q..g.y...8.(..G...g.^#.P....v...!..8".e....P^j.......i3...l.H.%.?zC...;.r.....}........:...l.0u....2<..'+$_c.kL.7..YW.(WJ7...U.!......|fD..6.r{I..*?y-._.&.`...p........F..f..G..S...nN9y...[.).rAv...R..W....1....+....@v..u_...l...f...k........W{.q.n..Y6..T..&......S..i..-....+..g....G...`..,..50...&.Z]..s.V$1.B.z%...m......%...H...j;....8e....n.n+.....Al.=.....B.t.o...O.}spRkda.gS....=>o3......-.a._.4...)..|.7_.c....J.P...A..6c%g.^...>.%'.....$.1..]^=\~...v....\O..z..1....b......)...We1......|..Aj/.......%..e.(~....y.9pW.j..;!.r..n^9....&I...r..{....h..*.....V....j..n.7.f.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1731
                  Entropy (8bit):7.864182738861884
                  Encrypted:false
                  SSDEEP:24:48O9TeVNrkHXvSToZt1dsHZYu69TNkUCvfXnW53zo8uHCsHEsVtJwskDUc:48Y+rk3fSquiiW5jjudHL3ws
                  MD5:743A425085C80BD6D692B662D94B66D5
                  SHA1:86DB4DF06280CF6F1A5ADF67D3B43CFC407DFFDD
                  SHA-256:6BDC16613F2901B4F503D8EAD7375EDBC74EBEDE658B491A7DF9D5931C202E2B
                  SHA-512:4B2FBEA242C7E6833EEC47636390B28BA5288F085EF8FA9914E4725EBF13F0DF06BD813AF2739CAE34662F43B552A03333503928FB154345AE6160630E0B38F2
                  Malicious:false
                  Preview:.[-.\....i.....Y..U\.K....j1..+db..].(t?.i.P..W_.]..N.....x.'j...4..x.X/.]P.R.~9}w.Q.c.0.0.m.Ggwq........x73..d.i{..!*.)`^T_C.b.g6.M......6.........5T.....e..*#..I?...s./.L.Hs.......G.L=...q.k...v)x.P..]....6.Jh...j..A.6W..Jr.v|z..7.d.B...[.?=..AJ`...B.B...z..9^..`.B..3..:.s..~+A.....B......Jj\........]}-.M}.!.K..K...2+........;.T;j.(Qb.[..<.....O.i..v...6...H...!...".pboT..'.a.j.............5..............D.P...i....A%.:.[f....<&.'C.n &?..R...c..Z...x...]#R*`.|..y..Q....s~.u.qlJ.xGI..4Qo..;.1..(..C......ykF.Q..r..F9.".$..E..l...........sj1./..2.` p..D..!:.#}.........t<.... ..(v.........y4%map....-.v_..Y..`..A..g.E..,.6.b....<.j...!".R.KV=.1..e..k.< .0.,.u.......H....p....#...V....D=Pc-.MS{.[.,9..5..x..g.2..d.\.*.?...._D..3.3*z...9yv/.<s..^..kOZ,...0.N.....J..`..i....R..lw...u...]k......Aa...Y..[........FD.,^.;..={...O)M..u.....^..L..|...)..?.".x.....'.....a.~p.al.r..F.Q...L....G...._...xH...a{@......%.O.0....Y.`..Q%..V1G^.9x...h.=
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1728
                  Entropy (8bit):7.862548751943792
                  Encrypted:false
                  SSDEEP:48:KYttk3yBQkal9a8W00XtxNxJAoL+UGBXU1H:hkI47a3bXtxTjLZGBX
                  MD5:904BBFD24AFD0A1F5DF2DA1C08749C60
                  SHA1:8C386387B2F1C06A163709FD303886D2D60BCA2B
                  SHA-256:55C232F861BBF89B2822FCEC18004D3F0FDA8CBED5B14BA384F7DD999EE58100
                  SHA-512:0D9E181E42E4972A59787D6E57A494923452C7A35A156FF851F872B9979F6B82F589ECBC8C9116DC7E8BBE56B9F3C1410505F04BC4D6F797FE30DA7FEE1FFE64
                  Malicious:false
                  Preview:...,b.t...^.w..z.E..1...A..*9Z..............K...u<.....w.QV.l....,.X..._{..5h.J.J.9.'$..<,.^..G)n.ul].y.t\.a.........v..p1.....d<q9.....^d.{...F.D.o.....s.H.....).j....O.$...TD!..yi.""~..).`....t.....\vq.oRA/.....!.s.....BR.mJ5..v......V.z....V0*.P....]..\..<.t3.A%...Pr#.*Kx..lXy....Bo.).I=qn."..\.4=u.AU..$.6..0..S..?.L....F.3.-.m~?........:m..A.....N..r..v~oR."M*o....N.nF...}...._....h~f.B`S}......7Sl.y....<H......oEp?....(..=..`.... ..Y.....N.D|g..vH....`.D...+@.S/b.......g.W.z..L.R.O..4.A/.K.Y.9F%$`f...r.h..P...[../.1.)+!.=".t.......%n.C..sWu..L.......Q2P..........i....,Di./.Bw...9..W...N.y,..e....}.YAxB.. v....y.zO....mf.).3\..;"E...If9....f.G.ZB\....tZm.8..p..5?S.g2^.Q3..l=.!....R......M......_.c.....~;.; .7?"......a\(r...-O.....(.......3..... ......o3.'u..+.H.O...........B.^`...fY.a6.v...]8.....!.5.0$._..Xv.>D."?*...Zt....9.L%SgL...R.\.(f.K...8.V..~m.v...>...!.......eQ)v7.~.L.$g.\.`Re....7...q...B....|..~..Rj..m.&V.*.>.v
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1095
                  Entropy (8bit):7.754542513171334
                  Encrypted:false
                  SSDEEP:24:O0AMBfVcXVp+NZBskdCAj59gZ3gW94F/T7DLYngt07Pz9mJGOzu+:dD9cXVpmBJ9aH2vLYG07PiV
                  MD5:D1021A6557A9236AACB341956C5A22B2
                  SHA1:0DAB0FBB9B47A5CC6BA5C7BD2D9D8D4491FBDAB0
                  SHA-256:565E06D7872C490D783BAD4EAFD392DD13C0FCC98655EB1EB39E699227C6E39B
                  SHA-512:585AE857FA7E56EB4FFA258621A24BC6CFF61C9E77F9FE075EB7635C9A11B3362C37648B67A2D3104B5A79F4320075593B42E760B1D6EF5F6792F25672EE2F30
                  Malicious:false
                  Preview:.4.rp.W.U..*_....>.h........9.../.5...\.D&e.b..H...Br....{..o.../...S<g.!..n.:a......ME.p...O/..<7..H....`5Y.W.V..T.F$c..b2........".".....L..";.|..r........g....-.q..Y..R.7O.x:..`g.rj/..........xY..ZJ..I..U......%pe.n&m....Q.#....p......1^..k.z.`{...';..Ij...(..C.5.V.63.\vsL.N.=...p.W..`....8Xb....y0.$.V..-cn...}.mr.h9.%.g.....@A.w....u....+...W.+.....C.V..6h.m.W.....+1R......o...JH.0.X*..|..~...|RJ....;.H[..;..N.N..tQ..-..!......,.Fh....X.U}Z......>*C...z..... .E,..A.T..%.j.e...%.....N...V.t...Z...._.&..e..=%}.sX.k....".4..w.i.0.o.9.k-.[./.sf,L...P~.U...mq.....w..w.8.&....y.n.}..f..$.w..U*.......IO..vG.........."~\.."*....u..[.^.'^....X.oMG..Un.e.,..B...9M...0.'..].h....t.r.ar.klr...[.9.............q.4|..f9.#.gg..[)p.v.f.b<1..w.^=$..W..}[.W3.B.:..m..s.W.T...../.-1'.P.K..A;.l.~..s..t.r.S.J5KK.<c.......t..NW,....`TH..Q.3.&...ar.....b....{U.NU. d..h...Qi.............I.ZN.}..w.........H..nV6....v. ...S\..z.t.1B......B..:G.....0....f.r..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):650
                  Entropy (8bit):7.556917676567802
                  Encrypted:false
                  SSDEEP:12:etdrUqQ3N0yTrjYvR6wnyxBdKY0v2cLw3iGa7fIGi0Nju8bnyA:et5Uq+rjYvUwmKY5coa7kuq
                  MD5:66826C838BE958D56285C3EC9449FEBC
                  SHA1:E97669A430D876C8E0BBF7410C1E763116CE1D58
                  SHA-256:14C0BA7941F494BC4CA4569E779D79C26D4A1D8C93A935246311D7E9CD13875D
                  SHA-512:4AD4E348930DA5FFAC713201DAE28B7C97B3AD59515E43887465BE9046A69091EB0EF6D6212F3435636895DF08F39E32425F4E2495432A6CA03AC1F69E14EB5B
                  Malicious:false
                  Preview:X...w...s._..R...+O*Ir..'...8.3hU.NYP3....n(Tst..;.ynP....X..^..m.^...Y8.f..O.C}..X..v.8_i..J,..H.?D._..6y..C..>.n..f..).. :X..Y.|............E.L...w...oN..d. ...3.g..R!..:.D|9..1..F..u?~.)..r..o..!..,@..Q.X>M.$.@a.g....Q...g.K..s......K. ....p~..e..<....:.?.k.1...o..V..# .!.rg.$...W...cp..'. .r..o..?L..}..A....0.........q.X......bX!.sJ...!.([3 .9..B.9\.Y._p..</.2..2g..B..=;..>...A4.5U.}[..0..0K.W. n.H.p&.....Q.......;.g..q6.....WWq......p.~W.d.Q.._....p....$....L..I+7.e;..lx.4.s.k~1*.a-`..\...T~.r{...k..T+.....z.F+...@p..O.........9......j..~..Z....hhA....j...x@&?.x-.....q2..K..L4.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1550
                  Entropy (8bit):7.849058596933753
                  Encrypted:false
                  SSDEEP:48:4YHyPATZ7+dI827QGuZBRYU3VNRPkDP/:BJTwC82xATt3NAP
                  MD5:B30F0A35EBA8666D247AC8C86AACA052
                  SHA1:69200482829E91B93E097949F892E777FA4698BF
                  SHA-256:9BFB8A167AC20AA267592F7C691BCE070C640EFAA66C499FEAC4E14F16F2BA65
                  SHA-512:AC37C2B3DDAAD7DB537E9BD7242387556B5D4DAF5DE8E3AA92E07089DDE03B0F891219AA88B7BA257778D6CDBFED059A2344730AB6674CC5D4A2D75B91023FEC
                  Malicious:false
                  Preview:.E.H.....C......uXf.[`....k..m*.>.|U.'..d....qe+.8n6.....Z..P........Ph..%.........+..b..x...Z...h.NA...D.Q..=..0 ...FK..o......9.oj.@..nc..........ko..p!!.KV...b....'...b...HH.w'.P9...o....yw(.V.....M..ZB.V...Z.br...>wh=.....!&..q.G.'\.. .A...Rj...GR(...x..R.M..y...NP....x......5O..............D..4s....WaAm...<B?.(.b..&.G....sd......9..@....w3.H{.c..0.#jY.xId.$C....7i..m...../.?Q..........cHf<....7=.S......b...|.$f...w0sB{...F,...._...D...}....F....c...\.q....Xh5Q.....0L......N....&c..S....R.x.......*...+[..|x.~..m..Ow...~.=..?.$.r.R.wU....d.y...^....}.[.{..?.YK.G....L..K....w....$..h.8.$...mf.?..Q......I.].`Z.B....@[..B..7...w.......<.(,.!.k.E.I....d...<.\.:.y..>......Av.M_~..iN.......'.u..W..6...W...7.....{.jv.....L.A...#..>..o^.9[.?._lQ.].e.bb~9.}....v.#...3.-.~...Q..!P....gI.>5..M.9.i.|...s....V.d@.D..GE.c.U.1...h.$....!Xa.....R...W.."N.....I........T....9....G.(..3..e..v.CX..Ar....z....@..=......vp...*......]...6.b..%;.....6.:.?..[E;.k..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:SoftQuad troff Context intermediate
                  Category:dropped
                  Size (bytes):1550
                  Entropy (8bit):7.865935015654793
                  Encrypted:false
                  SSDEEP:48:EHJe/420hK7UGNDcyD8tQDlyauPe8g/c0qM:EHo/42keDSWlSW/c
                  MD5:46985729BB17F08BF52B9F4A1321FBA6
                  SHA1:20E557C5128D8133BFC00E5F9A330BD713327154
                  SHA-256:218BA808A67B2FB08FB2B1E8A437330053D04DE8812E72BD15A6AB809691943C
                  SHA-512:6992529F0EE5148B5643EA5AB1F14DA7CC0E0C30C254595EC9341C9AE29B8482B2E0AFC10E252678FBC9293C9352F3E65632C5E3EDDA586CE6FE4A4CEE255623
                  Malicious:false
                  Preview:X ...E.1.....W.uXQ4.t..'_y.`......z*X..^......j....2\..0Y.c.....:....P4...W...g".......m..2.t......%%X....Kc....%.A.......o......7...`8.Z.l`...F.6t.PJ.....K..Ol.C$w7Us&.S.../...z.....3.....>.~.{....H.......:0'hql%.....6!mR..Y.u......$..K.?2..b[..H..z.V~..M.....-R....`.*&..q........\Q.2.~..@.Z-a..f..C......(....]./TPt...{...<.c.{B.Z.B..(......mlV._...3.p~.Z%R........o{mZ......;...;..&.......!.Y.4L...'..<{...3..1o+E.".Y:.kL...6b...U?.<.#4..=1..G./..`.#...u......z.v%.]e...\,..}.~.S7..z....e.7.a.......K...kp.[..nIO=Z...}.d7.$..DDw.~.......'...>i.SM.X....{..N.....KY....i....P..7..&...B.IJ.x. .3.....P(..GB|F..4.z.z:H?{.']a..Bx[._..../..o.0C..R....}.j..<.........|<........_..>.....J...|1H..p:C]...O...%.\....2..k.N..>..v...kG(Um..(Z-4.*.....);...J.L.h... ../E....0T.....^S]..;...xn.)w..Fxkg.Q...:Qq.k.a.$...m.4...%....8...6.2..h...d..d.e.....,%..g..2..m...&....`...M..<...q.%j..%.H...l.C...zm.bJ..@........\........8w.Y..<1...>..1...B.#...h*.Y..U.E
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9110
                  Entropy (8bit):7.979377312730575
                  Encrypted:false
                  SSDEEP:192:arIm1LZJ6G3q57Q/bLd1QQGmodUdR377CbhGa9CpqYswOCFwiBh0GLL:q1Vfi7abLdQd852bhGBJBjrLL
                  MD5:1E98C8713F18A0F8A7E78DE2A024F1B3
                  SHA1:E69A942443D679D7C53272D85A9711F55E51749D
                  SHA-256:47BE516800C4E6FB16EE1419A67DE0A7393FD1F78EC3173F8C2EE9D04DFCCDFD
                  SHA-512:E6ADA132186BF81E5E0A0030F3848AB8D78628D454B47C53A7FF70316EE994F49E4CCFA6E0FB77DE1F1F5555AB2231776BCA0BF3E38BC0F94072CB843F28F4CF
                  Malicious:false
                  Preview:I!..:V..l%"..m.`.GfP......I8....<=..#%..a.."..o%..kR.W.Le........z...|h9..p...(#Qo.B..61%j.Z.r^q)e!2.T8v....t.F.....g.R$o..b.....C.T.......-....C...9S.........}.RS.....i.x.....?..7.&..gc.T*._......(..[..3.....g8..<...s|..d...-.C.*...E?.g.)m..i....A$!.Q7...;...pL,.5....`..p..h9........D.......}$...qm.~.5..a..9.s...Bu.aJH...D.u..S.h.......dG.u9@...J....wt.o.......;.....]...8a9........a.r;.,fk.h:.#....E.W...V.E/.m.K....x.k.r..3)W..io99Wq.\"..8...X...Jf.X. ;....o......i.\k....<1....r1...H...v....9..{q.T..O.V.@.+..._.....hT9.....^..f..M.....W;.4...9..K.'....P`#..sn.../x..C.[Mo.c.....".V..U...q.*.X"&..h...aB../...-..d.....( .Y1.........(s.*.T...1......<.$.;xR.F......l]...Q.h..@....h7.<.z.....~..n....y.....]...nDYAY.?.......]..2/.q.p4aP.%.<b...$..l.........XlhUP....'........}k.e5..p..Pn...d.9.6L*+{.L~t.AC}.k .V .o...C.R.5 ...*U&_B.#Z.@^~.$.9...w.UW...4a......\....S..9.w..[.)..4l..sP.....V......j..q$l.k!C..J. .......O..gG^C.........<.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):18937
                  Entropy (8bit):7.989126029356357
                  Encrypted:false
                  SSDEEP:384:14hQKNPKcNbx+2t7oMhmtiNEnZnnLJ/+kE1FVKd4JvPENF/xhbPQmNhIk:oPKcX+W7otLC1KuFiPhTjI
                  MD5:B6508065FA55FC751AA64FFD881734A4
                  SHA1:441BB7E2B2FF7A2E9137D9A7D95E8EE5475104C5
                  SHA-256:FB410D32565B370A9C9C9810F79EEF2B60D0857A676DF04CFD9989D8D73AE6EC
                  SHA-512:AE455D67C73381EDCCD20E4757AD7FFB2A63D1D81AA6EF9455AF299C39FA3DACCD26E789B158CA97EAF3D2B6645A25DD961C95FBD96474C73B26BBA94320E1ED
                  Malicious:false
                  Preview:SE...P....[r...t.?.k./I1NH.....[.....[\.LW.3..I5./#......d[.(lc....9D../u......-.).]$.[.......h......'$....(].{.|CK+Kan......l<....v....-....Rg..[....>..7 ..~.......:.....$]....j....&.5Kr<gn.X.~...=.=!n.;.=...\..C.+.|.%.e.{......?zw..\..Y.X......%....9.QM....._6i.....;.x..0.n.[.8]..0....O..ow.gL...S.g[...a....{8..5....u_....=...NR.>&nH.A..lG....D>p.r..%...OU*..,....3....y....I.1WTI..x...y$J.q"....s_..J..........Jw.b...zb5D....$|.I2....l.:.u.~/;....p.....Ez.<I.....j.L.....D.G."..T.......F-T3/.&.....c..`....Y+9.....yGhb.5...t..t....'..l.../...^m.Mw%.4......v......4%...%..<.].R.F. %.......H.."..nr..3.~..`k.......h14. J...R..!|..t../5..|....O......_TX..P{..$Y.!.T*Ky.tW&{.....>....s.........s...C....m-.^....;Eg.0t..!...t.N..amA..Wu..i.D..........l..I..F..]1`q.x*....I....1|...>.5^M......J...2..|..r........b")..M......6b!..19&.p.....>..g......$/.R..m2.AH.id.$...j.af.}.../.*H.....v@t.AJLkv..UJ./.f....r..F.p..qY.....q.>R..[...N..x.^@j...F.D.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9343
                  Entropy (8bit):7.979174496304082
                  Encrypted:false
                  SSDEEP:192:6qPv+ily7QcZSvskw0h5Kvk6XN+1Kzfczeh6po:6sv+is7QMSvsNtvNd+YaeZ
                  MD5:044CC402FB7C12F76E1A3F18045150C2
                  SHA1:E62FF87FDFCB056A7EC4C163CCF2E8B21B4B93C7
                  SHA-256:4767F42D74DD821DA8A3695508BCA8EE4F3595107CB0946D30DECD7E3C306161
                  SHA-512:94459B08FB9401DF3B5837EF2303BD024573638DE788FCF1F0024AE1DAD2F2B8F78E607A930D953FB97FF75CBD1CF628D8ED364A0B21E4AA7F895A9943CAFC1B
                  Malicious:false
                  Preview:.e.&....7......v.D.6.g.tVv..@.=.{.Y.o..=,-.v.O*).`f.Zo..........E..a..P.9.............2.o..`.ti.....o8.'%..H.)Wo.....e...N/...&...7.J.B}?.UDN.W......o=.O.J....~...:Y...Ty..%..k|5.h..N..JX.w.Y...y.Y..WoVlE.q.KQ..y..b.".L!BlG..>.n..jQ.3......3.<<..H.....fA... . ..V]U........&.z.I..Fb. Z.'.h...........'..Fx.K.o....{2./ ...L..&.?m.l..$.u.6.f`[..j.$.z.....$........|....e.....G.........s)p...E..... .Y.T?1...........!.........P#.A.....-.[G.>.......j[.!@..Z...L.x7...BU.2(....\a.\H.z.C.-..... ..6_.)(5.....p.u.oE.d..M.'...+..#BT{.k...3#.u.:.f.wy2}.X..I.P...u8m2....32.............T....w$..^..V...}..A*?.Y{(.<...M...kL...6tI....Nz..>.rWT..Y...E...f......./..E&..Z.:.oWY.h<\..<X..AuB*....7U...e...*.3w_M._.K.3.b._.?.....l......|`%_.#...G.a....H9....t|....|)p3...i.(........s.i.a.......Tq...^U.nD?>...hT.....(.Ps...y.8A2.X....0IJ{.jM.G..q..,.%mI..s.*........Z..N...q..nw.;...d/..,._S..G.*^Z.T|e.;Q............(FH.].OQ08.\O1\......%.s=.`....l..:..<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):19396
                  Entropy (8bit):7.990695910777381
                  Encrypted:true
                  SSDEEP:384:JCy4mKtGzEe9MqvIMScPl2VNNqxfRbkaWbgtYcGJgVEJ4P:4maYLv72IxfRBWs8gVEa
                  MD5:F7684141307C93E5F4CE42EA0ED333E6
                  SHA1:11F0F6613E15A7FB642B307AB2715E512ACCFA4A
                  SHA-256:D52A626D32BF91C295E3977187909712D2B18C5463C9C5B33986CDB77040D158
                  SHA-512:2FEE3C7AB1E39B1E0C22EA78FD6E415CDE3DA514DCF333B0917A57E060EEA8F70D09A9C12E698F0B65FD131357A351AC6CE0D2AA3BD7AFE306142D753BCA2FF1
                  Malicious:true
                  Preview:.K...1...l5...>.Bb..B...H.......~.A.UO...{+NZ.f........_.K......./.{....&...B.+.E.|&..sS.0.+Q.G.jU.&T...J...C..G6..7..$.q....6d...y..z.%.9O.Sm..Z....nzw.r....>`.[......DOwbE;,..O:.$|..%.6.....].......2myuk.w.....wI..;3s. .z..._T2|1J..'..|K.......=.<.._.d........r/o.Wi8+..|...........%{q..XS.._..X..k...Sqd......f.Y..F...}z.i|.F7Z.n.....J-....C.:.;......p....\(.'..e|Q...-......oc.K....w.Lm..<....Z.|..37..+.;.P......z....O....D.|.........g..^|..*......, C.a+2x.i...:..+....:.gz.x..`..b.;.=........)......4..dA...<..9}ta.z..'.!.8..`....'..j...y..\y.1........./....R}..oN.$.O.........W...~7...a.^7..O..0*\....:....KTI....-6....kc..h....|....pK<.X!.&zV...8.q...x...A..ZR@l...........l.......\...g.W...L.$..|..h..u.Z..lg..Z.:..5%...t.\#z._'Fr..-.G..#8..u.2..W..........z}@?..',...s.k..>..`7Y.!.[..C..y...YL...B.l}...].............7..N....^.K...i...F._]s.....;..+_..>..+.*N..>..G..>...v.s..........C.$.j.p.}...K..%k..8.Q...>..C>.......vX`...1....j.c...E.a..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key Version 2
                  Category:dropped
                  Size (bytes):652
                  Entropy (8bit):7.5950548615346865
                  Encrypted:false
                  SSDEEP:12:pLj15K7x5Ft17QofiA3BdfD1VO20SkuRJz00lgIvg+7f77CqHiVk2E/aKQllC:9REbFtffioBdRk20StJY0lgIY2HlCVP
                  MD5:495CB3A66177ABC9165BF2F4AC776659
                  SHA1:212AB5215272E6E1CC7C66E0988F81DCB80DCB27
                  SHA-256:9C13D3DA343141CA4F037C7F3D198E8BC17C8A13105ACDFE0E5F7E2A9775BB2A
                  SHA-512:F7FCF5CB22DF64097BA776B3C86510B8C40BE344A40F7A010CAA943EC6B287212E8138EBB6D2F8B509C66B5212F580E41EDC22682D8543991814B9878551A441
                  Malicious:false
                  Preview:....|.V..u.....{XQO;{....r.....y.u..4.h ..R...m.ujg.".d.l.J...&.=p..s......f.....PV.).....1Yd...e.9<1.W@.n..\......x..@s:y.Fp$.6!...mVj.n..%.....1~...#.3...+.o=p.f.0k...5.C..4.7.C.>f.....ZC..".......i....5..f...(5..........{...=V0Y...3..^.....`.V...-..U19...<.:.@...e.U....Y.U.X...O...|cA...</##..2..l~..]....9..K...".k..E.^.`.V...|.Q...u..<g.o[S[!...:.9.s9..EX.qb....#...."+1...<...X....c..A..i2..@.....E&..H./.N.....e.?.\.:.."....5.6.................fX...E..W....$...p.....h.. .~.A...[. Y.%`....r.&......H...:5..e..Pg.6Iw`.@"..........-Q.'M/:J....B.....D..lb.O.t">RX.S...fsD....k..q...........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):921
                  Entropy (8bit):7.701824058169944
                  Encrypted:false
                  SSDEEP:24:osBJNrl6Pzu3kDcCXKapdgxUey3zVoGL14WcArmrk:rR6WkAmIxHkzVT4lb
                  MD5:5681AB90F07DFF79953BFC0702F5ECAE
                  SHA1:9331AAE642186D5422AFC39183C7C76B3C19DF02
                  SHA-256:4AD6CB3C48A554ED9F534A621D8DEFE8A253A29BF1F7E7FB5BA22A53EE5035F9
                  SHA-512:9741501B93B070442E6F06F057F61540969BA2C2F7B05B3F5DDEB4A29EBAA3B5C838BFD40496CE93C614B1DCEDC6856E7C9601BB6C20282B5830A91CF354FD80
                  Malicious:false
                  Preview:.i......[ ...M....].......Z..>..<..D.Q......1..z.z.qz.#...6...s...+..b...l*3..X....G.....e..."..F.bS#......-u.d.z.......y..E...................>..J...T.T...g..#@.DRS.O..w..0...&.3Z.3K....1..SQ..T....zyr.xQ'.._J.....%.A\.R.....?.-..".....]........._:..D.^.F}....o.-..h.=.P.!J..w._O.K9...q......8s[.a.F...1.b.O.pk.....Z...\e..T)...@<`nT..$....S........H:M.D..h.gk.:i%=.....H.<;z..x..\..p..`..Z.#*$H..Fr..t.c..q....A...c..d..|...l(..".7.L..;..(n.qp.H.R.EPd....r..;.F..$..pc7........f.._..r.?....&.KtpK..<.fz..>...ZU...%.K.A...fh.6.k...Bkvr...^.*....df/.....X......x..)..t.62k.F.`.n!...33..4.`..\.}.4.C....U...n=EFr..Ht4..2.......c......}..T.4..;...#....`^......P.E=i..]..i...+.J.;..j.0.M.?..w)e...Lr.)....S..{9.x[...?...<....(..;..........k.p.'...r`7.e........X.7...z.].....#v....s.Y.....P........xc...1m.I}.@..D.T......C[.....t%.tr......9.9.?w.W..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5573
                  Entropy (8bit):7.963711375120998
                  Encrypted:false
                  SSDEEP:96:kBUNelJwuOuz5LQtr69x931jKGVbcRgM5I1S1s2GctHvTg0B3JQyFii:kBUNe4uvQtr6J3N+I1GfGctPE83Fi
                  MD5:565638148BBB36E0940D4C428EE83C0D
                  SHA1:7F03E654ACAC6FE7FA1A551C58359551A42BDEFA
                  SHA-256:9849637AAB1B793BD7E965B80BED42C1252018FBBF3F9E1AB5A6800A6AB78253
                  SHA-512:84D292E8188C7A4CED3301D043FE8E4A819AAE3F61AE543896E2171461E9EB2AFEAF99BB3DA58D9CFCA580D37AAAEFC7E993316B76BA2D4253534997F0BF0145
                  Malicious:false
                  Preview:.H.....(.s....)y.]Y)..MZ{.D#."t\P....-xL.*....L/*.V.q(e...f..h...K^.....w.3...g..Q...O...~......F.o..w.n>.".G.".5.....O.....+..=)....H.wr..(..<..|&.......$....3....}..*N.....E.../?...@]x.9F.?..{X.a.CH..6...Z..k.*.......[Q....~}..veJ.........W..)......;....W..Qc...}.w.:B.7.&.(....P8 ..-.A....ooJB.'..~q\9.Z"..@.Z[-..~...7.v..V\...O=..:J..8.dU..J&.n.Z%....rHXi.....,.C..}..x.)I.O.H...=........F...%xt;...j.....e=.....v.v.&."0.....[.PC.2....\...G..q..'8.k.m`.;"...@......u0!@(...ti-o.......x...qY....j..@kI...5.n..C5....P....O/D\...^z...H.E{m..%......9..o/ -M0.p....y...k?O....Z.....5RE..#..;..... .v.._.s>....6.....:S'@.ew......../..{.M........Y.%-.2v.]HE.....b.)4....4t....wt..oTF..}..0p.x.A ..;...=,.c..$...<6....o.!......7...=.u.T...yj;...3.....a.npX..4.?.w."+}...a7..kqZ..\...{(J.B...C...BAi.!...j.D......a....Hi.....v.z...2...fH .....I.J.^.Q.Zp.P6..W.._.....,..dXz..M..3.4.-..... .A.Be...V........R..VN..kP[/.....$..Rx*...K.A5"...@...y[#W
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):12456
                  Entropy (8bit):7.984041750279513
                  Encrypted:false
                  SSDEEP:192:FyLjLvR5UV/arlrfgDIh710mHpKiXWTM9nPXN31Adv2fX0IM:FQjLvR5fLBWmoisKn/gvSXdM
                  MD5:D9CADCE62D5E2C24E7437DB44A7080A2
                  SHA1:D9DBF5A92FC46119206C87D1594EAB64DF0C650F
                  SHA-256:6D3B2C2797E6B598E2F16AD95B62FFBB2E06E5DF43726C7CD6B2C020D96BF945
                  SHA-512:F14B992BC920E0387993153C82705B7060E62E8FEE94F678502867B4AC477CAA554F3F60FD2363DDF04B5A0F0532DC1206730B06E553ECD1D0E9CA696DE7943D
                  Malicious:false
                  Preview:....]....v~.t8..o3z.......8.]...Z.H .......:n.n.......~.B.?+|..AO2...E...p.g..*... SBV.}.....v..,.....3f..h.jTyS.....;.....f.t.l.,{#.G...3.-.c..f....B3.Fe....]N*&.3..UBn.C..5.@..Ah3.inw.{.....L..:.D.^.J._{/E..Y.F0<.....3*.....`...>~.&<.5Ay~0R.GK....._.7....S....X....r......F.6..i.....C&.8.5%.j.X.i....}..~.QlX.U..g3...G.~.D.a.....V.....!..G.B}..W.[].,...)..>.....W/+.I..*...M8......z.......G.wZNa.KG\.W.L.9J.:s..G...;..GH..\...}..IG..#.n.2|...Rp...)..?zgzY.:...c...g...~.....*.?..g.vg7.).OK,..ggn.....a.4.:L..#4....}f...........1u.-..M......Os.5f...3..Z.YhO.......uo.4........M..|.E~::4..S....\..5.V(.......5L.tz.m...........!.G.jz1o[..i....B.y...../d.9.i5%....EI..U.j..p..Hl..f3aI.c.>..p.-xB%.M.W..S.B.h....U.C.b#.l6.)..a......-.jg.D..lye.*.>}......L.y~y"K..4...w.c..u;..."....F..H..c..J.C...JZ..iu.eP._{0`..y%{.$I.KW.Q.U...3.Gx#.$.....,..M..q..m.b.d...?G.....N..r*..........BZD..Qn./...l..j..Z.8.,y..<E..F...{..F'.x.>..p9.m.....pNL.cA...o.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2522
                  Entropy (8bit):7.914215364600785
                  Encrypted:false
                  SSDEEP:48:wa3LG+L3xkaXUtI1f2Q0WD9+K3hTkxtMmwTE87r8ActkedN0:w4TLX/2lK9x3QQEQArkeQ
                  MD5:302C596307D701B6500F0BB64C889626
                  SHA1:754C624C2C0637ECF6D050FFDAEB2183F6D34910
                  SHA-256:8BD74A1A621580404F7D077398CD47B5149F711888770B02501823B96FA670DE
                  SHA-512:9D8DB04BEA31BFBD155D9BE103787E98235D6B66BBCE438FB15EF65AB92956E42036C685651B4099AA31C4ED5661B8379158C5ABFC0E259882AAFB9630859CAF
                  Malicious:false
                  Preview:@..V.WN....6."...m..%...=.bX.;...%S....N. ?3{S.Qz..z.....b.N...y.{.....3:.GS5....G7...l..,#%..?..._X.O..../.jk....H..Ul..@.]P.Z..'.B...(66t.z.*'..J...lt...wQm..Z..Pu..34-_..r.+...jI_-....'..m\.4._2'.p..Lc.u.*..-.;.....-v....k...E..h.1.....Qt.x.u..k.I..s....9.X.?..y..3..."h.;..FV.+,.....}..P.=!R].T^6..{]f<.m.U=.|...N..'..u.V*.:.N..d .J.`..x.X$J.z..S......)..}8f..K.2A.1...q...[...E...68!.<..pTb...V......7.......Zr.I.....!...(...,.$........5..m.s...@.K`.t.t...*...Zc...s..>.Q.5.D.hDw...a.....Y...X.....w..1..R...=...T%..j,.O..`j.....wAm.H"..~.....W.....m.. .......?.Ki..Di.[..U.f.s)........*X.&.t.^3{..i;..XW.y.6}...T4.Z..S..Wf....^....]..0<.......3.......4..Z`.#9&."..B0'....3..c...A...B.M]..H..m".,.`j=6......9U.......q.G....mT...x..F..q.#..Sq..OY..T........Y.v....\I.e....R..A8>...i..c......oo...D:...&. ...yx....*;.@#.]..aK.7..+......D.'p.)...@.k...!......gg...A3.W*....$..&(......W4pqd4..y.%.<..".K .z.7..#rG.{.~./....Y.$..CIsi.P.Z$NQ....Rm..y8]...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5155
                  Entropy (8bit):7.954933075204215
                  Encrypted:false
                  SSDEEP:96:gjIAqKPG4pOwephGrjOWisQ6691gNDgJI0gA3g4Gm5PXU:KqKPG4pOwqGv/69K0pf
                  MD5:020AF1B97E1FF21F3A9AAD43C72A29D5
                  SHA1:3113076126AF9DD95EC71A6605C40DFF8F637233
                  SHA-256:4BACBBEA3693923672BAB84FDC9FC411DF41452F07129DCE4DFF0E5A7D7AC5CF
                  SHA-512:5308F11410FB92E1D8F1B00F2B3F17ADEC469078AD5F1D3B501FDCA7C6DFFB13C661B7923124803A637058BFD1584DE6336927DEAF871EE88E2FDAFF5FE0826D
                  Malicious:false
                  Preview:....F...Te1p.m-.`..r....)T......v.wD1s1_E.....8...U.Wc.p.3...rO........$U..F...}JR)C.I.?..4...d.+`...k.....~....A..0...%X!..sx.../...6.\,.\/!.m.@.."..M0...{7ONK......u........0.Vl.N..n.ym.B.&....C^Ni..q.x...{.p...>..?@.2:...!..6.b:Y....x.f....o..n.n...f..*1.n5.#.D..b....@....R...y..<g:.....NR....,.Tq.OZ.E]..M.].Y.|r........5>.a.5v.;.....2.........W.$n....$.....S:...7...J...........=H...@.B..D6..C."r.c.".W.h....].I.VR.......GIZ....h...I......6.i.p^XjF*...'#|.u2........NFP.....@d....CG.A...c/f(........j.......... ;.4...J#...L.EY.B...u.....Y..A'.P...d.+....P..1ZU...).G..n5...y....O..EE5.2./r..k...jb.g_...^..Ra......+......=...q.p]...{kWg/F.W.`LI.....Tx.(.f:....s..\&.0.Tsc..D..1o}....?..a .. ..~9.Bl.q........[...z.}.7..*Mt.).....;.s.LIV.....|f..<..>........r.L..UR...-E........%...I...x.D..u........I#.a..~..E9Oh..q.<^........*.b].'GU..P2.ny.@..."......g+....{.*.`.....s.\....5....00..0.<9:.z....A..sR.=...u..$MW.......e4..8,..+K..\...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):847
                  Entropy (8bit):7.69412787754943
                  Encrypted:false
                  SSDEEP:24:92TeBwDgOJcjjIUSWfdm4pTljM/2yUlaS77C:se9mcjjFlj1+
                  MD5:8FACD0BEE03B08EB3CD29357D0687E5E
                  SHA1:63EBD1AAB8F755E045601454F2D8CCFCE67B0DAA
                  SHA-256:B3B633AC92EB8694AD992D72C2F292BF2F51E1C8781B22DA3BE66149B0FDB083
                  SHA-512:DBDC76056693316021A63715B49F2C7AAF4D6FA4670BC94CA4EA6CBB8B7D3ECB006065CDDEEEF084031407BB7B43137C996D92740B227624BFFCF85D2850D658
                  Malicious:false
                  Preview:.k.J..&4.....yL.Kx..9!..X|....j.?)....XS...R$$::x...|!.ke.........[;2...,.}w....]...........^O....f.zK...Not..zNM_EA.t.9cq0.K.././...w....4,>R...1...........b.%#.>.H........\..%cX....~a,^....[H.m..c#.%(.A... .V..nt4[.p... 2..........N]..m.A~j\..-..f.~..A..Ye..A.I.....f.ED..?=J.3X...*..3..[O#.D....akQ..bQ..J..y`.M..4.bx..qX6.....\.............@+..-Ae|J.(.}.I..T.v`z2..[O.7.?.....m....<....4.........id....."/...!..?.S..........5X.0..d..y......Fb.f.K...z..e8. .g....v..[..t+.Qsb].mL....l ..9 ...e.9....;U........)....(K...3YWs..R.J.l.. ...^.l....k.OO.....ks..?>N.B.=...?.>.......e'k5Lo...j....].D...".... .N89..?`t.4.c.s.(...H0..$K......J*F..d'.T!.0R.i..A..0...O..p..:.M../.lxi.D"....~Q.6t.X.\X.oP)..1D.5V.U................... ...W5h..\T+...X..._...>...oe...R.v....*K.z.\9.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5661728
                  Entropy (8bit):7.999963228676222
                  Encrypted:true
                  SSDEEP:98304:3Qok2KDEAqISn8pLlmTFogPVP5+yW7ULw/0e8FfBcEWxCETcu2Tn6Gk8:pKDJqI7mKcVPEy5X8CETcvT6GX
                  MD5:FF4F79A271888A3283CF409C8571DF31
                  SHA1:2D74E932C43B714063F21F85D1198AA2E7EE8DB4
                  SHA-256:6D2A2830AC06BB9BE37BE335FC37E3C30E8DF85276968E033032179A4E06FE7A
                  SHA-512:92A6232E89F4BCA43ECAECB96473726B06556C3558ECA008D3F9AA4FD732446A1A5F36B2BA7CAF9EBCEDBF0877310C87A5EBC2BD335280F77C4A840769441DD2
                  Malicious:true
                  Preview:Fe.$......^...M.q..r./...NH<Bx.<b..k.".^.O.}t.......&..!..;.....GI.!....xn.4 o.z.M.:.G..s..i...2.......~....c.(ii..C.a....m...>....%.3....dY]}.4.3\.I.$1..m........|m..I...}.Xs...W."XR}..n./.>'Qs.'........g.JE....<...#E.o\..xF.<;e;U;.p...<..8-.F.,..(}....m..........&....MD^:...y......_(..-.Ab.A...D.Q.F......g..0.t.Fw..d..f.3^..)...>.O.._../..xT..;......OI....&%.z...9fL,a.{..;2.j..c,z+.#.bA...n...3...5..w.P.._.xsF...{.O.m.-.6.n....K....r.!A...BH. ..H{..S.....?K4.{.d.8m.3g...$I.}....7.....%..0..e.i.....*...42q..i....v....%fM..*S...IuK..Q.8...f.'4j.E5Vs.......d...F.../e........+.o..c..gq.G..Y1...E...bFh....f..........G..ulMS..4.3'.c.4o.E...N2L(.!..9..)..5.........6.-H.D..A......C..:.>...kzLc.V71<..~. Cf.9....a|..~UB$.s....\.A=l 5.|.:.l.k..mRW.c....rp.L..|{...=....l.m..g.T...._....~.....g...f......s[..6....d.....D.H~!.)..It..l.f..._[UslT-.t5..d.L.Q.6..k.....#.Jz...6..*.;..|...'~v.wuUW..b,...]M8.t......p.<9........:.(......y...R....S..K.%l......w...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:PGP Secret Sub-key -
                  Category:dropped
                  Size (bytes):11511
                  Entropy (8bit):7.984481106346053
                  Encrypted:false
                  SSDEEP:192:nRTmrgSZkkGSwYYeVTBLmdG382jF5qg3BhisTLJwRgLd76aE3jOCzEme22Qt/:RTmr5k/SEeZBq6PjPqg3isnJw26TTOGt
                  MD5:51B7A8796943D12DC4AAC0BB8BE240EF
                  SHA1:1371AB2DFEC383AED1167EDB6C4234C81D1BDB1B
                  SHA-256:386BF33CAC050082673BD10CA99E1A09B385D81DEDDE410A25FCFA2CD0DFCEA9
                  SHA-512:F27C51802C60FA2D576B764195AC0789F81B258FA6684BDF6B6B0CD19CD3487E8105987B5AE49F2CEB50EE99AB22C0DE375C58CBBE3B61C804D2E9C97B636FB0
                  Malicious:false
                  Preview:.`...P..+o.d..?.dY..30-u.,.3.f......|..W........U.H9.E/.\.T8.I^.ZE++. LqE3_dB..q..C`'.....N....)-e%...7IwH......WTP..`.....2..q.M~...t....:.p.M.M...[m..\.U-.*..Y.N....[...j..RT..Q......}....9( ...v5aw.....t...L.k....`.Q]r3....%.....g....q.=.[8,.....)....%...{@`nK\.$...mb...U..y.8m{..N.L....\.q..i*......&.......1...@X..w.CIM.x.3..<.d9.;.ci.$.'Z........\@d...{~....V....'..s...S.....".wGk.......T..f....E*..AX..OM...a.g...=......:D..y.......x..?t}....D..i....v...:$9(^0....cE..EO>^....bD..6.Q&.P...Rt.8.h@..Nb....XL.........in&....1.5..0_.(.f...i...duP.P...R.|.n$!a..1].....\024F.a..j...#W.o\..`==bz.U..A..U..Y%VjB.)..K.C.j..b.......6..)H.k:.:~nkp..<}&0.X.)>...D.7K..).W.U..M.$........&..p..B........b....,khX..(..&.I..x.k.,...P^1}q.;..4...h:.[#]&.H..=........v..Z.....E ...+#fH>E.yn.s...v.5/..j.Pv..=...cX...O..P@0>.....d...q..Y..+.|..b}...a."..c^<)a..np....C.....,....}.p.x.4.c.~.....!)n.NO..h...5..<5..:....B._Z..C.q..|M6s,...NC8./.J..>.,.J.{
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):19594
                  Entropy (8bit):7.991705110416478
                  Encrypted:true
                  SSDEEP:384:cZPxg7WVwnRWgRhTB5mEtaEAg9GrxfZBgUtjP5q3S:cZi7A4jRrwQWgoxh2IPw3S
                  MD5:C9C7FAA7FE25BD096D2972608CC5DA68
                  SHA1:6C1B9D451D73DB5421FC655A5578FE1ADFFF0667
                  SHA-256:5034421DAEBF38D6252D142CE6D5EB5D945EB5048FC0E8F41D448F410FF34B9B
                  SHA-512:72C96AA010E4083CED6B9A6938A6E3386ACD066A076625DFDA8DAC6C9615AC13B521E0A09CE5A578B5F51E52396F208DC2CCB898053694BB8B668CCC13679055
                  Malicious:true
                  Preview:1/)W..'..Xq.=..h....>.f..*..S...|.2...J.<..<..p..r>B._2.T.m.z..O>...vb......-4.vq.#0./.6.ym..<<.fYK..d.>...>...2;(.)......ZG..$ju0 .=.%m.l.c..4.A....TW...s`....$SQ....1T.M.....l..*...O.o.oV.....x..Q.......K..\..C...#.O.<.O..!...........D.7.\...T.P.a..\3........C.B...q[....J......{......M.2a......W0w.Y.!{........h.R.QR.*#U.(:} .fs.`]..b.......[D ..'%].7..u.......W".......\2.f2dyZn..4m. z.WN5!U..M..@Wv.RX.26.U.:I.t.~i3.....2.............4\x#.z.......V....J..Pg..EP..H.w...n............d.}.qL,X.9..."47...m!HG...L.sE...=.<6..A.9....v... J.:SF.C..7.j...1..I.e[....z.P&.j...O....~A.{..fZd.....:z.a....Q.;..&4...8...[d.........N...^Va...c^$...!H.......32.eG....c.U.....6.t'=..U....5..S. .k.+..#C..UX.t......M.~'f.*.7.....!..Z_{....;...U.6.^}7.I.*..............0s.z|..~...J..f....I.%M+d.e77'.........\..B...Y..N.x..?..Ht41[......Lz...E9.x.o._..G...T.R.....G\.sx..;.....3..Uh....H...E8.<.F-.|..Y..!n.gvT_...f...\v......k...:..T@...K..r./zc.|.]<..($..m...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):22889
                  Entropy (8bit):7.9912625751277675
                  Encrypted:true
                  SSDEEP:384:YBmAhKJyi/tquMfrnVkKcX0clGi1wBQsOdWlKXSVmH2JHPAFgYwMswIzIIQWPTm:///EuXKc7Gi1LpSswHP8gaspIIQWPT
                  MD5:EC5114B92B36BFD360F6C33D91C274F3
                  SHA1:65636A5CA1D559DE67468349FC99D5E544635BDE
                  SHA-256:2558242227824531DF90E64D269DF25C97F9303529DE575DFC58231D8868238E
                  SHA-512:428BAAECB4EE59D7F537F71A6579FB077B8240A5325E265F7C00B194BF7C3289F533FB038D33A0D2B4901289E00421FD93EC3054F1510B1D299F8F00C0BB068E
                  Malicious:true
                  Preview:.y$.K.5S.,.q"....9...g.....C..+e..0...8N...>{|.... x&#r.j.U#V...+..X.&......).@...g...kW.m.\....XFE."...m.7U...GL.`...Q.l.p...ZX.......0..9+7...v;[..s..R.X...1....8...h.O..!.t..I.N...rP.-....%W<5x.Em...}Y.."..w....5>...w...+d.]/.s......^Z.........X3......c>...+......-.e;.D...."f......h....i....'.*n.@X...q@..3......J....2.((x..[..S$.O!_...6...S9_......[..F....G..'Ze..<...1$.Jg."..69'..R.. ..w.?..F...)`.A.....3..B .Ya\.2u....3..4\F..Tu.m...^y.\}T.......?...`{../.K...1.I...aO..(...H.O.{..y?g.Yc...3.F..z.Ln%.}Kr..;.M(z..l..........;X/l$$..a..v....2..."W[..@..b......-_.K%.......29"c\..r..!..B..f.^. .m^r...n.,.l.........L. .a.....d.D.b:...=...=tU|((..n}$5h.[."....R..c.....V.. c......Vr{.........S....}.^E5..UJq.Ye...ky....02($Psp.y..3.>...j.t..xk.-....5....2..{|.P".6*.1.'.U\.;...x..(..kZ|~i][I.A gF-...n|vL}..F.x.. ...0..~..._.0....t..g...i..k:$........l+.....=.......Bu..l...a.....[.7.T.Sb7O..'=.....`&P...j.*?.C.......SA%jW....:\t[Y...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):999
                  Entropy (8bit):7.721974832367897
                  Encrypted:false
                  SSDEEP:24:YWm8IUfK7xGPCOu5y5lxHziJvUTf2hU4kbZvS3lntAyv/UY:nxIUsxMKSlzWO1Mliyv8Y
                  MD5:59B9E797C2EE1AA092819031C5096065
                  SHA1:067C08F24546CA80FD90F9154563B43198E5748F
                  SHA-256:30752C7856C6C7DBC49E83B5B3EE1DE6116682796328FFECC62F1637AB3F656A
                  SHA-512:977BF91F6370F539DC3DC4FAE7C087F82CB23C270E5B26827D93C9339B98066C7110DBFFBE114AE5A8B9855A21EDFD4F94E6B5305ADA08EFDC21A2F710B7A24B
                  Malicious:false
                  Preview:...7g.V......@!]....h)..._..o....c0.AA....-v.W.ph.\...R.....B.I\1........y.j5...h6.fKo......>U.....a<.O.7....j.`..]..-F6...%.a.8.......m.#.].HD.8....6....LF.W....!.C.T..Y+........:.Ph ....E..$..4.....0.......I.R.........P[..+g..S.......[HY.p...Qo...j..WN.g...!.D.rG.../.B.aHF...a...h8..prZY......H1..Z..V.a.UL.wP.Y..a..*$!...;.u...(...........%..-.&.(.,.../e....x...0Q._..xO..8.[.{.s.....1.j....p..E..d..O....8]..K&...am.K^g.].......|.....Z%..v.C.2.B?.|T..7m......u.K...._..L...").U`v....!#s..6i......[o....%..5m.......(K_.5.$..q.t._.....'g..d:OF..z.4..H..g.g..:...q....-w....O.F<5...Gy...m..#..7...%t.......$&.....Q&Q....O...l..{.0.`..$Kd.[.\.i...V........G..&v...*...Pz%js....W.....,..+.....Ey....x..C..x.b.J..j..E2<.e.d..n......Nc!.q"..4..9xx.%6.|..E.a.i.1...............?q$!..Y...!....A_..`]..AI..M.4>..R..Wlm7.$......%.i..7.....O.1.T.C9_qG.o..c).1G........S...v.s;...:8.EQ>:..).H.|..i}.E."..G.......ZY3...........G...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):21400
                  Entropy (8bit):7.990545586110355
                  Encrypted:true
                  SSDEEP:384:wKzlWiFzwf9P2ltgpSK3QJSaS/ideuEdYiybgriDDDEpuEIJMS+gF6dAxSVaMN9p:wKJ4f9rSU+SaSadQdY/AiD0FIJpQuMF
                  MD5:7C6E93BB05776EA49704550184C79F35
                  SHA1:A8C90CA611DCE5B2A271CB2B98C22579A4D4DA06
                  SHA-256:668B21CD512F69363BEECBD7D4B910F22EE843DE7C9089963AAFC4BBF3DEC1D8
                  SHA-512:8423C2A6969BC071DD0027002C070EE02FF162DAAC3FBCEE51110CFC180CFA48718CE376C252528B0A5622CBFD62CCF1D2727E0F77C7F7E03773CCACA7313D28
                  Malicious:true
                  Preview:..pe|.M!*V..4.9..........V_.@\.c....` .WXml+..O..N.t].\.K...X...v.l.....)t..........G.7......^.6[....v.".\..#X:"....&......x&mQ>..7cs..P.c....x|.%e...\..C..-6.......Ji.&.*.aH.....i.a.........S..LV/.jCkl....I]c.w..tU.|%}Q...........-.j.L...P<H.Jo.*v...,.-;l..a..................W...B..z6..e.AX..O_._.G8.J.r...]O..'.+......'_.Om....h....j........)u...C..#.P.<.S.S.&.......6..#v..A....u.....C..(..&.6o.;...e;*.\.*......j,G......<.K%.-.......{.KiF.... .x.Y...\.......x..T....,.YI..\P.......9;.j..EH..d<.......i..7.........UG.D...T....mK........P..K..`~...S\z.u.....y1.N....%".....=noNd..[....}.@....zP..e~.....TQ...%t,.2.....a...y ..m.....7.{5..q|x..)...F<.5.W....q.....N...W.>..sB4+1...[W..M......(......_......2/...\..E.Mm5._.Z,....Uy..7.....s..n.._.M...&..!....c.@?.....J...Z.. .e.......J%+...B..Z....>6Q....r.......M9.R...OQ,.7o~......i.....~..'3.,/c...k.Wx.@F<P.6>...p.1(....).r....Z..Y.x(.....khU.`'.l.T...@.~.k.e...68.uX...I.[.:U..WH..j
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):20977
                  Entropy (8bit):7.9918962479524955
                  Encrypted:true
                  SSDEEP:384:mZKgGYyJNpZK6SwXE+/Zn1vsqQNyJuijH/zYs53asKnK:mZKgkhpZ1ET0JuAzxSn
                  MD5:FD7B33E2EBA89964D881A6655F993774
                  SHA1:81F504C90FC7CACA966FE69C3A0E1EA529A8BC1A
                  SHA-256:7553CAB8DC0FE7B055C50E45321B9517025755E8F7D9BCF3BC54560C03DD1D89
                  SHA-512:5D1887D38C73F717DB9CB816B8E60594D9AA0DD9449B4C66550FD9BBD5513E5A0FC204D525FBB32CE1DF0759F6EADD8B413896199A465C0752DBAAF25D2C7B12
                  Malicious:true
                  Preview:q}h..89,...<.....$|cZ.j.Q.:V.......Q.M.VM..t...k.....kg.g%..|..Z...C../j..h.s.y..HK...7...N.^..H....S.(....O...r.ac.!.9..... .d.tK.....#..N.<*.5.'......P.i4qPN...)S.+O.7..b.1..M...w....W.S...w&.mf...tH.T.w.)0L.(..Hc..../...NM...>N.J.g.>..*Uy..I.cEh.^t.%.jH+.o\S..T.x...Z.....$..F],..!&..t.zv.j.m?...Rq.nW.A....>.. ...^.?...z.l.........w.1>(V?....s... ..<..Ao.;.?Z...2..'4...V.N..F.....U..........Em>..+.5...,v..........b...~r58...f...........ql..S9f...D.J Z..4mK"Xm;......k.w..........k.j....1..h.).8.._g....kU...J.|vs.:...,.=<-U....0T.u{...w..@EB....!..o.).7....Ii..(FO.e@.0wD.\..3.........R^r.5.1b...(....s.G8...../..`.:E........u..fZ>Zp.?JT...gF.......3.....E..Vu}.|2........B....._m.......r.....tu.=..?0#;...6..C~..Uq.T..2...@...ha...`..(....@:......I.[;........[..D../..|.H.1.7a..%....~6.-.Rn..2..(Bk...\Z....L.K.|......]u....=~...".\........q......o:X!/.U..JO..pu.j.]...0........ .A.V......v.b...k[..7.V.0.c.a..6...Z......b%S..aJ..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):22784
                  Entropy (8bit):7.991905454918568
                  Encrypted:true
                  SSDEEP:384:CKm6RvRZqTUnIYZiBcREjrqGvpjv8FkZ0OUFAElnZS6917uupm0+O1KVHZqu:CfmRZqq8BLvxkiCVkS17s5FVX
                  MD5:EF9297339DBD5A4BE331FAB0C3B55EB0
                  SHA1:62DA13A40D99904A3817A57A7151821338E74EED
                  SHA-256:8FAC0744E21F23E23F2ABC481C63A5E89C2B633C9B61743B2672B4D899194805
                  SHA-512:41466638A4E74C37E50CDC26086653F5555B7A03DE4293B8CEDDD7BA9CE75F14C184BA80D11BF65E51993B8A657F8F3FB7CC617BBDFC810B6791CA9F43620817
                  Malicious:true
                  Preview:/......G. ...Lc...U.w.LL..|..-.....P>..L.[*..$.|=P.R.....w)5T.....q.6..\x.QD..'.3..K....hf..M...Us...*..c4$.tz...a.3uNz.B.......-HF6.......I...F...z.x Q!.C'..Z...OU.......u.b.tS....h...{.....i%.."...=.&....N..Q...Z.fI...s.. .....y.qF?.w.....k)G..|...O.@.D....W...9..8C....Z..Cs^.......8..W.y|..i..9.-.........6D........T...$..s..x..ws.!...[2.TI..v..VOf.L..K.{..z.J...R.jp.1.+...p.)t.v.o+Db,.'g^..3 .}S. G.:BG.o<...#...vr,v.._)T.....Z....AwQ. .....p:..L../._....k..........&.-.s.~.!#.j..v.1...?..Jx.i..e.r..i.....$..R.5.=.M....`..r8V..k.u.9.^K.:...{.YB.x}."...&.......5...-..Z..;v..deU.< ..6...iw`.c....M..Rf.F..{2..-C..r...t9..<...x.K...w...3...l...|4w...a.:.#..4.h<.....".P.wcR.....C...%.p....&....t0....&.Z.....D..Bk&,...'HxZy..s.z.P.G.$.R."!J:....fCq....b/.......D.,....Q...8C.m8*2....v.y<...4z.!).m....y...}..s.}..P.e2_PZ.X&....)<.jwL{f........5`X..j...f.?.N,rh4.d+]|...............o.....n....F.A.....1.X.d.....;..b..6.#.!...%9.#4._.2.m).'...8..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):20472
                  Entropy (8bit):7.990472608038196
                  Encrypted:true
                  SSDEEP:384:m8SP2QuLkeG66wYGHoFAj5uZIQXgtkME0DgLQjLP6OtzaW7dyZZ2E1c23iflXsGa:22QHXGnuZutFETMPpdh7dyZZr1c2Sfl8
                  MD5:83C52B286557E28613F17960CE5E8C62
                  SHA1:4C14C53FBAE9B8D3C03EC1AFB3F1333069A0BAC0
                  SHA-256:E9EF00CDC44312F28810EC542A5AB5F50453F226230B945F69D614E1C7EFDFF1
                  SHA-512:E507E281024C107CB3A8F6BCBDFD70357F5A614F59D3404965DE7556A6DD957D400C2E04CB93F52E6C0EA0292CE70DF7F9EEF239AAF77AFB4649ACA9A1C912DC
                  Malicious:true
                  Preview:.S(.85sa..X....X.r..S.V.kT]...i/o..*.... .ro......i....Q.......!..-..<q..{.!...S.......!r.6.[..$Zx..!..JXHr..pL.MY).....pT..|.?..v..._L3..._.W_"..#C.{e.....S..U..L..&.[u.>.-.dw.k....o.42..ehd.......{4....08.C...T.Z...O\`t......V..W\=...h..Ba<.j.w8+zA......*..x+?.+Q..$...8j:...R..7.P.|NA..d..6....$u.N..c...w3... .>p)<.Pf.}............1bt.d0.g&r.,I?>.{2.XF#..b).......C......5.W.R.{J>..z..l..K...+v..sh.\.>M.....7.c...B...!v...oE.[...q....y..k.6......T..nE..._..!`...Atsg.B..$.R.,..s~.....8k...rw7..6..<..M?.Lj?B.wN..c6.wdwD.3..W.rE\...N..eFVc..-+.l........S.8,6w.E..8.....{../..0....l....R...>.y1._YH...7....!3.!.X.@.....,..l:..2........l.R0)>...vT..c....&.....j1S.h......{.]`.,"#.{..B..O.].N.iN.....2.u$>7.w>..D.....NQG........g!.].=.K..tn.w....|N2..N..C.U[..@>.+...>#....-.)...$9..K.... ...k...xc.....>.._..3.F.{...k..O.%.fv~f..z.X.!J.....Zl~..$b|.]=...U^.`4..r.Z.{.\O.E#..P..\-....a.V....sp..?.3....... [..........).B.D....3..).P.......&i..ji..-/)....`..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):25714
                  Entropy (8bit):7.99344870706712
                  Encrypted:true
                  SSDEEP:768:Xn/Gt0mbaPjN7yzdJ3cRfqRQ/3r2IZe+MwqFqHa:Xn/SKjNOhJ31m7Ro+Mwq
                  MD5:E379A4AAE26BD41B0E805131B6D34611
                  SHA1:D87EEC6D3292E3A2D42013BA8BF6A11F2E6887D8
                  SHA-256:6283E2660FDA236DFE04887E7EB0DEBE0F49B55CCEA8339238F4315B639C32A6
                  SHA-512:F0BB01B6AB63571F43D28FFDADD28C084C404A02D0CFB894ACFA4D5C597A6AB77797119A6247A559DCA7C5D6DFF8402EDB292577AF843FDFE85ED041820D5592
                  Malicious:true
                  Preview:.T.....s...|..V.dG.6Dr*.....^...u.!.}...b..ZUK..]\xB[../...........Vr...%b..(s.L`$U/.wK.y.....D/...<.p..@C{d.X...1:.#..l.>..z./.K9...+...G..._...t.^G.. .Ln..l.B..p....K....u.....Qm.o...U(.T............v.).(Rl......+m..w.dD........p..$xe,..p.M..W...........^.5yu.....vrf.`!.%.I'.H..-~....?.ykW...z...b.w.8.%.......^..q..)....5.fN.{....<.F)....V.....{'.'...............N../...c...;..I.G.....q........#.......x...7E..qc.<..........T.A...+.....h.=.t.Z.....ZP-"......j39.HS.Gd........!<.A}bF..........Q.i?.....:...->.KD.9^..._.4+..A|.;1..e..n.."..q..Y=.f.._Xh.,.IB@..%.b..8....=.7[|.......D..b. K.c..w."xYI.._{...F.;.&....O`........DR.].TP.....aX...]*...X..>.....S.v{.".|%....T..S...V.......?.3.<..|.>....0~.A.bp.Y.D......h..y.m.....%..|....H%..{p?...s.@r..6k.>.l%Ha...v$...M.aG..%.j"...j.J.[..]...T......KemQq5.]...i.='...Q..m,~B.!b/.K.nbRt....E7.A}..GaV+....u.+K5....[58..U.ky.9...U@.....Na.?..>b..!......~.c..."_../.{&...+x.]....)......4e,Zg...&}...-oQ.R...o
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):19600
                  Entropy (8bit):7.991253980425665
                  Encrypted:true
                  SSDEEP:384:fDJXgzeSYdaHoRLo4eoVtlG8cUHFbhlP1nM0HFm+1XSGYutmQi58lZJv:r1gzrUaHoRM4eoVbGTUrN1Do+1CGYj3S
                  MD5:023035EFE5BDDE9A1619F4EB0634AA8A
                  SHA1:0D0911DD0F5B6F45BF00EEE8D1DDFA467E9F4DA7
                  SHA-256:D411B2E6C48C49391BF085C6C5362452E78EAF780C1DE73C6863C362F907290B
                  SHA-512:1DA038B12154BA85E393C2CB210E948EEF592D77F7A309F91AE991A1DAAAABCD132132DEECB0A81B4F70FDA4B0833DBE219047441F4B3ABB16B30678D0D5665B
                  Malicious:true
                  Preview:.I.3.q..M..R..-...-y.{S..G.Mp.&.....lZ........f.+4$. ........d&V.@.Uw.....:Y.x.KM.q.......r..........0..&....J+....].P.w;..#......B1.+......pib.....2.0_........T.R.R.C..VL3..MP5F.%.......I}..}.....C......v|..9./.pdi..{Y.PP.G.D..0'?2(..lX0y..7.&1kU..st.vwv.OYgj..........=q......,.R.Sk.......(..M.......=....$...Yq..pc..,..xE6..wC.s`.....I...2...[.`.KN...T.I.K...|,."..|..9..h...V...7...B>J..bD^r....Zb.Y.%.{........\,..Y.............f...i.^.........L...m)Y.w...R.jG.t)%.n....t.Q.D.).}.o.T.l.O%".........<..2(..3u.x{.#....5[.1l.!...|n.f.u..w$..i..(....K.MqOJ|.w..]z.S.i.$....$6B^V..r1..q.{.#..?.r.me{...pX...z..x.....,yI1.u.@*..jqH<.w...=.2...tN..Q..ALCw..C.P.".o.G.U.w..3.....WX..x/....b.......F.8m...U...J.?B....W..C.9....,o.D.#....k\:........h+....-..k....B.....-....F...o.i..+.f3....A.7.n........5._.UEA.#..a..8.0+.?...O.p`.K.....x.f.=L/..S.W r..w......{..p....*....0..G..z..JC...\.;o.d 0...]....o.....q...L...&....mu3.=.X..S.H...@....H...Z.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):21183
                  Entropy (8bit):7.991986344946291
                  Encrypted:true
                  SSDEEP:384:dK0dhHEUika9T8Hz5sIgZprQEUVf59zrk7Yep5sVIFakrP0nn:kqZEUiKHdsIlEU9jI0epmh
                  MD5:CC7B11D0F041A11C890E539CA4BD683E
                  SHA1:EFCA17F3B8812FCECC99CE755177797E248F3B27
                  SHA-256:8F0A85A8F1B3D6656F06321661CC6DB94B05C0E84AFF3310711B8D0DEDD01C8C
                  SHA-512:41DFB95F369C8ABB7E822EF4FD8B371CE5A31580395322660B7B4DA3CF0455FB68AC6197A69C62BD775939649A09CF22183D2A30760F5D7DBE5C6AF1E9CFFC07
                  Malicious:true
                  Preview:Q..1t.~........C.. .Z..RP....#.."w...1.U..1K..lGz[...p.@o........ks.Z....nN.....l..2\xR@....a.'...9H.Z....L...b....C,A.w.:.../N.&N....?.....}.(H..|;..F....J.9M.6..U?.R?..Dl...g.ct..o..]........6N.N.....5..6g9~....'.....%.U..l8.<T.ke.]M..R.d...v.,...y2JP.......fL..5.@..H..5W...90..E.%q..b...m[.PB.R......e+.(;........E...&..F..........DK..HS9.........d.a.#.....B.T.x.....D#...x.9..u.?....Z4s..ZN...k..l.u.p.=........:...A!..U.u=.v...#U...6.!p....O...ad...GT..u...}v..@..".g..PD...c..._...JC..(.z..7..d.g*.M..J..&..................L.......49.^.;d..>=e.w.k7......!S....l.(b}P.qj.I...b#..nQ.}...e=....;zH...X+..w...Y+...a...s..?*v...,N..uj.R..1..i.v..M..g4.H...Tc...&...a.....;.j2vM~..4.F.."..~[..7l%...$..}{`..SOR.D.50...)...g|.....[j....n%.../4!.?.g.....q...S.oYc".......T.....F..p}r(..L...qv.....l\...).G...D.....Z....l.p.....?~M.....T7V..'... 1)*$..P.:...}.lRh.. ...p.6.r....t.%.;.S.+myb.sA" .S*.X,...JDH3.......oVw.....|.=...<..@.0....\t;p
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:zlib compressed data
                  Category:dropped
                  Size (bytes):21118
                  Entropy (8bit):7.991946148013325
                  Encrypted:true
                  SSDEEP:384:ABBdCydrhfkEXGtiqmgbyeHIqGAXOQ61GBkmsaoSVqYWW+up2SBrqYwueL8:sBdbdrxFgGcIq75USVqY4KG5
                  MD5:FB897E1FBA655253BB529FD7B37350B9
                  SHA1:EFE54D98CB4E738DEA2AF5D7A1774032561AB39D
                  SHA-256:89A77413D8A5E7666B2DB7E69A2675A749C84B0772314AB5EF39746E1C7C1406
                  SHA-512:127F21B88333D9A3E23C7CB427F287621950F42B6D9FF0261592440F1D8E515E64BBD72A0D8C6A227D48740206D08DDDBDCD0B885340E7C2A7026F2387BD2199
                  Malicious:true
                  Preview:..5....6<?..}.a.N;O...+.[.q.6...ph.....3..+_.q5....4..Q.@.b.9f.$.F.QFJ.E.......y...'?.5.....2_...eN.dy.F..IU.....4..CN.s..<..C..i ...b..5.n..G...8_x.T..Q.;.2...[.K.F).........:......g....9.R.....8.B...2.....SF1..,?z....1}.>&/......//u.T ..#S..M.,.......&f..H.....4...=.#.r..:...Y....I.A.XV.....R..#y.fo.s...k!`b.D}.....`n"..J....;g.P..@..pA"......G.p...~.2...Gqx l......M..u.....S.<...>..=k....i#...@.2..v.j.......?...t.l../....J'?..gw..c.Fen._.X\....j..I...X..|v..b.x.&At$...ro..W.CB/......Ep...j.....`...:Wz. ..>."..6.Z..fY..5.[...uu~."..?...c.V..V.iY4..{........ew..n.n..O.2C.........h...i. B{..qf.z?@......|..I.....<0b>.6.g.D9..'S.".....V.e....._.{..:|?.^.?mn@!5".6......tD4>J..B1......{........P...:{..B#...E.nqJ.FG..\OO..n=\..?..~.$q...8w..M.iQ.h.qJu..^..x.r)..........W...e.......L..U.Fl/......f5.}Pv..5..2.....}...ja..>i.....H.Za^.).z.....Z....^6.pc7. xK......9.T....j6qY.....~"Xk-&.&0>......3\...0.`5bjvA..g..5O..&v...">M...q..|
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):18048
                  Entropy (8bit):7.991009202700508
                  Encrypted:true
                  SSDEEP:384:EGU6tYFpjlCO1fDFyRIc8B+ftZnyMB7yX2hEpaD+5vQ1EoiTQhR:EX6QxROq+lZnQX0ah5o1Ee
                  MD5:E90A88A4993E668028517AA493C19059
                  SHA1:D36FAD52DC28F8357F708B8C3B684273F16EE2ED
                  SHA-256:7BE9D874FE8ABF1D9F20F4BF452566EA1946501C5EF8F632DD47CED8781FB265
                  SHA-512:3131E168152B2E37106CA511B76D6816191CC601C9E6770D74C377FF95B3C552F43EB8FB20947E76E3E0030A50BA32C64DA5D49900FAA167AF58D95368A0D3E3
                  Malicious:true
                  Preview:k....e.....).l.h..:%...%B._..H.NG...&..9&.5....H....@%.&".r..F{. H......@{vFf.k....wG.!....L.i........U.."..M..c.u.le.3y..u..F.....?..V..G..&.p.`0..Ll.V...D..6.N..D..g../&.46m.U.".._.#...+oQ.].:.$....2?...?...='.g...P...K;KJ.-.&ks=. .....T.\....+..............I\.......w.%.$_...G...I....R...ws.lR3/..-.".6.s.|..P>..%/.B.....m./."..=....S.h:.. %.....A..7.5..s......[.B..x06...DC..3>.j..."..[...p..)/Q....E..J{W;].D.....'..............-.[,..8..q3T......I#..W.g.bf..'.R...^4....2.\../.t..K.Y..&.6L...(..X.B........*.I9...p..i.5...j1...h....l..k.z...U.9&.7..c....H.....+8........t. '.+u:.....K&....M#>q.&.lK..a{b.....2...F...U.k.y.^.nG.U.a...Xt.lK.....L....*)|]l....&.S8........r8.\.S4..N...'...w.......)......OG..O.|.R.l.*.-.Q.cC...X...Q2...;CwW_2.....^.8......L.....`9B..ArS..=.Q..r...PD.R@....#.....~.R..p.]...d8.Ku;r.l..~......0......../...o.<p......>L....5..MI..~...d....8..1.....+.....1.FR..B...kE..J..6e.g.[.t!.......{L..;\.!1...b.+......~C+....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):19975
                  Entropy (8bit):7.990631835834644
                  Encrypted:true
                  SSDEEP:384:1zAtZnPH5YPznbyJ7PVX5dziMUWq/+r1ZHtdgV3r0SREG6m5GiZpA8J00e43w4a:hAtJ2rnWJxX5dzi/3WJZNSVMGzZJRY
                  MD5:881D00DB43921F2C156A1B2BB6DDCAAB
                  SHA1:AAEA178B636BE858A2CBDDF31F55FA0ED3EAA484
                  SHA-256:51596250736F84073C1FE4672EB1110AE5C8C69AD0626CBCBE7DC436AFDC738D
                  SHA-512:0A4BC85A739F901ACB2C9B36788041F3C5637B763FA114DB5BFAEF0E628B7FA0A548344E4D2A41354936331EE5C3CCB8B983FBAC923F387D2911E167F78C2A73
                  Malicious:true
                  Preview:....k....J.d.x...*...5.<(.V.s....Q.@..d.......@.<.........8@.6.*....4........HKg.kZ.....C=P.2..BS........Jh.3.l11.....L].9..d>....m~.....V......d...'e..i.].qd.i?J}.,...Su.....b...=<.)...C.1,...)Z*.,....0,....P...'YEJ.......v#$..{...x.ohi...n~.7t..F.k.lDI...O..s..m.d#.Zz.C...`..O....e({.g.J...T .$.Q..[.k.B~.&...Xa Z....M{.wJ.P3.....%J..a...f....9.{.2.}.....`..".....<E...H.$..v.:h.o._.p...s..bB5.5.n.].`.3..W..#...s..(...p.K1SQ5.'...p..@fb..... ..h.,.+..F.....h...X.+.O..l...*?...8>....M..gz.*.\.s[....k...........MN .R..U.7......;..-Z.....}............d.i#ou.o....D.U...A...w?..k".%..%..vT...._Z>...S..4.z.;T..X.C.:.....W.....W.h..=B"O.w..E.ZZ:....B.e..A..\cr...1......8.a....G.7....w......1.......{...$.'.y....M3.3..y...z<S.~.+%.{..G.J..@#..:O^.v..F..#_.C%..4d.".3.q.].....|".{x.t.....6.9z....|....h...m....Z1.(....n......B..N..j...T.F.;j.a.)k..I....?....b.0.d......" a...._.....m....e.75B%.&.T........1t.._.M.)...u.).'.....@}.8..%@[.`;v%...'?..J.F..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1375
                  Entropy (8bit):7.824035120882025
                  Encrypted:false
                  SSDEEP:24:4mcn8pUdIIbRdAGnEF3ISe5rLQsckS9C6ZfNbgPYuR7M9wT7:41n8p0IYhEZQrUsp8C6hmP9R0wT7
                  MD5:E17B2D1024607918F0E1B6A81FA59814
                  SHA1:06EBEE2D01085A2A10F86374B2E8611AFDBFC1C0
                  SHA-256:5AD5C1C0BA9FF5DAD6351BA5C810240968022FD24A1C640AA5AA8D0946DB4550
                  SHA-512:A080A842D5B7D3C0923BBAFB427262FF3A8E12D5C1E68F0008021BD7A19992FAB3EAE28B9525F31812FA5AD59004EE712CABD7DDBD7A95241E5BA63CB497B9B1
                  Malicious:false
                  Preview:~...!......|.....0.ZgAp.|..L$../;....F{.-qq.......E.M.,.JD=b..!;..........i...^...'$o.b3...Q-\.]..../..`./.W.$=i...MT.S.fDL.b..<...VT.:c^...hi..D.m.o..'.W.Hp.f{.....u-g..R..t.!Rh..w..2..4.5....L\B5.:...$...nT..PO.......[,..N..jC....n4X..g.eH...#...y..../].b.......c.?...2..&>...E.....t.2..L.v.S....>~.L..FW.......{.._.#*.0P..a&...i.W...n.......1t..:....D8..r.s.V........Z...8..#1g.I. H.S.>V....hT..r$..0..`".....]8.=t.9..~......y...K.....y<.6..C_l@p$.".....<......J-..?...i.z...o..:. a.3.a.e.i..0..a(...S.8..`.{..E1.9....)8W..f.Ul...K.^..n....._Z.Ip....6 .)..@..M.f.).w.xH0}.........,.!..FL&....U...}\..3nF.......J.>X..Yy1.W.I....P...g..M.;.b.Z..f.G.A...u;_.;O.....k0.S.....qXp.#.....TW>.X...n..[.N.....2>...qo6[..Y~....1<U...M;pW.B..#..,"..#...V;HHF4.d_....^6.P.Bmak.;..n..NS.f.tYK...r..64....WeZt.%...gK.P.E...8i..a.@...jC|"...P.p....S.....t..7!]1g"....^.r..C..}_..3..{s...Nk.F*.f+i)+C@....C.^y..f.....x..&...y\5L").V...N..^.*..r..H..Y.h...fr...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):183014
                  Entropy (8bit):7.999139016626108
                  Encrypted:true
                  SSDEEP:3072:XddV4WLUy2yEJgPkZD3jWJB8RTw+mNj/VQym5EI/h06vGPYsQk4oUZNaC:HV4WoPyAw6fWL8RTw9NmeI/JorNnUe
                  MD5:D1E6F1C290790E4A0D03B046327BDE36
                  SHA1:F43C045C2BBC28215B5D3CCCF37136F283A31EB8
                  SHA-256:0994F7BF91CB9B5B4D1D4B333B50787E6DE5C37BF5E37023A69D33B8CE7662D7
                  SHA-512:3EABF3FA3252C5701561F895C7527E04223D4E673A76F0D76B64C756250FF1555C0B49767E9096ABB410E0393E58B097C4A8F016D7DF65141A78319312767721
                  Malicious:true
                  Preview:..T.q.0tC..p...f......G..s..~...fjN~...P.`..;.......|...V.9.E%Y;.g.|..K...4'C!]...D...X..H.ygm.u`p.",.AD........z.9d.#...*.21T.[w...6.%g......'...9<.....C.0.k.?.......4...z.%.m.~...d.hd11......`..H.r%9.WC...........j.".Oa.`@.J..Hg".+...(.......2.P...FiO..*.....]...@.s....'|.Y....tyI.t +...\...i.Z+GE.....}d..FQ...F.U.s...q....X9.Q.G.@...7\\v_ /..%O.o..G.U...].]w......c.<=fK.K....3q..p.....?WKa<).j.<..j.yh.$..R.N(.....OY....!:p..&5./....8.....1i..@......<....P.i....m!....].#.gJ..>="...ybB.@..{.@..*.yM.Rp.V.'+p.Z.q.y)Jm.....I..m......N..U.V.Jgf+[WV?..X.5.K....O.7.O..r.......A..FK)..(c..Q....2\pl.R(2E...WRu...:7.X.....i~..J........./.l..jN.pa.....G.......r;.2.g......+.0.O.&..m..a(.*!{:...!(... ...KF......w3FE..:.F...Dy..O....(h.....q..Vf%..A.#.c>..P........Mi.J.....)..6&1...&zd..{._.g.jQ..Z. .A......u.2./.q./......;..W...UP...H\(....Oq.y.PR+n..1.1..8.....p.t.....w..._]...P...].T#.]....?..d.C<....BMoz.D...z..Z.....=...oR#.l...'...+*h......I...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2803
                  Entropy (8bit):7.917983998142786
                  Encrypted:false
                  SSDEEP:48:DXietk0g0dU52Meu+VgZdlTXAMdBVi0YPTAerOATeP5OFwbnZg6xA3Isqs:bvNhY+VgZdljAsY0SDrO0U5Ywb6pYsq
                  MD5:0832398BA69E403CACEE9888B76898E1
                  SHA1:740A2DBD8987679C4D5AEBFB88D39C504436215D
                  SHA-256:1B53A49F1577B2A2ED9FB9F7E37D04C83504F4BBD8E1DBC8BF996CDDC4C8EF70
                  SHA-512:75042E8714EFFF1E9580582736D28E8B8DE04978DEC8608D33CD1EBD0B3FEAC7ECE09ABE55B0ACE2852C8CD22A2B250DEDF3549F3D51B05CB310E85BCB5569B6
                  Malicious:false
                  Preview:....:..5.>R.Z..| .O.L.m|El..gE.}..>...Lm...A3u.Em&e..%9r..#U..";Z...WCcY{...HA;`.eZ .Q..a..E......]N.;..>...;....%7.).%W<......].R.m.#.-.X.1....1.OK.L.8.....jSD.!.W@.B.0...d..d..`.\.c.e.x.J..p.....(...(1..hT....E.e....1...-.C.$.9...S(Z.?E.....:.5...."...m ..8.....#.*;;.5......XH.N<...k.{.6..b4@-.Wum.).}.H..O..i...E.<?.(...`8W....,<3d..KvDc......2rr....kq..l.v...G.^....'|Y./fq...Er=d.....1o..p.>....x....SU.2.$.d.FgA...2A..sRB@..ryn.o6..>S6..E....T.......s.=/s.Q......mR..Z.. O~[..a.....G.q.N..HD.j......`...>..j.0..B=.{.....RD...H..RY.U..K.^.*...6...o./.f.0.c....9...5.....{.s.AP.(_.D.R8.m\fN.C._.......=...o..;...+XH;..ea....Q.g.....E..M.8..{J!.n48...o.u.5.tX.<..%Fti....%.k...j2..G........W.u..V./g.?..I....M....................W.=7*...{....w.@C.X\..YKP...f*.T..*q.s(.p...:....h...:.:(.<~B).~.#.....].2V...M...(..pC.2..y.....u0.Pl../o.b....t.o-..B<4...X...M....o......./..S.1..Yx3........sU.@.v.4....@X..........;.....T..4......~.9)]|.3`....Gg
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2584049
                  Entropy (8bit):7.999935071312803
                  Encrypted:true
                  SSDEEP:49152:Hvz7eC2s25zrAfLU1HkLDl3Hp0XNmWv3q2lq21k5K:L7eCQ5zreSELp3JeMCU2E
                  MD5:57CBB85934CFDFF03AA22B52ABF34BD5
                  SHA1:094A31BA50E68AF48548CFD772850DE4ECE4B88A
                  SHA-256:08D1BB96DC3A31497CBA8342832F3E6490E8DC7B9D86F934F6BF0F77936364D7
                  SHA-512:2D52FFF6D71DF21B5FEAA42CDD8197313C4FBBA2D17D6778B0DBE038B8AA7FCE87B46C74BD948E9AA1C61B6773C3E47078A507B6CF8B35FD93B5DF84F67EABA1
                  Malicious:true
                  Preview:`.D..M.|'Lf.9.0..T.{JbP2.p!...bY...i.....1P.j...%|..A.......c..g}..U..:y....$...WS..n..4{.....d.N..OU..., ../O.S...N..\.....1.h..+.......O...'p.@..$..j.....Lq...S'...q.x..0jAZt{g.......k...].fy.....u3..&..|..._.E..q.....Y......0. Yg.mB..L...!...T...*.gsy u.maM..........a.1.....bn.G.4f..i"...y.X..)^[Y.y)r8\.h..|.f...v......'.Z;.1d..]...3....9..C..i...\......Y.......A^U.t......;....-..i?.R...#?..>..V..r...?%b.J('.zh.y..+z@.II=B....0..Z.8.J..ezE..TN.'|r...].4B/e..0p....n.........W!..x...uZ.x.>4-.e.V.`......mL..Hx.Q....1....!kG...V.Kk...v.....P.P...;.s..+9o....f.....h.hy......M>..B.T.u.F7..E....S6.r....B.%.GGGk[ *.....m...m;...y8.[.....y.x..q......Pd..`.%[..Q1.?.....a.R9.-)..e..iS.}.x...U..<..'.E...g>...}...q.@....%EZ....`aBW....c.?......aT..:-.J...2..^`.-..9...W.s.J...d........!.`<.R?.<.O....&......xdx..g...D..n`;c.L..s.;......"..jE.{g.cLo...F<\.=..R. ?.....Y.n.O..K..J.QW..F....BJ..D.t...w.hn.9!...6L^.....2+.....4.0=..*{....@##).^....*.....w2
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1181
                  Entropy (8bit):7.785112164473525
                  Encrypted:false
                  SSDEEP:24:cx10knwqSyDMqq2jLBPzRdeIbUvJtV05PD8ojxmGa:cxbBSyl9RdUJA4ow
                  MD5:E3060C7C9F6342614EF93DEC76030F8C
                  SHA1:081703CF72501AB20A12987EB38CDE75C226DB4A
                  SHA-256:ABF9CAA28F454862FCCE82C33C6DA702B323E3E1ED1076EF668038E241799EE2
                  SHA-512:F062547F24AF880CBB2FE8CD3B0493DF587F85A0D22EE7786545F980ACFF709AE4B92A90186712F146E351F572519653C69720208CADEED40F2FDADE468F23CC
                  Malicious:false
                  Preview:y:..A...YTSd..-.,.4...s...K..4.@.....)4.P.h.v.JP.p..j...1.,._.....?J.....s..5..5....j..(...P..N...j:..S.I+C..\..CO....=L......q.y..@..B.d.\.}../.t..&.....e...h}.I2... ......l...AG...F....p.....H...;7.......@/.......-.<W.&.. .<.x.[..l...z.1.........V{-..2....'.P.N....p..9C.....4.Y...i...c........4.0..y..5{J.,..I.2y..$=.Y.le.KA.M;...L*5w=<..c.;b*...^...'Erd.@....JC.b....w..31.H...}.9..1..RJy,:..B......V.?....Yc.W".fE..Lb...W.#...e...;@..,.h.3.I-.l"...x.}........` .Y..F.cpD?....N?f..<.fp.......R...uC....6MB....Y.MZ.g&....3.%~.*D9....0...R...{...5.....Vw.......Q..e1..c...........a0:I.S..K..E.....(v .q..[..[.XE4s..}..K..%...=Q.......Z.b.$....T.b.....v.D}..P.E.A..>..U.q...e...ovB.N..T~.:0q&..l.2.u.Q.).....l\)s........K..C.&Q..ew0.}^..Yos.W.#aH.)h\R..K......<...=.[..$..:aN...M.k......_.'.Q...~..;.v:....E......E...]....g&.9..x.Dz..........HF....=.oc{...+.>..7...q..7..._..B...qt.{.E.D....6o.T...,.A..T..x....Kg.ma.7.......J..............
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):428
                  Entropy (8bit):7.2836617403201585
                  Encrypted:false
                  SSDEEP:6:PeTYPtLer4AnTIxwXgZQr0ZPeIj9ABaIFAtKCIAN3BYZ8W4OArPUkfNX5FSqWnt6:P3ekNQr0VeIBAAbKtG3u49rPxdKqut6
                  MD5:91968E92F5DDA67BE02932C353E6B60D
                  SHA1:0C7032DE504F5293DBEE154D9ACC84A8A2B7E384
                  SHA-256:0EF2625642F71C4C1CA3B450BC011046369277FFB0724FDD0A479F2F64ADD397
                  SHA-512:9A7349073ED8811D22D04C235D12EF47112F77C90E9B071BD4E74941E84D38D66E5440EEE0FF5D74107A168BBE13E5F5673D44DF5FE657BD54D68D5E7881F319
                  Malicious:false
                  Preview:. .H..8..R.}.\...........>.............&.L..(.-.=%...ko.^..=B/>..q.U,B2.R..._'w.....!......i..X....X2...+v..B..U..1`I......~.[P7...W.....,..........R.I..U....`.?....Z...9.....C..{#P+H.....+........m!CR..(If........OM4..rz..J..[....s.u..>..a......~4..N/n..[.@.<mR...Q.Vn....se.."..P'..T.b.....ii..Y.e..-.OI...........ag.........s..G3.c.uZ.8.....3.eiE...x.f.^.m3b.....O%...B.:{.4.yU0........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3164
                  Entropy (8bit):7.925940818620327
                  Encrypted:false
                  SSDEEP:48:8E9hci3nPZsYAXWhd6PvMPhU+mERrY9ooOFVRpn/gnRiWMe6WfDbnySAUh09:8EhcUPtAgd6sOqRrYCVRp/wihe7Q
                  MD5:74FF4B16C892BA93D8720FD825D2FE1E
                  SHA1:8DC84AB41251809F47E4F7B27E7BB605F8450CAF
                  SHA-256:C12D75413500C07EBA892371B9ED03DA565BB9BF3850C37E68AE38D5FF623480
                  SHA-512:4271840F55F770519842C91DA7DEA4B391726569D8DA9586BA4EB7033617035166C94F6C70CA98BCF77BA182592FFBF4986FE98C3267071ABD4E76C749DD1DD2
                  Malicious:false
                  Preview:N.`..H...ka'.h.p.....X9....[#0.S3G.{......Ug.u..._....$f.>|.#M@N..6....1...}!.X...@.Q\...V..Q..4.36.....Z..\_.N..).9c....sD.:J.O%..n@Ks.G6qbo....#*...w......k...On.~|vU..w6o.J^(..hv/.'b.L......!...........L..R.[Fs.z.fb...9W|..........-.9.R.@{.p.g.yh..Ok'i..R_...+n......0pq..4L.$~..{].....VP...Z...H....@_.d+Nk..hO.n..1.....?..s.!..v.}.i}..ii..{9..Zu.*._.....q...Z.z..1...{.-.S...F..?O4..^..5.._...=..f.`....%....}2"..4.v......S}..5.Ow....IY.$R."6..]x,..HU.l.%(.6..b....]..e^.... ..4V.m.....p)B..{.W...x+.'.B.J}.{I...(..0L......m..0.._V.w.*M;(=..D/....7..,,....$W..O@....Wd..D.....K%.~7..ia.{..M/...t%D.i.....KQJ..N9..65Ox....a.....n.[.}.(.\].7m.).s|`.x....=...?..e]ICT..3..........r@m._...2.l. .QA.~../.C..ad|..s..Ao...~.XCxR.=!.m>?fs....U..p.0.........V.b.R`..f.x8u....C.3..%"kW...WB...QKg5.lJq&...f(..a&.w....u..a.%Bd..=...#.H..s.[..b#`a..Y.u.f#...b..R..!).......E.._;,.Q..6.K*...j69....cMZ. .h....ag<......ypkX[8....^.mCD]..h..{.?M.......5...='H.....f
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):458
                  Entropy (8bit):7.378113756767033
                  Encrypted:false
                  SSDEEP:12:jyKTGXeCjbxAPXvJGXC+xEjsB99qLDbb2Ltf:jypZxsMlEA9o7
                  MD5:411F10676761886C46B7DE0EA0767ECA
                  SHA1:E1A370D6B5458430EA5BD65BA13B005B1F4B065C
                  SHA-256:944E187B66212F846639FD910EF16A2617C550C1F48979B9252814DD2E438A77
                  SHA-512:9E25F73553912CA5FCBB3A88C946D1D2B3BE1C79579E1ABE1A426C2E21F184AD4527E0BA7BDBA62CDEA7A3B98506638FE8EBFBDAA72E5A8E710DD337AF75CB85
                  Malicious:false
                  Preview:f.FR...6.<,U.c..h..)......w...3.t(+..^>E7.......4..<.K...~....Yg/}.P.....A.DrvF?n...es.#.g..Z... 8.Z.j.....a...+U[W*.*Ik.,'....B.....).c.-.....S....r.n.........{q>.B. ...{..C..d_.ZIM...0>...F.Y..:"ZL.AVL.....g.u+/..7......Z*..P.L...]W.C.o...R..x.y,..:.k..,P.8I...*b.s-..;....$B....O...O=@...MS.?..V(.6D.e.$d....[..H..|...~..$..(6......_a2.h..j.*........S......9.R..ys.db...N_....V.#D...ZCd.....E..Y...|.........*...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8388
                  Entropy (8bit):7.977702263920083
                  Encrypted:false
                  SSDEEP:192:5iu4U0CDnvr2IzY933CzZfC5xjc/PUKGnYjWPq2rutXZq3dGGgIEpeRv:5cU0CDU9n4qcPqY0/kMtQIEpeRv
                  MD5:905B393F359CF76D9496AA7D1C530B92
                  SHA1:6D425AC8635A821206A4E5BBA24133ABAFB869D4
                  SHA-256:88A970A072451B4B89223CCE1B39FE55802DA439B828703B1D59A9F330D942C6
                  SHA-512:BB2E59D81DAEBDE0C4DD67A4293D761BA79161111A5A70ADE212A2058F9F1981504135563578558D2B3EFBFBBF90417346A56A4A1DB0C0DB94398AC706A41141
                  Malicious:false
                  Preview:I..4..".j.t....M.w...|...^.YC....W..'..d:.0J....utAd[....c.....G...Z0...J.4.r.../I.x....Y:.R.Iz.v....cCJNMGj....J.0.@<....dw..f... /...eB.?..w.....F.FO.3....p.....OP.)42...+.....F.,.UQ7.I...&....r....=.].jqM.......0#L...-n..[...l../).b.7.Z..f.......{.YL%......W..X.9)..,.H.....^3.s.j..U..k.C.?..,E..8l9H...`.di......e~.y./".).Vx*.).!lR.....5i?%O..!|Z....H.[(E7..X..O.a......(..5....a..N.8.v=...&.. .nwV..\....<....FnH]5..\...t.I.X...6.Cys2..L.....B%.........."..j...XI.f.V .D.Z..#...O............]..{.9.5+....E.6........t$l..0...%. ....bL...s.LT.S.........d.y..{'F..u..#..@ws....F.Y.^.......Dk..R..=x..B6_P........0..=...^.....z..4d..O5|...GAWN&.2...P.{.#..z=.pd......=.@.?.z.qc7..;...~8.v..g#.l.T..A0.._.......>...*]..P......f[.AV..L..VB.| .0.\..>.M......{......L.WW~..*..M..._ .....W...7.|..a....u.C..RN...'B1.;'....,."X.....xH.......C.4..;.^\.pBr....C...:.Xyn...O..Q..T:.?k6.l.Qb..t0.A..z..q....1C.[i.8.,u...6..y8A...r....(0........d..$.a..xAc.e^<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2921
                  Entropy (8bit):7.927101971451577
                  Encrypted:false
                  SSDEEP:48:5i0bt9ps1jgwG0e235AlabaxuruJcn3DaUDw/432pZezfFRWPllK/vtfqC8TMuDj:YkshG0hJoxu6qn3eWw/4KUzfFRK43tyj
                  MD5:E85A8467ACABC1486070BEA0B7422789
                  SHA1:41F91F66FB1B3F42AB8E991DDAD2FE74F26760F3
                  SHA-256:D71D441C8BDD0989BFCB74DDDAFCF230C29522CBB169A60B7FD5CDA3FD20C80F
                  SHA-512:A3AEF71596236062606EE056E4CD67C8493A5663065E6B9D499D553E026281A28712B62B01E32A717FF74EDFD3E4E953F0E0BED0F79A78372C95207BF51DA450
                  Malicious:false
                  Preview:Mq....L.@p..DQ...........:@..V....iib.....wO...v.......mFv....P...;..,3KU.gz..m.O$.]...j....N..2...{...U..1.u"Cv.C. .".`.x.hSY.^....g....>.P.."..2.<.l....g....#R9....I.....|...3a..C..\z{..(...Qx...X..)Z..a2N./...q.n.4&..8.....9`O...J?u.5.XK%.xL....Mo..a\).4.xeV!V...2-m.w.H.8&.M..tk>.....(5.......Y.]X.>...X..(WAI...O.....[..!p[..67...3...}.3._D..Q..QVY.2........r...........gh...N.hR....cY..,.3&Jo..H..8".....!.t.....Tw....>.Wi.I...U.....5~:...+Y07.....[......c.i.,s..MRW.[...l...T..g.CC.."q...7...S.}.(..f....b...:.'"4...W...$.)\~5.&q.G..&n......."..9..{...*5..)W.}.3.j..Q~..H0.r......yV....%...5.W.~u...[.....o.l...&...6)....PE........~......q..;s!.}+>.8.Fba8.....f(.....M.X...J3}d7.iL..8...5WkLw..'.q.b..;.?.E..L.....j.......D.. .AC....~Ju....<z....5e.....;...uu...Q.D...}.d.Xo.P-g...x....ak).yM..............I.sr.[~.#{Gz-...p..Y.h.W^..*l4..)..L9.=q.e|$......o............~ad?y.K.....`.=...y_.....Jo...4y.r..-.+8).........6..Oss..H".E
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):243995
                  Entropy (8bit):7.99919751573496
                  Encrypted:true
                  SSDEEP:6144:DDbSAs5flltWcqxF3P/8NrvrwyGR9L75z:eAs5bkfxB8Dwvbv
                  MD5:1BBB8EA00B6954C17A051E72F9F9F3FD
                  SHA1:1C9F65C8D7EE0FE0649979EA393E1346C1152040
                  SHA-256:ADC3DBED408BB32C6C882C8839C9A8B08CF4AFF7D6E028A2BB6147B2BB60D33C
                  SHA-512:D0C98B4FD9F0911C26A7513DAE98E48FA7DA81719A23D8CADA275C3164CCF2F4DFE192506A51853683287865BCE352602391FE1CA465B2D967BB5C37C54DC64E
                  Malicious:true
                  Preview:.<2..~ndp...r...^&.........7a.}...?.4@ Y....}.....>:...p\O%?.[..pfr_...5..%...Z.Yi.s..ji..:8A2.eC.......b.5..u.r..A.B..E ..1..`O.alPR.....n.X..a.........\..3<.Q..u)om...;g..R.......l..(..|.`.0K.3U..X.-*..^@.'.I.,Q.c.......cG...ih..S.. 1\._m.u...H...9.U.....H6..B.TI..E....C.......l.k.o..t...D...!=...(V...m..r..fV.,L.#_O.PHGs)mb..f.pVX.K....=. .*.;.'.4..L..a?h#......`C.Q.Ii.!.Y....c0nTU.......C.|...]{.).Z......:....F..6....f2.n.7....GWQ6w....T&..`..F:l...r..z..6,)b.x.Z.Q8..]...e.5...k...T...u.....+c..W.5.j$T.^...T.4....I...4"z.?.0...>.i..+.NG....]..U../.+=........_`.K.n....).&5..{...S..E.!{.Z.:.A........DT.A....g..upO....v.....9\"...J....5.O........c...B..^.V}`.=.......<<.......G34vJ.=0.N&N....4.5.....H.b\vl*.z....q....G.....|A~.My....F..o./..lifY......6%@.^.j..VG.L.e..R.5Y..8.n...E....N../.(N.......v...(....KXZD(E2.......B..N.fR..q..:.`u....*...&#..d.......U.tzNt...%.X...=..7oBI..w.......n ..s.<.Q.1....u..\L.aW.......x..;*..!M.=..\
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):132062
                  Entropy (8bit):7.998730846125381
                  Encrypted:true
                  SSDEEP:3072:19bACDCOtiYB9vzupKK1eS2TH/Tkz3ayoQE+xtsFP6:jAcCKL0KK1eS2TH/Yz37oQkt
                  MD5:1096AE90513C12F88CCC5F5C474F8DF8
                  SHA1:0C460A683D558C88E8F5BE99B104EDEBA5BC73CA
                  SHA-256:4424454385B6F13AEBF8F0EE5CE8FD65FF8F2D0AD3E69AD5E4FB2FE04D683FD3
                  SHA-512:ACD984733939F8C35300026543FE2B19E70C74D7AC14A0F2CC96363E2515406C9535C39C35F4270D2CF08DF2EBC2B344307BB1B3C85EE79BEAF0D4B94901E989
                  Malicious:true
                  Preview:.j.M..V#....A..e....^...h.'\..qL.........N1.4.P....%$/....d....d\S.>..Et....]L.L6`.....W......8.....(T........3......8.Tv.k.N.v.b-.. .(.7.'..u.e^....#....y....il...W.Z...8n...|.V...v.,....b#L..2...>.....|Z...........\..........-..h.<cKQ.....UIj%..b<"..)..)....;e..A....%......./.Y.z)..[1.Xvq.4..).......u..&N..lc$.|N.....w..#.B.kC...Mu.t...1..SxM+.E4)D......H.p....|m../..37R..FX.U..K.......8.Y.....R..]..`7...w....P....kh2..].S.v..BT..*R...+.U.)".q...}..A.WPs..d...._JO..Y...@..g...i4.C}.:MQv.... zy\[..E4...._nx..(v.9....9.l.T....G.V.....}..qe..G.j.....l&a.1(...7%,..k.8..SQ^..Y..h....hB......%.]9U.y.b.`ps..^.-....Jl/\...a@.8.6..H1.......m.....u..r_......w.$.~....u......U/.;.......<.rO.K^7..j.m@M.(!.y.+K.;P..Z@`....L.S$.....M...=.9<7.~.....LR.......6..#.F..p........m...IC....l..9....u?.`}.A0.u@..w.P.r2.6g.tb.............,d.....l..n..L/.;..{..y..K....6.]....5...w-0...Z.y9.....'.....1........eh....v^.@..kh.N.....H...I`..Yu..@"2)..,.1S..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3358
                  Entropy (8bit):7.943765002575486
                  Encrypted:false
                  SSDEEP:96:LqRrRhq8BinomTzwnKXeo6niuwuR+qY2Gs+fy:LqRrRRHmTzO66EuR+qYS+fy
                  MD5:23E0B6B79E79DA50D2355FDCF4410632
                  SHA1:D70A4884E5ACA3844E06F663D9A73757B574EFE5
                  SHA-256:C2CC6D38253D9EA9DD3E0D11A90FB4DB48BEDD062839081B21BEA5AC9538DE17
                  SHA-512:F4833034FF0FF8542393D8963DB2151DFCEDBBC3B13EC9186783F9A80C7322DE0BB22755E47D51C28491807E6E548249FF98B56B5A985DD6122F652E2F217B3E
                  Malicious:false
                  Preview:..X..4..Ef.0.u...u..N.L..C....26IM9,...R.>z.zoA..|$.....+EDT...P.I...Q.f....R...C... c2"+.....<...^)b..G........U>...7..N....h...N.|NRz.s...%.,.{.....;.6..pLY.5...t..)$..a..Xq^....B..N_...!e.....W|..@..]<.....(.{....]..t.z....P.(.D...{..,...+....X..Oz0.K..h.9......../!..{......3..s.52N...QLd.....f.zM.).f.Wjl...@G.|.....i..?J/P].q>!..-.0a&Ip.;k{.c$.hZ..}.Y...y..[...|x#..6.j.qV...1C.1.Yn.?...B.....I?....%...9.4..c...OH...'....b}M...1{......>.{.O..z....Z..k...5...n..k......N..f.3.5..*...p.i@....a.6...M...y(G....=...k?.c..G..EkN..k7`.H....E..mz...ZA....AEL?u..T!y..O..9\...J..........\.79....fg.d......FQs.-.>...E!.W.3.......@......=.....e.f..v.Bf.+<.,.v.//........O)..}..Mm.. ..Op[.p7.9...._...e..8f.AT.......a....M.........C.....K.5D.9TS6*k..=.d..8.-et..i...)f..0\..)..T....Lp.....t+....-....n..U......<............[= .........&Q.......9.R.....*...C......`u.}1........................U.+..0.z...b..w.....P:0...I........J."'....WP....q..U....5
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):85712
                  Entropy (8bit):7.99785949756318
                  Encrypted:true
                  SSDEEP:1536:fIT3ihrSqIDjWUELMm+wXgvmFwarQVaIMbbPRqJHNr++b5jrRzYky:fIUrSqIOUELMm+jnaQVEP0JtCEBrpYky
                  MD5:CB40A6B007F58C1ED6BD2C6FB30AA78B
                  SHA1:80ECAAA154ACCABC48DF45634C7B4B131D2C1EDE
                  SHA-256:47B5BFEED45067EF62BAC20D58243284A59E1BB7AE25A046A685411BF0CF1BDE
                  SHA-512:10E720974D6DAB1493138159DBDEAF6E287C7257EF1C1271BAC40F3EB24F04AE83FEF6B75CBFB33EB87D43677E711339A2BC3B3F06DA8FD3DD4492806AB6327A
                  Malicious:true
                  Preview:.0.i...{........-...wP....#......./.`G{...\.......7...2.i%.T.3..hx.\.fs....;......}._.]uF"..JE9gT.kO...A...(.....GS..)$%...XG?.s....{...(8r@..Lx.......C...'.4.D0....N.W.._T.DT...~+tE.\.|..m.......&....\.B.j.z~.Z_...+]8.5.J8E.\9D.J.D...`.<..2..4.3R...+...6.q...7.3....g..F-.n.x!...j.%.S.N^*..hb.-...\...h....K..C.h...........yS.1..U..*..W..j.1..;.....XJ6.s..C.."...\52..>'4.s.d......Z...k...K[.:.z.._.Y..%!s%....o{0.0.....SN.^..>..d..k..%..*.6\....7..d..r.]...f..k.c;.(....v|7:.C.i.p.....Zf h..%.....r%.V.9H.A..{^....$g...VY...k;.i....r..BT..qO.v4...`...+..#..fP....%|.M@>...j.....&...1_..p..L.9.....Z)...L.~..3..w'Jtm...[....3.~.QR....Cqy...s9..>V..U."...%..Bf..T.C)..U...}..N.v.-.K....l.y..............,...!.`%.i!...LZ....l.w*...1+}..Y..v..YG_..Y.:.0g......@.%...Q.p..).0..D.2....l_.H0o.@OvpJ`Y/.uI.0n",..w.o...c..$...%R-Z.G.h....x.M....}.G[..cb]..%{.I..n.U5.....c....9.4...f.?E0.[.8H....E|..S"..:.F....~'.......l.H2Z..{X0.h.a.*.......$...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30648
                  Entropy (8bit):7.994470710680024
                  Encrypted:true
                  SSDEEP:768:A8Yat16FU4re1PI1ivXsH7EC/NU14EtBrLtQ:Agt1+U4rex8ivXAfUfPt
                  MD5:574A8EB925D2A8ADD4749010D0B543ED
                  SHA1:8498613DD81435034ABCD0840D21DF892F167AFF
                  SHA-256:A7A6834A307C84F77073C2854F3C64A5631D57C1639D12510291579B3D07D7E2
                  SHA-512:79C2E6FE916E80A4BB9B21D8B123DE9897DA30B235FA8700FEC8199AC3FE288ACF78910DECAC858740A7C415E43CA13E0062A26B9B9A20D0F8571A8581DCD414
                  Malicious:true
                  Preview:}|.....f....<w..4..s.....C....-<1.w...]RF........D...(.G..%.nQ....]....kz...C.+:.vm..P..u..%{\.rb/......9..K..a.5./I`....m.......*m.l......>J.X.1.i.).Dt....t.r...9U..3A.D2....eS!....3.Gd..-$..6..|u.Z.?.......E.uJ.l....J..)^.....5U.....t.V..t.~x.@X5,.1v.W.......h..].K.2|l.W...K?.Os.H...Lf...++jQ.B...B5.qz3.iK.rG....g4.83...f.3..L)...V..~{.qX..uO...}MZ.Ey.[.L..X.....:........n..c5n[..............J).H..]d.m....r.%...p......*i8...=.{....y.d.t....20......N.J.\.G....8d@.!.A..7l..Q..^...g.....D...s8.z...t..:....}'.k.U...J9\.....O....)l....N....Z..=.m....+........h.K..2.M.I;.....F.w.G.Ga..v(.=....K.r3..F.;.....O.!&..Kw..Vz..^...B.".1..).((.BE.U.....-...f.......w.b..l.vSS.j.Z...8.I.L..y.?18..{....H......*.zd.\..2.UZ.~..o.#W.\"Jh9*S......eE....~.ArW:...IC.ln.6\...u.....FLz....p.~.......`.l.%d..z<.....*Y.....4=. ......D...T...h..$......k.Z.gp.zB...J.IJ"5 ..t_.....{.T7.^.....1s.W~...2.\0K..].s._..~hhb.~.B..Z.X....'..%.;...IQ..F.R..b."/..'.R...m).9.w.j.`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32108
                  Entropy (8bit):7.9944473201851896
                  Encrypted:true
                  SSDEEP:768:3VePPw8e3/TyKI2NamYcQBm2RT5agJW3FhGDXNIsqrl0rZuc/b60:3VeP48k/uKWuQ42np0cIsemlLe0
                  MD5:9F660CD26518ADE8B7ABC93FADA1BA3A
                  SHA1:67D61C7EF874D8904399FAA4266F5E37AFA19C8F
                  SHA-256:E8C96407615DE148DC1F0A6DAD0051983DEE6EC987D6CD38DEC81598EA58ED4D
                  SHA-512:2C30515CBD272609F68531FC38BF46529E9E131BACD6CB7F67BC0C813A174E58616F7FC393271BCE89BAE71C854CC4AAB29D8D77A35B633EA55CC5F018CDDD67
                  Malicious:true
                  Preview:j6.x...o.R.I.|.....I.F.h*...Jfk.....-..z0W...?....;:.......w.Dd=P...%.a...b....rw<.?..N..(.k.p..N.N.........,...[FP.ZM....1..?..~.. ......t6.T4..;.|...R...p..P/,.Am.s.....U....u...|.oQA.1.X./.?.4...d.?k...t8..Y".H...B..pj5..@1.)X?..;#.....aGwD?..;J..?..'8<%.......P?.l...f.N.C..R..|...K...6..Y::..9d,i.s3.7E...........^.(T...*....B.5.....=..6.W.*.oJ..0..@...qR.0..i.;.o...k..4.S..K...f.1.QiP.H.V?..v.D...F....i.sMX0m...Q....2k.G..A....g.-....8#..xZ1...p..E=.{...]t.s/.P(...P`.b....S....w.......Q......0.....%.h...b}.<...2~..=&;.w.l...h.F.2.q...IV.R*`B..p_.T...z.7.."..Z.l.....t...O.(.3..>......5c.>.#..U6..@..,.6.I....R.k.n\.e.r...ZC.H.M..H$."+...Kw@;.R}g..1....?.$6!...;..Jw..).M.2.xQ...8.u...]..\q..Yh.!...e......o..N..+...l_..p....K:.j....w..a'.G.c.VDx......\..1.z.6..4....$~"Rb.LQ_.A..l.!J~p.....>.Z..Pyk;.G........e..uuh..0?.E)q{.K...khrI.i..2R...U...7.a.d.".3...G....&4.._f......VtA..W.o....*.J.........dU..w.... RB...*.K.:s..9..:.d .R..Y1..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32456
                  Entropy (8bit):7.994402030593711
                  Encrypted:true
                  SSDEEP:768:JxzmYYJ071PmXTXnLjnYm8s3CqwTP5uHrDcs2zqO2XYwmaF5nkXurYzgp:OW7h8TX/Ym8s3CL5Kcsd6I5kXHM
                  MD5:D2B0C9346CCB620B6EFD4D6C43CCB49E
                  SHA1:7A3C68D1B1A3F12730DC5D0128BB8B2AD2A6D271
                  SHA-256:9FF12CC06ED3839E5EDBE138960750887D1F6F88DCA61C7668582C3D997A3E9C
                  SHA-512:27A1AECA02D1DE15F747399673ADD7E7763447E2B11F93ACBFB527323EFC1626A2827E5ADC943DB0B719434E694B0A9FB3720B1D7DED1FF14BA6EC589AFF68A5
                  Malicious:true
                  Preview:...Pc.t..3..XI.C.C.-L...40..Rr......3.y......?j^..~d...c..J8..T<...>..E...%.T.n.W.8.. r<.....e=.....".J.'.....x.4v..-.....6.D.B.|...6?.@c3.`f...C.C.........k|..;Q..`..X...O.B...>....E......w...&I.P../..?.1..,.MQ.OB."?..F&....2?....E..X.!..."..x.1T#h..f@...[..y. 7...?c..^F..D.......)$..e.../A.}.'.>q4gU.....D......7!.2/)/C.".>P3..c]t.GT<.*0..b`._f.........g>..fNCC.Bs.C.}6ne..4....O?D%......&.oh.]L..#..u q.c...q.D...3...:.H...`..A.R...]..iO.......n.P..I...w.(e.%[)'nZ..)..l.+.;.P[..K....F..L.....Z1..f..d.|.2.SF..-.1....E.sxKK.U...[N)5...}).p....~...]..9".Q..C7.._6.3..5...!..fb...........3.KNVK@.l..;...}f#....aQ.b5..{...gv..j:.M.A...-...KD.$.n..sd...|..+.*.}V.w.7..W....].._..."..@._....2P...&.J..n....<...V*h{s....S..QEu..N`;..X.SyG...XO4.....q8......0...b....,...L....r...pz..A.F..[^..LQ.;..C..mL.JR..2...Se.?..y1.%...&......*Z..._>.. ......QE..(H.q.3.*..9.......K(.t.........V.D$..j7%1...K......F5)M'.v}.d.z...&B.P._h.N(..{.....-......Z.!.&.*Jh..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30984
                  Entropy (8bit):7.993771754931683
                  Encrypted:true
                  SSDEEP:768:jbnUDXAH7tjiJpPusRUM8e+mxHFYSwrng:nULAH7tjELRwgHF
                  MD5:5BB408445E58B153E49CDF60D20B2DC1
                  SHA1:7A48921209AD14A580AB1E5DC03A340888862575
                  SHA-256:DE4349F51A29BA322FCCA6DD1F8980BDC73B49F95B01DDB2D8A9A59E5A73DCE9
                  SHA-512:3E207C57BE4EF2BEF4BBDA8CAE094F0CFA5455E30D5A6AD289866524811EAA13E7D5B9B885583333E9ADB9F6864239664EC029259E875C1DF2B35108C8FE2B8A
                  Malicious:true
                  Preview:{.+....@B.?a.$..m....fJ!...zjD.c.a...~.,...u..Q.8'.?..k..?Zn...._i|.2....#.T..Xk.....cU(K..d.y.+o..\U&..&xi."...8.....5lY...O..`0..:$.j`...{.........%,w........%R...dr.t.1N\.T.C7..(.L....)U....../....8...K..,;s.q.].#.#....K. .h..}..0..T%u..[.6.CU... ...N.iU[.\..`k.D......R...v....w...AE.OG.....#.}....V.<...V.:.....+....-K....#..t.S..I.}/...Rh.7....6.O...R8..[....f..(b..BP7T.}ZRYW..Z...x......m..Q..s../...Ee...}....+..lM.|..v..:>..".Xzr.y.....7.*.i....w|.W9.Y..pd....N..xd...TU.h.^..j%.V...^!Q.J..~;.x.%>....V.n.w.+9.o..r.0F*4.V..?V..&%.).!.......E.M.e.......V8. S...#.....D...).r%.=..'#.$.....jK..h.....T....r.{..E....k2%Z.B..&b.}!.....HD...%.M.....m.a..k.J.6.QCT..U.t...|4.;p.."..g7.O_y.t.I...tu.i.!.G...q....ZP."/....E-..O{.V..'........Jv.L.f..s.E.C...Q..r.4S."v...(wR...m.0[.......!Sz...D<>.....N..P..i..<0.:g....v......w.Q.t.Sq...&`Gj8J%......9.a..].....{........ QA.....9....Q`.z....Q...)....[...\..........qO.J..F.....K..........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):210444
                  Entropy (8bit):7.999142198781201
                  Encrypted:true
                  SSDEEP:6144:QC6csmmpPJHG5vhcgwIM9E/2Kz1aar69Y:76ducgwI8E/2Sp6
                  MD5:89CB7D59171C695287AD5CB5DDEC350F
                  SHA1:05F77BE076C19D63ECBB6E8CC25299CCCEB8D726
                  SHA-256:1FD1C5E1AE1CB68A489515493DE06E8379CE29D63AE5D2301A4410DCC281D4E4
                  SHA-512:D213369E6022415143A38EE81FFFAC467F8C9AABC6A66CE437AEBAEA0EF8EAD5EBC4ED15DA5F95EFECD584364092AB7C1F51E95172E55B3505E32703A76EFE41
                  Malicious:true
                  Preview:H..]..-...X.......d..-.{.?5j.2..QtC@/..a"I..5..(/V=\.rhk.K...l.&..R]..}..U...!....D.rP.|..!..V._x......Q.|.Ud........g.:~.\Ike..y..F.6.EG...^.&.o...U.Cm..q./..v...G$.]..L.#JC.<.f........A.!|.V>O..sR...c-.p.'........2...8..F..Q.+...,.#...N..m..L..[..M.>.L.....x..P...-|x........\..*).|...'.....Z...)R.|...1.$.\'..`.t.HWj....i_.+R.....U....RK.?.B:f.+.W../....xW_.#.N...f=.JJ.j$..S.1............/]..Q.>...U.y.X.2..:5i;.kD:....}.0B..^.{8..H....q...kt......z[....!.0;..=...(....cs..TA..f{M..... x..:.kc..i...27.}.t.>.c...J.....m.-6D...o.{#.T.d........b..)5f..sK....P....7..W[.......k.N}>5....".]...F3...$.01_.P.787e.W...;61..V..].~..-(....Y...g}L..vO'W...;....s!.{$...Sg,..cb..S......B..z..a.%.'......^.Qah..S...fp..g.5..t.A..".}L\..,............y...XR....;....LOV..>.T.0........;....$.h...f0{....y...8........y......y.+.....?k.X...a......%......x.y.*.f... ..i.....cW...]KX...-..K.^.#.......K....6@...%&....,.p..L..L.$.|E...=..v..._......z....c.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):251300
                  Entropy (8bit):7.999352958474336
                  Encrypted:true
                  SSDEEP:6144:OuzdwUsdDDjfJY9VZ1YRVWormayI546AMtaWryE+J//9f5:X2lDPfsZ1YRZZyI546uAyE+Vlf
                  MD5:21BC7873DA8A7508A99A00319626613D
                  SHA1:AC6A15DE3AEEABE0FDDE47D7F9F16AAD7CDFD954
                  SHA-256:64877150E0FB96BDD9E9874F8FAE1CB3469BF0FCF38B908E5772726BA4F1333C
                  SHA-512:720B2BD15C2F481D2DE6C0EFB7D80ACFE2FC75C12ED09D394FBF0FCCF2B8A87D60E2F48B3CC499D734D4A9A7678BE6651FF298193223E857577D73CC0DAC0E6A
                  Malicious:true
                  Preview:.....q[....Lo{.......&<.....;{.ic..0.o.~=ZU...}.T...9..$...z...4.`A..]m(.s......}..q.......p..B...4,.i.P..v...n...s. .@..R...x......5r.......o.9.L..!...\.`."a.*.P.K.g...d1'...b2e..F88tX..s...i,Pw..@....3x.4Lm.KdF.mD...b..Y..N..H....5.`_j.s>..0.....-...}i..:...".u2x3....$ .i.Z....S...&m..&.e..1<.PG.(.j.l.L.N....~v.s5...N..P.W..!.......[;.s.D..2..>x..II.........c............Ni..r....S...^.X.^L...I.N'.*!.;.....^.....lT..k_OBw.O.9..=....S........]W......b=.$.:<.....p.p2..*.@...?}....r.'.D.~f....!...../.u......R...........M.T)..oR.lU.B...;..;.TW...aVO..........i.....vQ..J.(..c.t.....D..w..{Ki..........h...P.!.*d.....iHt.I...d...$..0o..u...qf).,.{kk.|]......r1..\B1.~^0.../..P.8..=..t7....S.(T..X.i}..p.e....,..fk<...=..t..Y........&..l.w..~3G'...5.+.d.....hE. .......pTr[}I63........c.{*..J..\&Q%....:......[h!L....GE..?.......s..0..5....]...e.~.v.tnD...&..8.kQ./~.[.....6kc....^w...$`K3r..Y.$!t..z4....T<^........YE#./....&).EQ.......]..uT.....R..!p.G...5
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):252268
                  Entropy (8bit):7.9991251236411625
                  Encrypted:true
                  SSDEEP:6144:POaTppGEVVXmiB1AL9AaGvj1vBrLoJyl7Rl5MWq:PkViBKLma2/gmRe
                  MD5:42F683873C90401EDFDE2B592C589071
                  SHA1:9AB4ED83014EAAD469A8CA5F842574F24981290A
                  SHA-256:9D717649D3C6BC1A1A04593C58A62F27963A95A69E29292FB9515D4CD6C9120F
                  SHA-512:56131C02445DD626B2D7AAD8E5E89A66A4C88044542409BCFE3824FE5978A14127A5DC6727FF1D94303D5712CD0EB8BE50E00007E1E6CE4F8252B0E218F3A5F0
                  Malicious:true
                  Preview:.E.`..c.Y.a....m3C..+..Gk..'.A.3..f.r..#.....8.m...:.......H...[..T.e)mj.L.0.._..6.w..p.....>c.._}.T....Z..........L........C........#;P..h..1.LJ......Y.).s.p.6\..b.Dy......#v....DP.x..~...s.....z..PwW.v.....v-..q..f..GHh.l..D.>....O.CD-0K.....}B.c.....Z....ZC...J.wo.......?.....n5...(d...._....%.i.<+.Pu........t..^Zj(f.J.G(Q ..D....g.........c4..W....g.'..$.)c|TO.........JOTZ.....M....K8.V;.g...<s?..~..}k...]KT..*..g.. +.......~'D.2O......gom.7H......E.2.*...~pb_..%.f-n.d............Y.]oT.,w...j...-..Jc.-.........h#0x(........e....|a...9..5.(>...Ivs.b.V....<.c....d^.y....OR[h.`h.&A.;..6@ad..|.<.......|v~..F.|a..u....S.b...ST..k.^....bHm.p.\..Q....3\<d..r.\...@..G.%.0..]/.O..u...M,d...I.........k.....W.....mm.x.....z.S..[.G"m.i.[.u....Cx.d...,.f.^....N.^3|.w.U.{j.z...Ux...I .*rp...3f..AS.....|.).+.a.x>.~ ......?....9..=...J1.6...ifJ2.W.P.......~c...U... .L.......&<......V...1.:(c....&*.r.F...C..K S.e.+13...t..p...i..L..kJ..z.S...Z...fh.X
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):210968
                  Entropy (8bit):7.999164257246536
                  Encrypted:true
                  SSDEEP:6144:OXzjU2umlBFbtNgMN6hw6MamQb2PpWraAlhni6oQXER:OXnRumT9gw6H93bEp6aAlhBoQXq
                  MD5:A66AEDF0F91101D03D4A40B8F55E451C
                  SHA1:B371FB794EFAD6DA07B4BB5A800BDD516755EFC3
                  SHA-256:D9FCD4FC304540871A676EAFF33948992D84AA54444F693C525877916F603E8D
                  SHA-512:FE3553FA183E689FB851D74F96976CFF05719193100CAF505B543583A555B0A4D0F2E996E9921B14BC481DA8B46098881CF51EFB31DB2CC110E582CF911E4A04
                  Malicious:true
                  Preview:...$......R.,.C.I'!....%~U.&Iq.Yb.`...q.Z.b.!..z.I.2v ....U..*N.~.|.......j.'=.40................|&..V.T.....".(..w..d..:.}C>yF..b}.kI..y.+....[...3'.YH.N...3.j.c...h...n88.*.m...Y...s.D..9.N.z.n.w9..L..J./*/...s..[....C+.z.zEsdE.. eO.[.8.tt.teM.B:.H.....?..D.d....y...4....p%._ER.}...H......fK.I........w..^...q!V.fh1`.....!.....8..C-o.z../.~....}...)....V....*..[..;.N`d N.A#..8Rz.........5...H.`W. Q.b.Es..U.&.3R.}"...!..2%./.....uG.p...tg....][a..x|....@..M@..8.J.B|...@..%..\.&.{..S....I..t..[[...*....-.O.1.IN........@n.m4Y.t.5'.r.....!.-p.a".Z..[..v+.*).0..Ej .-.',..z...r7..~.v....ij....#..B#.`..0..wt..~.....`..Y.@^r....><......3.D..{'j.....z....PF.z."}.=....N.;.....l.....dzs.Y......I.xp7..ci.0).S"....r.t.....c....X..x.t.$.....1......w..bw..@N .@g..M.f0.;V=......._sIyj...(.B.~.......v...m.....Z.}y..i6:n.*.K....b....S[..t..x...^..TL..V.$/..........z.`.<.....L..S...>BgD...v.......4#..+.v.Z$.z'...3.k.....f.G|-..C.RC..3...._.7..dj........#c
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):90616
                  Entropy (8bit):7.99782219811051
                  Encrypted:true
                  SSDEEP:1536:OGVZ2JkmYXN1siZrFvdI1x4jY2nux7ct1A8CRT+z4WTFwO9cON7daXJpIiN/P9Fy:OGv2JRaNhZrRCH4YSIrRI4WTW4cOJdaV
                  MD5:7B08E75FD9080C4306C02FF9BD633DD7
                  SHA1:311C11C7D58469239B4B5264E1B8DE9D6369A4FC
                  SHA-256:B7C8F2DEF64106337BC243244299D311202A119172FC525F5E1899A535DC295B
                  SHA-512:AFB20793DE86C5AED0EEFC81978080041C63CFA56ACC3BDA4B5AFE09FE72766AC3ABECC981E911818AB21AFE0CEEBEEE94FA129F9E8EC5CC583D9013B348681C
                  Malicious:true
                  Preview:~6..w.....2P.Qu.`..."|.....#.w.8.J..j......|.P.v.|r.=...]....&".g.`?'...9C.P..F.O)}K..c.-...p1Jq.{......k..b.....U.....L.r...1.....2..K....Tq..+zM;n..=..O..R...a|.Z.!M..h.cX......._x^.1j...).\4...B...\e-^..N.-....s.....O....V..k...R].l..=.;C....x*}....L..;N.....r.....wl.....\..h.@......v..b.....xv.0`...Xo..wP.2....N.M:.b.P...k.....x...=.F......v.......?.@.5......P.TP.E.....A.....!AsL....&..$..o.f.w..E.z.4.S.Bu..,ml.z.2h.OH.T.8...p.....r..o.....e.....z=*.3x..2....{U....C.ac.I1O...s2 ^.)+._.O.e.RXO.......^..Nf.Txi.(|>-.d....p.3.....$.d..)...x..d.k..d.J..av....$.....^....B.a.K.5U......k....N...v...vn..-h...5e.&zk..0......\U...K.c....(..~<.0....vH(L........]..w....C.@;Sp.......D?v...t.4.82....x...1WF....et(.....;AZ`...3.X..U..ob.q..........f0E....k*..{.P.[.]\.r......].M6......(.+7. ..^$_f..%....N.....s....a6.....:.t&...d.k2.<..S.ovP.`...j....3...7..#..+..%(c.UM....F.8Oq.......0:.S..v...D9.T.u..Qz......G.....FYv<l'..UL..|...F...z.[i`.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):92796
                  Entropy (8bit):7.998240751865099
                  Encrypted:true
                  SSDEEP:1536:ypdeXgozdhydIcots++TLF+dIEH/JOZkDLW7u6yDE7K2+MlBjD12suDAK2N9Y:UozzCNIs7FmAiDLn6yDEHDF2XA9
                  MD5:61741AFA733CBCEB0CB8190F680FFE2E
                  SHA1:DD322ABC8B335D7B9857433C54EC97849AC46064
                  SHA-256:9E19BECAD954A129A2B06E50F36AA39FAAB3F8FA9D0B5B4A5D9C6F61E190CDB9
                  SHA-512:CECEDFB6BF1EEFFFD9AB6825BB2B77C754F76CD7C2A2A2E973E64C47D8E025B191CD9E9CB4F89B406655DDC9DAEE9F2D15B8C9DD5C205271F8DE464FD15A3970
                  Malicious:true
                  Preview:0..d..cs0.hS...<e.].(....VXh.a.....S7^S...F)....~..0..D.<3C..._.......).........(d.6"..A.2E[-U9..RL.D.b.Za.S.!...'.ei.5it..B......<.oq..0D..9...R.HI..&.&!...jp..7,.....b.K2..n._...h..\oKz...3..2.T........F3.......V.F.{[UC6...c....tg....t....}Y..<y........H.TQ.l.&...%...%O..#....P:.oe...."..\H.V..`......*e.E.y.+.....N.....u.....-J.j......p.d.~.j...2T..{......\..b;...5..vB...t..{j......z.i]......./...D.a<.zn.7eo.i.tk.e..YIS.=.!...Q.)6.r.H0......K.iJ...dP.w/......Pf...(...Y...&z,.`H>Z......-e+.B...}..s..|....D7.4).......3.p._1.M#.$..`Pl.^....T..W.N.Kq.... .R.8...d...5q.......W..k.:0.f.2....3@....|.?..I....YYx...k..K.Z+..cD......u.d../.(.......c..e..&!..!..I?".~n#./(..G..Zv.I.0.....)....)....~nC...x.[=.........S]:..2:...j....D..s.......1..6...`7.`.@..:...............j.e.;..*.u...^..L.tp8`..,.5.y..e.....QE.Hd^...X5O.BS...pHQ...z.....'...J.c...-V....*H"..oA.."LO.Q|d.i.#...wga..fD.....+f.D=.:.5.,.^......qv...\.`:.b.(.JS..{N..R....&T...S..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):91292
                  Entropy (8bit):7.997973858287387
                  Encrypted:true
                  SSDEEP:1536:fDPfqFsTy06qdqySoUnhvofk7rob7zdhxB9p73JaNEAgMKiF3qq9eFVLIi8:LPiqjFQv0hb7FpTJaNEYp/90lI/
                  MD5:B63AFCF32AC9DEA05BE466FECCAD91DB
                  SHA1:8A643F70DC1982C54DB56CC595CBF26C18664B45
                  SHA-256:FECF1F7EE359E07F91B101E6C9A91F7EABC334F7D263C9D9D2D9DFFC4AB8B7B5
                  SHA-512:72763A112151E8E358E3F6A3D81795F106843E91486A81D9E9908625FD6EFD7905F8711515807065BA44B95FD50319E26FC94D46FA3A8D71CECDF0E0A6DBF6FF
                  Malicious:true
                  Preview:..I...xb.)..cW8..2......-..x=.F6fO.F....a..i......|...s..YX.p.w.v..~.2. T@$t.n...zp.}..w8.T..P.......T(c...../.C.(j3..#.....2.UB..@.!.fQ.d...P.-.....S4..N....0W..!.......x.u........<a....O..[2...l.".J.X.\.T...YE..a.ws..h..M&...f.O..[.I..n..g.7...>......2D..e1G..-.5..>.......z.P..*...Sd....H..WQdh.....M..Q8.........3....'..O....$.LG.\Ek......M..^d<....P...:.nq6k).....h...GI....3...~..}c.......I......U.F.s<....DBK,...R.r.X..>...T}.h.../r...r...*_.$%.F..d..s5[.#F.bD0....D`b(.1?L.......F.~!..5.q..!h...6..+...>...|.....UGY..R..x.....X.?=7..B..S.%M./....u.p......".]}h?.-%/l.iy..9Z...,.i..6.U.n^........I..Y;?......Lw....^..... ..pT..{.y...)t@.2..Q.P(...=....A...sZ....,.).e.N.....a..{.5......1.j..yw%:.w.gS.M.._6q.pq.w.)Y........I..Yh.f..E...Nl..2..8.~.....E'\.A..l.....\.^.>...A......7...9.:y..0y._..dOd....,.V.#.`6B.....6.^..........xR6..... ...........X.B..F.a..i...Ms.no*#~...!..R..."_Gs..U...o.B..`.Gd..>....!...q..$...|.....xN.A6.@....I..l..E/..{.r4.D.f
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):90564
                  Entropy (8bit):7.998125354791482
                  Encrypted:true
                  SSDEEP:1536:u5FF50VZatKfQIq6siMaCSed9+cryQFJFWt+HhxBCKHLrH1Z6j:u5N0VuK4x6si4SaIwFJFWt+HDBt3H1Z6
                  MD5:AFDE7A2F35CA7BDA56B3FF70DEE2C92A
                  SHA1:F881A47033E29AA2F17BB9091B536E3C9F769D2A
                  SHA-256:95FDCFEE6BA4464E8D11F6861F303A867374A98F4C5279326B71BD79A9D9D9C2
                  SHA-512:C34AE18F17412D5A1B22DB42A0F15ECBD667EBEF410B1370A8CF10C8D79F63F760A690FC2DB52DF95CC16F29AE6141AF6C0A08FA48B1E4BCD46EF60DCD3D056C
                  Malicious:true
                  Preview:+..k.c..(...T2.'..}[...2d.n.2.RS.^%..p_#.......$j...U.....B...uxV......]Y.C ..b6%<...Xz!D.._.%..?.....\.p...e....O;HF....G...gaq.v.....G"..=V.u.....\./lLR.X.dr.Li.>.[...c..r..$..=.<6..xUd.u. .....7.$&..c...0...........^........h...OG...z..I..$%.Xy....@~vRa...E.{>.$q....oQcp.*...M.s.zO.gF.`..R.G...[>....w88m.|.f...+d........a!$...b.]..y-...~c v3...K..8@.lD...Y.##.gAyh.....~Zn..+C5.&.....4..).z..R.c..%.m......|.?Qb...F..DM* D.|...a.N5....rC.......hl92.H.::~..b|.6...!o((K../...E/[.....O.39...J.V.|>...dB.l...8.....m.Z.[....C.4..n..:c.A..1...f........I.B=.....i;..hH.P.kj%i#Q/......7..K..;G..Y.~......J.;..s....m....').u@.w.]...qV/..)E..$*..R~.....1..~..f...Mc[..B.c.5!wB........3.E.i...!.p.l.....E.v...).dc...$..v,.s...8....L17.h...8].;k....L..qN....nG;....I..T.....)..4...}..%.ro....zv>".../}...n.).?..Pa..9.],....0.........}...'..V~.2a..89....N..U....$..#.c./.$G.Ab........jI....K...?..".[..Gz..#r....l..ye6.._.......D6..eE...-]...9....:.|...c.|w._
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):832
                  Entropy (8bit):7.684065154858835
                  Encrypted:false
                  SSDEEP:24:ZvmcEyExgjnjIucXLa8hWGdzy5hNM8+QC9Yi:ZvmcJExgjjI7thWqy5D0dKi
                  MD5:F26524C072C92AE080B3082C06C99812
                  SHA1:31D5D67EBC1424A6867CA1818AB62F62E202E1AE
                  SHA-256:4CED582454543001C4387E63261D529CF9F6C151C072114EA4F73F560E9F59F2
                  SHA-512:ED665D9B2A10A392D57B277E71DB4E41154FEA30CB52051CF6610CCA3F6F9A37A72E6FD64D1171347DE4430A8A04F44299BF535F16E0B1D2938A3B81CF68E093
                  Malicious:false
                  Preview:.q..?L......V.....KT9..6..c......8.+AP..........l..i.\.jR.....T7.z .`......}....zj.E}P...<s..sr...'.."..c..E&.L.a:....gb..H..8.A.....?.ZB!.w.h...nr0.<N8 .....&C%r..h4{.7Y....E8.......M..&.Yx.J...M.O..C.*.j.g..,..R:.T(.s.>6@.E.rD....&...3d. .o......f..ld#.8../..B..A.j..?......"..m...gH.]...:.K.,.n}.;\..[d.xqD9.V......%Tx...".PZ.o#.pj.dtK......q...>'.w."..F.5.xe...a..=...V..J.rB.#.Z[^...~..,.,]......).d]....L......+).{nX.`fY..=.]...B...m=K..)Pq..@.X.......`.)%...l9[;....\..._....N.........V.....g..`.~.....Ps@w.Hp..>*D...T.a3.k..S.*j.6....,1)z....Y...]a....}...;.I.._OG.u.X{.JN.AP^...'.l).iM.....=.....~.....3......5.....k..CL..8R.:S.y. .'..9E....h.*1.....8M..Z"&|..V....R..P....2F..<.Z.r.........W&...E..r.jqWE...i&.w%`Ag:{.....x..B,3...Bi.ev.+`../K.0u........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):843
                  Entropy (8bit):7.684934351651258
                  Encrypted:false
                  SSDEEP:12:Hf9tmYcAXJupDSu3NTSdaCz/9srafNdxAwG4fSPZ3kIvXx8mv3vRBarkAe:+YtXJmDJodp1Ce3xXG4fStkaXxxvV
                  MD5:87A1B8AE3526FFF98FCEF13F4FD36FBA
                  SHA1:A996BD9E9E36ADA35950FA6FDBA29AF2D9A0BA21
                  SHA-256:E6C2951CF656B357716DC473099C72D80736BCB021C5BFF5FBDEA4BF749FBF8A
                  SHA-512:D8A7E217EBA3622AECC2A2C054AB57F81D5B7296338E641E306D40312A8D1208E372593DF1E9DC552C987EAD525BF0ACD9815D516E130BEB8999C0794F80851D
                  Malicious:false
                  Preview:]G..$.....rih.QP.[..2.4.`]].:E...1.......4B..'2.FY..nO....J.=/T...\.:L...x"6...Ku.............(.&v....o......^.r.@..._.q..XYO......-...!..y`...B....w.2.."k.).k_T..G.*?y..g.......`..f8.d^......p.......Zz1>.P.N.'i]..:PC....c.<..E....uxL..._Q....IX..GYn.8..p...^/..\U .`...95x..L..ZLS.Q\F...'...p2i3...FQ...S.li0.....*k.Wy>WI..@.-. ...1....].........@>...l.wr..U&..r.V}{L....J...!1.3..P.:I...jo.;.."..!....D..Y=..N]".b+L4..A.X........7...o%...7.<y#tl...L..EO........KI4m..:....1..t.....D..j...$..i.w.D..F/.-.......>.2..K1.....H4..mG!!..AoL.d1.;.....rBx)..xN...|.Gg.Z.&.a:...>..KC\S....1\...c.o%.Z.<.e..QKu.1$....Anw.~...o..\0..~.I.X..BR:I..b..8..0....A.=.v..2......t*._[.-..W...Z!...>L^.d..#....q.y.an%...f..G[C<)A.A........:`.8...6.a.B.Y......u.....L.Cn.......%... W.R.0..n..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):844
                  Entropy (8bit):7.717789938931189
                  Encrypted:false
                  SSDEEP:12:pmraCH0siGAC/GYv+PMwsbVxLdwQcv8HJ2+I7vPppYqUfvtNrzDuAv:YmE0tGHGYv+PMw6TLaQ28YppYqo7
                  MD5:58F78218E7B7BEFD046EF778030959F1
                  SHA1:40532F013CBAB7846BA1F10D9140C6982A35B883
                  SHA-256:17C405DBED0A592EEB927A0E63527A2F11933A007AFE3621F8727B91E506A81F
                  SHA-512:50E426D57ED04374223A02BF20CA57CA8D27A0D1B48C100BCFED2CD1F90D4459172DC6AE09E33CE1EF889167EF43CC29F5A5E2CF5CEB55E87A3F6C465626540B
                  Malicious:false
                  Preview:.P.T*V..Ct.. /..:.-.!...g.......:+./.E-. 2......s..."E...8..}z./... ._.Hx}gO....@..^.....>...p.")`.I..:..*...p.]Q..y...'.<D...t...S>.jA...t.9..H.....%..Y.......[Zla...-YV....a..<..ZF{.?.+W.....%@t.:..w.;.'c..]iZ..[.R..vW4..... Y.-TC".OZj...?R...&..z.{P..j......x"h..h.|er......(...Xt.~@r.W......>..~.Hb.'>D.....SN.$s...(d.n[..eq)....k.H.:F.2.EiJ.....J.O....u^.G.{..........#m?..U..MM.".>4..Lg.iQd.tE.n..'1....i...IfDq..A.G.T.6.(J:Zc..S..U...v.....(.#..T..n.@..S....''.X%of.ywj.........F.[....t......q.3mXl..R..w.$"..g...L...R\.ql.4...lM.A...+.".-....7.......%TK0..f......a...;%.4...RN\8SN..?U;v.k^/.Sr....s.r..........kW.q_W..`G.w...K....e...,.....Qaq..9..9Y.x..0Kc<F. ..k/.Ui5.+...U......J......=M.._..q..........@.CF%......J....do..O..v....;U...KK...|[.W.#....ik.,.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34865
                  Entropy (8bit):7.994638941648221
                  Encrypted:true
                  SSDEEP:768:RcFD1hCWpDUP1+KqWka+9BdKlUsluiYbbQ7WEuQuYhN:iJ1hCQ2bqWkZx1s977QQ
                  MD5:63345216E17996562325265ED19E0EFE
                  SHA1:816192AF7F0FB64DCAAB5CC27A3C40A94E923DB3
                  SHA-256:8701A00DE886A0BB3B5CF72159D63F48E1AF2AB08C7E812AE2B1F2AB305D9B49
                  SHA-512:14331CA6EA3440CEA271F3AB5FD70873C720BC5667251D2CEF2B6777B729FDAF3546A44A96DA245DA162AA0465F19B5DCBEF33B0158C69D2FF9170DF20C1D1F6
                  Malicious:true
                  Preview:a&H..Byg+Wp.mH..5.Wg...v;..*...av...=.-...O..O....6.......>..j.XEs^r...s.g.:....X"M0U..m.h:.Q..4...~..Bp|.... rb.u.. .ai..........d....7nC1kT.+......h,U..S....#.i...b.O.s.q......?...au........o..... ..#...l.~S..8.'.9h..3.Zk..."C...e....,.dB..v.=c..@.$;..3...".#.E...8.9....w....qv..bR$.).........?m.G..m$..!..y......p.C.....-v..q.=WGqT.5i............w.yK.s.#...)gwn.&...3.2..6|3....u..d9Ag.L.T.r.!wsv............*..(..P...'..p.4.xj.Z...>8.........O./f77....u...........M...q..uy9b.....-.3.r.?.^I.s}....K..p..[P[.CK*.@...q@JBI...PI.4..)3!.fjFz.nk.&.....+l...-....R....IQ.%I'.....rp...*U.K....Itg....3........-.>Ko.._@I.....X.l...p..............= .e..,W!7i.p..9e..Bm..q...s....J..|....w..G...T.....G......`.h.7.u.3.[P_[.....tQ"6..]]a.)lZ..|.S.ZSh.?..D@q.B...X....t.Eu%{.?-.A...?....}.<<.`^{fSx&........./. ..<.F......p|...p.SMPy.x.m.S..OC{.+...V.....dH.{...r..0wi...L?.l.|#.^...xp...4U..9Y..4.y...B....3..J...\1... ....,.g..<.C.#...k6. ..D`..o... ...;
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):75733
                  Entropy (8bit):7.9975512337626276
                  Encrypted:true
                  SSDEEP:1536:5ksns++O30J+bb62ArpjnwevS6UGEqc7aDe3Y7UocwuUPU:5kf+zEJ+K/rpn0/aDf7UocHUP
                  MD5:2CD934123F71B83D56F528679C87D5DB
                  SHA1:6517F418A4F9DEBFB2C3B0EE89C4D1E8E2B85C36
                  SHA-256:A586718341269A87A1E818CBD639E1D453FF2FBF81ABFC75AA9ED01C855C98A1
                  SHA-512:CE3B9B78358CD220B4A9C5EAA5819DF9F5DB09978416C5C9BB320B24F7E96F9DCB909F7943F88AC069BDAB03C47C2176301BC668478D5DFE71723F3AB8894575
                  Malicious:true
                  Preview:..].N,w.P...."x..(0:.8....,........BC....c#.R.E${fN....w......n.]l......9.\.>g)....8.7.._.C....7..hh.n.F...x..c.b.9..Wm\...|o..8.^g.n.n..w......L..."m...T...T...GL..?.<.=BQV...L.......A....'..&|..|..U&.b...NaK.......R2.l....E...!....c...C.;....%1A./......]|f.....i..(o.^.1./?......k...&}..E...$.f?..y..@..b..! nF..... ..........#th..Ay.....T.\vS/..u..iY..Z....2bol.z...k.r.:.aL.FD1.7B.m;0!.).9.X:.D...!.q..2*&.. .f....wU...X..v.........o..(.r..............I....xK@FY..PC..=j....6..=...1....%...":.....%..}...w[.....g. s.jC......%..|..M...c.hH.1...T.c...u.P.....o1.g.N^w..?.. ...1..\JU...^b..4.?8....../%./..\>........v.:.{....N.n.....#.!..O,0A;4....{..0@....S..f}.......s.h.#.w'..k}....Z..caa\.u.i`I.q.........pB..jg..y^I...R.`,..9..n..=...X=....X)...".Pi...r.I. .I....$o...bw.E.....IzH1W..+%..xg.F.........v..g.B....zb.;\../m1f.K<.ODAy......LDq...W.........T @..jPe.........j\:.S.j...m.#...A..^..}E.'[..\..x...!.fg..G....|h..D.Lm.e!/....O.<..|'..m;.)
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):96578
                  Entropy (8bit):7.998220970723235
                  Encrypted:true
                  SSDEEP:1536:6NZAZGEGiYng6buMiFzbA9OU71LWchbtLZBB8PbNwflREYn5EyQMEXCdZJlGcGU6:mZa3bKg6b5iBUXZBB8PbNwNR77dZP0U6
                  MD5:85918D0869AF465577252748F1FAE07E
                  SHA1:CDE918A9820CB84F865BA9A99BC54409A3E9C1C7
                  SHA-256:BDEAF5BC1334A42EA3EEDE1A9CD014E17667340E21DCC1DEBA03878BE7EF35AC
                  SHA-512:0C06638BCBDB4A6D88C6C54259D20B6552FC596875421B69778CFC329F700942AB417F935CA47BA219DAD77E0EF34FBB46FFCC0C5AEBA962E843678DC7B80565
                  Malicious:true
                  Preview:....z.'.....o..N_...).1.....n+..3.....mL.+<.. ....]...1F.... >R8e.l.e-Wd .d\N2.....rL......Qx+.s....$.].:v..|...d.f... ..X...y..T`..amo....9..1..u....).\..V.g......=...t..4...:.tE[!.BhC..\..6..B....&Kv.Z|)3@....Xk.....P../.....$....(.'.....C.i.0.......}i...W Q.3q.(d)...(r..^'@...oU..F>..o>.9....w.xq..F|:#|..sW..[N..y.........HHm|.&.LR@.....[.@X.V.n..-vzH.e%........d.J~_d./....~...jf...:.4oLfa.NK}I{$....DL.Y.dF........^.17.\..b...*d,MV.EF..^(.k)..vQ....U.......m...........-....:...M....].2.^vR....Dd.,$a.$5...z._Z.5p..V......!...h.....^v..E....7_..9..M....H.t..C.8..hN"J....O..............U.,.....U.50).F.dT...n(..X3...@..,.D..\...yrF...D..h<:{Re}....R.&D_..Q...s....3.......?<.).uX.k.... ....8Rv..S)...-.4B....zy$.l..UN.@../....gK....Y.2..*.$..:....4e.G...(Y.-mE...d....\.,.....?.[..k..8...8..7..6....lS....J`M..C.$.......J..b...Z-Q...'.w...U.{F7r.....1...._....7..V....]x.....;l.+.!.V..z..t.^..3p.@}......^..L..h.O..{m.r....If*..&.:......;.B~O..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:370 XA sysV executable
                  Category:dropped
                  Size (bytes):13884
                  Entropy (8bit):7.984373479565186
                  Encrypted:false
                  SSDEEP:384:lGDfRPlMlytfOWHoLpNTuAmjAFZ+j35gQGiIKeg8:lGD9c+cCsF+Jtbx8
                  MD5:7732156E1E8CE5F995F44FA45C7BA597
                  SHA1:D1630F918C24A3DEA01E8B99679982F5AD5BE139
                  SHA-256:694B93717B3321202D5EBD161AB2CE78948F3DE9C1BB466513D5DF27C54CF4B6
                  SHA-512:47CC9812D68767C5EF23C1CC739886BAC78464339E042B69F69E9AF39C126B792037FFD5F98966FA199D71F87D6C9FD26853794C46BB6FE1BCE1DAE9D498DE89
                  Malicious:false
                  Preview:_....c...7.}.a)...9--;I!...X..x..m.J0..)N)|..@.S.+:.B..%.1.<e.....(.r......4b.\\.kW9.:bZ.|...j.5..0.<F...I,.].U."...~....?'..U...LC..'.....4.9...e....Z....~r..._..Vi.'L.tA.9w".:.[,<....PR..5>D$...j+S.9.......p/];.t....S:.d..N....8C.yz.'.....a...B6.......:}...l..-i.]..:.....]......^..A....Q....<.!.\DZ`..O..8y....v.x...}r...V.j...X....^...<...6...K+....U....k......T.3.yy.bQH...D_...i.v..m@.g...Yl.u.....)..A.L.%.....:.E...X.`By5 ..c..D..gU..!._...j.*..rWk$K.....YO.H-!|...L.b..].....0..(J.B..f....*...^...w...w...!.s.....Tn....g.X...0..R...LUk.b......wEAA.38..i7.j.S.J...M..H..}....`f.w.E.,J(].FeE.....(...e..;L(L.@0...x...`.bW...z....;.h..V;t ...x.VS...n>R..Yp.C.m..e..t.XG.7.o_....u.%..+.|an.z....%c.._tZ..SH.%6?.&..FQ.c....-.[...F7.S....X....F..].=............`L.....:~..M.%OK.U..yz...#f....O....5S.....Q....i..e..kT....q.q....L'T.w..@..H.B..Tl4...:...a.../.(..j....H..Y..m5@...<...#.n.WRh.......K.;(...s~.z.Y..8..n.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):214672
                  Entropy (8bit):7.999119779716546
                  Encrypted:true
                  SSDEEP:6144:tjE2/ofrBl2HHOZjS1pjm6bMP8z/L6RGXQ:lE2/cl2OtYIPML6R
                  MD5:F2C5404B3E6113746F749A20ED122657
                  SHA1:70EC28C1C4F4BAEE05713F3AB540F852A4778B8F
                  SHA-256:19BDEA96B92E21765B3F7DCAD296E5C732CF0558DA29C5BFE0753EDB08E43855
                  SHA-512:035E0B866C18BB0D56F5123DB5EDBC15F48AC7129792F3642287EED1332B74B4ECC5D316B96091A1EBE4B0E58D8FAC728B01DC30F725731E77F75FFEAD5F88B5
                  Malicious:true
                  Preview:i}........O??S.*t.'...'.....b.|..._B.h.......&.|R.G...6..I.[.;N."<..x..ta....vVM.6.c_~7_..,._T.$Dp.<I+m.p.Y...i....I....]... f.J..gO*..m..\\d]....B....xR...A...7.M..y%. .].e..].O?....z.O.O........F.u~......X..m.!....@.......7.{._.G.gc.V..-+....q.U.'....G_1[..%>`.._qF..G...F..Ru.'..|+..(L~..T....l..%.CB.up.......u.N.y.......4.y.}.F..M...~L../..../.?=.b.u...[!..:YO..U.,.+.m.Z.&......#O[B'mG.|.N...f..9...q...p.:S:B.&8.$$..Z..7..g..m H.)!......G0! .i........\..yv6...n*..M+.X...[.W#....v\R."..P0..l..._5..0S.......gr.....0."...". "....G%..,...lS_j.c$...".1.i"Z.+C6...C...d...no.....ck..-&..4.C..oZ{.g...a..("/...?..F...3.C..1.9...t ]...~zt.."s|....<.57O.\C%..2.........2..n. 7}..vT....G.v..........J.7.I."..Ss..?GZ.ipyT....t.(D...L..Z...gD m...?...]J.?......B..N.n@N.x.>.D...y......Pv..D....a...G.0L.!..%...Y..BX..k.R...1..b........#F/`..-.o..h...h.k$]...U..J|".^.F...G.n....KZ.b...S0....9..E......hx..-.E..H....P..Y.o._.:.9%..B.{..p..v.....3..D..al.......2.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10905
                  Entropy (8bit):7.98225319946514
                  Encrypted:false
                  SSDEEP:192:6P/TTEkLGvOGvHSY0WwCaEhRq6hn/NL4lbMzVQjqbwH05nbE9Hg0/MawaPRZ:6P/nYv9yYjzae46hnDVQ+rnY7kavR
                  MD5:48CF6CC22D93539BE360581BA4D5CDFC
                  SHA1:109A680D095BA448AC2DDC587963D40CD988FA84
                  SHA-256:828787CD9DC3C866DDF7146E6E3B3CDA550F30F66F95EBC2E94BB35B68549107
                  SHA-512:5FDF7E33371381B6F3E279A441DFC13825782423CEEEF640986F4609D86FC79B4C01150B8DFD86A8403E21EFE9275A56463C5E7BF44DA69849E3D606E2EB0AF1
                  Malicious:false
                  Preview:9.]."....f.......:T...#...ds=.....q7.ND...a..&X..6.._*.Q2..34fvO_8$H*..U..?..DK..;j.6.....~.....OB1.`;Vwcr.)_....E.o!uHB.Yi..:..;.w~..J.4......x.:.l.b....[.Q..G.'~=.`..M...8..."...i..%...V...f..........E<.......=Y..-.....,J..y_.Wm...a{.%..Q.4.W..g....c.y-o..!l.Q.B....DpH.v..7.....hd...p.4......`.;y?M.;..S...o.........zh. 1."Mn.6.quza.&-S-..'......X;:.on..[./...zG.!.....Z._).....%.:..V{...d_|.j......,C..].V.6......M.{...7...<}..;W*.ju".)...>K.....'.)k\..V.;.......ip..O3JR.]-..pX..v.....t.^.8Z.PX....^.&.p..(..\<.g.D...E..&..,..09L. ..N.....o.k.S..xGW......O 4.d..rp.?=~.4N..i..&.S.R.............e.3h..M.z...PY_7..Jg.......Z.&.fL...s..h...{. ........(E...[......r.v<p...d..o.?&/j.-.....V.AC.E.j....:.......(..p.P..-..D...B.....X|....0.c.W..&.\.Y.......>9......f.k.....$0....,..W.e.........Ks"J..fN1.n....P....YK.....-.....N ..yXo.4x.=.g.u=....@[.?..,.d.v....3.0...A:!^15i...Pu..n.7..as.@x].......1...-.....8}h........]U.d....Fx...{1.t(...I..g..:a.I.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):12456
                  Entropy (8bit):7.984702813885933
                  Encrypted:false
                  SSDEEP:192:uM9Yhp5mnkTnJeQW4vS1TKepcdrK0oojtHu/Mx/2xPac+R+jlGSqspJmWwN:uM+LVGo9scpK0oookWPaNul5DpJ
                  MD5:2917952DABE237CCD737B822E2850500
                  SHA1:80054A48F1A4B22811468927AF13AE2215D87B76
                  SHA-256:78F21EAD432E967EAD87A56148882EF0D2D8FC7F525834C6C4DF30365FAFBE08
                  SHA-512:B3C5C4985D4F599097AB3F727C1BE56028CCDBA6A36220EC653C6FD6CDC5E4021DE8C36F597B58053E60191F7F696056CFF9A559C4D70F70B8879CF3F843C189
                  Malicious:false
                  Preview:...T$.V\9."......S.b...D......5........C....y......`.\..B.7a...wRE...P..T..8.$..g.#.....j....U....B.1M.....A!)EqF.....n..:./P:...8.3..._;..Q.....$...w........K`h.9......T.$.).Ad.-........L:...*....<.3.1.......v2..8..p.d..E'7d..j_.-....X...X....!rC.C /..;.w....S.-:.2].(..-.............I.zVY.8....v.<..B...q..g.y.9.6LH7*.d...........".Ac..I.)..`......."..h.....s..a..!...*..0..S....V.`.8...;.r..)..;.Z.p...].%.....i.v.....Vp..........b.tP......Td.Y...*.........nS..E...8.;.M.d.....b(.6"...a..7.a.5OF.....".t0.._H..p.@.pj...h.@.....a.m..y....W..*yH ....8/GcMU....$.....;........*l.,......S..U.....Z`r..j....8u.!.D..Y...bY.Gv.e.g._.....c0Y..N..Uy;v.V..."...9S*...WF@.M=h.D...B.......a...#R#..j.U...z..F........g...?...:x.........W.2.C..Z..5_..n...s.v.p.^Qc....}.62.....S.g......u.S.v.._..Z"/....`..^..w0D.d...k)4".....p.O_U.n^.t....m].b.}.)...x_...d.aJ....}...K.8G.......o,vz...k.Y.....F.^.....:*..L4.z..t.g(W...m..).d(n..A...1.x.2....)>8.;uyd.+.|E.......g..r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):13079
                  Entropy (8bit):7.986700691316066
                  Encrypted:false
                  SSDEEP:384:XFzhivRpiMwhsg0Iq+2XoTSUtmNu27Ngpyzc5C1:XFz2zTwhsgg+2XoTS9NgpyY5C
                  MD5:0E01A6EDE17CA612A20F28F8DF0665D2
                  SHA1:7CB432F783C9C1719382A7DE16A43AC9460DA8FD
                  SHA-256:D623F992A7AD4005DC4532D42AA97CBE34350AF13F36BF62CBF9A004A208272F
                  SHA-512:3D725697C6D3B13827475F2D7D15670D8EE7FEE01081AB09CBE025956C66C9D63258B95886DDB1884587DFD97D17DE08AE044A88AA431BC9C9BFBC48C3E9BB98
                  Malicious:false
                  Preview:..).Z\.+.g..t.........bnj...lp7....N.!.9.<x../...E..GU...c...X....6.[...j.%T5^!T.-...q..\ ......Y..Q..*..(..q.........d.".{......%...6~..@.p..:.......c*P.......u*,.#.s..|J........qS.C..h~....Z..~.V..L...@"..........!.Z.c.J.;L%....FY.F.....E....{!....,i?..t..FeaY....h...P.........b9...6cj..@.........O...........b...?B.c6..D..1.Q$.8....JL?.%F....qP_P.c#.k`..7.ly.H...Bw..|...X....FHOI.h.@..D"..C.......^[Qs......2"..j+...(....8...;A.{.....l,..A..9k'zjs~.;ZG=..-.....d*.F.........Y.......U.k...E.~?/....G-y.0#.o)R7.K..+j.q..n.....f=..(e._oD.}..4]..T+.&.....I..U...........t.....4.v..=..z.......-...aO.0..Y,..>|.co.Vu....#8@k...P....M.....:A\..`....S.#.t.T...2...4..tH..a.;..a.. ...)l...>..z.G:#..%1.*.>..CW./R...B....{.:).`.._..9U..M?&pf.....p....b......)UC....PK.%...k.5..nm....sZu.4s.O...P@...c .M../......f!.R8...k....O-.....v%@E.R+.y[..e.......M.OdxE.l|H,.+....4;?%...,.W.S3...._w.f..(..u.T2..<.-.N.=..;.RCR+6...o....x..e....lt$.n'...X.g...c
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):19083
                  Entropy (8bit):7.990653808360427
                  Encrypted:true
                  SSDEEP:384:BefXkjzF9fqE7khYhllmoEQyZew57cE1y03cGHd0qoCJB1y2x:KXkd9CEIeXIo6kOxkCd06B9
                  MD5:CAC91493DDE07EA3918A5A11548B12FB
                  SHA1:37C8DD9296F8B5EF4D2E02572DDA75FF27D8C9F6
                  SHA-256:05EF39E78B44B27F1766CAC83A71EB9B895CA956A2FBE8DDD49CF5C111CB8F29
                  SHA-512:6E11BAF7CD34F48BA394280EFEA4F6B153D8EBE6CDA5F1B2E42F58B29F3F5C9C050971D601C6D5D792028D7C4C52D67A036840BCC97B4995B41548019F7D63EF
                  Malicious:true
                  Preview:..y.f..W09.t.L%.v.5......x.F.......+..l..?.zcm.;n.y5AQ..)..`..-....vU5k\.:o)..t/.a.7..?..}J&lp...naD.[...<.D...d...q._......../.~c..m.......'...G?...J@P.Km..'.V....B.b.l..r.v..,Y..v8X...6.E.......0C.j.BNf.mX"lf..(..%{...</....}.C...u.".?s-.~..........u.U.d.AZ_.i/j.)..;.!.K.P..o.8.5..d.p.}.S.4.s;M.0........o.\^9.6.%...P.0c(YK9(7.7_j..V..Vr......A&.C...-xz.1Y.O..,.y....?B<.3..|..3...o.......l._A.X.'......J...</A.........^w}.q.d..8.s.:0..#|.0.{S...Ei..~...2..S...g.<]...V.ZeeL.........\.U.-K......L....|."...9...s..g..WC..T....26..e..N.;.............N....HS.................Od........`.......YV........b.(K.......5.u...iL...c..\OWZ...".....(]..p.k...~...t(..P..,.Y|...p~!.j.,.F....N.......5V..t.f.}.5f...kuy(....b....46..~H..).....$O.._....oM.e.$F1|.........u.w..J_.!.............q....'G..a..pZ.=..R.........q6..>^..F.4..w.`..4+.B=H.s..J.i......6zUp.A..3~0../.#)...Z+....7..8...+%.........mJp..t...&.&".ru$..:..DT4..}.>l..;4..0FIB}...........T"X;}..S./e..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):13683
                  Entropy (8bit):7.983745582892778
                  Encrypted:false
                  SSDEEP:384:AQsFa3AoTDib4DNHjUn1D52ghMKHh234fWNB/oy:SYTDib+Hal52ghMghrWX/oy
                  MD5:EA78AB5D3EB7649ED4F952611418E76B
                  SHA1:C67409F6177875EDE7B855C7A0533752523D8EAD
                  SHA-256:2B871221E6F568863131EC12211B7E4809DD06AA264339F62BE233D9889F93B9
                  SHA-512:F9F5058991C5F14B94D6D5E7ECD7D4832E1237BD5DCB2564095800F66F1AAC81478AA4E66AB431F221FD474ACE7AE0F8BEDBC7CC0075C1AE70123B11DE765F1E
                  Malicious:false
                  Preview:........r...?...+..M......q.1.Z;...K7.......{4.EZ.K..)..X4t...{.M....!N....T....O_..>..$*.5.Ts..1YO.2_a"u...~R...qk.^.=_Xl8.......{...[...W......;....a.........M.'..r. ....J-:B%.....'i...r.?.5 ...W..u..B._.Eo...W.'.Z..L...6...l......C\.E.F\.[Y...Y_g.v..\..-....h .....d....$.].*...]..\.Q........<.....[.....R.....y.I.c..G..ey...g....gF.n<..P)x.(..L....hjl.....0$...B;.N./*.k.....?....< &.f^...'..|...7...i..Xm.g.gPq....T...v.t..V!..UH.G....k..!.PFW..2...^>....p[.\.?...k..P\.F`..IF6.<k.\.g.n? ....U.............^...H...G...q.u......q....r.G{I...;.......I..........Q".,.j3r..............S...&.......Q...n]t..bl...u.L.4p..k.....C[..f..-W.B.[%K...0-.Yu..r...a.(..1w.;..oP...<.,-......(.l.5f.....`........@.&.N.......s.}e^..'.......E7G7.g..SG.k7.Gq.n|....s.q.F8..V.XbP.l.}U........d..j.X.....G.c.d...B'E.XVB.=g....{.u.F.;.t....S.R.+CK/'.p....6@m*......$....%.:..*../0.@}.n....k..G........?....5....;..7.O....-.~........Y^.F}..Y..d0...i........m.j....zT
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):13563
                  Entropy (8bit):7.988235060361398
                  Encrypted:false
                  SSDEEP:384:T03UZllwLo9aiSa4myjH6Lts/wOEhOiTfiGuN:T04llwLo9aa4YLts/wOEQip
                  MD5:4B1C4AB4E8BEBB97E9F489430AED7A4E
                  SHA1:CF6E5205F381413C4BC51A62E529526FE55F093B
                  SHA-256:89984A35597CDBC2ED9A6B1CBE06FD6AFF866A479CE949501EB477EF94BD79B4
                  SHA-512:F48E397BCF0D16AF94B30794ACD7AB555FE6E1ABA151E96E98D48653DD5476B78E15A15B139060EEE66F73C4A4D7E1E052DDD954256C18A06D1101322772F1C8
                  Malicious:false
                  Preview:.9&.#....<....q.T...`6KG..jL/..G...h.?.D......Z`..T8....k.....@711..]_.$YX.....}..A.......D .@Q.Lp.5....s...([...:...i}c.........mze...#.bs?m@.B]Ib....V>t.+..t..<].M...;.5h.>..p....L...F.....i..}.;...22..`.7.FA..M.Ps.B..v.}.H/.3q>......L.@l.&c..%...d....%.!.C.}m............-1':N.\.ZO.s)...?.....U.@....65b.f.T.b.<...gT.s...$.{@.....!..&F.........b........0..rp).{...j.....T...N....&{?.9..1.%..h...1.[...Mq.d......:HJz2HF..b...Xe.NL.._j...Y.J......z.m9....R...w@}...(.Wc.P.i...gp0..7...JP.....tt..@.gp...H.P.....o..%f\...%9.G..E*...>.;..ZQ......x.n1..\...:.L.......i..57..n.s9...9.....U......m..d..........]n.W.C...?.......L=./............9.VL.f....@E.o.0t.../...f~d..9..Vw.\F.FtU...\4....p.wM .d.-....|..4r:..wQ.F.RX..C3........\......}A......L..J.t....\'.n.O&}.l.B.Q...._R..O.:.O..."..}....0[.e6.s....l..E.'.]q..]R...y*.fd....e..o...~.xM...E...6t...q.e.ZBJ......t6....Z.iO.S}.I ..}.y XSu.b?......e[.8.J..vM.P.......-..R.P..w....M)...U..../.z....4..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):13486
                  Entropy (8bit):7.9853416957938075
                  Encrypted:false
                  SSDEEP:192:xTntjUdLIENaWR2OrvJ7+J1rzyvI/CF6cdclpjXoGhJSiGRT33UHwXJd0:hQpaQrJ7+J1HEIqZdclpjXDhAiE37
                  MD5:C70A980685C2C0DD19D2A621F1AE32B0
                  SHA1:85DD045C43F11716F045E2F68DE19D9B164867A9
                  SHA-256:89B05F38601D9C46D924360EC4F268E10C1BACF6C4D6AB283BA03E588F4448AA
                  SHA-512:30A0DB0A952E3E436DFDE47C4230B92878C738B0012AAA0935B43DE0AD2114FA3AD50A04C9D91BD2383592EDCDAF49E776F993B5A7A079EBC35FCA5E3D6743EB
                  Malicious:false
                  Preview:..."....4.6.....j}[)..<.t"...Y......o'.K......c....b%yl.4.....bI..'.Rhe.>...k....u.......R..6.q(........H....0.9..t.K..&...O.@^g.7...5.....+B.x..&...9.....J.J. `<.3.._...V..}.5.Z.E.g......@a.K.'.g. ........h.T7......"=...@..9...^..[@[R.....vO.f..-.sBV....*3;..t....F.+.%TH.[Q...;\..Z...NH..=...xxQ....BO#9i...}.I.+sd.i.G.w...7~.M....Z2.b.Byl...R..@.++"Bv.g.....w....(. q......e.\u|...V).B.......T..p=.Q3ao..3..8.J...v+...^.e}0......Q.J.MH.7n.VLh.<&... .T.J...E.4..,'....77..s.I-.....6.6.."..)..{..`..w...,..6.........e.2..|J+..W.......2.....q..n.....(.<.Hw.?9.Qqo_.~At"|?.xe..V!q...}..t.h,O.|.kfqd.4.@Y.dr.S(b.......V....k.K."..F..KQ.RJ.B-.;.9.|O`....;f.......w.eR.....(......W.lxt.....*.F.+...j...R...y.F.2i..q52....nW(...73.p,O9......Y........(......C....n...]....I.!>.....p..!.g...bL.....H.fL..u..c+..l\.2[......2..i.7,..3.lM/3&.1..s..;jGW.....Y....G...xE......'C..g.H............s.l.......#j(sY.......d"..)....\....*4..x..KAw...d.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14335
                  Entropy (8bit):7.9863253668160095
                  Encrypted:false
                  SSDEEP:384:aMgNFELAmhm08sY9RqIefVzR2h9LMZqlpCzalqEecfU:BgH0hm08sY7qTf5tYlW+ff
                  MD5:438428304BA085BC6D828C158C79573E
                  SHA1:2E1ADC13E837D56735490E595586AA602FD16768
                  SHA-256:5BED540E56EB0163BF7B2EB392248460DD5546E08F66E1FD880E279BF0EC5236
                  SHA-512:20E1C04AE0E5D419729EFDBCC64A3B064A63788584A41E1CD75DB13E29ED785B2D9908A7A3444A4A4A759EEFDB79241F5227E449494D0DDA9BF0912C4E1D8C5B
                  Malicious:false
                  Preview:Q7l(a..XO....6...Z$......j.....XJ]lP......5..07..*................S...X.k.....s...#.._....O.L...I>./.Y...q.+....4.H.[.i.......1^.....`..NM[....DQ.Kz...&./7....9..qt"..f.|9.......E>..C.......3p..Qz}..=.0.:."U.j.0...'.E...o.d.2.=.L...r".X....9pC|..X.7G$G.6.-&.x_t+.=.p...y.:.Ck.`......5............o....|...<....V.9.'(..Z.........0..K..m..f+.a..$L..A.-+.2..W..3.,.....%.w`.$.U..w....~.u.........."/4.v...TIS<.7......Bz.U5.m....w}.H...2.WI[......1.}_xA.&.h.0..p.Y......T......3k.....V...7...A.........WV8mh]Z-5......1......l......N4'2.S.......cJ.J9 t`W.44'..Z.a..!.....1/..)...Z.....(..R?T!t..ch..Nl.<... ......b.pv.U..'Z.6."gR.Y@.:.....C].I.dE.h...X.....:.T.|..DM!./.-hqO..#.Y.d....*.....]v2K..9l.u.....:^..L..c./....9,.S.>...?k...a.L...a.2..V..}.:..R.A$r..)....bV...V.x.2O..L..........mS:.....G.yJ....>.7.g..mNe>Q.:.`..%p.....y...._@..3....XJ...O..l.l.X.G./..[...y..".y.u....$.-.>.`.|.....a!.....X.o......c.D.c..=W....(...rf...f9....e/..EiDj.....o..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14554
                  Entropy (8bit):7.988335870537352
                  Encrypted:false
                  SSDEEP:384:7NoJOk96o5JQ6nOoEGr19VgDjwZufJ8ofArRMTSMT:7GJWIPOoEG+AZOJdYrRM7T
                  MD5:112BB2FD4F325B1FCFB15697E3F4954A
                  SHA1:FDD117D521691A54F12FDB72F439FFC6CA6E11DB
                  SHA-256:D46534459CA9A40F3631516438DB85ADE98AE1F3F219179B41110893956E907D
                  SHA-512:00888844FBA2709F9499A9F17089E0149D06CE3BEEF9BB82C3C7C29055122D8C02123EE2EF83E2102FD1167213AFC2675AFF57BDA60B0FB25025799856A8E14A
                  Malicious:false
                  Preview:..........i..g.."e...(.z.......I.......}5mB.../V..... x`.....N..^p.a....../v.4.8...Bq?.IE..?..;.._>....v..!K.0bA.$..m....)5Trw....6.".=<:5..C.X..&&.b...}....`sF.@.V.`h...,,y.f+7j....*.......B.PL......3....h.$...-.....E....y.j,.B.Q.".../..L..H..,..'.....\.[S..;.......cp..y.$.D:.@a..?fvD...Vh..>....... .*z.N.T....H.&.[x....].. V...Qr..n..j^SF..4.b.......^V.x.`..J..{F.Z0..*E.......3,..m.....O..n=.&.........0......e...1..[....4...2.9..9Y..%T.-.....2....3........?.F..;.P.3..F.e....W.....G.z...z...].....*.,....YM31H.g..s....:g.1...D..........:#|.W..H.jyj..b....6....(.fN.A..9(:...Q.Q~..Y..,.......b...M..Q$H....<.....|.&Q)T<1..u}h..E4.%@...z.q..+......?...E.....N.@..bq..Z}.T;.g...C..V^.H.bj..w.\.H.....p..k.O...h...<!...>u.A'a..gy._..d.u.......2......#.A..RZ........pY..'......?...#~I.#g.h.1.3.v@P.Tt..Xi.?I.....hHY.+g.h.......3 .#..U.<..-.P.U9W.T...0CA+F.%...k...._..."6v....;...m.......6Ks..2.I..a."...AN.....@..jlca.Rs...=g.*lw0...L`...J...R..(s..<..}>P...f[c...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14923
                  Entropy (8bit):7.986384334835072
                  Encrypted:false
                  SSDEEP:192:CIVFUfWPU3TUJp/F2znzn/N3rLZcQUCAbfoocVqldjFBFkCql3ZIQ5fIvK9pgklL:C4wWPPovn/r+CoCkr5vQ9lXlRZj
                  MD5:E01FE7D1FEDACC7BAB012EEAE4F0A672
                  SHA1:33C8AC15EE3EE0D003D3B27EF59774724961F8D6
                  SHA-256:3EA7649C24589408DF2E2D79912F4DFA92A11721F8AD221D3E38187FA76546FC
                  SHA-512:CD322F651D9F1A486F5B21A74AEA72C6DEE523617F0514369C6185398056123C372A8CAB9D59607A720AC5738FC10330C1FEB002262D9B114D5804E39F0E8F67
                  Malicious:false
                  Preview:.H.......b#..'.0.|..9U$p..vS.h..!.8Oa.g...=....y.D|Y./...A.X..|..]...q.....T.lU.Nm./}.....[........=&..EE......8.k....&...a...'.p.lr..Xu.W...8.KpV.Gv.....U|. I.\.E....u.a....K7t..t3.vRI.K.?.3N......>b.V...D.1H....UsN...!t.a.......\.2..Y..........>.._.t.1.W.'.l./..T=lI.:.jTk4&.......?./.....P...3.L[..Z*..\LX....9q....f.2u....b.D:Yl...UnT....,.....U..".o>r....[..........7.......v..{E....~...._$.'`.D. .p.$ek.......K...a..Y../+g~.I..!" PR...`Q..5.z-.b#..;.m..!..7_....v..v."....7......s.aC.i.......$"...1b;p~......>...x..Xf.{....z...u0.r..Y5.o...6...k.>.....G..f.........L.ccV+....YK)JL..`....H....uJ..d...\....{$Vt+..E.z.D....4.;....G.o...R.........f.A....&.........c.......o..$.... g..R..9...n.&.jJ..X.^tX....V.m~.H..A......,B1E=T.;.y....C.2..a^F..c....ZI3...m...PEv.#. '..G.Y..*.......`py..'...s[..iQ.4+G.V.>e...ce.T.tQ,N+.b...ib.).pL=..4?VZ6.......4=..v.<.o.W.K)S.mh..Y().QyA!-X.O.:.[.y-...a..>.Q......@.WaX.$...3...SSw....r..../...s.....o..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15862
                  Entropy (8bit):7.988088065549022
                  Encrypted:false
                  SSDEEP:384:9i834fsfx/108Dp8DOC+GURkmkztdCgMl3r5e5fBXY:GQx/5Dp8DOC+RRkmk5Azl3de5J
                  MD5:51FA781A6F1DB873E1A2624EFECC00F6
                  SHA1:5E458C4A58ECA3B706D3D3292285BA247A60710F
                  SHA-256:2F5CB6430738E2E8E7998A4D3E04973E86AEDE8733686CC2754ADF8170FC5B8D
                  SHA-512:211FA8F5D6EDE1ACD14075E632E60020B7A332867AFA34B567B706DFA0047C85AC3A061814642B896248BEBE9C8E4ECB77B03DD722AA44D5722F468985186C08
                  Malicious:false
                  Preview:.k.P.....L....B.TXc....>y.PJYH..C8 z`X..O5g.94....QQ+_*.<.>7...TS..Lq...WF}.g.........].........%g.x^H.h.)..?...i.wC...z....4..99...N.+\.ZiCN.gK..AY.l..7.4.....L.G.Q...t:...7.9.v#@Pm..K..b.iy..p...k!Qr,..N.>8....B.....{#"...~.|X._.F.+..6k..}.....W*.c.....L.....4.6../.Rj....3O........id...Jyo.J... ...^h.^...1S....B.XH.....%..8....%.v|O.Kp...&}..Z<M.#`.I..KB\...^w-..U8..O.2.]..)mdq..w.|/.....}.9...(.i.u..I.W...K.z[(..d.Y..s...X...M.Q..X[.Y....|.."g..F...z...2..g`.o+0..?..?.N..@..T.+$._..~..W....]....-..l....H..<.3.C.._0D3....#D.J)..k..A.@..e..UP.v.Y.!..j1.G.....Z....Z}..*.&.-..D....$?.r`2..i.g.....Tk..H7.FG...gX..hn4 ..Q..:..t....a.....[/Dk.1..t..{.]4..=...al.$.y...7+E..D.S%mP.q.......4v...[.gI..1..@ Up.[.-.r99`2......=`.I...M.....DQ..........#n.|.Q....'{.P5o....h-{Fn.[fvn...M..Y*.E.s...$."....I...j.Y..[....]O.J1".h.....u..E.R.e..T...(...G...N)j...l.....4$.r..PS.w.Qd.P;....]~Q..s....#/.#.......,.u-.u.T..j.......I......!,+.l.cg...K.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):12956
                  Entropy (8bit):7.984456826651595
                  Encrypted:false
                  SSDEEP:384:91ff/s6Om0zb/SjPrK5+uS9iXf/8cpyb87:Pn1Om0v/ST1C3IK
                  MD5:80299581D8C3D35D85F9AD0AD2D3285F
                  SHA1:7D9EEF1CDB945B6B53354BD050231716ECDFDE38
                  SHA-256:90D231ADC31DB3808D1121889BCCD440904720B4BC67F74414A1EF951A210537
                  SHA-512:B52CE4031A99DC5A6B06428E5E8FB9F6BE45C286F196C032F2F2168ABEA979CCC9EE717DDB65168E0EA2B5A7C9D80AEF775556896A64496D0D3381D895778A1F
                  Malicious:false
                  Preview:..W..\J.V..&.Y..Gh..=.1q^GV)...S{~..X..p.p..CiQ...q~.*......m^..t#..L.Yo..#2.....H......N..7.9...:....g..:......M.W.O..v..Z6...U.71[mx.Bq.....4...}~..1p*...P.^....f..^E....X.#...7..Dh..C.i..{-..A..!u.C.......j....x.?...?...c...6s......GN....EF..pj.........O.#E.._......r..r.0.2\^9.%.b...x..........cp...[g.m.2Gl.S..?0n.........J....C....u_.P...6c. }6..y...v......V.)...;.mp^.0~$.......5..,l.Y......>..q.z.I.@>..U.9v.._.........w.@...8..]l..<...h.B...qyW.j....%v..&5.......}....W....>...$'.Y.~L..N.|.lo..O.H.\..<U.,...."....\.H.!...o.!WrV...S ....l0A.wh...M..`b..q..........,.>...f...n...=8...T..;...l......*..x-......{..........S^.G.....{.cJq.fg.<^.+...].RK..Ku.Z..9@..*...z..[.@WaN;J.p.>..S.O%k....UxgI........,..9...&Ag/O.2......{....e.I..C.'7.g..^..J..Z)@..............L.=..)z...;.;.....x}.R6C......).L.....b.t.....q.......=...3"...qBf....1.z.4.b_.-.r?.;..+.-s8..}E...T..7.<....\..U!.,............R..W.{!0.hd#Dj..^gKq..7.X.|.R....7O..-wR6j....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4765
                  Entropy (8bit):7.95743911418181
                  Encrypted:false
                  SSDEEP:96:uh7dPY6x6mNya2qZSFnrLfV8IrZiolZ0Lh4E8z7iii5kxuYq:uh7Flcu2qsFnrLtvrZiSZSqr7iii59
                  MD5:41237E08D2A6A34E58357333793C167D
                  SHA1:F809741B79C89598367AD969B0AE2722AC4619A2
                  SHA-256:1EA9C4C3A959A734A7D5EA463BEC2B82B7056D1F8247F2E534033DF97B4C7737
                  SHA-512:67CBA103F8318524B0EA9B4CA0A3B77B0D85BD67AE0DD6AF6FB236CE98FF7BD30ED3D88AB9B996009B07540DD75099DBD206FE822C5AD4094449DCCABA1487DE
                  Malicious:false
                  Preview:.'\-.L...R................."...,..y*...qIw#....7._......Y40v.........`.4....y.?..x2...:F..#).."^;#..R1...g..j...Q.h..Y.....~.(....).....Y..Z[e.....d..c0..0.6~K.m...lE,6'd....S....0A!..e0.C..4.....+w.|.......v.t-.1.}.O.w.....;.+..(b..p'...Q.+......vS.8D.+...X..U..Y..*....(1!...R..I..{.)!.wE.5%.....eF..<.U..<.U.or...b..I...VYA.h\....Ft....N..S......S....4.F......[.P....S..o.g.(.j..D.....G...|<...D<P6.Ah(......W...mv.<.%.%..J...I....(.4.c1...O["....?6.G..a.%...+N..W.U86..$y......S7.C(M...O....<:l.<.)..n%Ze..)H=F....cvAj....j.O.'T..F..b...PR..s.#.8.G3o....Z .d4F.^_.&...D.T.......E.F..=....>........v.'%+..W.`..^..V.Q.d.L...q\.............'w....?3~...........i.V*|......7...D.u......n.{.C.......m....]%v..Sd.0r*.Rr.....g...cB.."Y....5...=z..z..f....G..../8n.2\.3D~.%5.........#.[@..HV...3.Z..'..9....&W. C..$0F..:..&..S..Z7.....4.c..4u~0m.k..{ E.#N<M....f@.X.v.....U..8;'.3.q...&...p./g......w...h.^TZt.B......:.L...p.......m.j/.....^-^...|.l.......ac
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9959
                  Entropy (8bit):7.980864472720892
                  Encrypted:false
                  SSDEEP:192:llrhSlAOQrHbo7rx5mI3411sNJOfJTPC3W3hXHYrQVpmqnb/xQygPlvuMtj2:DhSlAOw7u6u4fJTKmxXYMV8Ubx0uM
                  MD5:EF988DDC08725F6D8C7986E43548D26A
                  SHA1:76253E0CC9B71C159737ED7D3565FC10F7EF25D3
                  SHA-256:D512954205A7D617F7F41A5B2053AD73EABCC1E2BC0F6A8B7FD6C1E3E2A315FB
                  SHA-512:10AA071C01A8B631C715B7AEBDAD429C2FC95A2CBC251C7E990FE16AE2E3920F0A93E38AC8D9A73D32344767D269DE307285C48DDE6CFA6E2EEED2FE586DD481
                  Malicious:false
                  Preview:_h.T...".p....0,.=.p..%...,?.......<...K..&1.......l.e.5. .?.}.-FW...=....Y~...@#...W......q.Y..,.V5"I.FW..P9jW.X+...a.h@.@....2.!.1.!.....k..^.?`.....1...9V(.x.u=*.........K...R.A+nMK....".L>...#V.$..7.&..G."Ss.>..43E.(...u:.....`..X..UL...U......y..0.'.#..T.Fn...L+...B..;p3f>...{....y..h~..c..x!.#_..QS`........-.. ...I.s..U..a.K\...N.l....0._.._..'.Cy#....0.$....P61WMq..b.z...[x<@.<%...L...#!...bB..`4M...Zj._.p]...4W.P..pgVz..)./|l..H...aT...t.....G,...".%......P.A.....I.b.7~2....@ .D....PO.....~......1I.GC.@.%.M.mt._..........y....(sr..K#$......;..F..%.R..Yw....MV..\.<`.\[r.....RQ...0..\...!..f+_E..tI.&Hx.......R...^.J.(.E.......u...MI|.....'.[.Z2...Q.....:..k.a.t...@.NH*..$..lN>..<I......i71n~.....kE..0..D..ld.\...}0p..E.....y ..>...{[.Y2J.F.V.....jJ....L\.....T|....9!".D.C/,....[..^c.'z..P."bR.. ....X.Z.K.{..B+..9.f./n.ue..>..;.C..*..H..K.....RrL.+..`v......'..2..!.~.......|.._?..D...j...gE0.8s.........d<..U\B.....?.J.p:Gb..c.n._U
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9634
                  Entropy (8bit):7.978999804858019
                  Encrypted:false
                  SSDEEP:192:/F74xw0XMHOD9u638BYUMWfxxSJqq/h/bZC3jE/PK8:94W0zIFqsxxSJq6rU43K
                  MD5:E4EA0BAD74F02BC9E29CCEC985DFF1D2
                  SHA1:0CE677089151CA42D6EA189AB1F552C9B7D82D0A
                  SHA-256:F20C0D1CC2DB06E256524FEE2F3D6496672B72EA0E7702759C9FF5829EFB5FC2
                  SHA-512:0A130B5B0AAA73A69BDBEC4E92709990F4851157168AA7A2DEBF77FA279D7AF46B6AFA8F42062323EB0654C8A87D13CFAEE5BCBD1283ABA8C730159A806052B8
                  Malicious:false
                  Preview:.uO<. ...Ims86...0h.j.n>b+.....m....^'E..-.`..2z.F.([...@.._...\.L&[....F..01..P....fy.....-I..b.7.N.4"..G.u..."../W.'....~nW...7UV.....Ynk.U.....9..=/z1O6`..H.......L1..q".e."nw....pn.Qe*..T.$C..eH.....pi+....*....5....1g./bo+.....o...O.rt......,\,.,D...+....U..g.\.mi.(..E...g..?P..W~.&AS.#H6..u..[.d.J`.%9~.~7.. >.......l@......X._...w_L.@...,N.....-.}\.,...9..u.....Z........S...(...x.h..K..8...? ...Y../..V....m`1.l..S.P..T...k.f>.'...}Y..T...ZLA.2....e].Y...E..}G..;.....3...F7.Mf>)=.....K.Y.....0...A. T..f.#..lw...l&........:^`.A.Y.Z@....V...L..Y. 1W..\....I[,.b.&.o.u_.z..0"..# ......X.........ZA..;.)..M..A..g.W\R....3x8...,.T..@).'..'_W).....n...~VkIj..<..\../L..j...$....p......j>s..{@5]1;a......E!v..X.9.;....n...">q.;@=.b.{P.u.B.......`.G...bZ.R...l..L..a..K...S.7.wA..$M...[..]..S...J`..Y`.=.-...v..<p4.G..@...{.t.v.......4..^72."uY@^...#S............U.],...b...B/4Xp....sn!v$...[.C.d..h..v..,&.j{.........._.#>...S..Z....w.+...1..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9784
                  Entropy (8bit):7.981783681523505
                  Encrypted:false
                  SSDEEP:192:me86AdsxJT/1iJjNA0g/h3mfh9s9/Y844nZKizOWt5FlvGsLV67H0qppgoK+r/ht:mVDWJENA0g/h29xeZK+OMvHLVxqIoK+N
                  MD5:C66662C7F1FB630C09A6C655E77AA1B5
                  SHA1:59096D87BF00C9003535DF16CB58EB03178D2C02
                  SHA-256:6C84EE7FD1C73DB763049E26DC78682F47FC1EB9933FC49F06E3E485CB85F935
                  SHA-512:574AD886C2F82B2D66F67C1D8C6684EAB1DFE1C298C0EFAE2546BA509A9D1B5336276480ADB7E1BE025AE9E684F0E6436F07EB922BBF1251A9F96F4FA0CD03C9
                  Malicious:false
                  Preview:.g...Z.).S....n...@.w.f.[g.9LJ{k~Q_WR9.M..OG..+..'..........'&.....QX....=F..f...bB;...a..i.z......uZ*'.bC.......\3...y.....P....N.,.O.E.N.XL6....6..8.Z.q=l.*.h...<l......A....,..c.9..`.7G....[....:...L.\Zj..C.o.i..'..).r&6.~;..[......9m....BH..~.......T'$>...x..09%..I.E...."iZ..1........g.7.P....9...M)]y.i.vM..<S|......=Gr.{E..z^`M.r...D.)..".(.ks%?..h.)..//...7..G....'..V.v.'.....K..gl..z...oE...*.?..`.....j:...<.m.D.t.(.>.b.i4..I..0..Q~..._.W....+_...,.F;......<0e....C..(pmu......H.R...._?....]...,...1.*.*.v1.H..M.'?0.]+..K.."}...t.........d....Z....U...&e%j9....%..5&N_...E.e....O..A....K.T.D6E.[,M.?..*..wO........DK..`2.......c...3..2.;[O......."..x.....[....h.=.#L.s~.?D...I......|..YU..6..N..../.&....h....Mw.0...}...#.......E...Un9V..99..&!.n...\...^.0..qn.;.l.....i..t...._.4.a.....)......'...@qk........w..>..s.d...g..J.0o......"..@|.ri....8CD.Z....#a-....j.d.@.h*.6!...dp......W....!.A2..o@........X&|...p.S...s..`~S.f..%..x..l.^"...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9367
                  Entropy (8bit):7.977164202656162
                  Encrypted:false
                  SSDEEP:192:3EpA803dZiawiBuXGDYx4ceM5fxctLiz3AHlqG4e93oW7/7vZ3qblctQY:3GA8zsb65fKLirolD93PN3slcX
                  MD5:D6BC3F6B924D71E5C94610730A4A6D1A
                  SHA1:A57833D4E5EBA95EF3A31C4FC759FD6E3E849FF3
                  SHA-256:38A58D92BB190D05A33F0AFAC1FC8A342AF505AE3833598FE01060BAF696E1C3
                  SHA-512:1AE7EB2BA5ED13F0DEF70356E213600303DD15483A077150719992A2145CF2FCCF195FF529135E11A80462A0C9BFC63006BA2975F9320C0F1EF179B229BEF65D
                  Malicious:false
                  Preview:^..T._.pw..R.'..(..@..!$^.)O...lv.h,Zl.6T.F...LL...s.-..|..]-t.........c..m.(.O....U:.Nu..~..)1q"2.aL.....?z.....A....e.+NFi ..........Y.......n..D;^.. /..~....I..Y....l..l..!. ....8.DjCG.|F....+j~..FP.....n..l......6..e.b..&/w.@...B......o..1......`....H%.C.04.....f.h./v....W..ZB...y......g.]..pb<....c....f..-<....+`......,*.l} $.p..&....eJ.-..)e.......{..,......]]5k.+...>?.WQ.1...JV`....J....=.Zc.v._(....,..=.5....p.../6{.((..I...D..$..g.J.p...c$A.uk_..+............i.{.H..u..muI.......6....H...v.cR..E@.,lG....}.sh.x.RE+$x.....z.V..A...P..XW...j.-....<....F.....3...<l...V...(_..A.<...`W_.E..~.$u.K..X.....f..\N@5I.I.n....._.a...ek>(6.....+...b..@`...m)..G...e.s.v..`Y.....).$.52?.Y.-Tt..D[+.=/6...,....._.,.....\.......[...(.W.N.... .Z......v]..G...m$+k.4".H....j.0...KL..T.Kl8j..#.nq.<./P..]..f..k.@.#!K_l.0.....x+....'.!d......*....I.@L..............G. w.a-.8...K........i.{.;...r..i....(./...B.$k..%...G..]B.;Z.....e.S..z....../.Z..;..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9775
                  Entropy (8bit):7.979894338697051
                  Encrypted:false
                  SSDEEP:192:pwE7BRDwBWzjfl9cvXH7nfg0W2QX+IIpvm3O5Ex28KqqoXurepPuF0Milqmlt:+EVxwEjfvsHjfFqX+Ioz5h8qcuIn3l
                  MD5:6C65605C5FE6E298686365D72CE4F939
                  SHA1:5BB4FAC8F30EA04885237E9D28DD5D634827F836
                  SHA-256:DE3F18B67E8A8E51DF0612E63E25DB4E9EDD93D06BAC04F5BE4DC131FE91D9B0
                  SHA-512:C3889AB82E37B99C4AAD4A0CAA4242447EAF7500148AE925AA1D0DCD22ADFCFAFADBD727E355D6CBD1AEDCDC79D3E43ED2FBA84EDCBFAC40781A4B3E18B77F34
                  Malicious:false
                  Preview:..r...Y.J.Ao......}...rO.|Z....7.....z..TD..s..h.Y!Khug.H..|Y.kR.@Y...G..B.=...Rq..+f3G....LqN=.*'...D...(..w.h....._k)F....D..!Al....C....7t8..bR...QI.%N.........7...Lq.x..lS.v*F;.YDM3..`V{ 3,.6..y..AZ.'U......a.....o.a...O.Z..Z......IF......m...I.....h].f..G<.....~....)...B.81dT...B.qU..h=.....o..l....C;d9.ay.y>K....!.</.@cfd.C.X$.&.....%1..r...+If2...".F..N...}V.n.u.3LL......LG..]Y...+.A.i.$lK.\....T6.3\*....^.....k....B.1H<q.....2.[..ci@}5.......P.Z.$.H..zmI9.r].\.s.B. 3...V..U.FU. ....Q..Bg-H6.].37p..xJ....[....yEf_...c.)5.X...I50m..9......J....0L..}.s.e*...T.p.c.!o...(.pa.u{..B...Ev..t%.......X......0<f1....Vw.....jPX.-.....;.0..d...h.YV.a~.:.....YUD%..M..T......;.!..O..N...%`<........n]u.8...D.V...Bj3..l0..96.@.^.Z....O.O)..{Q.......}.T..<e./Po...|.v9..` ^....Z ..''.!.u..kz.l..t.z..\K.R..U......Y&.4.L..%.u....x......ET.8..H...(6... ..Rw.a.=.L.}.1.p_....cd.....p.p.=.t"G.Z.w:.hl7.\.9...."0K.w.....(...*....h..OW.}o..........Nd/p.-`6
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9647
                  Entropy (8bit):7.9785063081747065
                  Encrypted:false
                  SSDEEP:192:a4WUdI96IEBm8T1jwincD6jp3ZDtNF7nfXWKhhVE3sBPYxPuhn2GgskVVfopCsYz:JWsI96dBNT1jy6jpvfXWYhVGsRYxKeVx
                  MD5:0712C1100F312CA683E105ECB9D997E7
                  SHA1:D40795F6631DC4785393DD9BD2FFF95278E65438
                  SHA-256:E45FA3EC34BC55C7739D37C461062CE96098B09B0A4ADDF3C1DCFCF7D6EAA4A4
                  SHA-512:AB16E0D8D7BE3BF66CAC3FBB34E03EE8DEAD877F795BDE168A96B7C9DE49DD571D6748C77039C1F1EE3700A0C57076BF3D6F1B6F83F905FA86FC24F3547B90F3
                  Malicious:false
                  Preview:..L....<.T.....V...[e...k.<...t.Tw...M.ld..a.-...|............F...]g]....).H.R...6..?.).M.......uv.j....q.?Dx...6.......6.i..}@..^...+$. f-R.Z..A....4........Q....... . 9...W..M...P.W..Z...o<...'.....+..6>.,..8./.L._.U..PTS...I.>. ...]..._..n.k.E.l..D....~.....J.SW......l.}..h.|.V(.C[....H....z...C.cj...1D.= .J.(..6g7..4H. ......W8.x..g..#.@.0J.N>.T5$$....d......v._...V..~6.d#d..5a.EjV.>B..'..T ]T:+&..t#B%.}{i|...jK.Nr...?.*...h...........xa$.wdN'u.jRd.X+.7.W......].A.....L,.2(...[.|f.y...1&..+..0.8%|V.B.<.....9..r.aYE..L.s.h`....7.W.*X_Q...3h..MS.......H....Z...0.c8........K..q..Wj..A....i...x.x...;....W.F..Y.+;M. .|O..ku...+z.h.(.{^.n.T......h.-.+.....i>..G.i4.h.tU....u..1..|.......I..E..Z..M*..^o.B4|.^..........34e.o-....y...3n....$.f..z......_bt...k..p`...x.g..NA..o....<.}.*.....0?.j..s...<n;.. ....|.e.Af.V.....5....'..ZJ...lo.iS.M...<.lM.M..3.Y....F....8...R.7..~..... ...Bs...4.oD..|..v..ty.x#..*5Z!..p.2W'b..Y.D.9a.9Y"^
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9637
                  Entropy (8bit):7.980119223393221
                  Encrypted:false
                  SSDEEP:192:jVXFLqEKy/CiHY1jCbFiQZVXSeBSo68f+1I90kXpim4usuyFT3:x5qEKy/y1LQZVXFo8fLOW4xusuyF
                  MD5:4CEEFBAC43BC1B749F5BE3632EC33ABD
                  SHA1:55C7C8C3A4AC237DA30084DAB1EA6D00FF9F18AB
                  SHA-256:57050866D3190AEE3C57462BDEB3E538061AB65B95293836E7A2E866FDB9A911
                  SHA-512:1EFE67875C192414D1D2880D29C4DA788D0BAB7715EC6F967978E44F024C5B7579AD33B1CD3C178095E4EABC5AC89F648D1F9E60445C42A7D71945E96846CAAD
                  Malicious:false
                  Preview:.F..f6uG ....t..j.R......i^...I....&......0!.3.._Y..B.,.Ib.`...oQ....x.Wv...Nf....V|..e5...Oj.....g.^.1i.....~...+./.........W-...A....<B......?..>f..........w.X.G.+...\q.Xo}Y5.....N.id..x6.^Z._...\..X.{../.....T^*...;.6.n..,.Z....{.....`.s.?X...A.&.m..M.m..|n.5.W..ko...vn.9....o...bpl.m..x5.F.].)Rv..-[....g;J[.<.....;.A.'..bNO....|*..o...@.....F..u.`..V@.Y..a.(!..F.2.u.aKRP...Rg..M...h.?....Sv.W.V....T&.w..l>q..t..|0.^.U.P!T...%+GLd...|...E...c...\Fb...y.N...,..m.`..V.........V..W...+..m..6.%/..eR5@Nu........)@.F.z....+..N..H.A.6....8....A3...fX;..K...g..j8.^.<...:G..F.p..).!..~[.|....U...........Y....}IYC B..r..*..i.-.X.V8e..I.,...|8....SR....._.u.0....b.v..cJoz.......U2.<.J.{Q.F......Z../..L..?`.aD....-X..3.o......X.<4...Y.O.*._a.m....DE.Q_..........L}Z.@...x....c.#&..s.qn.,.=.L.8m7.$.N.0...Fp\.k..4=V.JK...c8.;..q.d-j..=..H0.......j....:^.....p...G.9.}.`........Rz.v.Qu.r.....0,.x.iW.x.E..3..?R...f.W...a...E...3.a.[......G......jG.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33414
                  Entropy (8bit):7.994632351959278
                  Encrypted:true
                  SSDEEP:768:v2hOOKsXiPKxAoNvqw+uEK2XIT2jfc71rodCdLkm:OhlVyPeNqlkucTl/
                  MD5:70DF912EDE8F94513C1FCDAFCB1D6512
                  SHA1:FD07BC1241CC13487BCF1EF45A21D9CE20AF5093
                  SHA-256:D70C84EA0B752CE35F359927474A73F144C9631DDF9AD5254E5FE9980B44D5A4
                  SHA-512:3FBA8F970F20C5FBE68D88F7C37732EF44F7F51E0F6731D6568C808464B1ED2C1DBE2920295837E66D8EA44ABC90C12A7D9B3B7E840610F3DD49C46816464946
                  Malicious:true
                  Preview:..8..5....vt:.x..]......f.m..f.`.E..% ......ir.qVll.*..11........./.$..vC4.7..W.x.....O...&..=..:.. .X.....G..;.pd1I^.t.g....gCn..V4.F.d..eh=|..L..[t.!..x9...4'.m...`a...%.|...u..|[1....r'.YS*Sz8....v..I.}..w...N.}...CM'..s,K-..w..M.p..6-.I...F.{...5N..<:.?;l*Q.ru..g...s..I......yZ..-.........j....I.oeX.$8.4N....f..RI:....1.U.P..X..UD..[._..GV.....m.3j.yK.I.^.$...A.....6iK.<|...=.S.H..,.W.M...,...z3....y....g..Oc.)..f.........4H.0...M.NN:q.}...;..N.....B.,[J.k|.]}C.....c.....].,...E.-9...L.....Y.....>........d.H........XM ."h....aw....|...@.I......s.Pj...Qn...._..X.-..s.....<b..vqX.b......,..Q....D......:D..{.~[._Ea.:.8Za.~u...f..M.:..%..3....`u..a.$....P.d....2.. ..$...i.....=.^.{$;.q.}.f.R.H..s...1.....-....g......<s.....3_.5.Y.3.:...Ud.._......@.d.yD/.^&.g.I.kO..a....0>.....j6.g...>5.........2.........c..;&.g.....O...N...w.9.gc.6~UK.m..f.9CW.._......X9./..d..f0Bm...B.o...........|.%/\D.-.X.;.%z...7.gH.\*.O.W.."....O..4..zN....e/`..u5v.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33414
                  Entropy (8bit):7.994322031798362
                  Encrypted:true
                  SSDEEP:384:jKO4tP+/oSrd/TbILyExrDgbE+GmL2JroNw1cpLmS13ewsbHPDjn4zWsGZZY9rod:eagG6yurhluplvOD6WR2dr3WC05r
                  MD5:EC1AB64621B4389E04A9F33FF649EFBD
                  SHA1:910E16834F02156048B0399337BE0DC1A516681F
                  SHA-256:4446432539B54AE1C8C474519AD70C45D42D36D2070A79C3EE1C2D8FB7EE569C
                  SHA-512:7E6D64E6FAAD1CC72E876A4A1F4289803B62E0C356D8FDB1903ABB0FD713BE51D341CFC5148718D72502DA9C0A350B6DFB37031E3519A22D4598BE461BEC2E66
                  Malicious:true
                  Preview:.......9... ....e...~....X.......OU]...M.@...`..`..K"..Im...k.)$."..mQC....OH.^'m.2.d.B.@N.#e....6I.x\.wk..4T.k3.=...4}..d.......Q..&%E......A&..'Z....|T..}.7.J..#.W^.g.~V...>X.#.)H.z..>B..bV..b.7.f..#.p..u.....W..H... '._1!.......W.....>....jE;..4.*..?....B.=.U N....0@.=...2.z.:b.=..s....(AXy.C.Y..-_i.u.F.....@..G..3>.6.......`..,..`..OB..\c6...;D..G....8{.^...^D..s.N..N@....1..p..aR1e.M.k.bi..l^w..[..vR../v.h.Y`fy..e4r....o...G91I.....pMI.g2...k.TL...d.Ph..2mX'....h...h..m..t.9.....@.$r...Cn.^.....K@B..O..N.....L.w..f.U..@....#.s3....9.......E....w..dl...@...f........o..K..Su.o.8..v...W.....T:R.....y.UT.{.<.....0.J..Q'.hp.....B?m...N.A.Dqv..y.>..d...U.u....*..9lF!........*..H.E..........;..XU...S.t..5v.V....i....K{..9.....9.6nmQ9!.....%lL..C].@.@....z.P.C...Ie.K...t./....w...4.......v1.X".s_Q@%/u...>&.l...E..3....8.. :.$p.b.:.^5...........\S...l2p.*..k......qr\>.aCaH~....g......).Z.!..QaD/...S..,.W...i...kP....o.H.OK.Z..H.V.:.?.Q...6..x..m
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.994358244118574
                  Encrypted:true
                  SSDEEP:768:NvcRhOh3VVE2AAe87UEtVjMAD2B5azD1:NUUFVE2PeCbjn8aP1
                  MD5:D8899197DE538D67959EC6A143BF6203
                  SHA1:FD4B4875719D2EC0E598969F966681242FAD6D32
                  SHA-256:70275F0B96F38FDABE3FAEE415521AE1B2787E7CA7186F55077C018B91C8A9FA
                  SHA-512:9D87EA480FD62B43E6ED38F6E22C181C548B42E4E05D1189D7505B0D153E6B714ABC2822F2408679E9B8234CB607B2C65A260473AB5E855BD88E22B7C797E3EA
                  Malicious:true
                  Preview: (......6.9I1....:k....k........"....."#...=v........m..'[i1/n4&F..........yc....%*?.....h.bk{K..n.`..D...M6.4..4..U...;|.p..Y.N..):.b?....l."+.zZ.....,.7.\x....Y.DWo..,......@nI..d...@X.n.fu.5#j$..Z.=l'R~?..{....2...X..c..l..>.o=Z.........8.l......u..b.}....q...#`.O...t*..G.E!...+;..$m.T6k..,{m...W*.......u.:......o.h.=..9'|..`.....j.y..'.b..q.Yq......M.........e0.s..:...Y.=.Z..,V}.O.*.IT^&^...6Hl../..>...Q..._bv.X..@B8..O.nq4.1..(......RXg..G[j.KQ...Y......G=.N.....%l7.....9c..6...Y:.C.W2.......q.....9AN...9`B8s..=....r..R._..PDs.H..^..d.+}-..{......N\...+..|..D.r.....u._..5..+........'..)L...4.....na..c.^.b^.....b .i....y.p L..+..\Y..n/&...T.iS..i....5-.6x.L2~.u.........E......|$[...K.&.'Kw=.g..`.Y<=..E.p.....C..b."K..z...)9c..W..dl....H..vf...)i..{...#3...s].....^>U;.......W.1..p.mH..G...~'.ZK`Q.hk.].$.09.KYe<a.].k.\.0..(..O.;!.V.......U.)...3..c....L.....&.....!...x.y.E.g..U...s..G........{...x.........5....{..H.lD([...w8;.p
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.993667348026004
                  Encrypted:true
                  SSDEEP:768:FbmxdAun7j5vMyryIAq5ISkzkGV1W9sBHkSq5qhkGV:wjAKRvVrHAq5ISkAGAQHu5vG
                  MD5:81F354533D648DD6D5829CF5C0EAC701
                  SHA1:C917CDA85A74AD10B267E72C90A1F8F28821F76F
                  SHA-256:8A8239868A9FF4D374C386365E233903C647B423425B925DE00C2E1452BBDC5E
                  SHA-512:FAF635078E174399DB8022684A0624A012262B3E43DBA0CA89394ABEC593365CB0B4DCB0D715596DBDEB5A82546DD699A414AB08A9CC7BFEA76CECEA9C5203A8
                  Malicious:true
                  Preview:..(...........ok1.K.r..Z...9.&......O..uP...N...v..%<..a.....\."F-.R..w.KE...o...:..$+AD.......^......+5k..q..=..C.j.W...V.....v&.p.IW....:W....Rs.4A.rl+E...7...\..bV......K...o.....X..e..........i.@.m.X.....G*..t..s.Q...a.........2.].".>>yK1.,.a..7q.u:P..+...@~7..Q._...<.?.-..9.(.f+&..@.....RaDB....-.j.y%.jpMd...O..4.).$..2N..g8..d.n..d..t..h;.g.|....TO@..K..._.z.b.X.;........dQ......s..O4..8TT...1.x\D..o.....o.!.D.R.9~....b>...Ng.+.b.....V_.".A....OEA!.)......j..t.gd_j...&). ...iK.Ot^.....0sH..q.....cg..1.*.U.'h.......GJ.Q.......a.%1"...=...J..@. fH.B.........h[I.6=..@.*G@-........B..>F..z.......)..e.1..+.`o-.|.$.Wp..0. [x.....z....}.n.u..>g<P.,%.#E....)&..]^.X.^.....nk....2#<,...!..#k..mF.ZT........x....8:.i.....:..^.._.e.}.#....-..G.?.....)..U....[d....{*.......#. T....Zl...:.5..B.nc......5.:......OB.....v...+..7....'~.gE.-...!..1....\..c.&p....<.jO...(Z-..8..0.F.U..@..2...FG.zy....*1o..6...Q..s.7..CM....Y&<...e!VKQ.7o\.6..T/C".,
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.995761178781615
                  Encrypted:true
                  SSDEEP:768:EBHcZRXP2skl/T3nCWnJPyIttvu8zc7Xaiyadk63W2ns2Ro5A2:EBHcnKVnCUKIttGQcjs2sL5A
                  MD5:7A9735DE4CA4E7C210D93F6E6E95C4CD
                  SHA1:085128C2F6B56D3FD9D5D299F632FAA1F970931F
                  SHA-256:D4DB0AE748F445F99869326E3E5298BCDBDF45E64CBCBB404EC015039B8EB1B4
                  SHA-512:EE96524CF01A1687B8EE7E0C6EAB3E53342FB4AA47A4EC5497131F507D5513185EF0A32DC7C0BA7779280036782205C32C0F66BE616F37999017B8415EB07A68
                  Malicious:true
                  Preview:M..!....D...?.Z..m."TWU....L.aw.,.vhR?..%.}.9..~.R7;v\{.d.R..Z..x.J...6..............(...C....j....J.o.#E.i.hqw.Yf.i.7r....+.....[<.]..[.pEA.69..|.....C.g8+.a.<E.....J.3Rw.'..6.Y.....nH...'...Ktx.....lz..q@..u..#{....`Z....a).^..XZa&..4. N...<...a..I.}fIGN..#QR..;.+DKL."...0J.Zk..|e)O..MFJ...........TG...3j.Z]iR.BO...Pp.j.{_...X!q..)..%k]?.?......o0.".....z77..8.vC...t<*.?jl.w82..l....$2Y.Q8L...}....+jW....5....RTn..]..8y.F....C8..K\0.......S.3...%..8..0.............pl.....,.....;.bc....;$...8n{A..+.%...{.ZJ<a......*.O.M.........R..z..2.3.O..;.*.~uk.f[Dy`.............N%0......>.@....D.#Z.d#......d..Q...q..."N......E..F........g.f..'. ....7.:...p..K|e.8$.##....a.......0.!{.7.....6p.n. ...EyA;L...G.Sk..-[L..I...-Nc"........M./...&,".?5.$n0...Y.v....L>...?...`....iY.h...mq.j...c....EsU.M.a.G..O}.J....J.<].g....V......z..o.dH.nD..,X1.o.Q.e.s.&.o..6$.a.c.D..q..t.0.E....r-.....F.m.(J.f./..M@........bjc.w.....x.L2M...7Fu...u[.pUk.).[~......F...y.Z...JLS
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.9944353821323775
                  Encrypted:true
                  SSDEEP:768:KVsrAi5/HUQBeYHJwRIXKwZuFXh8UUmtORxpVrX+phRUQKSHz82fTC:Kmx/e/RIXuBiFJ+phR15TvbC
                  MD5:8297B453A446282A4AC511D2142784AF
                  SHA1:6AF6152054747522C53EAE2C1AC2FCED2C514A3C
                  SHA-256:1D541A1394EBE2FED07E942E8AE06B1E59560380A5596D2AF8BE0C7E1A77B4F2
                  SHA-512:BC2F1A038B8C63EFFC13BF7060343A1397D9EF764FD078BE75231B22F4688B0EEFA70235FCA1D6DB89DCF15061824BD663BF8878914EF74C3EC8F71A9A99A604
                  Malicious:true
                  Preview:U..U...KP'[.ry`^\$...^F........b....7.{..-tT.f.mj..Q.\(..$Q.f..oh$......R....6...z...ag...U.&.,. .i.....0{.$.h....w..f..x.ls.h.....O.6......0(*Sp.K.......R"....y...^....}....Gt.i.1.>I..z3....AD..2.E+b!.6.le.-.^...{:.../E.WW..3...e.wd...Oi..W....d.=9...ql.LLt.?[.. _....m..*.a'y.:..[k...#.......9.hY-......dk[0....:..C.@.....L....Ij....x}. 9.k..Rv.:.a-..........V.5..7...1..n..C.z.......O..J...;0-j....6.D.....z.lb.;..clO....>1..ibJ7....0.."..t.l..Mi...e..tSIQ..k...+./m..}Q...z../Yy..Mk..?Tr.BI.s{.w\..Au?s.T.a{.z. w.6.R.k...$42.0LX..,.Di.....X."X8xpTw2gn..6.R.7.G|...T......[..1...k...*g...vV.@k:. .f.G/y.;.c...."..@hd....e...v.V....peC.#9..nP..h.O....p.../......d....Z@.z{........N>...D....d...l........u/.K^.}*..KPKm..0...5%+....Y.5..<.F..!W....7...c.i..M.G6..]...7... ..f.....|4....+...In.Z..s.....D23....).?....be._,N.:....."y....1..9p....{M.....c......c..<........T.......\\..M....Eq:..x.....H.(.S.....x....|...':_]c.B.3-.*rR.....y
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.99479229242316
                  Encrypted:true
                  SSDEEP:768:lwTYvc77LEsgRW4lA+iMvdx+83f+xs+O98ypvlx/:lPc7nrhWx+8WqBpvl
                  MD5:D3BEC7607506569ECCF1B97E9D31F7B4
                  SHA1:FB0B92B93D601413FCB732CA77CF884F858C0BB8
                  SHA-256:9AFE91D82A578F310373A8E5214B4A2F6F3F74FC8C5A41B7D9DB0977A1CF19DD
                  SHA-512:6C9BCA553632A28F395F66DD459A283BFE897A3E6E4A3A9C1F9DE2CB1B8099D970B18C0201976B29BD74565FB0001AC58B5366C25EBEAAF6BCBEE4CBD3D6C57B
                  Malicious:true
                  Preview:....I..H.....O.0.v(.............`....w.:.c......%.n^...d.~....C....F.....?yn$..78...e{c.}R"..e..F...... .?..zOC.!f)...f.~..o.*...;.3}......fJ.a...V:B.I..odn.[.:.7\...qB..8.7..<..Zi.>|2..H..mJ).....}]......w././...o?#.fd."....2_u?.......h......^.p...I....(.....+.q.:`.xD..Jn........H.u}./.~9\.8eN.....S.4......nE.^..R.X....}..}{..{..c..j...D.c.@.......5K'D........;.P.4....V9X.....{.(..=%N...`..u.ry[y>.s..u.H...}...>......U.n`...t.&.()..EM.)E..... ..b7.....x.@ ...Q...y.k.d...B.Q.1e.....sh2..6..\..N{..h.1........v.w1@{..dg.,2...o6 ....g"N......~..vR....3]&...s!..1...@.I.t...l.A...u:rP....C..M...y...U.}.._...._..G...?...Z,....^R.\..4...[}......HR.4....5.d...$c..!..g...G6.H. ... X.;9.s.0m.E.......5{.....NE.tM1e..s..H.M80......|..Z....)ee..../..Y......~iS.......A.B.".......i^.0....^.L..W.`...gK....w..)......_[.6M&s?G..K...U......A..._X.t=.<.T%p.o.....q..U].:..#...^Y6x...Q.;.........k.O.....#....-HDj..G.....m....e..1N./.eN....0.&I..={
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.994152714440731
                  Encrypted:true
                  SSDEEP:768:uEtCT443ZCB702sYZQAaBNO1JVbfkkMCFkQTOtsAi:uMP+2XaAZJVbfkk/6QTO6
                  MD5:136B6968782780124352A8CF705712D3
                  SHA1:FF55CA59E50C4E2598DE54F815BDE3DBE53A6BFA
                  SHA-256:959CEA4D4418507D3752E76A00ED6FABC21866178CBC3B5B1B1F9FF449273339
                  SHA-512:48DFA299B4AD64E021249E344DA52D07ADAA71995DE8F778EADC0865AFE9A3C5C8F152E55E60E3AD5EE5E7A8C1E0B6AC58F5DA809D885DA7154DDDAE2E6AB8F4
                  Malicious:true
                  Preview:P..zv..]...H0"...8.Mo........2.."D.rr..U~.D.$...QJ.7.t}.2+$.0..(....&.f.......\..O.;..O.c.......j..;Os..7\.tgkF..C.CH}...}..o.XW........v.1n...>..t.....q...>U.......Ia..@.2....2....sS...P/.Ni...?>.j._......a..m....r.?3R:w.m.8.Zg..&jD.2....5].BN5\.I._!.w......L..ArU...-3...C..,..s..J...CF.....`..@...:.^t...F..U...P.).7> .gy...;....N...\..4.PN..\U.|.(~..m..-....$.<KK.^ii.B...:|.%..%.M.v...4J....(c@X8.....v,...W..bS.........7|..S...4.U.U..9...J..Rn.E.!|.......n3U...|.<.;A_.Z...l\_`.gB.P..i.3.8-.._z4.{J...(.).\.4r:g.....s^...Y...I.......<.8..K.!.B..K......R.0.$..T....."....v.LH..:..iB...5(..aq......_YA..2f._.(~.R.16.H$..V.rz....3.l.I...<......=..HXLjSN......3.....i.)..|......M...n`~.j._..-Mz...F=....'...X....8....2.8f.......'..f.Nm.{..oM.M"1w.....,.p.B...L....X.d0....L...NosS.s.MG9..Z.cy...~~&.V8...#....].~...r,U."Ib*b..../..."xB...G.=. ^..jhv.o...H.-..*6g.*.:.>.I..........~...(...Em.\l..3....e.q;J....7...fT;_x...).p.*..l.rg'..8.o/R..q.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.994227268237484
                  Encrypted:true
                  SSDEEP:768:Atshl3nQLktWhnH9/eLkRn2MWNuOKHaN50PQL5pybGR26gE:Ll3nGktWR9/ZkMWNuOwaVbvg
                  MD5:BBC718CAA118E2A51C35E77EE4484818
                  SHA1:C7EB34470DA48563EC42B2B2ACCA3246F7FD313F
                  SHA-256:90DD41D79B302B278382E4E5B572022DBBB41CABA73239ED634AE0BF9977D239
                  SHA-512:F7517873317ED1755C071506B43D7FE5D57137EFF1086EDCFFBD729DEFBD1A7F5411343901C76EF0D3903C37E5B9F7FB2AD4B1644EAAC2EF5D5CC7CC57920519
                  Malicious:true
                  Preview:..a|bo......3..nDK=)..W.W..`....[..T.)O....=U.}]....`T..u..<....x...D.....a..u....w.v.._..)..)x..?..~.......\.O...[/k..l...]Cq>.)1#..e..6[.?..q.hJ@IH.9...X.l..jU.G.9a..Y^NID'.e-.......:..$4M..f1.....^_.q.^.........4j.n.d.L.0......Y=..yo.lD.;...C.....X.)&L..*.o^..M.|iK....J.A......L.@.!.I.n.X..F..p.I.\..j...=...l..........2..O;..n7....F@.9...43...2;C.O.2 Y.8W.O...>L......?..i.....y.Z.x...rb............u$...e......C.T.o.o....Jq3#...o....7r... .u8.....m!.]>+..y.+w..M....'.......e$..?.....j.^!+].p.s..m...(r8Q.^.P......#Y....<|lw.Q.7...~.?..j.(..7..I`......S..DcMe})....u.9.X.(..q|.$....W...M..&.......l;./;q.}.4%....pf.=.|...$k.d.c.${C...\....o.F.S.....=4........{.G?....Enk.(2..3P1A@."..!r..F.U..'L.E:.....'..."3...a..{[B..^T.^...Hs.W9.........}..z.:......;..j".A..n......<...":u.6...a}m.I..4..5....^/.+.E.Q.....b6...?..p....4.).MM8..x.j.YI.H.R.).}.Y3.....Q}WtU.Z..m.........\W+'....e.,9}...6...i.._.p....M.....{...Rd....P.].`@...K.E..#Z.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.994479595096741
                  Encrypted:true
                  SSDEEP:768:p35swYwE1qgw52lo5NB291oRXnu47eyL2ElKsnDglvuvj/r8FM:pnYlJmnBz1RlDnDgtuLa
                  MD5:1A1416373E94DF567039897597711721
                  SHA1:22D525AFB79B077824211F22A5C4E9484D3B8BB9
                  SHA-256:8635032E58F3168DE60CE60A6968330BB407E16B0004A228644DC8C312339004
                  SHA-512:173B293902AE654A2ACA184A3F653CD5C38308A8325231A816755EFA7EFFCF3063492F894487BCD8CD20DF88D723AEDDB7AE61A813019483FCF69E37BA9F8242
                  Malicious:true
                  Preview:R.^..r.47..R.ED..G.j..<..4G2.s.^.Q.6.#.....1..$.....f..5cb..v..N...Kp.....!......X.HT.U.*M.p.e.i'.{.".I....].C.uN....J.......x.s.)>B~R.KI.....B.v-R#..'.*..?.d/....T...C.h..c.ki..1[....K*.q...#....B=........@..x:>....-..B{y.a.gP..oKqS.7P....=F.s..G".c....)..r..:...{..4wU.....0uO..2E!."......[..,.[>.(.Z%...d.<..a..\E..Q...kG....(.g...J..Vch.2.0._;..5l...-S.?.K.O...J....o.>}w|..W.B..s.%..8&$..8..S.^W.....*.....|a...(1.......Q../..W:....!..2y%+.|...[..{y.%.Pk....'...L.nB.`t..*....r{...].UF.........._..Oz....?=../9`.0:...>?u.'JU..].}..3L#.P....K.w..~....\...cK.b.s5..7.l?5.".!=..T.^.d..\6C.I_Ya.(.P...;.s.9...Y..K.SR.P.X.'P0..O]....v....?...:....kc.....NCv=%.M....'...<.Dz..ph..+....z..E.e../{5....\.r.Ks=..7iRz...&j..W..b@L^......E...@..k...".!Jo...\.N...L..r.Z~i%.i<-d...+[....%e.}..1.,U.e.2`...{2bb..2...U...A...m9...D...V....H.../..Em...mh.....U..W.SW.`1o.m.+W.`Ak...(38.;..0t...B..2f...vT..kZ..:S.....b....i.Uw..~8.... 8....j..<.ihd.d=(... .T
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.9941751576725135
                  Encrypted:true
                  SSDEEP:768:KO82EHY9g055CYNv5t0hoj3Yj93WH4R7yI34zI0WRVEJ94NAKyz:KLKgMCyv3WxGH4RO8SI7EJ9kS
                  MD5:7E913B9A52FE2229007F2136D6855471
                  SHA1:178D30A937D2A58FC63AA2D25DC5D356AFAC2A67
                  SHA-256:AC72BF4158B32E4E9827353826E406501F481898F03246DDF033E8E89323157F
                  SHA-512:C3398F794BDF1FCADF9E622A2CF4FC3EC486ED352BBB2F8A7B204C3189FFB9A49CF0D0E9D7D2A13336755654F6D19DB452E38DA71F9DA14BE6A2CC86D37FA01E
                  Malicious:true
                  Preview:..jR.......u..m..|...y-.;.0..W#.;B..~..O......0&8.&~............oS.Pn.... .l..~.?9.$..#_..#=...d...!.....Z8../....ylV*^..........i.O.d....7.tA....k..g../>....3/dS..b..YJ..K..k].#....L.......=.4..$v..a..<.Xn.7F...f...X.\q.2.......CZ.b....xD........../Y.t.~..c\.J&..h......G.FV....>.I\?../..3....b.y.>.(..:\......?5O.......;p..-..A..X~(...B......t... %..Qv.f;....E....^e.....h....~.?.v..............{..G.{1i.i.jW..x..Lnu2.... E..g.}^..>......O..N.e+wf$.Y.Iz.._W...e.},...c..$n..so.%.m%P4w....xo..O I./.0`...N....`4[a#.j_.a4...I.o.....G.;.~..hU.k...#..r....F...#.J...S.A:.bX.....L.Q...7...tR!.z....TS...!h..~.).......q.'.......Rs.t.(Y..3...O...vI..5.....0./....L...H#....x:-"ae.=..).r'>O.s.@J.1..E......."9..t....%H..\>..{.|..1.1..6..1.u.*.y..H...Q......`....e..5..}.8.si?..d..].q...|9_..E....".g......c=.K......Cd<n.mW.(......>...pPGB[.'..Br....6w...ob.{.....!...M...`.E.)S.....{...../.K.M..Q.oG.r.......m.L#.T...n.@...e>...bj...bdd. .P....z.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.994696814476027
                  Encrypted:true
                  SSDEEP:768:00khAjfFjCsU5RLB7ABlosxTRRCQ144KOrCTo03A9en0ybXD:00SkdmHvFC7dRRX44KOrKNQ9e0yjD
                  MD5:5265DD69B99B6492FFF06BFF2E64B236
                  SHA1:79901BC1CD90165E15805379F8637D12E8477CBE
                  SHA-256:CA2BA756C293349FC92D2BA0401CC7DAE7DBF69682AFC22C60827B8F4910A768
                  SHA-512:06685C8BFDB0C846BA2BA9C8D71FC71D4B83571F8C592ABCC1EF70BB9260D94BD6296F581FD6DEFEFE17B37656E41F55675F1C0287DA5D8ADF6E34F8CACB0BF8
                  Malicious:true
                  Preview:..e(.....Y .o......u..$+..i...U',..L..]....c...A..`F......-p...;E.W3Cm.#.H..7.}xi..."Z..w%.(rt.f.\.Le....}.+..w.z...ATA]..dae...=.7.-...y.4Z.....3D.;.s.o.?...lr\\/....p).}...5%..|.?....!._.....zy^v8Y..".<....C.tU..k..4.lu..@....584M.3NkQ)...n....#..x...i.+.Y......&{...=l..1..B.z.[M......J.8(..S9.bH....Az..`..v..3......M....g..p[,#g~.X(<.V.F.Mt0.,..dI..7..y......`.._...}.)..w.e.2.x..._k...KN.Hk.:..c.vL.M^).N..k^.8.....>\R.%...f.._B#*oQV........@F. .;Q.;..!.F..W.v.j%M.,....o=..2:.Rry.g....\..D.-..J...f.....`..=..,...`...;..WoJ..6.q..W.R..Gc.J~g..b...:3.#..q...?...L.@.....1.....9.l*`-..#..-@I'72.I2.zN..o.R7_'.Z.K...'..P.q. #...[0...v.Z.5.M...1..i...3+.......=.A..../c...H.>.";dH.p$6..T..ngk7.A.......pA.f.7xI.4...eV..."..b..IOB.d..\{..1+.H.IG..r.,...m.4..T..e^q4.2....=........z..Cd#.4,7"..7....$..........H0@..g.@...5>.9Yt;..(^..g..%......|.?E.>c..H%m..h..B...t._..J.V..h.....?.MWx.7.tA.L.m......|.7@.6i.jS.B.a.q.....a_.."n.).....$..^a.H9....@>..hx
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.993832476988913
                  Encrypted:true
                  SSDEEP:768:xzTu0Joy+RZndsR9a2F0dKxnRKhFy2q1a58ndE:xXu0yFdsq2fxRKhUP1fn
                  MD5:B65CBB573F113883DA9F6D45FE9ACF68
                  SHA1:DF81F3DECABE6E22AC276F9AD97D7C11E82083BA
                  SHA-256:8BCF85B500C5F463D6E9554963D645F9A3E094FDF67D18168F54BF1A9035AEE3
                  SHA-512:12460A691158D2AB340B34FAF9B9996B5F58EF2CC114B87F4E13C418A3469F7B9C4985EA78BCA1EA68F681D765DB3DEA30715978B8D853A2BD5CA980EC3032B1
                  Malicious:true
                  Preview:..g...t....08...i|'.....Ew+...heh.`.....?k.(........(.....lUJK..W..w....P$!...3%.;_.y ..m.}...J....I.Ih:vHh...l........\.ke..8..^Z.!.K.g......Z3....+_.~.".....v........M.L....4D......o^~.J..I..V...;t.}....v&vu@.[o.y...Y....GA.'...#t...:...P.tW....?.*MRN....B.g:g....yr6..).......,....m..L.S...x.......y.._{....^/......LJi..lZ..%.Lo.....,.u...AU..L...>..B...E.Y....X!..3..6B.X......]....J>8}._..}....".Id.9tP..:a..&z..T...UM...A%{.(.....@...c..e..#5.so.)R.[.....S7.db.z...8...#.n.^j.....3b..*.)..g}..g..D3.........x...X........Y{.).."...i...7&...{..N.......?...+. ..._5.._....n.. B.,..P..CU.5.W)...W.... .E....K.Lq..{...$.....R.%...s..F.P<.k...>..J"...].H.R..L^.....2.....b........!.i7..b%...^+Y.~....1..0.S.....4us.tz...>.qg.....R...1....0...zq.{...#.[.8....O....R....t.".........\ CoQ.0..}[....#.......+..|.......O.xD0..k.0.-1....u.....G.37.X24..K..3..O.........LQ....u@......_9]A?.......xn.....i.-j....._.....8$...Z.ae....Y...h...8I.B-..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.993998601523314
                  Encrypted:true
                  SSDEEP:768:MF0C7azuF4xV+lNSY9tHChTpTII84FX2zJOkWK+H4dFKCG:q0C741VANSSHWTtdX22K+H4dF
                  MD5:61D4DD45FAE70993434F2617184B1C31
                  SHA1:1EF3B6E5680E624351888307763FEA18BBBBFC6B
                  SHA-256:3B69475CAC535FE6E47356CC88466C4DF94FB012ECC0B1972F0390EB10A74448
                  SHA-512:A2AB39F96BE2484A27B6275DBD61BE3DD64FEB267BE378FE6521D4E7C5B0ED159F30A2DD52F7F26F24097C73D9D4798C031BE3FC7C67D528724E6C1F82B2935F
                  Malicious:true
                  Preview:~....ups.. b .Z..... ....r....l...D..0. .an..n.;..j...7...r...Y.V@..z$..Nm...#.9..8z...B............<?....$/.tE..@...l=.X...]op(...c..+....J..... .Dx.h....}|_{e..{...-X.I".&T...5'.M.h%......y|......fQ-.Y.L....%.....*....2.....I....%._.I........d..1................:..R....p-..ARn.E1...N-R.7..v.bM...Q.....}.L.pC=.6.N?.....&x].-w..*M....@.0....v.;x.....7...DG<.sq....YS..-j.._M..:../aA~..`g.@YuR7......h.B.m...Y.f.WG..wB...w....10Qv.OZ.2....G*.....r...q.U...e..yv........9....6@6A.....L=_......~L!b5pq.....&L.&.\.np..q...~..D)5...d...y,...X.1.;..H-J..F2.kz.C.....N.f3....`.g..........= .>....._..d...X51.'... ......o0;i.<.h.......U..!.....T.<....a3.Ze..Od......Pjm.0....vQ....{2...c.5.4.>'.*...C..............9....+.......M.ZHy|.f...m.j^....gs...8rG....i..V....`....7c....T/B..O...:..'...]i.Q_..<.......U?s.r|H..dRb#......<..n.j.....>.w..h..Q}.@+3}.+..A....*..#...h....X\o.Cgag..T.9...-..oa.'-4tqt<4.6.8..q26 ........|.K.P........8....iX..ai.}Ek.x?..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.994751362279215
                  Encrypted:true
                  SSDEEP:768:MbChQBOX3e6I/uCcdr59Wpr4IHptQWAJHhs/HCt9v+KXYDeW:MmaBOHe6KedTWd4IHpGWA1u/it91ID5
                  MD5:9600AD5FA2CCF32B7B78AB5610AB2AA6
                  SHA1:59B5E6293961482FA5A13E03B174B9D6AE5A525E
                  SHA-256:9E02ED0D17512E9C0FB5BF5C7DF33EBAE5E513774030E0B7360B0E1A908E8FD5
                  SHA-512:D7420BDD7FE10DCB31B9E2B79C02DAFD19F92DA28E1C37F43BEC8CF2C7C6E1D46C6FA1EA24C40686922A9D73BE1F449DBE33F3736718465C87DF45A985BD8435
                  Malicious:true
                  Preview:.O..[...j..[....n...*.G.'...C..Gv.H......1....<...I..W ......O....BWM..i?...s|2....k..... 1....`DI...%8.s..L)2...NH.$....M.x5{2)..M..P.eo-.g....7.?...<4.....$Zl{].Y.C...j.Qlxy.w\#OQoD...M.(.O..}.ldvjSV5.K...k5u_7Zf`.....d... ..y.t4.*.O.;..h;......I....U...z.[..... Y. ]!:&.....%..}p..JR..%..eG.........G.L{.Qy.D.W...(......K5..K........;_.......U9CM....$.%.k..Fc@.-...P....'i.".'.x.......l.3.V.;...6.. .QJ5...I...v..`.r..<l1....T...q..$..A....A.s.=..6...$...1..*.d.'...bs....'..\.....&d..c.A.E."vF....w{r.H9AS.k...*.$.t*.go....C...M..Q.....!..0...<.R.z.....q..Vg..K"xEs6|8...9...0Z].vKb....@..z(.m;.........2....,^..\).eB.3)..6..j$..?r.+..=...b.._..1...b.$..y.=.gq$&.R.*.e..D.M....Z.S.....1......f.....f.....!^Q).....d.j7T......24....k.D.VVF...4_P.......D.q..S.y}....1gP..G6 .MF3M..T...*J..2.S.5..e=0|...@J.U...0J...#.x+..@....w8..nvwTH. ..k.0.&.z.I.@k.4.jV."#.. k?#.jVE...bR0.u..&9_....vC....P.*8...2...~...Uf...a......-.,.3-..d7D^5s...r...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.99429450492831
                  Encrypted:true
                  SSDEEP:768:UWwYq0D6WyYjkx3VsuMdGFzN9j9JrnZqPZOly/kZ:XA0jy3xCTcZnj9pZ7O0
                  MD5:E61A52073360D261BEABACE4B2A585E4
                  SHA1:8CD9DD7CB00FBD27D2609603B299107D0E4C9941
                  SHA-256:C69AEA631F9794D6FB3794C85A1204DC17E4DA3A0FBACBE9F6C27822730F38D7
                  SHA-512:1F3A72F0596DC7881320523B82CAB85269AB3115C16A7DDB45D8C9EA6D674C363B670BCD2753DB34DF821C2AD571A4ABBF4D8E57F356D5CBFAE912D14C55A5EF
                  Malicious:true
                  Preview:7.S....6..E..Y.N8d..22.y..g.oY....-s..p.89.kp......fWe.B.......j..k...m....jD.U..4..H...:#A...)f........U..... WC..Xv...._ F...<..x.H?I.....|Gk....s..D...|H....w}...t..x.H.'....>..S..e........)a$h..2x.D.e.."l;.~..T&q..o..@O.y.Q(.4..` ..R...'U..5$..$..).).rC4.!.%.ys8J.....KE......`.g...VjwM..!.<.![.....k...Sc.[.p.NgU.M&%.x....\.[4.Q..V.HY.9Ek!....Qqj....yg..l..+HA....p.....=..z3h6.W..>.....Lz....).].....*..M.6..%...z....(..*...e......V.....&.zDt.rz..9!.8......0e=.L1R.w...N.0VKx5../...O..^....g....(...r.$..:.4G;W..Nm.}*..4].X..<'...n.4.M.D.....E.L....|........w.,(..4w.kuKN.SY.(i...X.|.o.......6.<.....5..._S.."..b.]..yt.;1ck.....Si....WBP.*...R...^W..{=....K..8L..G.W.O..Kh*~..v......k..Tu4.....9&Z..;.tU........s.U...W......N..(..V;*$4}.L..gG.e.[.F..w_....z..{p..d7.."..0....$+.)...N.......92?.W...aA....j...n...u.A..B@3.E....xG.....n...y.3^.).?,.-....<.Eq.v......0......QP.Hn.lL.U.../.g...../.E.+m.?D.W..#C.W-....=V._.4.|..x(..*....~.....<\.tV|.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.995485676758572
                  Encrypted:true
                  SSDEEP:768:0DSUcylW/HOwD08q1mlWJkBh3LMy0zFJvDRKJe7QpmyQTGsJZc2Lt4:0DSnysvl48q1m8E3NwlDgDwHrf0
                  MD5:F30B067301C370C5939244B62715A047
                  SHA1:F82366ED34C9DA73EDF2809128CF70E69FFDAEF6
                  SHA-256:FBCED0D65C00F32BD173ED555DAA8ADBEFEF8294F047D8F85DEE3C1C2F56AFA3
                  SHA-512:123D25CE65D58E6CF228BF5122A90D018BCAB87A92207F253C4CDFB62E33FB26C1DEF5FDF5F81C8065B2C729EE4426CFECEBCC81FAFC3F498DB74C4BC97F08CA
                  Malicious:true
                  Preview:+..ng.G........t.../..d..6.!n.I-....F|m....G.K......=s.gj...n<..........u..xG....m..x..l'x...!.{.....t8.w.{x..C<gr....6...F......}-.....?.Y...u.v~........t...A..s(.g....t.j.$w....w.....7jqJ.].!g....J]...'c......MA...:\.s.f~..>H....N..#.\.x......NXU...$83....z.......#..@..8F.j_..5..N....B.:..@iuS..K$>#..]...i.^.E..1.zp+X.!......'...|.H.@HTC.L..^9...b.......CU...Mk.hm.I.i.]..M ..WF.v.._ZO{.A."....1..(.N.D.........8...Y....h..0e..i.W.Z.?.B!..ef..".1.D.|9....1...&8......i........Gu.}.'..................f.A.A..K~..K...$._.^..`?.g.L....".?.S.a...AY...G..7.DD../.....O.....]...B.3....SS_6....&#@.OOb........i.zf.2.$ ...^..,..3...,.)X..JI..$.N.....r....ff.3f.....!.)0......c..8...['.B`.q.....|.ro.%...s.......r"......h1..d.5(._........'..7$aX..2J.X&jUI.....c..S.p......c)F....qv......lS.l.JM.@}X.fz..R....D....l.1.C:&.~V....=1....M...._.oY6.h.....5.Cv.. ....y|.).[|..A..B.A...s.#H.....lF..]I....:..Gm.(._^Z...G...k....L.C...#..-..k.g.?...&GF..g..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.99404098904537
                  Encrypted:true
                  SSDEEP:768:Ss/QF8ZCNXW5ARyvNL+E1tQ6P5NmFP9mpzewJhvvg49Ai9uv0nyVH:Ss/u8Z8R013nHmB9mpzeIvP7fnG
                  MD5:505D7A46F655178821C88B2A76A68C89
                  SHA1:19ED491AB057DE9A99FDC2CEA7D73B177885B461
                  SHA-256:21C004C175C1178E2F9CF813338E514DC5F1B236B43897323D1F508ADA7AC407
                  SHA-512:7A2F2B3C90C03694F86179052206E9EFD1A5E898E22C8EA92323679678A29B6F7DC08DA5F7A21FDC0EC9FD9BF96712F9938ED39529962F93B2C885526235CD31
                  Malicious:true
                  Preview:F.z...RD......NB.U...-dV...T....,.......+x...b.bsD...-.w.......7B.Ng..O..).+.].W".]c.<.$7.3;.yl.{yH`YZq......+.>.e..-..'G.i..."LHTK.\.. cU.....2..Q...{A[u...7....M.j.p....vDe>..{.2.^.6..M...y3 ..F...Ev2._....k.!..8N...:}..MC..GQHg:.".|.....\..=.G....I=T\K..c)..+s...[.r'eN..#...T.......$..8''0...i..K.....|..1J5M7....I8.?..!....E.7..D3Q|......hkR,BR..0...a.faz.....\....6V..c..-..N..\....a.0U1:.Ghj....U.:._..Y*....?.h.F.m./i$f.8..Ty..".gu...x..`........z{...v.?.K.-..g.w"......8.<.P......{@Mr).,..>.1..;.....O_J....$.u@..../.&M..fC..m$.0F.....!......Fg..2.....9..(....T.HR..j.-v.....2.....S......?,>F..45.o.G..iq...7x.W.1...2...C....i..../.7...>t.......d....D(H.a0...AZ@......#...:.&%al....3.2x..cf.n.u..W.Fq..K.....!...xXL..i.!_.Y.....#.#.:{.>~.?.......w....]....io.M....C..K....j...O...{r<?....t.>s.~.x..\..x........\E7.E.....w.7.........+....'(...rA..a.7Z0.._N,..P....H.c..#..>x.f.................B....S.r.z...E....Q..:GS...>.g.S%...X..x
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33428
                  Entropy (8bit):7.99392218158092
                  Encrypted:true
                  SSDEEP:768:yTz3FRiiHz4VJ9e5UKFlKcZxbnvodbfAzat31RKPnmcF/BGBRsjQczcYDv:yTzPiiH4Gje6xbnwdbt31RGmkQPczc2
                  MD5:1F842220712B335E12B99A8D73725331
                  SHA1:CAADB42B2938CCB11ACEE9815E2E4D0FB6D54256
                  SHA-256:354B810A24AC1EA916A13249D96D060F45901504A1B99501D2C493E601EEFF9E
                  SHA-512:9D36B5BE89486BC3498975F462C2C7264C7E55E33DC7297E49CFB356ABB7023BC320CAF1F53EF474EC68C346C365A0B1400E47E7E46C9A94D852AB2F3882EF12
                  Malicious:true
                  Preview:.....+..1'....s)..Z.G...M,..8.E.......U.....3...x.....r....i..(.;.(l.%I.r...*....xDI_..N.....+}M.....VC.{!n..;.g.yCUa]1.5C...#."_.....@`.[...K..,.hW..h..Fn..ap....8n.p.*k....W.+K...7Zl..>sg..B=P..-...DD.tF.<.k3}.[.w*.$.z.ko.."...;.b........v./..qs..8......@...zKm._f....f...Y8.mE.2..nC.......D&..H..LZs.....6...I.....4..y.:}.JK.}e..O.&.........cZ".E.^...Q)O>{..../`...K.Z^S..\:...8GI=..".MOI....7...2....x.....C.Yh\......?-..,Q{......e4....Lh6!i<e.P....d....SFC...]...k..../~..H...&.T..z.f^].@.g.....q)....g..S......t!....4.L9..c:.:A.nVd...`u.!..B...;.....\....|X.Znk....&... 0c.?..........a..J,m....Z....BbU.o.9v.i.|...f.].T..e...0&.xXE..S..S.".qB..Y.... ....%.Fs.z..<.!..7..X...\.-3.}..ShY.Y.....t...1S.B....V...C.....-6c....s..s/7d..`.a.Jb....:.cg......o...I..T[../....q.+W..T.Z.G.....+.;5.@#../..7U....O.z..<..q.;.0".AW....r.;..t.mP@.....2..l.@..Zn......e.Q...i.o.].o..1.X......0.T.....5.P.w{.~..*t.a.x..k.|.."j.~.P..X6...h..o.CX..D..&......:n.r../....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33500
                  Entropy (8bit):7.993991622186789
                  Encrypted:true
                  SSDEEP:768:/yCIowaz8My5uNAPbh20EUV88iwO3YzwCLjZuNF:687zY5uNW2H9uOew0Ns
                  MD5:29AE209EFD04C6F55D030C9D07FD0E21
                  SHA1:FCD8260581E1D2C779F088E3F828349F16AB1AFE
                  SHA-256:23A860AA6D8F69ADF9E66A3FC734FA13AD64516934B4289500ACD0578CE8AEDB
                  SHA-512:E25759BEEDF062D717C81B6B3A7C787B2A1720E6C63E94EB8DE98863DDA695D65B15777EAD726E08A10161ABF96D82D53372B7FDC20F72D8E58AB1E651F89358
                  Malicious:true
                  Preview:..y...V#...@..........K....O.k....A..n.....O...I...k..nA..QH.8....J........9.F.~...0..a#..$.d...ml.YY.7V..;.S..._=.xs.g*.5w....+t..AI\.='......[.....n..%..:.+...*...`...`..K....].>.c.p......D\......:....#O5.../qv.i6..Oc;...y.Q....@.t%.........g.....HK............;..x....M.=..o.3,.zF.......!..O....I..n.+.%.c.Tq...NQ......<.p.7{F...zvNw..(..D2...(.wtLe.....p..&qZ@/^.V#2...i}.w....".%.}.X...+....c..CN.F.....E;....D6....o..`,.....*...}.......qp..g....<6...s....-.B.......r'|:^0.4'....3../.p.i.._.#F........Q..&....3.....N:`O.A}..P3EeP.A.f@.<=N.S./.b..aC......._.`....d.T..a[...|.J...p..E..D&.@U........Wk......em..x.^....n....F..@.............1...?..c./........<D...........l....-.6....E..(2W9.. ...{.u...f.@.:.,#U.M5.Z..r]..m(.@..k&...?#...B)e.z|......h...]".v.1..Ne...%>.R....*x.......Q..7.S^..'.J,.....3.$..._.6....z.d...c.d..6..Y....-.U....{...k..S`-.+.h..5..z.}..~...&.B. ...'..N=.Ap.0..c......I.s/.z.....$.Y..KK...k.....\.f...5..p..'..$n..\
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):33500
                  Entropy (8bit):7.9944087516841185
                  Encrypted:true
                  SSDEEP:768:M4t+z3ybtydl989aU52uSg4yo/2WdwmBPrZwvoXhI93G9e/UTx:M5CAkayVSgFKZHrWv2hI93qe/g
                  MD5:ADCF8A0A3F36C358330503D951CC3010
                  SHA1:74E4A7A8E0C2A45110B4EE13C63E2F8883010AFC
                  SHA-256:3FD9C2BC0F5CAB225B61B027B4D7151728861156193BFEC8FF2FD5BE02FE56BF
                  SHA-512:767DADF51ED2FA338E1D9F7452AC1EFA824236B816CB07E3D8940A37B2C129AE04D592AAA481CE1849B747793EB7D3A59A5C9061E4BEF07ADEA945AC88124222
                  Malicious:true
                  Preview:.v........C..D.ci..)...s.XrI.S.g.s.A.cmc5!.uA.....4.........9V_.....Y.T!..dm..>..?D%..~;.c.6..w....N...(....f.)..G.n........'...h.:..{.>.\.0.p....djB...,...*..&V..#..$.2...,...Pw.!I.zy..1..Bj..rp..\.X..p........a...`.Y...<z-./qf.~..._.@.b8.].....f!.S......A\......h...@...P_.J......".........T.A.Y|.........^..R-.6s...RTN..R.].....ES...i,.......|..Y..o.X....;M.l..U.........~.S..)...........}."..&..0....<...d@q@:.4. f...Z.l-..[j..L...:.Y..$......+....V.....p.G...:i..z.....6.n.[..2..=.#...'....%.y..g.;Z.6..CT..z5...../G,a..?..=.F[.k.&c._-....-.'..'....)!..........uc[..3..E..M%+..g,...:..*..>.":.2.N...J.T...G.b.!.@..iP..........`.^4?aZ.{z.....O.......~V.{....l...P;..t./.b.utq...............:D3wB1..Z%E...R......n.q...'k4...S.2.E./JB..|3?m..fkIE.s....1G...Hd9.s..$#....JX.O.uz.%.{O....5....D..c$:k..0.6.R..vxa.....i.N.7vW.zm.Z.."<..K.b....KK0.a.2,.t.........`.;E....g..J.F.x.w.....L....b..:.#..a.r.1..n..s..w_..Z....bO.Q|4.?m...29"haf......w.c....K/..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):33498
                  Entropy (8bit):7.994019377816483
                  Encrypted:true
                  SSDEEP:768:KugDi3aBiurfXBf6sFYFakkEP/oEajyoslFlb7CPv5kIV:KuVqRrfXBf6sYpkgjyyo6WXV
                  MD5:4AB41C8E293899CB7C8006D1A371ADE2
                  SHA1:4976AB3B658F4E61B11D511B105EE316180091CC
                  SHA-256:25EC2DABB6D36B702595979626F0C0E1FC093FE7DBB1B476E6023E30CAFF55D0
                  SHA-512:6DF2DF4CA60286E2B7D406B1906D3D80D2A757C4095B5F9B0C1EA2EBA14D067D25FB09CEE449E6F5069A7135E10B221F41E685F4603D0DD24FA4935CC40E4924
                  Malicious:true
                  Preview:.u0\.L....w.H....iw...MI..>).f...1.......HW..y.....b..C...=....."h..k.9(..N.7.87?).9u.q..'(`n.d..-..T..x.G(...eFqC.q.z...i6.C..`.P...g.. Z..oRY..ZC..4.].3..i.h^.|.1.'...a....9...}Z.t.....9..$.6S5....P..V..(..0?W.;+..m)....}'OGK.dw.$T?...v..+.i.i..f....+>....l..v.)9.v....8$...n.$...i=...B...E..ul.D`..........n.....ha.G.E.B.FjL..&"..].p..R.....-...m.....~.....!R.2....`..5Us.....h......(.J.....F..L.U..^kU.......5.lbd.@a3....%.R....%...Z..R.Z..<..].j..C....=........9..,z..o. .C..r.B.M.>'.t..2qO.~j.~...:..| x.+.. .P9..]._h(.yW7.`.).!...K._'....,.o.o..4...Z........0.ag\.P.y..J.}..<..jr.z.L.K.N..^.4g.<..?.J..le|.k....l.C.\*.y..=...`]..\f.........+/..W.-...Jo...-.V..u.w..9Z'..d..p..k......jsoq5.^...........ww.c;<.f.t...&.).M...w..*#....>...!.).4.....[r.....tzn...DM.r.g.?.wk.V6.x..!.(RB..I.z.i......W./..^g..L.l.s...;...K.....Gv"2..5......`8..Q..;.....M>.....".....L....{NZ.R.t........j*6%2.H[..,....A.(Jg..o...T. .!5).....DfM..)..t...L.,.o.F..b.n....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33498
                  Entropy (8bit):7.994625274602699
                  Encrypted:true
                  SSDEEP:768:xKaQAF1NI3xtzVRzfc+CAausQeDiH0tOkdui+0jJ/W:MS1NI/z0+na/QePtOkck
                  MD5:070EB81C06A42E0B0663A67C611F6C61
                  SHA1:C39048A01D5354C1256D80B20F14D872A4D36A3A
                  SHA-256:A4106F4C13F355BA960C038781D3487ACA8A0B092D76FF66903BFB0CC34D384A
                  SHA-512:03E21B726B21CDAB2E747324EFB63CA3433741EFDFC26D7D7F1909267A876C7AF4A569B6ACA0CB2EA0B1D8B0FAD7E77C5B79F290DD567080E1A405AD98D7A10B
                  Malicious:true
                  Preview:.3.'.i_;Z...7..J..Ho...QF..ZP.8.6v...e..V)"TV[.].....0{.2.h]le....j.....:..;7.p....5\7.Xq./..+...W........s..d.........g.I.U..J......./..JH..t..+J...=.....oqF...)R..M.p..,=.......)j....y..iQ..x.....T[[...5.......~.VP....,C..zq..V...R.t..\W+O.S.m..[.%...HS..U.Vk~..6p...l...\..cd...Vw.X.....L.t.9..XWA..c...6$8...O?;...7..e....).....J.t...y.y..t...J..x.....]T.M...6..V.....Xc.&..83...U....L~.u...[....76......a..).A.Et^./.K...%....~|]....(... ..`..xC..\=.......}..1,.S..p..{..1N.lo{kv...ja.?..h...y.........}3.....Nw.^..Z.:z>C.E...>,{x2......C.m.qm ....6...C.A...L.0...q.P;oX..W ...._....h`..J..=?R..w.i.......<."3.?wAM.K61..\.(y.. db`....>/o...=.....G...@.Q..).T_..\."..q.Y.CE..$..5.#...p.'&...K."p.Rr.2G...6c...x....g.....5...x....WT...I."..)ll]..4....2c...9.|.5..R7QZh......<..e].Qd..Hf..s.....LN...G.}f&v<......*;.......2O..<l..c...?.DbO..EDT..?~zNoq`-.P.l.+...v"]..o...;.......(.......!.z...V..`.......=!z...oW3.....d.z...p..(....e;........@.;...+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33498
                  Entropy (8bit):7.994294642030688
                  Encrypted:true
                  SSDEEP:768:MJ8ykXIxwc4MZx/WJFf6CAvyuI7ZQ3BZ0o:MJA0wO8ynTXRZ0o
                  MD5:149E53B4C2D451ED57938DF901F8E0F3
                  SHA1:F2748F5B7F99A63973EE5F553BABCD9012CD4C7A
                  SHA-256:4E367402F17A20063F2C28742BC5729664C6E2E2B66E0CFDCED5D3B56AE0AF70
                  SHA-512:BCFF836BF558D0A252839D1B365389BFC7F4B3811B590368309D5ECF9DB24FA9B2C4F7155C7EA37A7E7D7877FD9961D20163256C5E15075684D8944B7774147C
                  Malicious:true
                  Preview:.5......;.....1..._.7._|.5$^...1...K.5.L..F.v..M...p1.s.2.Kb.$...q..3...t...<.gg..H^.D..f....@.;........2..G(..3`'..U...t.p...M~.8.j..g.p......s.N...AY..j..M.r..j....-Fuo..6B.!o....]..>...R_..7.&.`Q.......#.,..#....?..,.....g.}8...oK...+=..V*.5....4....2.n.*a....of.-.n...+6.3...#.q....[....j8t.X....Bj.._F.u|4.@.V7.f.....@.-....f.!....VlM}.m.j...UbaB@.dp.Xl+.....;..Lt..=.L..U.~.F.5)mF.2>.i.GduOW.....o....3.-...bbG..y=C._..__.....f|FIyY}..~.t.{&.w.=.B&.;..f|+.-.|.]dTRj...@z.Ay)...a.W:.G#...T.o.e...X...f.....I...4....>_.y.8....L.)4.T...:...X ...........B-.........8.z....0..7P.(..Kl.~....E1..Nq.."gU.....&.......;.E%.R....@7..4Z...<.p.....&bb.u....`.:..P[..@.. ....n.aC.k.Ni").K/..po...(>..Q..,c..(..\'....1,...N.V....{s.4.V.....5.5z..I.`.&!..,.VM2{.GD.....C .J|..PL.J?.U..Mh}d6.n64v........FZ.s.-........E..{:5:.....$..)e.&...K.t#.J.Z......1[!E.{Ia.e...r.....;j..rF..^e.........9.-eI..K.a. ..mjF.....h....ry.Ke\zu..?..I)p....y.S91a.\......Z+....?,..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35524
                  Entropy (8bit):7.994872546968468
                  Encrypted:true
                  SSDEEP:768:I0jzBguUFYerSUqa0ikVsqH2tMlvwtgIyqoZW5pTmdAELqM0lJ:I0jzBdVUqa0bktoCEuM0lJ
                  MD5:98116DB599476A760195D9057CC5F4CD
                  SHA1:9F93868694ADE4F929ECF8D4EB17C7F5A64A4834
                  SHA-256:7A9C90D4D0ED41EF34BCDBA204980F5EEC1ADDF854211D1D7348B4CAE513CD76
                  SHA-512:64C796A1D2469C455D91F782DCD3336F75C884C6205A10FF634D52CB0F48DB0ED47592B5175345382B2E1A78A2E9B48622E9AF7242DA34D00E51111DD67C4505
                  Malicious:true
                  Preview:.6!...n.@.q....IbR..4.R..-Z....hoi...&@..I..d.....k.K..F...Y.D.h......l..x.@.......`.I.Ji&...H..f;.)Q.M..ux.{-..<Y7....)s....(),....xt.8.fjjq..@...f)N...........U......n..C..;..i..l.+.p.....(^.$.1_eWQ#.......}&.F.....Z.(..0....'7GM[Xl...*....?Y.........9.9...)?..z...Q4C.";..u.86..`'.w...m.[q.V.....X...ao.FEo.p.j.q..u.uj ._?;..}>.1.5C.iv..O...c...}.e...]..tB}.Y..j;l!..O]..3.8+P.<0.0...d}.K-.u..5...\jg1y.....5V.S9.....A..Vo.J.98T..P..3i]..+...1..%N..hE?....4u...]..t...GH6$..?.tB....V{....`.+..)y...eP.0.j.b....<....\'.:+..j.1......9..v.."... u.u.R.....bxU........^..>a+&0.5]\1.^...q...*..z*....W.S.Z]...-x..*...?....T..(......5T...e.?...,.?...=.@.mQ..f.\.g.......Iw....'3......Oh8....D.or...5t....rd.q...5.65T.*...DNa......T....i...2..w...(.....V...F]..m......]...q.*.4...;....K.x.{.D$ek..4..n$...M....].+...T].... .W8.........V....S........s4.dCs.;..u...............G..!p.@.....4...*..1.7..G..'J{F.u*../....w....%..6..b.}V.h
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35524
                  Entropy (8bit):7.994450610325654
                  Encrypted:true
                  SSDEEP:768:G4XQmupoYe2KajFBN19GsuL968QV0tQO/60JjINCdJf:G43ZocpKyeO/6ecG
                  MD5:0B572DF712930AD8AEC76FB2FC3625BC
                  SHA1:D8603F2FAC975A93FF2D9DFBF53B5FB6896DEA03
                  SHA-256:0267761D5B903AAD0DB0EFB42DCC9EF67EA4631965A7EB0340C12029C12953C1
                  SHA-512:4A9EE26D0735B16F1E72D95158905A79508C9FD0D41D9D6DD6FBBA981AD198A38F65D255CD543FB87F0BE670671F0B96D7BEC579D218CCB2CAB692F55C6415FE
                  Malicious:true
                  Preview:"}..{$_l........}.......<...#.2..).f.l*...;..9Kc..Y..J.i..57.;.Q..G.....#...(...)....&.L:..w.../...J...1....$tF..Qm:Oh..Wv........h...O..u.b.A.......p..o.I#.a.../krJ9.>..$Ju....b...v..hzrqp'/..$Kk...{P.b0.Y..%Y..S.. 2D..x....A.k|M..dH..$...&..s.>.r=%..].A.c...r...6..{.?1..a....O..<b..9...r.i.fO.g...,.:Z.Gci..W.>"..S..d..k.}.....}..AI..{X......G...&..MW..PX.W..~]v.),.`....r.O.Qv...X...S..3...E.3..|UW}O'f..+. .;.(.D..........5.f.h....[|5L.."....L.t.{D.u...l.C.L..]...k..$.v....;@(W8.P.d;5..N*...U........&..B.\.......r..A.IF...H.....%..u....6m.:.5k.>vc.t..(.....NGq.M..EfO..~.(.4+C.........o..TB....)..(...J.f....O.1...e.....apf....9.pW..Oa%...)j.6sh.......xi...{.......(u..+......w.......XY.Vh6.......g.....;............s.I.............F.<FRt...C4k.=..68\.N. ..<.)...[.._.+.\...T...p........5..O.~.r.i.4<.......k.o.B..Hq..r.e^8..&....{:..T#Y..M.c.*).B;.n....iS.O...b.Bm.9.%Kb...x....._..#..[.j.....h..=l.#x...[.s...#..~..*.W.`.....=..A.,.i.a..a.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33662
                  Entropy (8bit):7.9948227287539115
                  Encrypted:true
                  SSDEEP:768:6wma+/OdfcYm4wopuDJ0Rn2HlY13CU0evvrVhQUH0R+XhHkORJhL9LK2RmommlLt:6wPCOZwuuDJ62HlYpC/uvXQUHC+ZkOJk
                  MD5:9A0C4D05A336629C73DA6DD8BB8FFAD7
                  SHA1:82999971453BFD54E1422CB9F2518F7241287D97
                  SHA-256:18E548B236E0694D47D780666B8E10F0762EEFE8C3310E488B5DCC5A50B36C5B
                  SHA-512:0F69FDA95929A45E7C81122CDDF593B2E5D7522C3F5C6A785307A7CC50543D9D105A56D5265F974BF1ABDBD76D716895473D05C4258CF2CB47DD0A588AF3A853
                  Malicious:true
                  Preview:.|O.'..>.i.....M......h9...B....N...4. ...._-.........:....%..W........$..b.|^.i..B.t;.. ...i&.....Wk......x.AN..;#...4l..A...h.<e.z........M..@..@P.f.<.b.nN...c.4..8.>.]>7..j.P,.J.....)CZ.-....pH|s......'.p.....2/,.u..vT....O.[,.z7.o.......Je..,..Ql..9p=.......9-.Xt..x]V.KT{...;.7.c.f.8Z...z.c.A...p5...J.-.4...W...0..).....f9.....TE.5............K...7.K..p.`.<.\\.Au..n;.K........+D`...!. .F.v.D...[1....';4....{"eJ.....I+%.y...v%.a.]..._...Pm.g....8RR.....+Z.Cx!...#.P...d...->.Q..."4..........{....Z..m...~&)G...|.....`.U.}T.T?.G.0:.<..Ic.Z"/B.,q..l....U,..(.Vf..vCt..h....b.8&.p...yg....Y.F-.n.)...F.5..V.u......zb.G59......t.e.9...H.).$&'...c:..hL...q./.[En...B......qq..6^..#.M...o..7u../.....|D...A..r..0.p."z.....8_y...Q...........&P..........6=4.m..].M...v..Ym.ry..(..v..W..R!.p.$f\.\.F.... N.J.;.]'.....w.z.m....:...6?...e..J,."..{......M...`.5y...o.^.O.ah..^...d0.....G.f.......p..)N.....wA....6H....c@.5N.d.0q.\?.&.=...0nY..a..cF..R..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33662
                  Entropy (8bit):7.994647046941942
                  Encrypted:true
                  SSDEEP:768:bHEXsJIjKNL8WaY4qD3oNOW98R39OAnbgc777cQcFhIp:rEXYIBuboh8/dsc7770FK
                  MD5:5F60D4674ABFA045B9830C5659907481
                  SHA1:883D80ADAA7B2FE1676F209B487524A1787BD250
                  SHA-256:4F5E94A5B4803F3B82BA41027D356F63545035B115C94C3A93A4CD4057FEF3B2
                  SHA-512:783F957D0720B7C3741E0FCF66180FD420BEA34D77E9EB4C90DA9C3A3A900457F472303D263FFB24EEE5252746EC9AF68B18A86390DC647C1EA53EC8F8733A8A
                  Malicious:true
                  Preview:.'....)O-..D.[....g........NdM.N....X.F...........'.h_.u.....nG...z...f......#...AD....>...+.x*f..+..KRv.\..:....W.r4......Fw...(..K[.}/ty.v..h.Sg...'...ZM.Pw...ds..X.......,r...a.V......0I...{....A...D...Q2../..[yE...`...j.M.Ox..!.4..[.. k......Z....`..)...'6.M.l.......... '.r........C4.....Mu)...%.....H...)..w.2..#...u8..)l.5...gb.S.r.......0d_........0..|..?66...fr..d..B9/..a....W.:....SG)...A).:...C(Y...S.........N.`o._v........r.>...f......3.o.D..d|X.^...%q.S..'.....E....*..%S.6i..........g.`.....,.....G.....?C.X!.4..c.F.-+e...-..&...&..2.5.DE....dNE...i.....K.2..p.)...../.z....|wA..a.>....YI#}....%.._.+.@..L..R%...J.._......{Ao..o{..{.cP.PX....u..G._.f..qQ.=.K.L.....`......g@.LY.l.uo.'..'..../.>U.=w..DJdk[.....E...\..B.C...>..g.m\f..f.*.....u...z%Q......@.{.(L.z%.Cg....y!".W:....?Pi...$.CK......a..qFW.U7*.4=..QV...78.BxW...|,....,.:].u.(.......3..../vQ)GL.+..H..v.p..B.....r>...;xY<.....J.u.b...=...?..8..0).g%`.;.6.._'z..'b.0.|..?O.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35032
                  Entropy (8bit):7.993769960752949
                  Encrypted:true
                  SSDEEP:768:qQeWvDfz3FDoQwCYXyISDDatI7jEIfXjU2NZQAGVmIFwq5Jx5J62q:qQb3ZbwC4lS2mfTxHGVv
                  MD5:D6FCE92ED7FACE76EA63D90C3545E1FA
                  SHA1:632D924A9E27FAB68C2F066D6A27FFCD8E9D1048
                  SHA-256:3672B12D0063646195A3E6680F8AB1A554E40935FDA2B3525A9CAA42631C6BBD
                  SHA-512:79D77A7AB86D738AD3D72F2849558EECF112EA41F8F5699C946C14A540DB7C885AF9367767ECDBD8EA42E0B75625D6497B30D703A749D179B9E7A76E0CBC4546
                  Malicious:true
                  Preview:..2....ZCj..W....o..{......y.(/q.S.+..xhN..;...x...k.2.c3C".>....3.........$.n...]..*..5....P5.8i....hoX..z.d.g...@eDj#0.u/.Y..;...{...I.$Nhb..o..H1.$..1...(.u.0.&.9..s.%.B......n.....}..O+..W.).z..e...aF....;.X......v:....(.NM.....#......@..B....Si.4g......5/.>..l.....u`..wx.K3gib.._Bb*_UT..w...{.\.@a.....E............WG..!...G.x......`K....PWN.....:W.f.g......Z..r..I.h..Fl.@..s....K{c.~.......[..X.(..@.T..a.2x......A......mA....,x.BZ....@u.o.7Z*j.D.?T.6...YqoV.Sy..g...u?..7.7Q..N(..y`.....>...@Y..T..$.S..1F....f~?1.....>...kt./.^wa..Dk.}..jCy..'....`B......})...;.c..<.....`.h^.....y)H....$.\..[.{O3.vm.Y@.9....Q<....u..2Z.....i..<.Zo....?Z....,......2>..W.e.6jP..A.........6N3.6...10..\...].F.q.fFNk.S+.?......3..ex|`44.U..P.a...s.3.;...c.......D..]-.z..B\...i.<..Q....g.UQXX;.z>6c+q&J...BC.>.Xa.<.Xa....... "G...O....(jVKk..!4..g.(..z.f.B....7.J..:.....d7at.5..;,...._...(tA....cy......V..k...74]..^KTT....".. ..........xM._
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35114
                  Entropy (8bit):7.994833132890546
                  Encrypted:true
                  SSDEEP:768:3HwLv7i6Udgh7ZjoWR0HRw+Oi5fIK5tV0NPlxXS9H0uYcap:3Hwq6U4ZjTPDNPXXV4ap
                  MD5:B29C4CCB15C523D5FBD7D0D52444D63B
                  SHA1:55AF3BAE7FDD81765D1BEC8E99FF8E9D440035D9
                  SHA-256:E87A7B9E75913CB88686ED7B90193E7A4CF2DD9EF91083C20176FEF7BF5266B9
                  SHA-512:DF0635DD903F1C8534E7D6E8E79E51D5800EEBEC89E547205F129488DED94CB7BF020A1000CD89E6FD23A1C914A98D2EB0F5BED896A923D2F7CE903FB7EEA117
                  Malicious:true
                  Preview:6..6..BS..b......q.m.x..r....Y....rX.(/....a5.I...>..o.........(.R......Q.w...TR..AH..I.[.ewqm:...'|\...<Z8d..#..YT......s...3..m!.w.+c?....;<R....AD....l.#.@.m_+....W.6..w. .9.......wZ(....2....$.....'.....9.[g.,.....7....S.D.....7..N.......#.Z1".^.R.z.........%...F..."[.d..O.."*...mO..9.R...-..[,M.8.6...B..7W'.;.Dw..`.d.,.....3]..f..z.d...!.. .v.0J#*..?...@b.$<.F{.....Vn..9..7.Mt..W.[.....".k._.aM..x^....wA.K....q..GD.y...9..y...k........S.K.;.!....4QO...P/y.....g.r..K. p.J.i`[....{...n...I[w.?..+.yz..s...#..@.ri....\......s3.u..$/7.P.q...x..Q..u...V.9..f....<\....a...y~...r$.....!{d.W..4o......|85(/..nU..r....PeX...z..K....$....R..i4>...Eh..........v....4......vv.j...r0.....:z.U..B ..r......6..\..:j....+...BZ..kI....C..)..:...R.....t......J....-2..[PoNr.(........5..... ..8$I..*}..==.~....=.4n...t....."k.....R..XFPM"..#....y`.Z&.d...97..M.z........o.8\sN..`..b*<...0...2.%...3_._.N...=.k..]*...Y%...b...`}.......w..h.pK
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35112
                  Entropy (8bit):7.995115302035651
                  Encrypted:true
                  SSDEEP:768:b6gjjdZUKdcB1FrMf8WHaxd+2x8U/QJZB+MT2vG3fp:b6g/hdcB1ZMkWHaH+2x4ZB+yx
                  MD5:17BA00B5102342704F2D5A03C02B486E
                  SHA1:85B6EA520797C4B020917341E60817CE9EE3AE8B
                  SHA-256:54A63A577E9287B283897A6B69A8997B282ACE1D19835583DFEC40A4FB7976FD
                  SHA-512:76457691907B8810AAB6EC7AE2D549698B08D2582A209ABCB51968E48A7E84159443504012FD04EF9785F96CD3CB9B84485B1BF284D859FBB8B361765CBB49CF
                  Malicious:true
                  Preview:..F..I<..I..3...Mh\..L.....Kd./..c.1.F}..7^...o}..X......V....3g..vF.h.n.$..,E..E..BZ.......B0.'..*n....3.YVfh...B...\..R..O.A.r..*i....{..e...=........A...............iG..b"..2o..N..5......?i..j..g....U.......I..\.!.Y...k....w..1......;&.....bk...iu....z.._.+..N..mF...@;?. r......@..o.%.|.Z:.OT."L..-.,.U$.-..^h...tT.Q...A.u....c.v.._A..E..@...t..;l.".E...1.Q....^.4O........L...m..46.......k..Y...M.A.)..b.vN..Y...}.B`........[.S......l...6..../.....n3d'|.....@.iX......Qs.!.#....5.B.QR..8..]..L.u...&.......BP.\..t......L.5..<.z....*..0.oi.&..l.+...,KM.;...F.YH....`..5....M.'.G=@s/...].d%Y,C.O..../6S.@..US.Au........d..#.W...B.([\%I..h...x..._..Y..^....q^Q~...3.@.f......+.ow.[2s....U..*..,...U.v&F=e.aT...s'.ZzLq...+.UE.G..*.UK.........6....-...SVf.j~?..E.5......rr...}.t.Q..)]..3....<:`X..i...RKpg.9'.|#:.......YKA\......,......r......)..>)v`.g..."..2O.....KO.....4.......W.%.G*...&.....D...?.....B}.O[x..t.g..L...mM..4.....8dc..e.{h
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33936
                  Entropy (8bit):7.99455859418157
                  Encrypted:true
                  SSDEEP:768:pZEz/+aUABQeNQdzr5u9QGZ8nJX9AtPra409H9Q0tn0oyS+TK:pZE+a7Bvezr5u9QGk9ura4E9xtn0obOK
                  MD5:9291199559CB30F74301DF7ECE373BED
                  SHA1:1E82D3DF7EB50DFB4D3EF4FE4C7922E90C025F0D
                  SHA-256:B19CB1ACF439064224AAE94C5016A5E0928D866CDE2A45C04EBAB0184A220E1C
                  SHA-512:FC5CA882D12FEF75994CD80B7D89CFEA22231FCE7D42DD29C031AADA2B8E01977F5134E6C2AD67D1FFA2F1CC8744BF9594526712553485089A7C34E21C68B799
                  Malicious:true
                  Preview:.......7..5..a....v/^...........`FZ=.;.=.&{.0..t.;.....U@c.m}.1....o...I..0.6.....o.....;..4d..O.}......\.Wr..5.".2..f.A.8..K._?.......2.>...~...H..M.....e..h...atw...7\..@K.._(k3..?...x.$.4,.* ..o.Eo4.........DO.V'.k%.......#..&. ..`.......c.../.}.2u._..Y.....#....F.G.Q.2.^.?r$.......b........U.8o........nLL..z.1..M... ..XS'v!j......|..Vm....YS .=a....J...qIH......WP8.x...'..g2..UA@6:.O/...[.Y.....zM..._....KA..:.?,z$T.d*.......Y.&q.4..*nS|.u......`OG.u...t........*R..f..p..VS..n.....*y...R..^...@....Kj.T.\...5...n..g..|.8UQ...l..s.NcG..z..~T.N].0.?...i.<.+.....G.. .#[....9.s...:.?5.y....G......^.3...p....<l6.8,.^.9.Cgx.N..V.NXV.3.&MOj/....+ ........c@q^h..x.G....o...?..hK./...%/.tU....X...z..TU.Y..`.."..Wl...1.`z.P..]k.-......D2.{...36...UCI.3.X..<k...A.?8..RT..s.E^.ob.1..n.A.........2h......=...:.@.N.@.@.....k....".*.X}K.D...:%2..mXB$.Q.v..?."$.R.....t...K-..iS.2..G..j.s...b^.]........Y....G.@0}.0...W.g../T.*...Z $..2.T".a...e
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33936
                  Entropy (8bit):7.995109171054306
                  Encrypted:true
                  SSDEEP:768:Kox0j3zO/ZOEw+kqHz8e9uTyf0mMWKfUyFrIIHmrGLAjgjBfYMsDJc:Kox0fO/Mlrqp9ONpFr7HmrGL7jBgMsDi
                  MD5:DC252F56FA8A7A748AFFFF81554E881D
                  SHA1:45854B18E452AA1EC0F7FA31B746D316CA4AB8D5
                  SHA-256:430F5688454F66083BCE108EF3588FC2AD640846604286A45612BBB0805966D1
                  SHA-512:C6EBD2FB3C626A2D9CB70F657E3D0FD9EB44E9957F780828B6B7F0BCD707AB500428FC4F23EC58CA61180EE3FE74EC9E26762BA75B3485A98AF4A5E5657CA759
                  Malicious:true
                  Preview:...\G......X..[.js//.C...._..\.......|.x@...v...|.........C\.G.a....y*.b..K.....Mo...O....p.....b...J...hRR/[D.j........<..$......J.mP.W....^.F..re._ .x..{...?._...*..-..Y...AU-....~......8D.B..l...%..%F..X...................-........P.\~b.W...y)...i.%.).r5...x.LNOW..Z....|...T..e.`r.Y..D..............T*.U.$........k...iS.sl.v.....e..k... .6......c:/.......M...J...N.q.!.\..A.M.....<..1MurH....w,.=....H'.o-c.|C.....b....#...6...Z....v.%f0...z9).....}.[.R...G._-.-..u.......3.'#.)......T.x.=|..&.h..&...e.n.~v.svf.1......%.6J.G.....D.j.....qj..&A.I.......pD.......t..'<8..-.r.d.P.........._zz.....A..p.V...'...Pj.....G(~.......H..CW.x..p....y.~....c.f[?.L?a.........0g..$./.ZL.o.......l8j..>.9.7.^...3..i"..8].d.....47...a*1sp5|UX.....j,.........;=5.%N..+5J..P|.h..G9...].....C.W..."H....r...#.J}.-...0.......T...x."|...N..k.......P.4..?|..47....).Z.z...0.DBP.. ..[{....D..u..Ct(.u.[:.m.....;r..5s.r.K......gJ....U.b..C~5..?....<y.B.H"
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33908
                  Entropy (8bit):7.994821527040549
                  Encrypted:true
                  SSDEEP:768:er03dpWuyGllFZVMXOfJqLIfmvBj1n58slrFf0:er0iupFRML5Bxn5V1
                  MD5:9B3097DA722FF95B7D50C89C91E06489
                  SHA1:1835EF13A8633BF0264FBB44071B84B5BA5331A2
                  SHA-256:44CC057204F48A00A2B83DFC2A12F838A227324DE1BB78B09FA91DAC4E7DF957
                  SHA-512:7FBF20DF246CBD3BE4301D75A78157F820686674B969A984674B9FC352FAF395136234560BBB4BEA51EA885E9A46698C6F9F2D4072D918632059D2D0DD20AF15
                  Malicious:true
                  Preview:n..2(............ .......m..2...8....Zz...p..0..........5..1.....6.C......k.....F..... Z-.q...w.1F.?.....oF......Z..Ed.....h[.....~....S.......~p.P...{..x.....#O.....&.2....ne9.Q..>......L..\."HmU.a..:%l4:.U..3.OAB.....E....Q..V.....f..`.y.|..\.?7nbS.qW.d....T...l..9...q......&N..[^......?.a9h....S......;...W5.Y.G.bP7:...Uta......GI:.....AR].VO. ..~t..@".p...(...?L..I...=...n..i...........d..6.....8.o;.]...*~.~wR...fMA..O....,..>.....@,Je.;fz%..u...k....s5#..|.b....#V<.4.".U...{#0..@B...#.B[....R9...F..*.e..o.{..[.I.m...o..;.6..9..!..Y&.....d..A..........vN[E.M;.9U.B><.XO.*...>...Y....|.%..R..2.a..ciT".Gb.H...Y.]...cWJ......."....&...c...F.......O+.K....Y...%/e..........Y.m@..^..V...d.v.v.U.K3S5W]}.G&.....l....(....F.\@..M.oL....9#F...8z...Ub.:%.r...U.........LV.s....K..D.....U...O.....q..mL.X.......u..xc........c....A...v./.....p.....55..)......[..|..0..#...<0..q....Uh.1..7.<..H...`..(....$......"...|..e&=.=F..V.r:..x....8..bnq.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33926
                  Entropy (8bit):7.995131864429383
                  Encrypted:true
                  SSDEEP:768:Yw/q3XOXTDEYeMKh0+6NKcwFWFe+ZFSAguTtcXAeGQikJfrP:YZ8TwY+0TNRFe+ZWuTFk
                  MD5:24811840FC48C42056E7724D813F4087
                  SHA1:5B577C621D22172E7A78ECFE3F3D90B39D423037
                  SHA-256:D1D184FE74B6171862D0094AE10DBAC34EA9391CB8BEC52F83A2119CE38960E3
                  SHA-512:3A6B493CCCBEED912088CD82AA350934CC03D8D87C337F97715CAA503E0C37C5CBFEB2FE9B486255AAE33381803E90B9C4BE63329A3211995C860FE61FBB0FD7
                  Malicious:true
                  Preview:...+...*.....l.e@[..,[<.1.x^7".L.g..=.w.W.(H.ulT^U.L...$.n..#...U[....?%....*jIx|x=..}.......?h..}....?..{auYg..V:..`.....c..W.........:c......0y#.F...L.NZWJ2..td.o.#s%....H....M.!8gnWr...i...]h..B..F.YO. .Vl|.;.8.......5rOh..L.n..U......J..h.....m.....F.iF.<.....5..F>.....}3.2.g...U......du...1F..9d@. ..@\.a...(F...!...;.8^..i.p2>..T;.-k.?..|.1.Y..i...`.>X:...\..>:...,..x..H.#..8...[.;e]qcnm~4.>....._.HO.=..5yP....&J......... g...|.*.t......Ax.i........S..5.o.+.e..ey...YC..pO<"N.s.N-...c9P/..~...1....W.:.f...]..ND.9..3u.d..>2.z.>:b....%.k.....e..ice...X.C.m.{...v.....Z...y.....M.[.w.......,."6..N.}.)......2HI...`..M..V....*...r..u...dh...8v....Y.v.......|...K.7.F.R.CG.....z..k.v/..s\]w....Pn.........#`... ~.U.t....S.0...H.=g.W;.dT.....r.N......I.,.#..#..y..()...$..X[4.#4....b...'.;."....,..t...Y...........!.....C.A.OF-..!..=.q`P..}.s...-K..c9.........75Klg{~S6..8=./*........?....T...........N'..^..&i4.....w..h"..lZ78....... .3~D.?..H..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33926
                  Entropy (8bit):7.994278859614894
                  Encrypted:true
                  SSDEEP:768:6fRx5PXbV9uRHaPEzJzqzh5Niq7UwynnWAC4SMq0p003THL:65rXTutauxi5N8weWAKc3
                  MD5:56CFB375482A25F8044DB267827BD8C8
                  SHA1:80E9C28EAE913DADE1C9787DBA65F83D15574CCF
                  SHA-256:E002553C329A420512EF2BB2240EB86E0FAC702D5196E52FE6FF78F0791C6CA8
                  SHA-512:B7C0E7EFBE8F657BD9C90358EE7FDC557F82C966C2BC9C1CE479C197A16F55C6559AEB0B900045A482B4D086F526F0F89D71E18E57872857444F5F6DB426EC4B
                  Malicious:true
                  Preview:%?.W.>.".?...iq:.[...n....W...."#....$.X..q.C.B.m.n.......A.....Z..M7...+0..6..K..jf..+..b..r.F1..9./.s.x.n.........l5`...MM.......F8..r..A[...z:....5.~.z...GU.,.........aX..ZS..%....S..:s`.9YK..><..-w.......ne...X{...._.t.y.W...QIK(|..V.....L.l]\wQ..B.=..]ty........$....2[..#l......O..u..!......h.b.T.......y.q......d.....`..c..+.8...dT..r.O.S...&..C....S.+=.....esh:`..0.4..&v....{<......[2..W..Rm5..9.E..(..:/...",.c.^M...h9.&..i...r.n.;..'[...[M.3.O\R.....E...F.w$i..;...|.!...F'/..#)...7.(.*B.?..V3.H........u3rH.......u...o.h..%.5S.&......9V..{l~.>_T.1.....Wa3.K\...^....... .r.%4.;..EeY.X:.6.../.KNyi..J.i.>-.)&....`7e.#.....5.....?.......lf....k...=...b.....0"..JQ.&..n[..Dr....^...Y:..2...h...u..C.>3......C...(....J....68?6....b.eOUP.~v!.. $'..|.j..V(.&R.K....{....9#Hc.E.:..0K.....1..T,....5....mS....Z.u..nA.....~..v.PC# ...%........A..J...+.%.+.L..qA1.s..9...aq...g..#....G....E.$.d.jY....a....Vx......P..}...%.M...yxf....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33926
                  Entropy (8bit):7.993512238364147
                  Encrypted:true
                  SSDEEP:768:yJiPB6ZlPvUD2j/6/cioIaK3/UiNTCZaU3Y2gK8QvBQefVd:0WUjXUD2j/603IaANTC1ojZefV
                  MD5:FD3D5694A934D1FE78701A2B842A69CE
                  SHA1:657221FD11DE3979E3A7C1F9FEC636547B6B0DAC
                  SHA-256:83CCB09FC6731956C7C01E80C6FE833C3ED9FB19A5CA8E70D9F8636F710C5415
                  SHA-512:8FF7EE57F8DD48BCF9CC308B712397961425DE328D3DC337983B754261F738A6E94E8832E288B2EB0133F3C4B743E47D9749129E68497B57DA70B52713635429
                  Malicious:true
                  Preview:L3...n:.K....US.b..; |.~l.7.......t.@.t....V.(.,.9>4iDR.......).&J.....p...!.{..em.c.L.(pW..{iA]$._..|. ....{....pJsGdP..5AZ......Y.......x. .\..l....WA.&..f>HwC..........r&.(k.t..j4.}..Q...!.s...J..n7.b<....F#-.S..^.g..q....g.O../.b.....4QP.dp9..{.-. .e.&_...XW=)0Y......:.[....C.....F.n...AXd...Xj..Rmt.[.x.2...h.A..j..*.4... ..J..4.u.....A>:.6=ft..........;T.Of.....um...z...E2._.)..Xk..{c..[c.g$..~.,-..zuS..j.....T..3S:e.'...8W....4.F....\f.d4.wF%......tj..;ws..n....].n.Fr....z0...5.@..p.vF.{..G.62..Y.%..T.%......T~>....M.i..%g..4B.5.a....CBk..4[G.+...{i+..U...7$J-..6........6..1.WV..d`...u\?(..o..%......"............Ux..h..|n....qT.%...64..'..d.....S..U.z........x.0.m.#~.lX;..([.`0....h...C.................v$|/...[yq4...u...$EA.........]~...c.e8.'...N.S.&$y.fg.4."..XV.....uj.@F.'.8gX...].97.(...b...6...M.b.TP(..t....S^5{vJ2....%....c.....!.......)FoT.7.4i......~...X..of............'..>.2.?.$H..T......*pUL.S.,S.{........,.I.]V......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34268
                  Entropy (8bit):7.995011517987057
                  Encrypted:true
                  SSDEEP:768:+dKSWJ1rDvk5CNXCVPf0t0trzEAj7/bzow/NobEf42TdwDawU9noXwUrarK0KuNE:+APJ1rD85CNSVn0tEzEAfjz/nnqeXoRR
                  MD5:BF38529E2EF4BD0C70EFAB2C31F9B300
                  SHA1:2FD7A9833F013DB24B1E814BDD757B02A4BE131B
                  SHA-256:86F0ECF8268310EB6A04D913D9438C6CB10C0F7328F2EC0F0EDE3AB145928D30
                  SHA-512:841CB346F9B2304DDAA9F35A90EF5380F42D28836A10620427FD162247A8F914895ABCA5F90C4B9563C69EFE3F3DE87FA1908016B7417C3C4B92FF6C537037A7
                  Malicious:true
                  Preview:.........#....q..x...66.......5.L.........j6...BH7.OI.........8Q..=!VS./%[......{GPAe5....=.G..r`.>?......G...Nz..D0.......M...~.r2..(2p..w.l...A.?.;"....L......eT.....Q....S.....<..*.,...(8..]k.,.....v+"r.d[...)........W.(.:.d.C.....2x...."$.Z>..}..........-z..B...jW.,>.[..$.3I..!K7.<....z.y.=..l.5..\....+.x...,...7.m.En..;..m..>N..W2q.=....c.h.*...r(.x.;..2.H^....\.......W....b.....\.O@..j..~.......r>g.q.......m[.y._.c....I.......]..p....'....c..RM.;....c...D.....E-.. .....g.T.....p..6...H.A....=Kf...c!...-.N.t;.B.k._.Pz.....;I`.....z......?.o68f.S.3...P...Kv...9.........&.c...B..Y...d8...h.O..-..#.h ..7j$..4....o.p....8.cA.....7:1..H..R...=..L.V8...B......z.L...b.......*K..v.......J}k.o.q.......U.).)`\...t.>.:.M..KN..@.W.F...1..|.G.V...ol?s[.f..I}!...bv.=..&...<..(.n.w..c.6r.T0G..K?..a...h.....=..t.......l|.{;...,.P>.../Il......(E.)..H..........f...3e.qQ.........q.I.)...Q...;.....z-.+..j+.U....7.Y.3iXF.....(.+8.!..rS_.H
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33926
                  Entropy (8bit):7.994534929078276
                  Encrypted:true
                  SSDEEP:768:yPHx4RK/Ai0LPu53sNWPj6wRxqV8uMyzaC1x7fI8ddgN6e34XS5:yPHeR1Hju53T6w/K8uVzaExcQa0Y0
                  MD5:4FD99F8F8334B295BD12D26A33185AAC
                  SHA1:91DEF187EDBDDC8342582E20C991BA7593332769
                  SHA-256:F020AD7A26F1D668BC9FD9BA6594F50CBCC63618020AC197B9E864201882B8CA
                  SHA-512:0920F44CEA1314A0E51FDD391778C6A7CE5EC19C3C08652FF78F25A9838178A51BF4F5A941A0028383D27FE69B67498770D20922E8FAC8012358AC0B2F4B54C5
                  Malicious:true
                  Preview:....Xo.^>]...q'G..f.[.^..1...V`ISN.........D....9......jS.E......&.o..u.#pd9Z.........6;#\..6.X.|9.%.nO..N.SV69,O...U.k.....1..WN...../2.m...z..W.Uj.;....Q.:jo.....,l...a.D.."'{..{%..:...7.lZ...L.q.j'a*@....m.<S.cOQ...|Td....k.f......?..p.Z..V=.|13.P..+m.e .U......[._.b......sU..0.7..w]l)JP.V..y'.7.w....K...s.2...7.L......7......t.../.p...*c...@"Te6..#..b.6.@0.S_D[..t.4........n.^h.^1.l.|.............:...W..hLyc-.Ahs.....KmRV....#|..I...X......"...8..B.3.Y%8.........Ys4.R.:....=.. .r@......K.H_..C.P...q..;....}$%........^...q.p...~N..!....d.....(......i.dY.2}..R.!.cs.`.r.v.. .>e.~.....V.<..8n.l...t.xlq..:.qP..0].y.\AI..$.,...|..TO.m.......]..Z.% ..<..V2D.@\..4@"......n3..,.#g.~^.R}ue..C..a..[.Qx.+...9L .\.-..S.I5n.LV".m..8.3.|~^.;.|.....h.2!........`.#..d\&.J.b..7X.B.m.8..ph..........9.....\J..f.]..=..S...S...7..v!G.....c..).{.@.-...2.4.....8.pn.....v..P.l..7.A}R.)........`...o.K....I...,...#.._..>h..$j.X..........r./.$d.<.(.I..bT..$....q..u=.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33996
                  Entropy (8bit):7.994261629048413
                  Encrypted:true
                  SSDEEP:768:3OUG1jf9haCWC4rnvsq4LoNbja1/4gEZVaNnrgAtj7KRouYTcD+ZKU+Dt0cM:3OUGNe+kDCgjaNkZINrhKRouYID/frM
                  MD5:148B7C493B6D69D460070F6AD3A8FE82
                  SHA1:AF6A8436195B70332220805EC13CFE8124C7EF92
                  SHA-256:C6EDB2F7193FC9850045A7B57DF62649E7C5F70C23BD035DD91512C617C8BE31
                  SHA-512:3738CD48561A7B3BD26F89FFB69C73B67D55E1A1E7A4C169C0F8BE5EBFBACB04AA49BBE2E45689429B33732B73BA1A8C081CB1D0676D1050A8D4081778BDB4F7
                  Malicious:true
                  Preview:\.,X.}..{.X....S....`Q.....c."...e~.}....6.9....H]...5$!,....>Bf.%0_.9....'!U..B.;.9X.ua\.^.$sfgX.x...}.cG......X0..%0.fQ.sG...MC.?.&..R(......U.K....b.B.>...g.zk^7....8.5z]IW..t.-..Uc=.C.$...:......6.....V..!e....'.+.j.9.G.........E..;.iN.B6..[.X.{..eS..]..........@....a...9....1....]....6OU.~.!EL.y.tE.;.......UZ.,...A..1q.S.45)~..`v...qm.Z..].qbr..Ny...L..%Jp..L..u..............5...7......<r...9..y..('...j1E..UF../5..(..c...hB..g.3...?.(t .....#..5..8@+id.&46.....y.......8.abt..q....d../.]Pg.:..p.^....J.!..E..F.Dl.....a}.@i.5...r{.t.ze..`...~.....?@.FDR.X.%..&..=.....\~H..K.K..]...~.'[....,..V...r>..]...!/B....vZ..^:.0t.z.......].r*....eZ...$|..&.. T.k$1..W&R.w........w\.......+*..o..O....m...&..(I.%..zS.u...P;._$......k.l/.V.A.hh.y.^..,H. .s......A..L...;......pU.d#t..\O.Hqc....P...=....+PC.......K.d..u.Z....'2puy?.O.".%2.X1.b6._.t.H+...LYlh.g.....6.C[O.n9O..m)..1..../..S...{..*.``..c.h.aI.f.;..m.;t.x..2.1|5....SS....?.W.Y..C....+...U.T._...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994736542852735
                  Encrypted:true
                  SSDEEP:768:WH+eCg6Dfr/wnclKl489oGj71GWY0q0LgwSbkVpdgERmKEKAY:cYgOD/3ACGFGWY0qkYc5gKz
                  MD5:ED89E38BB28EBA021FA369E0F5C1C15E
                  SHA1:F9C8F5BB621DF5B583EE4A11E9A0442CB608F9CC
                  SHA-256:8521918E735CCCC53A88A8E2E5880DA75BDEAD59C9EE42991BA015613B3832A7
                  SHA-512:7140FDB4CA85F6D1761CD3AF9583FB6604796929BF337CE7F8308398EF01DB97AA6AF5AFD5D5EED13FF5F54C89F8D2EA7EBE7FFF3D9DD94FD3A101EF7FA462B8
                  Malicious:true
                  Preview:9.D$=!H.J.d..a....:..f....}h..O........~..w?...W`../.....M.P0.......uB6L.&]pK.o..$........a.:c..Iy|.:.J..w.......f.#....3....e.1c.:Q,P..B<.....z..]R.....m%L.RI;..^}..SL.=.fc..3.5FO...+....+(...=.....}Y.....".,...%.f.Q..&.!...*P.A.....Al4....G^.S.. K.?.hh*....R.H._.}s7.4.5V..h..!..p.Ds..zL....... 9..`L..R8=..K......*...Ye.....>.}..`|..;.,8Z...|.2....-.Xk5...5...-...c6.DM.j.K..0...k.1,.~..?c>N*.....'._..H..H..hz.....^.!>8Rg.=+g.`q...N.-Y.Yb.GOAr......D<.........q...[...hu@....r....!yOI,.F....a......r].Oj..Q7.....E3u.V.D.O..".f.&..m........,...>"......%.i..B.....9.a}..].A7j...g?g....l.s.....UOFd....f...&%h..e-xv\:..d3s.x.V.y..j.B..=. q....Z<3.b...........yV...w.y/..].-.....DXY[.O..3....g.R/....i&1.-V.y..q%B.-w...Z?F.B....1.i.N..;$e.j:G8..28u.3....M...Z6.....?...i?....V...`.......tG*..N.P.Ro....Jm|_..4..'Q.^.....4..@.....em/.Q...xX....('7w..y..........y.F...Y............a...BV}.....),.Hs@.'.v....+..Y ..c...o....p...@S..^....v$J....H....44
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994167431472308
                  Encrypted:true
                  SSDEEP:768:exj+v6tJAqGBeq3KgQySoC9/btA+p5cIbzq6Xf1g6:ex2AV2eqaTyS/55cIbW6XN/
                  MD5:C8DEF2F3F0C2C48800370CAE44D8805A
                  SHA1:9D2BAC273A5830ABF0736FB7A290C0AB790620E8
                  SHA-256:A16ED14981578DBDE5A7DD5B2CFE68C0AFE9B6C51F1BA1841549237D7CA54A3F
                  SHA-512:66524DAC5050342CEEB145A52629A2F328AA46EE491B5FC7DE4CBD5A1FAB24C3BDA5DA19B6AFF55BF3A9902B4B17904495D6992CE2FC853A8D54BBB9A179A993
                  Malicious:true
                  Preview:'.l.[.'..\..V.$",!.H=nF.`....ov.4+....Eq_s.1...i..-4.|.........QF..\e.)(|........;<.........'...>.wH.&....#......-....T....b."P...dGr'......!..(..q....J.z8)A.[X..R:bg...Y.-....i.`.2s.r2....,._..Q*..s..T..k...\..).L>..B".A...F3l..H.6.CJ..F}4b'...-.wB..mz.6.S...g.Q...+.!.~....u..M6P....G..xP.....O.....F#..n.xJk..[.]..#x..,.r'_+?..S..O.1ioN.<u..;4.A8.'.A.0.Son...{......@...'.l....)..vkic.!....`.k..........X2.VNB..X.\:...IP.....*.8...CEw.y<.'.A..Y.y4...1..2.D...q[0.a.....C^..?k.1....7;.t.J......1'....va.LkV..).........J-.m.j..6.<.].$\ .,.`..V..F..;r.S.(5v..L.c..b.N....M.._&$,T..."|.ug...do..S..z......,d.l{.x..\.%.X;.T:...&..$2....@.Q..~.:..>....o.....R...X..c.V..]....my..Z^.7?.mH"....R.....U.S.]~.m.~....w.x..C....2..?.yP.4.H....1.g.cR6h....L2NpP.%.t0..g+..D3....Y...'.b.....t.7o..Z._.D.<f.3A.iz.> 2.."........;tm.i.Q.!....Q.a.@f...m7..;.H....h<..3..i.Z.-...n..0.s.Y..O|...=.@..A........PT""...Ur.t_@.9.....Z...0V)f..Z...y...Y......NY..bES..TfX`.7
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994260593454455
                  Encrypted:true
                  SSDEEP:768:nnCmY2Xcki9Jpt2BBBI6Y5x9+RwqqHty6zZW6/mMERjxj2zDm5TBsw:G2Xcneq6Kx9HqqMQZWCmNR92f+Bsw
                  MD5:62F5AD474CAE75516A8F677B18A83D56
                  SHA1:5D84A5269BDDBB55716716F28AB1AE2060D5004B
                  SHA-256:570295242FF539A5D1F2B2B5D426361050784E3A9DFDF735203AC4B3B5A10D07
                  SHA-512:FCEF16B53DF3ED7B0EF01331FD03A9E3C1E1EF394279ABE659B528E55D6C81848D90B76BFE1780A04B13D2AA56D95C890AABFCAFD7AC96672F766456075AC776
                  Malicious:true
                  Preview:.....#..wI.z..f.Y..._4.....d.5.......\K.#....&E..@r...#~#.J.s...n.[`......A..n.H.`.&c.0.>.R%..!.~Z.....N.Zam...D.........V........T...D.N.(....6....7.Gfd...#..%..q...x...X5......P...j.N.....f..1y....../*.F&.m. ...l.F[..=......S#..X..E....v~G...hy.3.........Q.>.zx....$....-..5.....0.b(.h.A.6..wF..7.*.eun....K.p.....5*U..tw.C.Q'$.K..x8.E...Ez.E...^/...|3vO.a.9B...-.....p.&x...n. ..4.@.{...7...[|....d.R.I..U........zP:.=B...@.6..j.42.w1g..4&&...cu..tD...XQ.....J......R... .8...gP.........KJ...t!.D...l|..u*pi....XG.Rp.k..aU..X.}o*.s.V..O.=F.9P....^$..m.Z..(...............}%.Q..E<w>L.....?. ....U.. .1.\......&....\..S..J...va\....)...1].e....rKS.T...npM8....t8.h..h.....8./.g..JHp.Nf..f.8.pv.2Q.|([..2#.n.....ZC.!g:..1..,..Z.L..Tr.....,x.PF3..s.{....g.].3.....G+.[.J....*L5H...z.`|..lg..O.=..*<j.z.4.H..,....jPs.M.D......._w.h...i&..^...g<.p.i...._(.*.)*y<TI..m).{..,......k-.;..M......:b.0...R.z.....L..R...U.M.G.......jG[[...GT...x.'!.ip..!O..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:COM executable for DOS
                  Category:dropped
                  Size (bytes):34014
                  Entropy (8bit):7.994497747348329
                  Encrypted:true
                  SSDEEP:768:QYwQ+uA08+Y2nTetXJzoxc1fiDKCGCjB+Pl1hd8AWZ7ZMXZqdrf8t:nOV1+YGQJzoxc1fXP/L8HMXerf8
                  MD5:575637FF6C9E7B6D9088125785E0F36D
                  SHA1:8410D04F9139857D26EA5E13445DE264B295DDD2
                  SHA-256:EE90630674D9193883FF059E19EFCF67EB315D118E9F394EB9EB2425C09DEB65
                  SHA-512:E795E0E694DF376D11DE8A954E7BBF691F881A62FC9A39A5D33E51CF310B1C306A09C71E38337529340766F4F59FB33FF3D555B957A2271311DA1A1244B9F8ED
                  Malicious:true
                  Preview:.m..yT....|..........m..*b.."..I.(..O..Y..)..+z.....\.T...{]\a.{.....XZn.}.0F`.,9.....*|.Re..}.V........|..B.t)$SrSh&......\..r....@..+W.q...>[....J....t.....bd..D..c@..=..d ...wT/...[/....Yt..'y..j.m(.........pi..T....Q.M.Q...?..3E$P..iv..?.!s..1.Y...>Z....v...k..{..t...L.S".Z...)P..|.~~~.>..o..T....p.\.Z.....Pl...s...d.Z..jk.|..T.K...&.VC....F.$..+.C,.z.G...Ff:.._...R.BP<G.ET..eE..G.....B....o..s.?#S.lt.#.....zy..8.p.....uw.|(....#f....p..2...R..e..#.I.........8oQ&..#..&..w..t..|.w$(.YF..I...I]6....Zs..Wp[..tXm.y..<&R.m...t.9....e.....(a..H.G'...~.SI...6......i......2YZdOUJ.....a.O.{..'.9.....xs].K..P{..9...s....I.U.$G...| ../.&.]..:..t.h.^.t.E.J...3#....\..&......hU.,..iQvVj....0..hx...SHZ...<...me....i.h.s6..#.%}/....Q..k@.;...w.$.S...V.5|..."..! .yL0.....p...H..m..6...8.._.u;....RE.pe..y...V.Q.)....s..'.'...L.m...Y....1.h..%.2>q.9...5...;.7......"P...TWp0.p>RqKI_...b9....nU.I...m...F.$d.2..T....N4...X....ym.0..R>H@s.n.0[W
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.993243423820109
                  Encrypted:true
                  SSDEEP:768:iHQDpIyqH+b0RHtlgokMpKm55vP7oaNMpZ6:flqrN0Mpf5nM
                  MD5:EE7F727D3FECFFA5973721C77282995B
                  SHA1:E178EA8DE425D37CC06F3622B9DF5D54D6FAA48D
                  SHA-256:76FC5F74104694CFA69C4C42656EEB65898CF6B1DF0B2BF7910AFC8C09D7FC91
                  SHA-512:F9FD67ADB47707DED2C805C266B72E25E9EDD84631189FDF008E03CA367651613460018EB68B8B1B3C25B64E09539E0823D55A3E9CA5C8FB387C0ED93739CF74
                  Malicious:true
                  Preview:...%$/N..:Y..(6.q3.....;8.o..........7C....%<B..uV...:.]..]..b+6[...i.aL.u.?.1qm}..x..yG.R`7. ..0.....m.,Y}.....x.fcS....K>t......M9..%....I...._...lT.WV.?...n.......6.F%..".l..{.9.l..?.vz.~.%..c.FT....?r...x...rnH.Yq.=..W...\q.B.%.-i.Im....a...A.K.?..J......./.I9....8....d.K.7.&.1......F$t2.tj..Y..i.lI..t;....I.Ss..V:U:..YEs.4R....H.v......k.q...js.|...)Z.j.....]..y...L..[*...u..d...~.............}!...B>..........e..h.WT..*.=}..,.Z'.c.E...z{...p.~.;....<)2..a....[........*RL;B|..\8.........s.*.dad....'.ow...gf.pb.F.z.(kLN{.4.A..D%..(....7...1r..)k~.2+..........*.S}...B..gf.l....|3..9n."...m.5W.T.....q|4..:I.X~M,./.EL..^.&.Qu<F..<:..B.....viC..?0...3.QI.l.=H2c....?......n..."L...po..r...)v@.@Z.........U4.*.7.'9....-..>...uJ.7......s.>...b.V.....<V.2.......'....fB[.z.~..7.,..c.{....g...Kvq..L..(c..1...Vx....M......Sj....7.....O).c.....6.}.ay..<&{*-*...h.r3.`.u.p..xO.D.y...V.._.@".f..[vR9....0.}N.D..2.>...G7.".K.t.:J=.c:...[.{!...D
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994443873956823
                  Encrypted:true
                  SSDEEP:768:wQdirFp0FSOi4saQSOChKEUO43atSSbyT82bsXf98X3Ib2n/z60ySD:wQdOS0pYhKE3aaISbi8MOi3y2n/vD
                  MD5:726CC193957B0F4BF529590564D3607E
                  SHA1:A9496724C11029BE4E9BA5EA116450CA3D3950F1
                  SHA-256:ABD7FF3D013985F95F350572C8F3166D949301FCA2B85566211B9D207DFB397A
                  SHA-512:087B27333B37D72E2020804B1EB94155B4546C1D6E256620EB0AEE3462BF2884BA4C9A5CA6451A7A8C3E878873D0AE9F4F2712232A7CE9CE498D112572D5F3FC
                  Malicious:true
                  Preview:" ...'.r~..I..pt.G.S1(..5l.........F..$....8...J...r8,}|.*...n.C0..X......t.uT.z.g.5.n..=.S{.K.#...."R.wx.|YN..+.*D#...T...bl.&7.T..a.2....pK.u\5Q..#....Z...@.MG..!R..Z..U.....}`......X*.r..#..P..C....g.....j)%4.).G............>n+;).j..Zk....!..e&..D....:.'RDQa....x....||.jS.X+E.. y/l.e...".F...,&...x...D.y..$.......@#.G/3.q.bd.Gz.3t.....R......L...H.T..o.....I.fE(t.u..I.NCqc..Z.8.u.N.. ......6F.gJBg..zY,.[.H.[.(...#..]..L..............P...<.....U.%.B.\rS..?(|}....#/.3...=...K........f.m..o.../.....5.....j../%DD.5.....2.,..u.......6....y.I/..p.<.Gw-.%3.5.......Z...t).H.v..=.9.|./`F..........6........../..^.Q*..3.Rt......U...j.. ..a.=....a...ql..8.*#..R.uz...A........>........x...YQQ..0...M.."~.y...s..i-.....q.e.#.j.....+.../...0<.F][!..F...i...s.l.lC?.u.}v...#....F..k.k%.....J.9.j..7]R..=.....AC.*.e..a....b{J].....T.Rl...%..7....@$h.s..a..w3F..Z{.......U...?.g.UTP.|...T............l.;UD..<.A...-.. ...>....9...Y..Z...T.M.,c....)$....."J
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):34004
                  Entropy (8bit):7.994833895630057
                  Encrypted:true
                  SSDEEP:768:oZ5X382uK8K2EEwfLE63pZ2AoI3WF6MCedkchg/h2cKnV+Uu:oZZMdnK2ENzf3WI3+6vmkchgBKnUX
                  MD5:EE08F329A89E42B68E4E9430BC135A37
                  SHA1:75855DA5590485E45F67C0FB26A3793F89611050
                  SHA-256:7A8A8A89C4AA6AC322477BB5C1150632679999D8894C818034B5CF62B82C330B
                  SHA-512:CDCBAA9F633578FAC429840E6A62B129F5D60600D3300F90028DDB8B6CC7F110670AC87C87B75D5FBF25FBA0511385E381C16DCB9DCFAF7D0BD673DD767A8E72
                  Malicious:true
                  Preview:.C.{{....yB.\...4.47>.5..Q....v.g.&..*..J....;W7S...Z..o.gKo.L...5N...B~.^.....m...3..:f.#T...bq._u......t(V...XQ_oa..O.~.....e.....f.A.\eB$.'.C.B.?....2.*S.=E?&P..:..'&wV.c.l..z.F@.m,+.h.... ...n..n..I..K.~e....q@.....Xg~.&.c....\..K|..h-"g......o.J.|.w{..-.T..r.[.....;..{.X..I....[....[K.....]Xm3....\....M.H]...3.^.H[.!...^RG2.O~..mz*.y.!.../3.....y.85.!........i..>M...D..N4.G8.\Q..<f8....>..`...\e.l...._..z..g..S..E...9Y.U.....k..Y.6..|p4[.b...bX.Z.?._.xW.)?...q....+.W.4=Y_...P..*8..M....x.H^).K..<~0.....T.m..3f.....H..^ ...../.R...H...oO.._~H..eO...N..w*...R|..4...h..`......>.z..U.)[Em......a.f.H.s....(q......;.Q..q..w.|..2..d<...o...e..=.."....S.^. .Y..I9.P...=..*.u.T..bzO0G....y.../%..W..@9.k,t...]R..O..Y}......}'.......C.c.....".Y...,...i3V.m~..e..t............. .:EC..fZ.U.|_9l.y....,n$..>....h../.w....].:I6..+."e.c.,.....fk.!.y.`......jE.C?.}.7pA.9..:@[..%.._.L.7a<.yq.A..F..,{wr.g.....X.N.e.@.......7.w..CH.U'f.......^...A"...t.t..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33992
                  Entropy (8bit):7.994234803792915
                  Encrypted:true
                  SSDEEP:768:q2sg6NUTtKKd58kPLc26pLVb2whagrlQPgKHB/ICGuZb:q2LsHe582426NowhaIlQP/wCLZ
                  MD5:B25E1BAE6762CB971E3B16F612B04FCA
                  SHA1:30D4908614468DB2F8318366826C6DD97163CC34
                  SHA-256:A0DAD2C63DE44B8B5DC0B8587990EE15A69BB5FE34835448AD22644B761C0C9A
                  SHA-512:6596F0840DDF1CEA9E8F39437C7E933F021BCD779044935E6430BB34CA17EF437355C8613CD7CF0868D809BF25937F9B76D5909371CDBCCDC539ADE22394A425
                  Malicious:true
                  Preview:.?r..3.....3..d...d.....k..\k.V..|<6...r9...:...c ._..(.\~nGi........t3.c..s..2.gO.w..;..........~...g..-...A.u.?.hT..UxE....Rc@..v.F...AM.<y%.2..../..+.\.uE...^.#5.......=.%..>w#9.=...{..|..@......p.1..5zR=.J....V.!..e..b3O....|...L.U.G.3.3r.Y..y..:V#|....[..36A..._G.e..U..<..{.>.P..b.bg.B......c&..rlCZ.!8.^.R.&.'.q O)...Y..h..y#8[....[.VK.n..-5.}.n...R..r..).P.....6..Y}....HS...n.4..=.$P.2/4..3\..d..|.5({:R.....[E.*.]..&.'9U...+.9[..).......0.U... ..~.Z..&.G..!....>.v........,.E...z...~.|.....r.....T..v.wO.M0u8..HR......._......x.%....8;.*.?E....p8.+........ ...?...Z.4...._.t^|C...0...b5Pr....F.p.\......E................2...4\}..A....3...efQF..I^...xJ.....g.i..... .p.)%C..Gm.m...*ErX..x.Fgn...3.....;"....8...:..K.Gb..{...H.c*.....Rpn$...uI<....#.m+>..!'}..<.J).Ipf.../O.:..B...[.g...`.{.s.RE3b.7.x4,..........J.".,...$.0M[.3...F.j...S.'..U.WB.....y.8..LYMX.....c..h....S....M...!..S........h..>.J.9|.U.@.n.(......r.^(..%.n....o(..CA.Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.9949568877069925
                  Encrypted:true
                  SSDEEP:768:iEqtd+U4B4AV16zeg7ZzoH2nB5D5+l56O6EfOpgBH:iEc+BOewZ0CHPZEhB
                  MD5:C8AC5A3FEA8201408A9324B50BFE0039
                  SHA1:4BD481056294DBB5BA46BF7568303CA341C8A3F8
                  SHA-256:2254F0573249A3AAAB4FDEA823EC2FBC4CEE41BD16EFB6E517D4A419ED50D65E
                  SHA-512:D8C449F28DE3540792DF9AA6C298662078F1C20C2B4B7EBBA435749B4A914E4D19F0030329AF0F8131054A03FCEB78A2EBA59A578DDFC8193061707F1D9D2A65
                  Malicious:true
                  Preview:.U...`M/.m....v...t.a...o.uh.*.M-........SL.O....H%....S./3..\2.jJ.....b;...Sn..#."....q.^?.*.d......$..kU......`.4..n..Gs...:B..."1j..E-.f..b...O.:.[.l.^jN(..H..H....1...o.p......NQ<.....q..Pp.;.9W.I**A....S....&c.,;..A.UT3..sKcw)....s...>..W....e..9..9=..p.E.wMa4...Od.........X...J..`....u,...@6U(Un...'.W..X.....j.$h.g.F.y...%Ce...y".RTg.....6.<.w2C..U>....O.c.c.Z.b..e....^,.#........v....m...l.8.{.$.^.];.b........c.I6|..i.l.%..Z.U.....<...H._.@.J..;.V....B..Sx....,.Qm.6.....V.A...4J....h.*.....t.y.aB..9........rz..G.H....$F...G...Q.p..r.C...&...../S..n..f...9f..c..,$^~D.7.....w..-9S.^..BH....=.C.f"..E....b..X.....21~&.?..}.VPZ..'C...X`3....zmb e"{q8.>...2......g....m......O....4.D.|..`.u..&QI..=1kH..1..2.m*#..i:Sr....*g...z..['.f.`........=.h.<.8...9..d.UH.....e.`..w.(.H\[.K.@fd.........k;.b?[5...?O.N..U..<...0@=t..,u..(....i..H4..>......5...2..!..-.......l..........+.).....t..5...t..O.k...W..4.e..n....].M$..'mO..SE+._W...n.....J....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994270282821366
                  Encrypted:true
                  SSDEEP:768:ayXqPcX2oX/mNBPXWf0tMhSsedN+HLRzTeP7ySy:bXEQ2eOXWf0ShSsQ+lzTYS
                  MD5:049FE202D2F3C9E3E3A952954D906564
                  SHA1:C93B045B204D2B15AF7D332C81D88CAE3CA7C211
                  SHA-256:768F74A59722A5858378D62DA60334306B8FA56443E7CD693E85BFBCD1A6AC02
                  SHA-512:56C9975BA3EEF3A78397BC058271140FD5C969FB397691C12E1BDFDA27E9671962B038C9E969D5D620FF2DBA904656845974D7E09075132BF5543810751652F5
                  Malicious:true
                  Preview:.L1..I9.@.r.x.z%/.hFsE.J...^j.&...v...#.z...c....v...;."...m.V....J....h]..?bb..O..z.94)..2....].<.-..s8.V.v..Xo4....[.../.bA..".......@M...D.!E....=]`I..=j....y....SqP.P...F.L.....n)..A..pZo.....}.....(<Na..y?......c..xap.v.........1..5..O..'..W.F`F...R.....1.!+...V.p......n`\..-L...)..*.r.]\..9.AY?...>..2O.^G.rL(.b.V,.$.\..W........M.u9.....90....`{`FG....0....:.+...ons.s.b...Y.!....qR]..^..9C.]..[..c X...c.....4......{.......6......T..W...........zn..f.7.&..JU@|.?u.p6..u..z......j..)..V.a... `.j.i.gOeY)U...,W>.l...C..i5E....;...$...2.b.kb......zK..(.'"....SGk..+rS:...K.GO..J7]~r#.x)..P'C.c.F|.7.*FO.8.j...}*.......D.X4 J.......r.uX.J...#K.....Q.51D.}F...8.....7..E.p.+...v^..].K.C.#...f./....b ....b.wA....=F....&.......:.y.i.u....h?.X..".:.{.1..Toxu~g...p..:.........\.|.=A...".~.D}.........l./G..$.......V...`..f.}.Ml.F.8..o.........%...F...rt..'.......j)a.x...X..Q.!|.A.5.s....'..zK....6...N-../.D}.xj..9......&. ..T .52....^..s..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994160777998472
                  Encrypted:true
                  SSDEEP:768:eN7pSGHy0ttEgfaWQzf8S2ihhP0oPyVcJhHrAx3UuAZSRlMvbdi43jM2nFH:upSuyo14zkSBhP0jVOL+O/diyjMw9
                  MD5:E707AD76AB85917CB288069CF534E5B8
                  SHA1:3E37598CEC9C7C39C53F558C63A4720E2CFE47A2
                  SHA-256:2FAAA4C780AC1746AC9BCF9AC22E9E595D89E8BA4A259A6864079D6FA46658E0
                  SHA-512:9AD617FC342374006F8C8F4180D315CD7292BDC06FFF9A9B50E4773E9F1D0BA63D8A1B4B2EF2C88BCB656584C4056DBB626D0F1BECF994F57B26DF8A7939147F
                  Malicious:true
                  Preview:....Yy.p.<.L..*#..H...N...J.N...!sl./......i\Y.7...$a...).T.5..C.....R...i.cm~/.O"d.e..t...$nb.....i.x..6.'K..o.].1>bU.V..[ ..>c=../....y.~lq{Y._fWcaE:.x).......<u)...B..'.~...e.O._..q.[...D&Wm3......;..,.%.....A.c.~:V..I.|...QY^.}....?./gRo...S.:..l...}.d.v)F...GKimk.uYBF...g...*...&..Q1.B>c...!.`...B....RW..A7C_.Uk8t..u:.........C.m=.bC.z ..;.L.sF...K..I#G...y...W./...VGg."...M.d.5m.b.c...l...0[............+..i..&a/.WqJ....S,.P.O...v.....9Gh....6x.i...4......3..Z.+.$...qZ.>.....4..;o.1d]W.......w.(-..r.P.6.G..V...k.ed..]G.:.....7.Q..r.......DY|...R...9H.$C...y`S..Id..qy..}...........:MN..T....S.h@4.>C..%..3...T.O|..y.b.1..ey..gz..}....Mb&.9...S.K..........I.Co.....u.G/...t.P....XVu.m..0.....zA^n....?....e....Z...RKv..T..C.P....L@\-.@..ojN4.X..}.J....._.z...p.......R._.$t.'.d....>.5..O_zb....y...,..<.. .....V.*...O9...r.>.2.|.b@......ij.j.g....DMlp...)...4.P..Dh.7.F.m..-.(.mR...._e3VG%.....RBfI...'...S.$`...bT..L.m.&ej.;...~.@...!.N.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33998
                  Entropy (8bit):7.993907428097829
                  Encrypted:true
                  SSDEEP:384:7ez2bpHmTd/nAbGV7Y8wjo6Xc5V2XjXKrup4m2Fa1qaANCw/GVAA0khZ2CkG6H2C:TtHmZ9YhXfKruiFYELyh3kG6HUIkfE
                  MD5:0F8564D8BACBD395CB00E9445176ED70
                  SHA1:46FC37165B787F787E951FBE0C8D1D3ABB5819F3
                  SHA-256:21B63B8A799A38E1A6843C7248A7641805992E860DA5A7751CCAB300B3437F7C
                  SHA-512:FE611922AAEC6A8052991A6AB909AF574FDD8E9BBB8035E3D3BCC793D35CA6B7ABCE51921706CD490E9A2A98CC829D536DBD275409E6D58DB34073836C63C9D8
                  Malicious:true
                  Preview:.t.U./?....x.C..G.6.......4;.IUrc....A.L... Wq1..P...s..m....d....P.(+.)..Z...H..<..... ......y..s....\...K.u.o..R.._..(M..kM.0r.z+.kw..{...,.....M..fU.....W.f.....Z.........I.P-Nj.S1U.k.....(........p.>^....?.7.s".q.....'>....C.*9W._a...~F.6.)...... ,.m....Ly...".{6#...^.:~.'..P..Vm.*.'.o5.{..........F,@...n.OZ..vv.+/.5(.....]V...,.!>..V{j.z......t.9W@2....#......?%.Y.]...Q....m3eA..L./j......o"...............Z..>.e.@.e...jx..z.l...Nh.t.?1Y._....].2.. ..%-V........-TV:.....K&/.e..]-eF..i..G5_...,. D..&......[....4..s..8.*R&C.Jf.9.~E..J..P..R...4.).s.....K. .P.dJ..vx[....m.I...........*..CE#}f..i.\.....1...f.\..@....Q. .p..2..f..E..8..)t.C..\.......<......w.S/%...<.$N7......6...M..Yl..+.-d..(.vT.....n.i0..Z.s..]!....b..F...6lR...(.XMN............%.=M...Y>..h..Vx.}...U..fUM..W.5..RIPo.._....>..Z...%B..|.D....>.;.....4.[..U...T...-...|2x@.R.zZ5.E._....loo..-9.%..%...S.T.!K......4...L]Y)A.Pxeag..>.....]}.........5..}ox.Tj.&..d.fE...5....\>...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34010
                  Entropy (8bit):7.994057389020134
                  Encrypted:true
                  SSDEEP:384:T7x7v9xL8E3XSJvyS7/ENkzNPDZkn5O88UMqQ9u/if0BOApsO7/msM9idnrySYe2:Xx7/AESJd79p1NseX8BVp5zdPBpZUAg
                  MD5:D7C4614EC16ABB528AA538E8A7C60EFB
                  SHA1:2A139B92F3A26549FAE6B2CA4597EA32FD921C04
                  SHA-256:54126A42E87A085E82713D943A7EC89B410832BCAEF8F591E2C4AE13531BB90E
                  SHA-512:BFAC2B2D9583B8809C377E3D5F09E481ABEE3B897E2FD6245C696F7366BB8AD1509791BD42B176EFE660033A5E53770A1544B8261586682CA59338A8955FB95D
                  Malicious:true
                  Preview:.....K.o................d...Y/O.Xq6..x0M...;Y..s.....~...._.....@....2.Yi.....i.b.]......62Q.."....G..W.._?A.}q7(l.*.......w..Iw..U........-.@u.+...[..g._Up#..Mt.....vq.".%.a...JQ....W.v.c.Y'o..I.S...V..^.U.q..:M1E..g.]U..+. .O....u.Pj.#_.k..S?P...&)?.v@v.J.m.....W4N..o~..V.-.,(...!..mPJA>....}.....}.n.n......l18..........0O..../.%>{PZ..L3xN..Y..S.s8.(o.....As....q.c.(#X.. ..........].1.*.y.^^.@N..x...U.....yv.>.E .mR.t.UA.v.8j."...t.........S.(.At......j.Iw|.. .<......q....N....7|..=..!.4"...Ds..&...ITw..J..........I|PB,.S.u..G..W ..~.N.o....,]@U.l9...:.!..:.9.Nch$.....F..17.T.....E|}...x..eW....9..$....n...$.5y.ihg...#.*.9..}..GX....5q..... Z6qY.q..Z...h?.sM......hY|.U.._)...p......}...p_...]..$S9...i...^;^.=1...l...K....gx.\EZ..C...6.....33*.J.....Mp.[.R..U >.d.3.C.......//..%o.|g../...r.@.......0...h....0.m...C.t.+c....yr.%.u.6.qw....@.....?.(...v.O/. .I.....o.....;..n......!..eg.l+.|...?.m..,2...>....Z......a..m.6Q......-.C!
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.993841896553463
                  Encrypted:true
                  SSDEEP:768:2XwQMSOFwuG2HGL23SKleYMXTTtorx42XV4LEcC:+2mL23VQY2Txol4EVzcC
                  MD5:324E882F1EF70EC15A3BD7BD7BA1637F
                  SHA1:2E7C1ECF26B188812A49EE6959C8C32CA48AAB00
                  SHA-256:5B06D526729F901EBED13CD6D991FC7AF5EA6E60FACEC64760EB8B9C60CC91B4
                  SHA-512:53D02C71C611EF4C84879231CD3E65B99734D8E7418F74F6E0B89E0CC1A7D0F12BDB3B48510CE781660EB3EF1DE5A1A0BA163205FD85448D17AD68BC54751A42
                  Malicious:true
                  Preview:...b.%ri..-.|..t.hH.L.A.VZ..Z'WN...<...... .~...`.'.....o.h.........^==#...ho...h....`m8..?-..1.um.'.......b......[q.v....]..MW.;..#..}...A..S6.&..q.P..oR.).A.l..z.y,.&.x.i..9.....f..A..l.T..t......b.Y..yk.(L.|z.o-..b= ..[.u..R.....{I..Fvb,.........l......y..[...6......X.!..<.._.[..H`EL.*C..!.,....h...9...p..!..0".O..=.:C...%Fg...A"7.4..`.......P..2.3Pm..S].n.G..G..y.(...#...Q/R.6...3~A....I..(%CA..e.+.h !{....M..c.lu.. ...;w.b..q...P.....K....#..$..).V.....{.w....A".....Z.y8.H...#<....C.M-.....Y..D..e.?.E .....Z...Q4..e.\Q.N.N...i.@.=#.ShO..*....<Ng.....Z\&...S3GM.{?.....M<`..*$......:.g..[.. ..$.~...'?........Z'bX.+V.......H....5.p.:.....7...S#.cC..,.w..5.^u\.bf..q..V..Y.......^...n.V...D~.C...3..W..r..z.e...`@..D.....4.v*..S. c.....wz.J4.t.{....>..S....#_4..<.....?.q.)T'...]ZY........$P-..F..&.L...LY....Y_x..__g.*...j....F.4y-..P$3%.).....lRc..'..bt6.=....D.......{..,..4,...a.....5F3...o.|.A..J........M..gO....0.....E.X.o]..x
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.9946426071177505
                  Encrypted:true
                  SSDEEP:768:SVFcyse4HOANz59bu4rkk9zE6hX2J1B+Wqt2qD7ZgtvLm:SLcy/4Jz59bRdE6hX2J+/tZD7ZghL
                  MD5:571EBB5B17BCB3D23C8CB0D7168C7F02
                  SHA1:0CFB2EED75CC3016AC66B724DCE7C4EE67B07DE1
                  SHA-256:D47C6FE2FE0F6D514010B7BD3AE1275B86489C86BE03D66FFC9D1258288B965C
                  SHA-512:BB461C2AA734FB9926ED4E3E5A6C5EBB1BB2B5331B01D1418F823AD10C30E0DD2641988BD5915129EA288D49CF8A74DB43DC23F6A49516B59052B538D476F985
                  Malicious:true
                  Preview:..R.#>)'Z......^_?q.-...Ei..j.]....!^....'.u..ak....uoy........NB..;...C.e9.N.^....s%..W...Y......+.f..=.PF.Ew.'E.u.y'.Xr..5qP...?...... ..X....n..._.........s...........u.t.I..'..be.(..@..0<.g\G./W...A..Wc.~.&e".[..9..x.:.D...?.[.a...I.O.s..y<,94B.hl.g=[z.q(7....#8TJ*......J...s.....M.......Pf3>G.......#,.O..'......s....8.hd.n...>.s..H.E..r%.u........Dco.>+;D..._..F.L.P...L.7...o.........]8.x.....2*....bMw..|.;..C.R........ezj.t..1g.}...t....T.B...D'...>y...........uCD@..W...fZ..N..%e..P.z......LW....?*G.t...H.VN..=...slq...t.....,S...$.w.....mryZ.%....M.i.. ..m>1..0.m......qf..'...............d:,?}.t. .W6...|.`.M..I...`....0.$c....4..fH.9.KV.../..RFM.;...;.i.....Q..^....3..(.o......?...J8:.,.`.Q.....$.$"..O.....6...D.....G.j..8h..mv.B5.j.."n..c.p..i:AV......8....m.G........{wE..J.._H\..a*..).y..C.J>......].w.....V$.z.]..k4...h)..n.6I.".pB.4..k.5"...^...B......L\...U....[;.b{f+.../...u^..y..+......[h..*....d >N. .... g8...7...bf.M.mT....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.993628113641682
                  Encrypted:true
                  SSDEEP:768:titPIK4JcwG7Br2tbUBOkgIkHJCLUlL8JSm4//8H7CGWFT9Xy2qHQ:tiNIK4Jc92tbVbIkHsEL8J54sbcFsV
                  MD5:709682B1B485F70EFA5C4F6D4203E989
                  SHA1:BA99E409CE05EB7D8AB66E07D199311A42EE70E7
                  SHA-256:FE6C58155063C77BA0BEECB17453627D1BBD302FEB2EA7377D0B87557DDDA5B7
                  SHA-512:39BE85B6E2093577532F1258F2C5DBD256D94A923925ED6B380D9809CC6B5C85E4F59F1E166D8457BC79818D0CFCC29954A85B0EA608F9F7C47EF807B830E356
                  Malicious:true
                  Preview:.m.....-...:..&=...%`.g.A,o;JC..c.....8.aP,J.8.. ...wr..q.@Y.`8..\..C1..A>P.=].6..$.|9.....xB..3.j.r.~.:.........Q!...-klv=..'.D.0..../.|._.(......b7.$.@..y..o..G`.....m.C.l8;.:Q...j,j/..(...P.....^..ux9H..70)....X.<g..O.l...i.#i....?....G&..9& #..C.g"...$.......t..?...6..C....u~..V.Z.....8....S:..`..]......M-K..^.K...y.'.+E.:S".DT...?...&F.1Z.G..v...f..`B...^.k....M.f...'..R..... ....4.....(.wkE...........N...'..v...9.0..<..F..F..(....z.f.Ek...Xd..A..h..@.n.o.....^;.......E.2....4|.....e.r.....<z/...2.h7...#.ce.2P.b.z....Z..(..4..+_OC._v.|......D.p.{Y.ru.#.bj.`z1J.....Ab7II...BK..e.t...}B:.L.4.~>....[."hJ.@\.b..`9,.4.00......g...Y....h..T=...%"|*v..=F.....;.&.J `..Z-|Q.*..7..O...@.0]..2..aQ..).j<[..B_iB..r.b. EO.Rq..7..`M.S.h}Z1........^...;..*.Y.f..bNO..o.h.n.1."[v..[Ji..6....Q.'.D.0..x._.#`..y....$9..;`......$.g.*..r...7F9...(.5......n.....u<N."(&Y5...x.....h..nW.%.M...,....8S...Fov.s9y.....x...J./t.........~.eW=?..2./[<....d...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994355736346927
                  Encrypted:true
                  SSDEEP:384:5Yc8IIP1js3JuoLXmdX42oDhyt4/hcGEuBV0984AyJb6A2Hf9wzbDAUrBfzXb3Vg:5I1jWumU4dC4WuBk8S37bwxoqV22RP
                  MD5:44691D94C632DBE18D274571B7245CF5
                  SHA1:FCEBF690B88809AAB3819D2DFA2BA33879D7B9CA
                  SHA-256:7022A9F6AFD27759B5365B39F1C2859AFD2F03FC6B148C50CD55CA78F1D1A5B5
                  SHA-512:37F52982D3F9B7A403A6CACF3E855A6928646B1299E7EB31480E0DA14527324C3B8A0B0A3FA1DDFCE8FC92192DB3005A9199512303E1273DE34D67944B050DF1
                  Malicious:true
                  Preview:.....E."g;[X...[.8._O..t........F.`.{...51.p~...C..nRA.._Zh.#.4t.D..1H.*eEa".,p.&.E.!..d.p3=.Sd?8.z....g..o.du....8.qp.^...(.q.....<.UAi.....Q.....G.S...bW..1.....#1B..iX.....6C...2..Ik`..b.TOH.........5lK.....P'..9..:pd...C....\X..b...8..a....Z.&...).../=....F...=..h....y.U........r^_..1o...U...]..LF,.l<.o.K*.Ws.../..zn...O..y.....6.$..."...s^.<...Sv..hg.......N..?.J...jS.C?...d.a...8/.$?.E.#..1......d...Q[.".G.x.k.....;x|}R.+H..N....U.X.....M#.5+...`.ep.r..W...VM...$.p..........Y....U.;Q.o.+A.=....8......!......+.B./x..:.@.7. ....kPc.Wz..).L.k?....4.Q.m!.|..g..Ph.......M..k.X.g.*P...|...T*....s{...........O%..a.g......zz.z..Z.pZ(.....O...6 i........jD.. .....m.;..Z...P.!...F.9AZ....I.NI..T...<.Ys.D~.x..R....j{..k..!.{ ...wk..j..+EI.....(...........&......F.9........\.......O_TY.N%d/..........*..\..b.+i"d.......9.(y...x...~S-.h...V".u.U.&9...(..................m...y..R.e.`).Y.. G>r..Ma.lK.ee..C...1{.,eBbt.X.%.^.C._..3..3Z.....!-.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.9941323643391105
                  Encrypted:true
                  SSDEEP:768:fLX2NdYoq59pXjhC0wI6LjWGPbQmL7qZcXMjt:fLmNdYX5Hjro6GTQi2cXS
                  MD5:AA1582B866F0AD76D86E2EDABEED794D
                  SHA1:B5C4DBE4F5A6DF3B63C95D3E1E35AB8074232672
                  SHA-256:5830D4341F1B9ED65D84213E9EAB1B3EAA2ADE0B442EA2606A83ADE132FB888B
                  SHA-512:80E3862F094B4686786727999D008667099CFED2A1C7F4F3A17CD57A4E3354DE218E6B70B36BA6A2AA1BBB900BF7AF794113E20BBCB172938FAADA78BEA69B11
                  Malicious:true
                  Preview:'.......T00~.T.0.B...ED.{...,7M.......sg.&..7w!.......;.Q...\QU>=....p..,.0...@.5..O.=....}.A..-..@....6N.6.PW.-g..BY.-..a..!..2W...9.}_`.i..:..gF...).V...,...NO*...n...#.U/........G.Odu......3[,F..g.[i4.........~.......9.A..c.C....u.BZOh`....x:..OM..[...c.>.....{).i.3...'....]........i.N..).Z.V..:...Z...=...>.yv'.3...8.3....6.'/....v..mY..U....1.f.....>G.:..........{*...L.".=.....X."..m.GO.*..}.q.LI..x_....+..4..a.y..!_.......%.:...;YN...*..*..5..o-y.E..r...s..........!.J.<.RK.f".f.T....QpU..9^..u*.=.........B....L;;..&..0..$,....M...1x.........Za.mF!m..b.....?|U.L1..kb.H.NU.O.q.8.,IE..P.,T....S....9q..(.....!.W(k.a#.Y....nV<{.>yMDg7 .+. o....AK%,...S.1[..o.D.Y.w.#.z4.m..*........Wg..#.........$..h......"u.Jph........../.{...q......r.4....z..M.Z.u...{N.....^...+..b-&j..Q|.s..y.$.........\s...]. .........|.J?..rr)b..f.. ...bO...F.f...VCX..&....}<j.....f../d....8.j.%...w...v...|K..K..L?].i..y...O.<.p.1..{.{oW.^......{4..n.,..j..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.994456094111879
                  Encrypted:true
                  SSDEEP:768:wMgi/WAOV7GYSUx7QrnjfI51tigJr0eARkb89xTdc+FCvw:wMggWAOV7PSc/5rt0eP87TC+FC4
                  MD5:353642D35CFF4FFFD4C7B9B726331B8E
                  SHA1:6744286A67EB2DABEEF95A5F8AA39DD8C7FE29E8
                  SHA-256:3C27A78EAD90CD0DA4D3C5F8EB7CC84AD50D5770582BCCBB052FAEFF1ED3C9F9
                  SHA-512:B8E2900334C931C8C059C5B2543F61592B17A3E4471299109D29E3B9056E61D597754E7951CDB4E9FD01017D0C3DB40E070AE442EA6B32E5748EA1CDDA363334
                  Malicious:true
                  Preview:.I..ch[=.......P.^.9t:.+.[......lm.\..Z...P./T..D.qFW.g...Q .......JW.-.o..Bh..4e........Xz.M=$p.l.I.7..l..R6.tw.?++.}.F...(.d..bs.".|`..1A..r..."......y_..\..f.x....!U:s.D.....a..C..cE0+.....y.i.5.".........'-..b.{.g...L .O...V.w<KU...2.........`5.......{..(.}......i............{{C1Q+....M..8.A..Y..R....b..0......a|Q...pG.....&2...X3~...Kn.@d..F......K..+n|..57)~.V..5s.......W..i..B4XGBF..v...<...'6c,*.~...h...q-..|.y7%..oT...g.3".)...+6..hA'.......`.........b.o...?............b.|e...Z...M....5g....G...%z..(3...n^.vZI.q..X....d+..........Z..0..s...omOS..&..@[^.O...m}..E.1/T.... ..g......HJ.os..B.@~.jl..Q..r...O..0.k../W."=...6e.....L.Y~..x2....k.../1."gAP...)..X.7...<J(\^.....C...=X.-..h.......E.t.......e.<.8K......sU..3M.&t....-..;....586x..Z.b........9p.."....Xw".....(...Xtv%..0TZ...D.w.T...RVN..ze.........I....|z%.~z.....a(9.H..V#oBb.+..m}|jjJ....k.9.XT!#..8w....!...F.......E.G$.2y.,..Y....U{....?..mJ8.0.Mw.#..@. .>..{!..B..n..{ %.q...@.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.995142265444937
                  Encrypted:true
                  SSDEEP:768:r3aH1JIDI0HywDIMoLUy5Bs4G9QjcsMWriTlaTNyxHXj:r3aVJIDI0SCDoF5BsZ9QRMuimNyx
                  MD5:5388AA6975FCD27B36E4D00CC93E4397
                  SHA1:1F1EDACACDDE23BA1380C23D42DE8CE6BCBE9F1C
                  SHA-256:EA891E6CFC4E5EFE4A638C143551DF9A5BAFAE08379F5ECF276E0DC666499BF7
                  SHA-512:C04622F583B3787B5FF9D1BF9B6E8A28342851D7C1F27B61F1C6FB45EFC2D35C666EED898599987CCA9F5892244FBFEB459D94899EC82D6D05F8DECFAC9F247C
                  Malicious:true
                  Preview:..4.Ka..h......<..8h2..c..3h.u....V.K%...P..X.V..9..H....G..[e.%...^l.. .M..5..6D..g.pu.....M..T.].5>....4...N...TS..cp...Tp<ox...3l...,..#SWnTyO..:...&`SL*D*j.....{..z.>.H..eP.C..D.P.e..M.....hD.....T-."..&..,?..B.z.F.......j.S...../............/\c.>5.....c.J..}...%9s.c....P`.z...I..l.....7S..."r.[...%....B.e.f+... !r..H...P.{....-x..n...:M.*`..6_..]~ooM/[Iq.2..tW.~........O4.WU.WE.<.....\...*nI..<;.\....w...A~f.@..2Q.3..._..(z].VQ....D..8.....z%/...sH..C..._../K.Kp......n..=:.Y.m.X5V..:......w.e.TH4?d1'..&...u4.T..a!.}.`..&._H .D..w|.Q..`.a...<..fy!...#...#..T.k..f...R.c.N.Q.'. "..<.X....sWEb....nfc.*......i./kb...R.........)vX..i...../....@CT.....Ul...2.....7..W..0y..ll.6.j)1....}..f..uE...Jt..zEi.....?.N?_K.......T.+..K\..6.[./[q....a....fO c...}....=..........39..ux.U...g.m@UO.3.iY..y........O1..!.g...3...g.<N]yL0.........Q.$.r............O...x.9<w..6.5"...........pH_.Q.kd)5-Hx....J5....e_.2....=..g_ZY`.....81...&..l.d.p.Jerb..M
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34006
                  Entropy (8bit):7.993992434491751
                  Encrypted:true
                  SSDEEP:768:67nuchnwRY6kjKg7P8SyxUtI0q+KwBrRfMAEe6aPspC10l:6bBE2xP8fAIdwBtKe6aPsps
                  MD5:48230445B9355D9911D0E60F1FA531E8
                  SHA1:5B386AF87A15267A54673ED3A12B709ACA32EE5C
                  SHA-256:4FB0F81EE1DD799299F84D5C1143D76F6DFF16C443EB46E1641B30FA4148ED1A
                  SHA-512:9AD37705465532752C22F37720D2F1C73E892780B4B77F131ED9806FB154EF6672F520E6D114B186DE71E41B747E2AB70FCE983612B9809B8B4F3631ED838358
                  Malicious:true
                  Preview:.=..2.....HT.......r.u..&Z.......U..^>Uy1~K..X".h.....b.:....<G.RPi....&.)....&<6..`..g.;.@..]:......3..^.....[.L.xQ.2...k..D...Fm...lx.q.[..QM...n..]2.#R.c=.S..?N.......q9b.....@=S.0..Y.....B..cbmB...vJ...-.....^j......4..........C....P#.l..'.....^...&.R......#..F.!=.f..........g.5...Dh.z..&.e..d.....ItUwz=...@B.:>y`.M ....."*......2.4...y..J.....>M)q..4.$...o6..N..K,.V.EX.)rC.F..E.......@..M-......X...,P.....pH......{p.[8h.%Z.....+.XcG..}~i.'.P7.M.+...|m3;...fM......^..ul.ma...`.I.'F...m...f...9p..s.G.!q.~.+.:.+......WoU.M.c....`*....sE..........6.T...4.}.e..b<.H.(.SY8.`.>....4.......l..V......, .s..aF..)n.Sgs.b5k.9X#.T.A.*.......~9B.~.I..az..n..r..K.^r....p..S*q8.a..6..........M....J....#.>|.l[.UO...F7.........^..^.Cab....$?...@.....I..BF!.9....C4..W.%:.<)}A.b..8aW..Y>.JK'....-..Y...~I9.w...4a.!5..d.e.C.L...@?|.j.W..&.X\.V.!~..ZS.j..k)l./.q..[!..B..u....Me.>...H.....V.T....hh...]4tv.Q........]....C.u.._.(.."-.S.IO.Ng.....%}l{R.dF...U5&
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34004
                  Entropy (8bit):7.994673885735025
                  Encrypted:true
                  SSDEEP:768:QwUk2Cj0mG87ksKrJ9ohVr5t7RT+EuVST7hoe+KIJcRfzTXOFLRa9:Q11dBrJ9oxTR+1mlX+0
                  MD5:EF71F5580C717C0D72BE4B435CB0B1A6
                  SHA1:376B184581DB16541B23069A7E7E2E92FDB90502
                  SHA-256:E35A55BE5FBDE508B1395B46AD7CBCDD897A9518869A2D3984B1E7D7C28B5039
                  SHA-512:1787F98071F4653481A894E3211BD8276587C2DD75E284A0480F91E7C8C2F9E5D2BAE4636E4C4F8DBD1D34B29E1AC9C1D0003280DE10688E0A3982D8BB9F5823
                  Malicious:true
                  Preview:....Vh.=.U .M...yP.1~=.d...Y..\c/TF./r....i.7..x.....,a!a`.0..G.Z..VI..J......DU..Pl.:k.:='.s.-/...0[.Q.;l..~_D.z..v.q.%.?}P...S+.....@..=F.i(..W......i.....Sw.+,......x......a.e.}*C"..$..g3. ....Ly..c.%.....6.Jh..Q?..#3:..b.)/..+...r...T.?[.1..-@EM.u..gH..z#S..w.......... .f...]...#).<....W.GC..7Ht/L.....f54..dW....O?.fk-6..2..>.f...C.{..............,.....+...-?...r..fr.(%.V0 ...$jR.5...q...gXg..4i]...b.`.....).A..9W..LM.-.t.l..=t..kI..1......LD..[.n/o...R.4............%F....n{.../...h4....od.>i$....R.J..q).h...U.......>..hLC..DsV...h..]0.....#.L...}.2u.C.f....i.;.P.....k.j...O...t........u=0t.j.....^. .b..>`.+........r..|=Y..;.Fp.}>N:p.S?TAE.8..$H|.M9Q......k5..v^..z"|....H..7W?W2..kZ.5....\|.0...L...e.....4.,.|.z...O........x[..Y.E...K..^...t\.+-..e./....Bm[.....WC.Y...#..^.)N...+.i.US.....N..5D.3.`....%....p....D._..........,...O.7c....<..."q+.c.V..s..Q.h..lj......u.(V.VX...\..qPz.....y...8........'E;..e..m..../*.s..~..^O(...hm..-..!.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33116
                  Entropy (8bit):7.994667105159996
                  Encrypted:true
                  SSDEEP:768:qLVdooQPUwCvE5FnChf+Vz7eJ+jh2V6AznDjnJAHAThJ0Ok:qBdDQRCCnCAVxl2V6AzkKJ0O
                  MD5:9E41CE0CD01B7D0EE8370DD130B67CB9
                  SHA1:6434CCB0B11E1DD2891E519E5DEBA9DABBF38C66
                  SHA-256:C6A0534F4DFFD87DF59209BDBCE99FBA720275B1F65F7DB7AACE41561638AFC0
                  SHA-512:7F52BD8E0F95FEAC4DC8ECF0393333EE42360E4CD65CD4B00978EA8E0821E59A5CCB60541D4E515F69729254873B6989C23D6700C83CE4F324946EFB44C2F30C
                  Malicious:true
                  Preview:.?.A......U....x.y...>.j....r/....\`...R.@.W.9.. a..!.d.(C...^.x.`..S.fmr%.\#...x..k.}.7.J.!.........0.%"m..M.K..i...[...u..)].5L..va........c......?(...u....L....>.._..(I3]W..g..lO.jzC...Q.\....E.N.Y....u.F....GG....l.k.,.q... .t2..rp|..q.:.j..U?.....(.].....A..e{Ss.)..Y..j.wn....Y..e%.N..tSb.3<.W5.K6.k...:5.zt>W...0...C.Do..S=.~.Cd....N=...Y....a..6{...m ...I...>..:3.4.g>..%.96.....\m=.Q.......S...^..6...!...A. .{>..64.X....^..g.....rl......p...Y.P7.G..#..H_.2...z2..Sz.2.yT.'Gh. .3...+xO.....|..{.Z...BF....B...Y.Z..n..r......E..k.b.X..&..h..Y+y....f-\!..Su..3[......%.f..^~..H...n..F... x."x.*.....f.-.L...........[...dz.F,8....@8c.....\B7....V8...%.<F.u...X..I....]...GQs......s.g.h...L.>..f......u.6^UH`..R.fVn.>..).K..Y.8....a...,.....f..R>.d......_^..,o.N5N.n...a....w......G.,...=..I..tcMzL...K...,.r.....~.7W.#.+..1.a...p....lP.0..Z......5...isG.J*.Y+)..._..........B............@.!.1O$.#..g..Q..b.J..c..-R....T....IK.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33116
                  Entropy (8bit):7.993099947903562
                  Encrypted:true
                  SSDEEP:768:7BoseFkmL3bdp3dXn6DJmKe+f0aTSy0byQFCq3zEL4pDE:74emLrdpNqDJmKewdCCqYL4C
                  MD5:B09B858FAEA329E958DD00321C296E74
                  SHA1:2A7F2BE5F6035AB34D5583CB71A8B95D568D4818
                  SHA-256:EC7C59AA977380850B2DB3AC542FE33700CE6B250F49C9ADBF0C21309D699179
                  SHA-512:487E0B63A1C3FCE89B4984C63AC7C109E6E024567C24ED03D9D72C15A27625ED57E56709AE9665D523248DF03FCA887C8E766C6EAB2EE5C49EFA28EC8EE63A3A
                  Malicious:true
                  Preview:/..'..."l......=.Qf.}.D.=.DV;.jH$...........{f.L...k..."-pV.........N.._......V.f./.T..%..(..5CN.K"n..{.........2a....k..c....e..w..X...&....u#.q.1`.Y...] ..^.{.c..;>==..t.d...n....+......".B..e..L..v/I'..2..`....(H........!.).........u.n.@..0J+s.Lc..s...s.....G.+..tv,.".....H&..}E...P.q"W...1VW....Fyx).>9)ZM....g.Ame&/.I..N.zMCELG.$~o]..&..$].,.7..d...r.._..h#@..d.|..n.&.y_.q...........X..Us...E....#~.....q.o.l..%`Y...-5cN.-.6.j'.j..mV.Z......P`....9.R.O.w..HL..G3.GO..3...y..#....j w.qQ.../.km...D..G!.h...@....).......7.3.........5nj[.YGft......:J.|t.r.A...xu.Z... ...Qn.!I.1.:=3.....+|w._..z.L..Z.6.y. ....*@.............E....B.h.;...G...MP.04...T.\|..H!.9Q.422..U.&.;.%...<.3./=$..~.s...mv.........9\....C.;H.$:....efT.i.J:.h8...2... .....u:..7..*.7.<3J......Br.`]..~..@~.o.m6c`2O...&.=..K...Eb..d..e..T.u].XM....w.`..L.Q.2.]%{Lq.....|...WT.....3-2.....R.2..c....0}w..@.Bxi.,G...................w@..t....ty.o....GE1....J0...m.N|.{..;...J7........o...,..1..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33654
                  Entropy (8bit):7.994703779797161
                  Encrypted:true
                  SSDEEP:768:XdX48WHoJ+HjqSekSILJLXJc6etZxB/x4umzKm:NTWYABLXyxtVqp
                  MD5:E9E3E39713293807158AF0A78A88D2CC
                  SHA1:8C8BC359E16BB3E6A8044014C64B23CEF60BE181
                  SHA-256:787105BFC4EC783F902123F9774EBFA6DD3DCC537C210D4C58045ABCA78722E2
                  SHA-512:9096932FCFEECE0760B4D52B34C61368E4327627DCD99F86C0673B6B57C964EB7A511FED907C7F93DA4DFBBF4B354B00680DAACB0B3939CBAB23EF9063A45876
                  Malicious:true
                  Preview:.7.0XvSo...U.9.qm.uB.NC.sK.8.l`....y...7@.^....p..K..|....9.e"..'...]!.. ~#=e....p3......p.d. ...P5m+.x.6.K.g..k.Q.QIPY05H..Z*.`..ak.4F..`...b..{5..4.R>....>.b...B...c@./.k{......1.3:.)......<.H.7`...k.1.u.P...6~~S.>i..y<l.............]..-.d..:...%.5.9.C..o.(.,...P.dj..;BMMV..:U...'..E...L.....%...q.......]R._.um!P..{.V>.DZ..._..-.aT.N}.?:..R..p).\..!k..........p."}\...AHr.:.m.$..2...1..w]$.Kx#..O.@..M..h.....LW.r=].u........e.%K'?.8..*.....D....P9.0..3.P-....)..Z..o...j"Ye.....>j......v?..8.N'0.."c...T:...bSu8..@..)%T_....4s.%.`$..b<..hr^.u......p+..ecR..<;2:....~...RY.F....J?.1S-..rf..)...+.U.A6n..)....O..4.@......K..t..*D..z"e..(....I....tU3}....s.uh.^....,Z...`..........5<4.'...A..C.........._..>(s...H:W......J;F.y....L...F.e...-8.).......+W_]`.^........,8.....9..#..I.Z/.+..l!v........x...a.<......:.W#..Vp.WI...W..U..-..>d;F.6...LV...=..v..h.....zX....a.S[.....Wr. .a...7.[.=E...,#od.Qs.FIG|..`.~.0c..wF.uQ[A.Y{.../2.....}}}....... %.._`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33654
                  Entropy (8bit):7.994582055208979
                  Encrypted:true
                  SSDEEP:768:nZSDstEAexKqeU+Xym2YcjSiDwpUHoAF6FhSR3P:n0DstEvUVU+CVY5iDwGoAQyR
                  MD5:4829353CDFEA39299916FE50C8D45707
                  SHA1:7F35113B85E1D969505D8D88A744555568E1AF98
                  SHA-256:CE72554210CA1C44F9C6C7B4556DCA83B3335BBB9E651E1B3EDFA984162A0C84
                  SHA-512:6459529AE8C63E69E8FE7D3BD823105579E18F32165FA1F79EEF46E59E8DBDCBA4655F0DE13F64762E41672DC66DD3A9D2B794770390AA8CA802AC3B0149393F
                  Malicious:true
                  Preview:.`.h.HF..KV.$.F...W.Vqu_.H.>*...p.B.O....E.p.m.*..*._....VZ#.Lr.....n..*..v..."C.T.....EH.]Q.l.......k..W`-Is......}.,....p.U...A.a6*.q_..|.s.5../.8....o)..Y..T....V......~Y...}.?F..J..:.. .W.....)V.f...../...HeC..U.Dc...X.7..o]..P!&....2n.........O./v.~.q..j6..#C.G.x.I..T:RA...c.....`.B..V.g..:....-ojA...B..}JU.s..e......[.e.*.........g...+cv......h...E;%.\..Me.. n...J.Md.W..~...{J.h.Y.p]k.......r:.;7Z.....E..z....L_.X..[.}...>......60..9.dz.v...3..".>9.._Sa....]R\......l..6.............s...`m..V.jC.......#MD 3{....>.}.c./.<.C.....i.^.Y..........Dn.........u...-....27..OO.8.V.0v.7zC.h8..r....CI.^T.N.....j..............d..Q.s:R..?y.%.T..R,.._............n.X...%SG...zIg8B.}..........V.U..%8V.j..(..........'.r.%..........;,.jYb.....ma3..:..D%|3.+.....Ec......P...{%M..Q...F...m5.]$E)..6.+\..-.wg..>&...q.......Bn?3@.c.*..8.M.......0.........d%....*.....N.{.....o.e.t.f."...q.~.Y...Z.3.M1 *&.k....".....tG.....w*.~.r8.?.e......4.|..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33660
                  Entropy (8bit):7.99411290123561
                  Encrypted:true
                  SSDEEP:768:YmF3KeRjenLsDzMh3hwpbkwUlICQxhYWlCJ:YmF3KeXzMh3Op1xxhI
                  MD5:D7CDE332E716C7F846D767EE2532EFD0
                  SHA1:60CB884B12F3C906B4E605F121155605C017DA0D
                  SHA-256:5E281623AEF3A880BB5C75DE6EDEE62FE1F49492DB10B2B9BD8B74F480B0DAE4
                  SHA-512:100015F4026AD5071BC8E92FA7368D578C5799F199B24D538D817513BBCE1ABE07DE077038CB4DE7B5869183E791268C15FF9C35215E17FD4CCE07173833639E
                  Malicious:true
                  Preview:.L.6........._|..&..R|`..c.....:n....-....*........h.<FM<;6|.!EB[.....}.....4..t.'LC..U......#..W......_.....L{.........X=.v.x.........7..R\h/.5I.G....[...3O.Y......j....v..*....K.7P....*...n<.D.[%.5v9.k....g.^..e.....M d....:N.B!2Y..."...!.. ."F..d|.i.(.Z}.|..Q..%.....d.......u.Z.8'95..,qu[F......q...w.i...V....jz...N..6Vk..Vh...y..\...d......>I../{..Q(.....[aZs.K.4..5:....l...T.cZ.Birq..c....A.......<.o...t)......T1...b....9o.P_.."......M~.TO.. .7.(8.\{.HKE.......BLk?y....Pu..+F.Q5Z..k..._.y-s..X4./../s$.<]W..m..r...DL8.z.|..W....aV......k<..%.r...M.H.%w;.GD..%A...Zb....].0:.%...;....&._..L.D..c+.&..<;..9....-../...D..r..Y..B.u.;n.<>.W.H...Nv.Y1...c.2.av.7....q..)Y..n.UGE..A.......~)...........60.x..z...!..H%.d...uq...H..s.ONt...w2m........=.!..(...p..._..YNo.20q..n'*m`_.....3@%.|.....e9...3..22.0..A)..pR..B.]t..l..;..z.q..SZ..Y....AR.-.......5cK....CW.g..(...sF.Z.l...KO.DS-....ly..0....u..'C8ux.2.........0...1.8.V.S.G.......B'
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34144
                  Entropy (8bit):7.9951885950419435
                  Encrypted:true
                  SSDEEP:768:UDp1GqoZHnjD+tZhrkBhJCaYGwQg87xWDyEWGMpSq:UD2dn+tZhABvQYVWDyPj
                  MD5:0B5D3C9349E3D83B2C066670713004B1
                  SHA1:D912786FB2D8019D75A6A1C078E206D40DA58CAC
                  SHA-256:D95D6F3189CF382CB063FC404651FC6948C974A1F078B21243F67BD9CD79699E
                  SHA-512:748F2A5B7A9F8A2CA4FACB57AE2BF5568C8BFE409EB08BD6892C5EEEF475A66CCA29A29D33EC0A2FC2346D3378723D281500F4C9FFAF069C7FF3E11204C49AE6
                  Malicious:true
                  Preview:.t).zw......!..Q...V.`..B...J.......G......u....^fK.=..L...X....:W ..=..).j..Gu..|.=..0.Fj....Z..~6.UJ.Fh...Z?_.&.>...&.........GQ..f ....Q.`)y.......*n...$.......TY.7.c{.3.@.a..fZ.........D....e.T..g..<.YQ....n.D..'"6I."eu|.H..}..K:}+...A.x.....7...+...[^u.7.V.Q+...t...yf.q.}....*Y..-..........@.m..c"k.]OcS....V....|NhQ...;3~...~j>1..%N.[.W..)..;..l^..........q........F..G3].-...n..x.@....c...7Mc....1...l@N.A...h.........1...Jd5...y.#I...`U..J..Z.eG.$.......>.w..>.......1._m.......V.&..'?F.a....;.{.>..s..K...E..L...6..NXlQ......~.N..M../@.<...... ;.CTIZ.T.;.>?...o...22d..iZ..r..........y.......u.M_.LX..B..0.E..W......ZCS...s..!.x.......-..o..1 .)M.....)...A.........h...w..X.j2.c...79.......R.X.~.b...eKB.......:].....f.s..g...~.G.%.T+...rvW..m`.mZ1.....U;gY.B.o.....kn..".GQ=G$..UW......Mf...56.......x\nJ..,(..J..\0d.....!.e.Y.Kv....+sv}._.F.?....j9bfYO8..+A..J.&..Q.NE..,...z....vh.0.4..y.OxhV.....W...*....MQ[...,...r...*..8]......BC......"&{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34140
                  Entropy (8bit):7.994807441812816
                  Encrypted:true
                  SSDEEP:768:nHimMFyp+C26Nv/sWX0o2U2AeEEnBZ6LNkFwtZy97h:H1KyIC26NvrdNeEEnBZ1mZyh
                  MD5:3A4D47E4F4057B74AEC7E7553A13AF5A
                  SHA1:E2AE6F7A0BF6C766E8775116C0BAA7263C362A20
                  SHA-256:5CD0EC14064F789A4BED1E5E732D8BD819BF7B837CC72457DAB2AB12A2549D6D
                  SHA-512:FF3B3D9DCF6FA8ECFAA914B18F66628D74BC6BE1156A5A33132EC8D9EAC554A7FFA3584DB837379D6008AD9F38B6A7D8D7D661F92E3B941401C31875289CBC1F
                  Malicious:true
                  Preview:...... ......".)X.C.4,..rP.L%.........C..u..82..x.._.C...+6..N./...~..M.Cm......5.K.....j...P..;%r........wZ...c.o.K..-&...3...z.:...._x]........z..-&...,..>..Xi..+A.*.o..k...|.0...N-Jp...."....%..u+..q,...F...3,M.Jq..H.D..g@13{....Z{q^........:..;.C..../...`........h...k...O.....]Gw...Q.........M...q6...a........o,'x...4.2.QY..h.....Z.%.sP`9#.f....'?).....Z....Y?<..0n....x..u?...h>....W..DHp1Y..p.'.2..0...~.~.};LD.<.y.....lq.^.....Qgb.]f1y....l>.. X.wO.].p...t..x..q....Y.n.U.(|.(......I......=.]v=2.Q.32./R..........Y.......4e#.MF.+#....w..t...P...Mj..Q:%d.l..j..gm.......+.R......5.5.p.,..c..z.G.Q..0..S.,!.,/v...h7.mrU?.......yW|..P_.IwWO.p..E...../=}.r...Z....?]../..*F.h...K.7.v./."/......h_.y.u2GI.o..H-..Zwd.qo@...$....?gX.._..T.%..sj=.f)C7.]........./'.....h..Qc_S...L.u...~...Z.I...c...Au..b....2.$.<.}...:d..^..qi.O.2...T..g...X......W ...aPwn..|..!.q.F1..H.{.(....M...4.m.]........s.97.W..d...@.z.Z...@..y.i.......s2u.k..*.Az[
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34140
                  Entropy (8bit):7.993839526656456
                  Encrypted:true
                  SSDEEP:768:yM2AVPd+lRK4bESUJGVNt7ti2y3+PUkCSVJUjYN1Yk6j3:yM2AV4KOEfJwNjiHOVVejYNi1j
                  MD5:9059779EA5CB7B1899E491D445B293F4
                  SHA1:9C3C95301013E02900DB4EDB33E3A1E80C71F298
                  SHA-256:78C7A1A8E4868A4F9009CFD078B1A631DD49A4B0643FDD9E7E76670A564C9B55
                  SHA-512:3F25547AE3042D31B362EBE8EC08BEF705B367200E2D6E7F533F2928D9DAF522A82894B6B0C63EEBB4750EB14AB99B60839A59E7A45F97D0CDBEFB5F1E9A9517
                  Malicious:true
                  Preview:.3...!..4.-.C.Zb....#p.Jt(hS.#.IJ..}C.@.G.....%H..H..Z......U.>...W...mXs.....f....1.p..x:...`7.%...._f.k.X..*[.>f.L.[...:U...I....1Vi....~..{\S...j.V..<.Hy...'.2.f...~.Qv`......u...r..Q........J....b...U].....@.y..%Vpa5R....P.t...P..........`.A_r..J..z^.bU....6.d.............97..v:&o.._.........-B.4r..)4P..PB.?.{)..a.."y.}...r.;.2.......i^.?...C......T#..S[N.s.S....\..3.`../...=R..d.|d.Y.............h.d..W...;M.1..T......X..M......0.Qb...'..Y.].S..)..kg......f...I...R...(...U......z@.q.N.L0..E...?.zn}O.(..Y$.=.....gdb2...M....x..L..........FO.m%....><......}iT...opl`..1..C).Kp....UQ...{....g...{lJ.8..I.}2%<.`.j.c.l..]....C.. 9.6..A..]'."..S.R[..R.N....BJ..F......g>......} tZ.rW.n..v..H..l.>..T....! ....5kc.Tt?...}.F.0.p...++.,0..<^........8...mi..~(u....a..0.......X....(oU'._.......g_..*......w.3.5.....}.n.9{.F...t..]..(...:..d...9.V....\.s..T.Z.m!.,.m...;...ANt!1...M.....-Vmr....a.h..@9..9.....Dl........[..sJ.U..eiD..i..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32192
                  Entropy (8bit):7.993380140175705
                  Encrypted:true
                  SSDEEP:768:GGH6In9seGSvwOtgpw53rYcSVr1OSKjbI5PXI+:b6mPL6p63cVZlKbI5PXI
                  MD5:D181D38C3ABC4152DE595B4A4D83581A
                  SHA1:86191261E0D415A1B9A30D0E3A7A9DF6775DE7CC
                  SHA-256:BECB1148687BC3E7AE72DB01855FEEF17ADB875070DBE448A18ABBC6292AD55D
                  SHA-512:976A33CBC93732929F8199A886A1168E435B6D6DAD1604E3836D75F745C4E7B51BED199BEF8C2A43AE36D6E1DE38F5292A490FDB1E534447C9FC871CA0960A1C
                  Malicious:true
                  Preview:.W.SM.[....Q.DC.....^.b..F8...7N.5..Nx.pNc. .o..S..FJm[o.........=..p.y.....:...FF.2.4..9...\z.k.).......F...........t..|.q....g..._..[.0.\..#../.^2....~4.5.f..I".x..=.........;.*.i.o9 ..#..jA...1.H....v.....dwCy}.hq....y...`...... ..+!N...B,...V.^:<.<..J.{.m.%.=....9.(.z\.]S.....L<.$+.L.s..:......!}k..GK7H^.TN.......G..&m.b.1..m+.1~e..%.c<?....w.=.em..@.{.....9.V.b....[.Xw..IV.Rq..BB.c. .s.`...Uf.Y4.F)5V...N..d..\.]n..dM...H..:..j......?w."C..*;.....5.....&x..2Y.4...,+..pK-......|y....=J.~Wk.T...L..J.Mh.......&N..e+..._.pX..)N.../.3..d\.e.:......{....H..A..<...8.M.z7md...P.'.ST".cKlp...oM.b...C.t ...j..J.i$.....a9]..z..1, ....k.6\. ....y.h$X......B..+."m..eD...lR....+<..DeI.]....j...,#I+...(.n....Tw..z.T..`.t.._..D%.!..,.....4Pc.G....0....]... R...^...U..."_.....W.v...R.`......cV....5...W/H.....-j.+ ...v...._..G.KCw(..j.6.I.P......BV:.m..s)....(...;.]..>.-H#.{...>. v....Y"fp0M.%|......{.7{.p.Z.....i.,.....r.....C......U./1.X.g.04.^..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32192
                  Entropy (8bit):7.994049846999131
                  Encrypted:true
                  SSDEEP:768:FSQyvFJ01/MJe0r2om2guEivRqqUYMaHJcOuoCe9WEmYeM63tWj+Z:Fti0UeI2f2gudv8tecOLiTZ3tlZ
                  MD5:BED0B348BA60FDC8BDFA623F342EBF9B
                  SHA1:D6CB28BB6F7AA9E5B20A89D2A922D36D287F9488
                  SHA-256:3E13B16707DBA0BBBF4E99E6F4103F1F5CBB582384877A55EBA837475108F4F4
                  SHA-512:DCAB40B01F9786821F63B444E77CE7297A1ADBAB0EAAA76D18655E84A1394809CD0DE4937C83C1721813CE177ED13A09A585E4460E6365FEF102B33F985C0B2A
                  Malicious:true
                  Preview:..X...mE.C"...+c..0.}.Ha.9bc.O...y..D.0{q.i.~....6Fo{.:..D..l.2bQ..|N.po.y.k.b.....tb...Tl6p.;..&.6L.O.5..c.8....>4....Z.X.f.t...!.8ar...........H.m...2..*.....)....1d....p._i%.B[....KU.);.e..+Ap1....g..}...@wH.......{R]..*.m.Dx...L3...?...f..l/.....a...oS.?...7..$R...G..T..Z...el....T~...es.f.LS.S b@d....`..\...B..:wiC8....E.800.?..q.m...0...u7.\....P......N...8w...^...Y.T...'g.R.C..}5..).......E...84.s...H..K...k.!.....j_;9.e..Nr.e!U....P.m.W....'..k.#.4.00.xd.Wt.e[[..M..m.).a."P.t+:..?#.\.e..........v.p..a..HR... ?|.......B..<p.....+.CM.(\.*.\..p..[..U)4. .......P.'....K`..&+.fZ..F$. ......S.....R....L}El.K..}(.D...z..q.....-Ly...&.v.....z>.hP..L.0.2.g..X.....e....9.l.i......Jl.....m>j......V.N.T,....+...k.$..k.S74I`.D.....rg...q....."-....6.f.V$+l....3.j....+...%'..@.8..g....R2.i...M......o..9...o.N..V....,.y..j..f.FA.bd..9.u.`.PN...idZ...7....}.\.... ..Wm..S..f..N.=..T&....fS..u..V..>....P..f....;4Nc.D..RJU...."......6..:..kV.|...!
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33830
                  Entropy (8bit):7.994673968180733
                  Encrypted:true
                  SSDEEP:768:+kApWfjschYeO0ulJnz6hAU7S7HUEwuAsZEcBzYL28:BTjaenuST80zNcJW28
                  MD5:B3688BE6D7B70AA2477165665DAAC94F
                  SHA1:8E40C3DD7EC034CEF46EC736122A74115F5BC5C3
                  SHA-256:4F231EEC507896B87696644AC78D0F2C16B4A495EAE1D5A34E09EE4C535F425D
                  SHA-512:8AB2E24D92D326027C57B4A6931FA9354CCF0A68AD501094E6A74C7921B612E669291D748800D5A4E4941F2853F09FDF2A80EB475EE3003A71FAF0EC8AF3D629
                  Malicious:true
                  Preview:..{.3.,...@..D....U?0."..C..W.'=...g....o.}..j.......\.on..T..D.Z..@5O-8..Ms......L{x.<...._.r..N}....k.*.x...|'R..g...(.k..*.M......V.z<...X@..q.%n.t.j.HF..8}1.Ip...JL...9...W.Q..O_...........u."I.47|..2s....)...[7...#D.x.=.......&b.|Y.x~...N....c..R.v.x...e.d.....P[.S=ChR.H.".PXI......F...j9/Y..*.....4.k7...O...r_Y.......'....y}.2?.EWF.[.v...vp..\.7.)m{C..{...n.@.~Iz...*.6.N..S......d%...8A.;J..S]q,.$.....bS..u~w........De.v{K..-s2....|..n...].........V.v..#...^..jHV.*.........s...#.%..;.....-o.mN..al..l_...S.>.w..3.f..g$7d.;.......EwWv..1.>....*2.C..`.e.[. jrj.."K..C,..j..?o.h..M.&.].4......Z..>...l..K ..M.5.NX.O.G..iv.e...\...M..T. ....*...xD 1_<&.a...x...^.0=......g.e.("..s.=>........g._M..M..g|....T..'~Pp........gC..I...%...q...6.a4..@../4......8...`Mn...._..t.V....p..si...9av.."@e........e.Pz*Eb0.Gd.k.T.....|.(....._Nnx.Vj..N;*.G.!......q7..Q)......3.....V.7W.?n..u.D?..".h.:......b..(/1 g...Mz.m.K..xx.m..}O..A..%.}.T.......Mx.%Z.l..Py.9R.Q
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33830
                  Entropy (8bit):7.994424937455505
                  Encrypted:true
                  SSDEEP:768:f6VhbBMPKuYBwfyRT07jO7t2qi8kXazO3fBS73UgwVR4fnJ:fWAbYz07+08kXcOvBS7kR+
                  MD5:2829032180CBD3F10C47A6C24851FE6D
                  SHA1:F51BC435D82E3418730C419825F604F8FC9FC8BB
                  SHA-256:610DD919AB417A5FFCC23EB5940FC5242885652F6F1A8D55555A80B1A7A3C690
                  SHA-512:BA0476E50CA480CA9BDD7CD5C3707400F1B6476A7645061C77FF20A547BFF999BCC9DE88F0AC6BE0DA7B680E652BDC342DD1D6800BAE0C5E3601F3EBB526A0E6
                  Malicious:true
                  Preview:.*N...C'.8.b...C"=.9Z.?"...A..G.eG/p..r%1..W6&L.(.6.h..d..].V....E...QS"....X4.u.v..N..l;f..u....&K...A...C.....:.....2...F.c*=...BQ.;.j...e.8+..F........[.N.z_0.v.p.......Q.2.n=......l.z.U..Z.g.l...w......![..cg6.........O.'..P...i..y..ym.R..k....N.......8.i.qs.}r].....9G.o..8....j..*Be..l...\...=9.6z....Eo0.`.g..J........}`....@.Wb.8....}.S.p*..p...r. ..M.../..8...=G..Q*.Jd...5h!..v..|."Q...C.d__a.#.La@..U.%.@.[.c5..a..!x..*?{*..rr1..gu.."...*.kif....U8...8.:._.s4.3i.b..).L....wH# ..k.E....E.8..=l......._.p...-....e..X.4....c..;i+..E&.N.{.S....=._.Pv...>.s.....;.>.\.ab.+....P4Rs.....Rx.".S.y..C.T".s........i|...;...U.Tr+.j...h.....m..6../....^.c...._@.(BQ.3.]Q..k...6"...Xc..}'I...........[h.O.s.....4...:...`@.h`...]...'.K.`..F.IH...@....}.gdz..>J|e.Rw;..Ft... #G.Q+;.! ..3r.z@..K....2.ywN.k.....&Z....5.|....o......k"...#...F.o.);$+...T.ri....w{a.x.+.H./i........7..x..vN...'.L}i.kP.|.mL<.....cn..<x...j..1.iK...P0.gg..}u.e...j.~K...Y..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33804
                  Entropy (8bit):7.994495891176744
                  Encrypted:true
                  SSDEEP:768:uwLXnpxy1xKtC0homxcQp8pL8q0l+I7AKrog2oAzrTE/Pb:uwLnpITOWm7wL8WI7ABrA/P
                  MD5:435B05712A12975D028514D492CBF4B8
                  SHA1:2AF22883CFAA0578491E1CAC886BBFE8F927A5D6
                  SHA-256:D9B332C2CD01AF277BBE7E91F7D6B2D7FD9A1F283C9CA81515933B0E5341DD45
                  SHA-512:45805F4E035D1716D73DF8CC968E369A5DF75C7F1885E22A7AEAC410B22F9E0FBD75FEA67C12934F66E88A3D6A224247BE5334D4C998E3EAB05CB59EB9205DBD
                  Malicious:true
                  Preview:.^PPJ..X7....<uK?.p_O.56...X..\n.........d......"6...N.\un.. .&.d ^..b#!..D....!:....-L...H..R.f.6..M.'I.j...........U>'.'.'`...j.yBI....nb:.|.k....(Kt.G.....^-@@...L....<NSN..>....L.._.m..rlc7...c.`..R.....($F..#......i.._.Z.;_sW.W..3.D....|.t.......w..x....G......p......:...I...1..Nf2.b....%v..............0W.*..2T....+'3..k...8.e..n.w._W..|.......Y.Ls..*.].s_RRM...]..YJP.|..#........l/..4X9.%.}....l.^|.^H..._.@.o.^.|@%L8.1:.).o./...}..u@.B........y..E..YI..V...U$?|.c..s.^.N.F.h.Jj...e,&Xe.pq4g.d.../!..W./o.@..aY.I8.s.VZTG*..`.....J..dS........xq.#....d.|..c5.<..(............-.f}%....\..<..O(:f.....c.6.K..h...bn......0-..l.]9.N...>.iz:Y..Y..:....{`ua.Z.[..".,...ac..[.z'..5Za..e1S9......\...|..[-..C...e.&... ...q.p.<y..L..g%.....S..N..X.y[....j.o...~bm..EJ.5...z.O.....K.L...G....S.(.......\i9.z...|...>.BN..G...c..A.(.'......$t...G....L.$/...|Q..v.\5$...g...?....aY.F..OA0.2qk...E.....C..7Xm..6.xH.)..r5.&.....+ 4a.l.....+^...:...'f.la.@.P.,n..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33804
                  Entropy (8bit):7.994787222537993
                  Encrypted:true
                  SSDEEP:768:s/pF+TnKwbHLjfGuB9GSy8xUpQe/YMyh3PkEU3o4uAG6fFVWni:U+TvjeuBo+8Qh/xP4uAG8F
                  MD5:2A0E87FDC7A8AFFADC16C266E4BF49B1
                  SHA1:7EE8C88F59EE2F295E9AA3633518BC003899F2BB
                  SHA-256:9333B3EF7E7AA2CAD015B49300DCE6C4E484FBF547FC611CE32749E5C26983EE
                  SHA-512:4FD52A7EE975F32D03408A71B459EAB33CEF647B5126CFF92FC481EA3F0049DF7ED4DFE4B88F149D803488673E2DFB113FE258303374A0B846490A445A546EBA
                  Malicious:true
                  Preview:ff....[2!%...:...9.j.../.l...S..g.Un....R.BbJdU.....LJ...a..X...b_@~...3@x.+....B.......xsd.05.U&.u..#,.J.SJ.SL....."w.o...m...l.A...uJ....w.'.....$..Z... .....v.zD..}3QQ.w.^.z6.9Vu.......pP0..........,.lu...I.tTps.U..E.h...)"z.P.h..B.........J...3....0H...W0T..T..$.....`._..|F;.<iJ....q..a.h..6.>\.K........Wq..F...SI#...P}q...3_..........5..........j..a>.]\.W...../D,.2...fl..J.-Tz..@.5e...z.......W...1.,R%./..U..VI..3......,..'I.+/<.^./82..+H....50..0....eK..<H...FM ..p-.R...M.~...Xd;..J.Z...1+.G...\.w99.Z........i..1-....bn.........B./........h....(yu.,1..d....r..B.T.Y..41...A..t...\l.9g_......c....:.LE.~.H.ucb.wq`*..@!...^........[W..F..h(/<....P...7..a..q....._A...EW.9....e....pZD...5)%...8...c3...kh. .(8..QG5...If.....{..r.....WL.i.|..Q..,..Y...=_3...h..y.t...c..nFb....k......h9.u..:..mW*.>..^q.\..%.NZ.m;X,+U..(9.T...`CEq........A8|.T.:........(..W.r.mr..@.o....f..%7......8;**D.&}.../......?...p3../......s.0...%...$.Rt.{..g%
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33930
                  Entropy (8bit):7.99467406840839
                  Encrypted:true
                  SSDEEP:768:KGHWgsa9gMSTIgLE171GwaQ2B2m0d6g+YghNI:KG2gsBsgL9waD70dIhN
                  MD5:040EC233D8AFFA8525F9F52958941671
                  SHA1:EDC9ACAFAE99AFC4F4AB9AAF76F01595337590E4
                  SHA-256:B6EA7354094F3EAC61144A37EE758F50F718CE83A2C251CBA37A095AA1ED9A69
                  SHA-512:8AA678577A2F19169A89519D024311F4751D92C05B09B102C0620E159F03074E26C275B0DC4CAE1CBDE61DD430BD43D37CEC60C536F3BB252F9704E5C49AE652
                  Malicious:true
                  Preview:.G./a{+4.^.V.K@.mo.;{......O7...X.....j.H.....+.\6.6r......'7.1H......H.....t.....W........C.r.{.|..j..........K1..m.da..4vO...A...v.K.).....e.....Q.T..[_....e.Y^.6.....iL.8{./..{.S...e7.gb...l.....j.;e.i.WV.0E.&...i.h..l.5p.? .:<Y..r..3G..8.!..'.s.. ....8.:y.:..3. ..F\.S..8.....n^...A........-.-B..a...i..9 .V{...aAv.s.&..S.(._.!.c.v'..4.I.x.p.{..s.kz.".1...4..J...4b.m..v`.&a...]R.........9$....$4.@..Jd.?..=.9........*........~t.......G.....t..8..0d.....k.X%-.......A8E...G.H..I....s..0.T:.0...9..L;........;aSD...x.f...f..FQp...pX+W.#Xl.E*...c....A&.#*.2^.C...,s<...h....X...S.... ..J4....o..P......Vn5.-..z^..,.d.wx8......$M~n..a.bLT.W..M..].r].u..c..... .t5f..."~.w...D.$.........pw.m.....n...E&......|.r...E...\...+.......$...x..?.hY.Jl..V..2....L....._..jg...r6eC...y......H..wv.a...;G..[r,..r..i..n9x8\f.p...`L..(-./...X.!6...e2M;......@..Q.....V6On...wu.TC...E6..4......`..%.%K..)....%ya.1....$2.."..@r...!....I..(6V./.....>...z.O....{
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33936
                  Entropy (8bit):7.994157892244444
                  Encrypted:true
                  SSDEEP:768:TR0I2w9ebVeVk7hb1eTEdSZWqA3DH65FbntK5t8YLu:TQw9e0S9b5dSZK3bcK5tu
                  MD5:247CAFBFE63D53B76A95350E0B716A9B
                  SHA1:C679438C0AA367B3DE0644E2A7787BC4022488EF
                  SHA-256:723F0806E2A0BEA2E55E3F3BA45FF49EFD27D0A9EA332E6529424252FA9BC217
                  SHA-512:5D8FF4B85BB6691206C49CB1BE5F901C8F2D1B1DBC62D73AC6D640EE815FF578A82F160AC93FE18A776B1F59C70339899580FFF95FA18454AAADDF1799D3CF03
                  Malicious:true
                  Preview:...."f..6.q....n.;...Y.Ou..yo....B.?...op...|.......K...Y.,...+.........b.b...y.A....:...I~n.}.PMR.:....%.?.9.2(;.....W.C...S.....h..c..&.>U....k.K9..^.q.N....a..;.9....t..1.3$.&...d..g..Z..p.....!.zrs.<.E!..}.[......c.@...c..la.....8z...f....-.:..J.W'.X^..?$..K.............4Y"xB..........@7.b.............Q........E.!..........m\..&.h.g.IJ.7.k...>C.O.r.=..ZIfx\.).g..k.......`X.M.E..qg...P4H...U.r$... ............/.\....&.....YN.+Y..2.....>.L/.6R../.......G......C..2.e..5.<.eNY..g=B~.V-m....L.....2....../'.....=)..wOJB.......J..8k..Z"-..J#%..B...$._l..I..9.+.....i.6....Ne.y"....l.=T[3..E.....o.F0.9R..k.-$.}.....V....'-p..1d..[.:_..n....<U.......bBV..a'.e.!0.q-(/8.._.....w7.}=......P=3Px..;..=..!.?.9..$p..g... ......-fu_{.h...`..&B..r..".R\.{R4s.Qi.....s.7P..].#.j1W...A. ....B.-...DU....a<...8..U..6.F)We.r.`..T.;...9@..Qb.z`........y.F:k.....e4...:...(J...Q Y.X..w.M...._..HM.tG*.Z..9h..h6u...M..'....*F....N.b@nV..>-G....H...Bi........F5llQ.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33930
                  Entropy (8bit):7.994874712984067
                  Encrypted:true
                  SSDEEP:768:rcmpnZnZODZvH9wulylgytY6ExhnaxXm8hEvYzIfiJa:jpnlAtvH9wugOEYn78qvYEKJ
                  MD5:583BB91E1BA75533B33260B58D1161FC
                  SHA1:6FFC8FCF89CA95E12D0ABBE43CD8EDD243736317
                  SHA-256:EF7BDC378562669A04A5D46AF2312CEE401237E5A3BB9B65C03C222D7EFDF5B3
                  SHA-512:D018AFE1C2A896A6A02AC8E9D71118B0A281138FD11E3768E0C2A2F3AC21834D0AF5D48B1EADD707AFFD1AB0304B64CFAFCE6AFE50D98918EF1882BE3F2CF8B9
                  Malicious:true
                  Preview:.>X..p4r.].#o....&C.+.f:...<......[.y...P.R.?.....G#.{dJ{..F.J5_...2e.OM-....5..t.q....p.........$.^=|.lD.':...8*"...z.oJ.I.G......+.j. .._.k.S[..B..LpdHgd&...."...|..xP.7..eP_.(M....d.<.....Z..........jw..*$WT..8+...T~....H1..MP..X.'X45.:...4L:`...dhB/.R1.5;.o.9_.x...EY.D.@....2.....`.." "...|6..=x+.N......n"j...U.N..n.{.]4|....eV..5.f........7.M.U........(.[c"...d.8Z.2.....D.|.e..'x...B..}.W!.vb...y|..U..._.B%+...w..3H.D.s....T#/..aI..u.[....n.%6&.;...e-..ir.P....n.x..Uc.2....aq.D.W.YsO......l..C[...?.f.4..0}.=.3^....|e.[.'.l...d[.J.{&.fW0i..[.WB....:.........r.........n...\.Hr.,...R^...x.P~?..<..V,Pg.6....b.L........=.. ."I...........N.S.M..y.c......t.-..Z.|c.w0.9...X.)....V)..n8......Q..4......K.C.h.]../.>.l..D.|..6.?6......[.....3.%...l...zv../..6."A.O2~)..;....%2J.....o.[-xX..a.Sn:\{...s....$c.|....F...B}pRl...Qz."V..<.E....F.@p.*,....w..i.. .g<..+..[...W........@~...|K.@/.m.9..:..l.IS..=.8..o&..6)..N.i..+|.HVf.5.QH..'......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33936
                  Entropy (8bit):7.994862821357059
                  Encrypted:true
                  SSDEEP:768:TzFVs6v8bFIcVrwQnmrymSSbUk+didKRCl8QS:Xse8Gc7mZI3IUo8
                  MD5:D47207839CBFD5C20D997D52F37F6C48
                  SHA1:30A9C194272BB5C0AA6DFC714FC24AF83561CEA2
                  SHA-256:31A58ADA973444EB8A25E19FA4CDAE002B6B84558AA24094F8BA3991DF88E9DE
                  SHA-512:2CB9FE1431E84A9C7B808B517D624055CCB9D1BA5CFA3C5E51643D308D7BA48349BD8B6B384BD8CB2A84FC54263C4B36521D18B9A7359DDEABC11B7FC754126F
                  Malicious:true
                  Preview:.^..Z..<).>..{j...,..&_.T..X....E......(h...@.....r.Z....`..\I\H.08,.IE.v........z.d.5... ,..f...{.9.h!.y...*.w'...Gy.....\....a....gP.'..7....j...p.d.....sRPQ...A..'..4...F+"b9..T..O.R...(..sx,..@vm.a]K.=..Qp..v...iqG.]..P.....j.....>.4.g.....o6..a...r!=..vzb.........).Fo...2...Q.{.......I.?.%o.%7tL<..R..i....wG.....>.....B.Q^w<D..$..i....4_...8e_.QEn...[..7f.U.*.G;.......y.R..,0....H...VC......V...r..V5....)..N...o.<................+.k.S...p?..w].g..%.J.4...bE.cC;......,...m.J^..q...&).3.....@.0...F.71Yg...Z.........K..[..Y6..+o.y..j..z..==..>}...x..0c..4...Ot#.=..B.K..:..D...0: q.....eO..r..-..z.l.5)..s.].Z..._..w.0..|*X.....i.8...U._"h.}/...-....e.....b........0ls[.m......\..*.....~....:GX..].nB7.1t.....M.k.\.z..Z...{Uw>.jQ~...r...>...7eh.SJ.UD.'.#.&..Ve.?...hJ..,Lb*.wn..w.l.M....TP..."....D...q..........:r....y.z....R..m..g....3.*.4...W..`.yG.......A..@.=.,#pF2f.."$1.@.j.;O..hpB1..h~...w..............N..#..K]...^..)..........t}..O.;..}.4
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):31546
                  Entropy (8bit):7.99449411807676
                  Encrypted:true
                  SSDEEP:768:3yqrpog5CHu+SGYdg6cEio3BaswKSHN77ZP4ieRWnXxagbvhW0k:3yqeg5LD0CRrwHHl7ZPDrnXwgzh1
                  MD5:C7ABD28C978D3B31A597398776310E8D
                  SHA1:19102747F2B99817A6A5120DC4A2A666D01BF2E7
                  SHA-256:EBC2C9B53343E2E17AC69FF699DD5AA82E278889D23AD4E1266B2DC8A48DD4A3
                  SHA-512:0971B7F3D65ED5AE5040A668364DA926FA9CC900526EB64088CDE185F1B07D30519F26F2FA1F0BC90A9192DD97B0B2137AB51152709D50F06F274166A820F03A
                  Malicious:true
                  Preview:......<...[O....y..u+.....(.q.0E0.D..5....M....-... d...."..I.h.V..=M.&..T.!.44.z..q*1.gk.sn..`..@.C>.Fy.....6.......=...9..nf.>.Qv.DQxQ...@.......TW.....P7+....D]...g.8s.HT.!.}.3e.....Q.K.=Ghc.......X...>.9H>W].OOd.......5.n.@...?....;..X#..1...b0.+..ehi.r..5c...|8.Xx.m...@{H...Bj.,5.....e...Ng$.Y.....:.|.}.HOp.=f.d.$d.w2..,./tK..Z..r7;...{...H?nXC..%?.."p.......6q(........Cy..Du......m...Q....g.^g..o....U.^hH...mn....bH...s.Wm....B.L;....x.(..Y51..@MI..*N..|....G.0" K'..N.R+..Fv...d.A.L.s...T.Z72.a.f2TQ...6[PJ.MK.4.2PFs..^.n...|.:'<..w......&8:*/=m..O.../.gxm...i.v.8.#}.H...!.C.f4.....Vp..r.[...K...6..0R./.g..J.......p...B!04...s,Oj....b.....<diIc/7."a.PM..Y..O..Y.)...M...._.!.j.#.(Ou.QP.......w..%...N.O4D`.i...x>H....l)....ls..S..C.........<\!...Scb......:E...M.}....e...Npo..~d......D4...=y.v.".z.....YaS^..R.,..0.......!>!q.....S.z>....8.....{.p.......`W..u.R.7.|..-.Jg.S[.!...Q.....Uec6K.5..h ..../K.@..m...%...A-....U.^.R..(...*m.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):31546
                  Entropy (8bit):7.993866512165162
                  Encrypted:true
                  SSDEEP:768:oQYd+coJ7A/2lJ7ERDbjYYxKAVUdTFByGBF0nQAJk6M/LIAOSp:FYd+WSJ7kD/YYxKAmdp94nN9MzIg
                  MD5:9EA523E5A8A741E1B8C52A1C7065A0A1
                  SHA1:13183A1754DAC0A506D354155DB73393D6BB82CC
                  SHA-256:079DD6026FEFF108A269B5F5DA52B2CC2E167D46A3400E2C1588FF16ED405C88
                  SHA-512:999172B166368412628B78DD1A19458861E28501BD80FBD148E44FE61FFB191D832A40DC7DDCC2BC156DD76CD60EDAF8577E6934F139258E2B07D64A9321E0F6
                  Malicious:true
                  Preview:.....".s."...i.UA......6A.........).w.?J..^.I.'..Qv..u...N..iT...ry.!R3n.z..j.T.Y..>>.r0..].....HU...vr`.}.'U*..2........C.yb..........`p.......u.?[?U.1.lJ1......\.l.B........8H.%.F....b}.&...>....e..c.).A..=.#1..?.[..C....-.rG..(v.?f....j...%...R......,..t*..x.H.d.!k... ..s..5j...\D...C.;.%.3..qj.]....u.&.e..l......Bh.!...._".L.ZoH.......)....vX..$W92.:..P....[.eO$.:.l..+.<E.}.+......0?m...Tx.nl..0.,/.Y....!.}.........B.......L........O./5.....C?..CEnu..E.YD.".GZ.9..=....b...k+J..w.d."..*.D..~....C..N.eK.........+u.n..w....W..j..;.X....d$...X`#.x.......I..u%..j;$........VM...,..n.F.1.Y...w.. 6.....T.~(.l.n.Z.Z#... ..c?m..m6.....T........3.a].....L[.|.....Q.v..|..>.).J?B...0....O.'.D=yn.wR.}5vm.0..6...1nA.x.s....\`.2Y..`Q.]j...L.P..r"...4.n..^..}.EYk...\:@.,..'.M...;D..n.Q.&h...T....v...{....s(T....q.~..f.>%..t\..)_....4(.xY.$. ..).....%DU.\=u...*...}a..2rq.|".l.55+.h.1.5..U..<..w..0..b@AG.D...bxK..x.~.-@......*LX..g.p...`.,.O.9
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):31610
                  Entropy (8bit):7.993815122615885
                  Encrypted:true
                  SSDEEP:768:1c4O+GSUMtbabKbSYy9Ub+dLxHYtEv+T:JxGzM8ubSYy3RYt1T
                  MD5:6D996784793D6832FCE77820AD760716
                  SHA1:93C8A47FD35AAD606098BD23491772CFA153560B
                  SHA-256:BA1FE3E23E05C6156E146D2B57244552B7DFAC869B701FCFF208894045B60FD1
                  SHA-512:A66BCDB898C88B132EC89D2A1AEFC9B04006FB587C362A8C037CE34DD74C1B0F92B1AA6FFF319D88106D5F4377008C8E38C6FC7983A080C7300E5703012DE922
                  Malicious:true
                  Preview:...L.i.LsZ.^....es...1...u.*...w......vO9..f.,l.7.i.,..7.....~u..,....e...+hE.......=.....g...O.n..1.D7..,.W....oK...u..8../....r...oa.f$....Yt...Y..-\......p.H.s...D2(....u...6...{.9..R..:........:|`..".mW.%...:..c...IH....E?./.>6.<.<. .=#e.R?... .(.;..#|"V.....h......p.%...a.\(.......x.n...O6.....i.yi.]...R.O._.......;Q0<58......6.{C...`.yUG-`....#...).6-.S.x.(...#c.2.J.O8...N.f.[.....e..k%.8D........C6A.8.b...YrCS....B.....bY.`..8w.2\c.....5/....e...{.....G.(.._.@......\....?..u..#.5..^d....f"w....*..c+.s[.Xo..k.ZQ.d..)<...M...K...:.2a.8.`t.T.bA5?T.D@k.t..mU.=Q'........Rc.2..Py....E.j.vAZn.....!...}I.Zwc..(.V.G.X..G.I'..{....k..'....t.......[&.....V^\<..H.............5.r......U...'...#..U.x...5 ..}..c.q0.t.1.y.ZQ`...3.O.y..Oa.B...)...f%..~X.(.....B..f...s..[.......N..a.&4.w.v....M|...$.+.l...V.e...#.P.EZ5..b...z.p.h.x\<HA!.......t-../....z:..i..$`.....M^..s....S.).U>#........./...'.rm..}........`Rm..Y.........r......b-...o.@N.|..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30766
                  Entropy (8bit):7.994123613943722
                  Encrypted:true
                  SSDEEP:768:Vcyf2mCsgmZyz6XJUBv4plVk1JJLyBHZ/AbWSf:esT9gmZFUBvGy1eZYWS
                  MD5:4920C019EF8BA0CC34B42AC4DBB1597D
                  SHA1:F156DE0F543569999B80DB12647DDED0B8ACF9CD
                  SHA-256:F72E9DE15F10D297295B7802DA9C7F8C8E54BF59281E2864B6C1F37FCD04954E
                  SHA-512:61A4D3AB437DF4E9D33A736BC329B17D1D23143FCE4EBFED4FBCB18C5088CABEF972C31018DF0DC54DA99F529278487C9A1942BF4F0F06E6CA1480A047339A8A
                  Malicious:true
                  Preview:..TM1_...E..a.j....gs..s..... :Mu..p/.\.....F...{)...%\..L.f..MU..}r.E..|.x.....f...7....\6.h.H...'6.i.<K...E...>;./..W.*.=.@...t.....fr...$.;.0...&.UH....aH?g....{..7.8l.o:......3...q..&.-...1.....j..\...O....OfPB.=.G1J.HE.\H,......~..u....9....+]..Z`>D.8Y...~.>.K..d......{.%..iZ.Y...~x.3..%.7._..$..t.1...yX.!..m...`.{4...hdXF.^..Xp....E_.B..a.....L....e.5%......)../_..H%.Mw...3..nP.2..."{.^.k(.K^.......;.u.95.CZ........(t....;vCV2....#U.....s.....G-...+.....Z_.H...nzU...TD......;5..ef.:...)$.......q_.5<....?g.6..{&.'...1.>d....n.j..5u....so..R.......v.I[.C/x5`k%T.....G.W.?*7..Hx.R.T.".|..-E...S.dh..*o..7.W..a......xh~..X~=K........(.`.....n.k.......e.. ..o.=^Q.8^l.-....k.+.....Hq.....,......`*...&......R..`.[.x..X@".!.lt.Z....X"..B.k..&<.XNq.k4..r.8Z....r...ke5s(|..o....:?:.4.[...\.s.i..8.{~I.3{.Y.0..<.......W%.9..S.....7...a......J..........:...Y.....*.^U...f+gG.Y?/.gl....@..n..Q......3........u...7;..Tf@1...X...%.>$>%E.tPa
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30766
                  Entropy (8bit):7.993571973161996
                  Encrypted:true
                  SSDEEP:768:UDfgVF7Spm/K5tJvNLftpZFfixbcIHOQ1OwbWqcK:UDoH7S5dVpX4AQkqcK
                  MD5:BC14A4A62FCBF51E6A5A86E6F535EEEB
                  SHA1:D23ED39930C2F460B1EA43C4E5FCD8AF062C1938
                  SHA-256:E4633891679AEF45C28EC9EDC84724C4B6EA5929301087B5A23D0EBE196780EE
                  SHA-512:A19283F885C1C1965E0C7EBAF8FF408122BEBECAC45C98785775CE9C29154C19C0803D8661258E2CDDF8CDC882B633F1ED5BC9BD2537CA83BAB6DC74CB8E0783
                  Malicious:true
                  Preview:.b.L.9N.!.\.....Xw..y{B..<x..U..#=. -/..1..D._V!../..Mc..V..G..4...U.\...V..I....^...O...h.|....0......T9e`m.....>.......t .;+....#.......1.v.*........:.f...t.4.q..K..y..l...pk...........U|[....X...Nv.s..(j.zUk./.).#..._/..ASMB...g..b.'..?.....q.w.Y.W....U.`.<.C..%..g.%.I.K..5...}...1...E...G..|../.K..|g.ra.6."..Q..P..h..gd.-..\#T.t`Q....`;...M.7#v...c..q.r.....}9.5.F...t...]..\E.A.b..4G.7H..Y......9B.n.B.#.*Y?.Ze.l..O.2.b......8vTp.P.'8..`.~......z..'.}..j.YxI...zb..?.AlWB..P..p..HU..D.+..3....T..~k....@.....`$.#...G.....p^.P.......~&V...W...xe..l.....i.X...f..&h.4Q......4..p.%.&...,..x:....0..".O.(..b.8....?..C<.G.Z.....mD...y.~.l.....a......@....dMQ.Tn.y,..axm.......FV.......!{../T.V.a...bg..._....=x...0.\*..@...b.3..qw5..B..@.z2..^q..w.....0$.t9{ohW..vu.~..p.4.<..S...o.pV..>@.dC...0^..jZ.?.O*..........Q.&1..N.9..P.]..)..-<.+..b.P<....b.t,.D...P.)..Q....'....>^..t...c...2..$...$(.8..9T.^.L.^....pu...;.....M...J.}..W7.a"7J..`+...\...d[....b
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33256
                  Entropy (8bit):7.994497368401864
                  Encrypted:true
                  SSDEEP:768:DDsbHGOn0nya3Z6q32zVzf6w5VZoCxXrZnIhbfX4EJ7vMDPSG:DmnewVj6wpdINbTSP
                  MD5:40CB49E53E285B72E03676162A8125FB
                  SHA1:A04D49EB34C582AC146FEAD5FCA5EF2F9C2C9F39
                  SHA-256:96AE52D0112D6C8D40F5374355187FF83F0D781ECB8B1C98195F8FC5DBDCE4CB
                  SHA-512:C329F0226FBFF458942DBD1D0A15BC29E39C3D211BA1EDF81F6896C3849ACE2140405A0DF6FD18B6793FAA1D38E1A4396C91114D2C7C2E35A2629FD6A985469C
                  Malicious:true
                  Preview:..:..tf2R'}h.=.4!..Y8.$....=E.q27..40....}T......r....o...V`.i!...C....S.....X...s....\s...N....~...w..=a......# w.&7..Ll.*D...K[tNNib.n...(:.......Y....q.......[.[./.Fi......V:.Z."q....qWO!.....:/.k.P.M.87.mV(>|......(....6...u.....Fpmi.....e.]V.....MC..i*e..w........eN........S]..I4d....n`..(p.[...sUd'.2......h.:d....%@..%t(......j3R._..D....x..JZw.....o.!Gty...3.......q.......I.9..a.$S....s......AvJOQ?)...]..-b.v....a.........]*/..*A.n.h....0.{%.;...3..**.bP...&.:..).*.. k.u.0.7`+....1...1.x.Kzw....^oj^ h#Dp[....=..vo][.T_>D..#.w.T..-{%..,......1y.@....)LR ...........nu[...,'....i...!Jy..&\z=..TB.s$c.!..o.f{y":.$..\NE.].[&...\..>......^..C%..x(=...=Az.]{..C.".:.....)....D..oix..w.<..PW..|..r.r..4...+=m.P.JU................_.PM.?-P.`..."I.b.(9....0..;Y..Z.+.8..HK.s/.h...Fh.@.;.rj..@S(..........Mc.q.. !.O..>|..I......x.k...B(.<5......$(...*..?..................-.cC..0.\h.kXd...B.6i.............jv.t.:...^....!.u.).m.z.\.).....Z*.-7?
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33256
                  Entropy (8bit):7.994661508143408
                  Encrypted:true
                  SSDEEP:768:abQWiye/JbArJ3ju27pOTJvm1E9/KUqCP7lmBy+7sQF:aPiyeBOVjPgyXGYBYQF
                  MD5:E4D78D5AC87B7F40842463A9B3D22CBD
                  SHA1:D3C0326CC3CC203C190A670B5B41584BCDAD89FA
                  SHA-256:5A4209A56ECCC9367621F73ADED6D5D88D7CB3732ABE9D424ACF53A2DF76E091
                  SHA-512:9EFD3D847395840FE033ABBA5DE502C03AB5CF65E948B4539180901A012F506107484B5A6A0796356716AF502980F2BCE3F4571905D928F2976FC79A259ADA33
                  Malicious:true
                  Preview:>9~.}M\j....W`)..D...Hb..W|i a.j......o.....CR.....C`.pb.z...%....8.L@.;....D.'..BDj[5...(q5..%......m.5....}o.(..../4.....YT..0[/..+.Q[.v...$_.....7.....v.E..G.r../..:..?Y.B....|.K.....Ox?.f~....S.........d...s..L.....'7..kN....).B....}.v...(....I#.~.^._'.$....c..H...~..).k}.F...w2M...t.X.p...k.K.x.b..7..:..B..|.u..4.Y.q1r.p.P.T.e./...t.)h.*.........i....+.1b.......3T..m.k.....3......k-&.c...s..%...-r..g.|k~g.=.U........L. ?2Q..F...#..4...S.....Ij.-..^..M.....7.S.ZC..z^.W.G...7.}.X}.[..........2.).G.3M.t..=......C....Q".J|;...cAK....7.|N..?.j.G...c....w).v~....C...e=0..v:.........@.)..._.5.$..K?.....%/.1.>..(S....,...,a.V....X.~S.S...=4Yx.P?=..5c.|w..2.w....jG..N...a....../|S...8.8W"..'.G..'....Lr?..K.;.k4)>6........T.Hy.\"IC... .shf!.m.69|...3......k`.......[.P..*/..rQ.F..&.d...T........&.&..uM..?..At....-........|..>..F.0@.../B..r.s..%\........u,y.7g.......l..|Y..!....\K.p.....R\.$2.G6mnI~.....v)xtx...Mq.)#@.'..^ h/.9....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32940
                  Entropy (8bit):7.993578372759965
                  Encrypted:true
                  SSDEEP:768:c7vZaGm2cCBIMFsnrZwdYlwijTJRCSw0XBeWidDVf4kS:cbm2RI4Ww0DVhXBejPf+
                  MD5:27DFBFF27AFA8DEC3250013124395767
                  SHA1:5012DC5F2DCA7DD993FD666674674989D0F36104
                  SHA-256:B0BD205D7D0F3E0EF0A59CD99B3EDDB995CE24DDFF0E176A341500BF1F7B392A
                  SHA-512:24412D6B1E48C22511ADE3564A8917048BAC76701DAEE040D47A7211E79EB6DAB010C64A0244021D806C5E92F7F1E36761442B62C7A5F979AED16ECF988E176E
                  Malicious:true
                  Preview:xT.S..R...l{]5aXL...S...Gd..$y.....-..o.8...w.E.@sY..&{<F....r...&............R.y=...4w.juD..P....$..`G..$.Y.1(......hd..t9e#{L`!.B^...d+...W......$vK..9.k=o..Y>-...=.+.q..nrE#.[....."....L.lR.....O.`.<.NqD..N..:....T...H..h..... ....A...s2.Sv2.^0...H"...[....Y#..a...P(....u...V.l....E1..J....`......:.............J.p.+hEh...m.R.?.#.8...afI..A........._.:..L.;.L.,._..T..`.t..$Y..jp...E...._....P59..pe+._y..(r.....R.T...2b.e..v..1...c.T}/....1....S.8?...W....0....7...WB`lV....:x.......0.......sr....#.dR.........n.6a,.h..s...7Z.SWy.B)...{..._Sf..j...j.....\.h..p..R>.<u...}.AZ.m.A./..;k.5.,.Thg..GN)'Y...k.e...Vl....}..o,,,..Wm..G.O.R..C.RB..I.@...2.."...2.w.....A.a...(S.'ff.Q.e(M..~..!"....r..M...x..=.V..W.....>.~.zX....N.F.:.$w0.1..s....!..e...^..C.y........S...0....j.[...%7.u..W..\....j.4.f3...R.#}.....'....9/.X'o...g.*..Wl.X8.(...."..V..K.>4.I.`.>..P.z.......,U.z...."...I.U.I.)...;....`.C..a.3.H..0Ca.&=......?0.DX=.{.H.1.g.....eEwi...r.i...hp.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32940
                  Entropy (8bit):7.9941106178129795
                  Encrypted:true
                  SSDEEP:768:JvXK4prK3Gh55UDUXwPWZG3vbijkx9BMF1YRKI6ieKmxA:JvNFh55+UXAWZGOo9B4W3QA
                  MD5:9A4636A79820D684E47FDAEDA963A03E
                  SHA1:AD97EC84064337F3CBDCE572A34A62162652E53F
                  SHA-256:DAD4D455D970932E8BC4F13DC276038A307A0E698C6343D0330AFCA0DD49A819
                  SHA-512:7D0183970410DF5EDEAA19E817D5A3D63C9296BDD6F68804F8E80173CCEBA8AEB28C08C2368C074EBACF4B4EF113B2E4FEE8681B7F3DC445734E3ABF7BBFF6B0
                  Malicious:true
                  Preview:iS..H..M..{.kJ....gG..{n...0V.Rkr."!..X...0.,t...,+...w.....i....l...D#UX.^#`...T.....H.N.W..Gf..j.=....L.y....u....b.g'...?.#m....&.......37-.....o..~...+.5...o....*..&e-..%...~.J.H......S.....6J..\....o.E..W.....b}...P.L5..p...W...A...h.\.~.pu..:.[Z...J.&.......h...-X....]....).f.[..w..S..|\..........c..5-..UT.NK... p...$#.B.P...x.w..0^._XS...K.m.xSI...{.y.\^....//.......r(l....2.....Z..C.....B......5v..H...u...}].qQp..V...Y.e..6.a.3..S.#.nxh.y......Fq.....W&..<f..?(A..G]I.t...0!_6q.....~..5.wo.....tKa16v..m*.G....IP..X..gl.j....-../...W.].R...T.h08..(+....6..r6s..>.......`..co..}.......>..m.C2../...~R...(.N....TrT.yn..f...a3.....4.u{.2.8....v.0-*.U.;........F.3....Nc\.9?.ml......_k..[..;....m..ga........\..VtM.......|9.....*.76pL..;..yuP.......-O.*^...Gp8+NE...tT....'...,'.j.........t..,.c.C..I.6u.y...kH..5...4.|.......Q....C4&y.4.[....vh...E-.Li5p../..$.US.2Q..WY.B.N....6..]..{.}....J..lq...V.D.~..5L.....+:..aZ.:..\U...k..ZW@.1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33774
                  Entropy (8bit):7.994251234307311
                  Encrypted:true
                  SSDEEP:768:hYa1sIqajPyBhWCASQftcGUfKRK4KzBYA3pCqff58CK:yJfajuhdMtcvySzOmCCK
                  MD5:497398ED978D26A4CAF108A489573282
                  SHA1:AA759CEF49F6BA15060B60F5A1F791A85A7A4BE6
                  SHA-256:86505DC93C27DAA144F1B072F006FB4047E1C8EE2FE947D7E0D7DE7F11573FFB
                  SHA-512:8336B6DCE59566DD76F1B6545C5109B3BC1A33EC6AAB6A92D1B6D9C1AC68E69E32DAE6145CF817609E41DA783C216E7489C36509CDF070F441079AE0D643D322
                  Malicious:true
                  Preview:.m.8...[5..V2N(F']..N.a..O.....8...I...b..(.'HW..?.....V\......,.S..$.........E..F.h{}-..}Y.v.H..&.4Y.:..T9...CN....oM.iH..%.[...>.B.g...1.....0........+q.>..].h.G[=..g4..@F8.v...z..a.4KYJ......j.2x.Wg.9F.@...{*.e......2>...X.U:...j{#.t....w.).H.HB...(....Y.pl.$<'....... ...(...\......)....l..N..4....H...?.];......]9O..$...i?.$k.\.e....?..O.......s..V.]...b.....I..|....s..'..:.*....q......eS7....(E@. d%......Hm.......D0o..,.F.....=P.pv...6.I9.z\..l...O@....h...j.Rb..X.n.....!o....3<...p.E.2.....H(.4.....PZ..0...vN.gp).3(.m.[\....Zl...l...$Gw..QF....N....e..<*...b%.Q.n.S[...sie....2.5I...t...djLa.|\...o....vE..~.e.L.O.o...'x.=..M.\Mh.T...s.....A.q9.E'h.......G..o.l"..).l..KH..j.q.].N.q7.j.z.O..\p....qU\.8.....L.b..}.).)6..?...V......;....B+$.+...r.=.u..*@6./......6.t.9......E.......:3B.....b..<R.....>@.\JXo.....:K...9IBK.R.....`.mNMk.g......q.:.&Qk(.{.G....y\.....M..9..&.HXz..g.R....l...e.{....K..r...wA:...` e.b.e8:...I.....3X4Y..m.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33774
                  Entropy (8bit):7.99493555323485
                  Encrypted:true
                  SSDEEP:768:PCYKC8/Il8CKgD5m0cQpteWCxPweF08FcLpvzPx1+:P3rFbD5m0cQ2WGoa0NLpbj+
                  MD5:90D12E094BE354A8DF73489A039E6FB3
                  SHA1:F9FCE7139A82DC3927B8E6CEC73184EF5CB59170
                  SHA-256:928339BA20F09AFF85196CAC69BF5ED4F7F402129FBF6D7DF858FE81D1F103B3
                  SHA-512:88589944A4351617284B8D17EBE2AF475EC4A39A8953BCAA3CDFC43C7833752A5FF28960E3CEB8CB7A8122FFDA72DEEA51A46A8EF717AB1E207F19007A07FB15
                  Malicious:true
                  Preview:...9.q.p......).K..~OU...].h.'\a..u..$.M......_.F#.../...W^..lh.u.4.@Of...!.-.=.!zeV.w6O..9,<.K2..Tp:......,...#I"v.=..w...it....0.X...]6k4o.~.Qg...R.|......Q....^.S..j...h>.._u...pVI......z.a.....e.4p.`a9....,...O?Bd.*Iw.#|X..m4E.....{'Tu.b.q.......@_...R.....N.6+.tSxsZ..7d............8....q.......hg..hV...R.z..z..3l..Rv....2d...:m.X..P.R.6.>..^.)G...u<v..5.#.._eUX.Yq.B.y....\.v.V.T..w.....0_.?g.p.4T........\i?..e=....P..l)...E.g..#k5........Z..3&.h..G39.9....{.....].U|!..!.C\.[..1WY3P7n..1u.`.m.Dw....1'......M#.7...!.;J_........Z...u....~..5T_.l.}.N.u.U.i.U...b#....~.<.0......8:..../.=6........mu.j.1.........3....'.......#t6.......&.........z ...A..ou..."u=...\Y..8.."...;n..x..."....i......U.h.)..Z..v^.J..r...)..=..AP.Y[!(..Y.....7..o.G.J....l...&.|&..:......f.=.<.....$...!`E&.....7...._U_..m...J.Q^.l.*^...L.f...E.[%A.DV.....v..~i.......A.2...g.K.............F.....Xj..O...Hbs.........n|:V9.O.d.....F.&,....=...-.Bm|....{......C...ua..jS...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33744
                  Entropy (8bit):7.995115695590278
                  Encrypted:true
                  SSDEEP:768:iSgg5zOcute0jDyTd2KwH/2dTyHl3Hx6Y50exFnfXOh4T:iLcuBjDyPw02F3HxB0mFvOh
                  MD5:5B8A4B2B047A75B103C7E316C95065D0
                  SHA1:3B49A8CFC0BBC6C36AFD7B2BEB3DCCFBC95384FD
                  SHA-256:222B614114624F929449D7DC5936552AF6FD22C394242B7833DEEADA4EF2AF50
                  SHA-512:57A58B03806A6D5A0129E6106DFEE15D7A6D0DB5911B33FADBE557A0A9E8B6DA15AE8E667E137F902CF5B25CBA2D1C5DB909AC45D3497D99A7A593E870251DC9
                  Malicious:true
                  Preview:..-g...ZO._.p.v...@.*g=R..\o..d..u .yA..b..Q.j.w+....j..e..8......:_.~......V.e.[F65Eh...V....P*.F.~=&.....I......|.B.-.I..y.u.5....9.4M...j[.,..t.)...&v.....`..D....HK]..og...4).....$W..Z.d..i.p(..k.._..2..i.2:.$#G._.....ez'...W.|.Z..R&2..i*Ch:..x...Z.Hh.8[....D..+...5*..U~=.DxC...m..._..q...c.Z..z.m...r...Z..?..r..../.u....6.f..C.g.u.#..}.D.)...]....Y........%l..C.>.2.s.......[i....).m.....\.J..Z4^Y..c...P,...s.MP..e.....2p....*Q...%!G...U...*Y^...x.....P..._K.].A_..$6...N.1."{~(.~..k....s......T.f...: ...d.A..6....Zz6..l._...h..Q.}...m}....Nx..b .>A*..Q.M........I\v....5Y.S.}d.S.rJ/.......M.3.!..t.$....j....\.l.......!qU...-8q.|y7uq..e..0;.@P.N......%.....e...MK.V....v.....w}......(..&.s.F......%=r?.....h........q...D..!.-|...PNx..........f'.{.i.4j...J...@...f...o...v..{M.....\..u8...M.:...x..dD.A..V.HCp.5....x........-.:...gq.. ..Z..m!~.S..7...{-...W...w...@.Z.|_.Y..]vW"..]...a...._..F'.+7,.....rm......Yt,v..u.;J.DUn
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33764
                  Entropy (8bit):7.994480669685054
                  Encrypted:true
                  SSDEEP:768:u84HWmVEQ1rhbdm2GkN+ztsoKqZAJs/uFd5vok/GAPJwG2KzdnsWo:u84HWmeQ3BmtB2FsuFd5vokxP2CzZsW
                  MD5:A7C2F84944CD7C0D3485F7F13FC1B56A
                  SHA1:FD61F70181E126B9F0FEAC4C3591C13D4F2E939B
                  SHA-256:F4805B71C7D07DBE10FBFAB495B1864419EE9904602ED5A912C7F705B564A849
                  SHA-512:58EB92A6BD27C64D0FF62807034D156E9A6DB0ED76E5AD9905D34C596B497308AE0835018D301D6510B7ABBB44D64B95C1145420250BE0956AC7B79906987E01
                  Malicious:true
                  Preview:.e.nc...=.......);..3..R`.k....k...."../.@... ..3.....B.L}.lH.g.......).~Q..}5z....S..A5......E.......4....}.FK....i.Bu.v.H..u.2.O...#...(.Q.... rI.t.qo.5......5.N._.=..z&.O.._>...Hs..8.B.t...m].H)...<Q..t..t..]...]..R......ZfcF......P....+....CrE..b..QfV/M.:<fV.}W.".q..<*..M.mZ$e...3...%...r.L....^Z....$..!1L.C.....%..Ml.<"....)..ZU/.....]d!0.).8.."...L.[[bz).].#..R.. ..D.D/0..L....?..C.......o...K.Q....O........$*.ld....6..,..'..G.(........<c{`.....b.d....k...L.x...N...G....P.....1Z.N......k.........D..1.dwh...w..{3.@uih.Zj...t.Z"v...\e..t...j....D.aC.n[.*|*(8..Y..1.....B..5.i.#..T.;.N;D.y./v]W8.!.J.$..C...E.=..1....>.vnT...wO{d...l.......g.-.D...7...6....}"....F]1.J......5)I...-...k.5p.mp..W6.}..Th..$.2).]\z|....Y.....M.....!5.....Y..P$+.H.F..gb.....2.d;.b..e....)....f..@ ..T(....t......7.....W_.|.X.+Y.x.K..R.>M..'.........fD.L..F...l<W...PU|.*h.}.*..Q..~.DwYb.}U|h940..w.<.,...].gX....Ld.b.(1........-u..r'P-.m^.......JC..12..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33764
                  Entropy (8bit):7.994517116337907
                  Encrypted:true
                  SSDEEP:768:Bck5PTtwicIkuML0u6W8rKoYrZOusZB/ZQoUhLSBnNo8pXvPcfwhnyqqY:WkpxXcNwuEJAZOusZ3hUgVNhpfhhyJY
                  MD5:11386BBA506A20A7519EC67F60AE308C
                  SHA1:12B20D1A2D95A3B0860E1DACC8C94BFEF1C436D4
                  SHA-256:466A145786583C8A54A0726E55EDA4D25A86CD82AFF73B4315F1AF6F17542C86
                  SHA-512:836762AA70C2FBC934554B21CE8BCA6B1A7429D566817E2CC1E4C70BA1B227DA56A37B46B54EE00718A75C0CDBD722B3060EF3B01777E5EA75F9A6B63D27520E
                  Malicious:true
                  Preview:C`Hn.P..OEr.i..7......E..;..M...S"...X.o6..L.N..J..l.f.E.M.|d...j.....].......7.s*.n5gn.z......R...9XC.K(.qA...Iy.bs...-.t..j.RZ....2...S.....k..........r0P.=.'...$.vm..t.n...\.|KS..H............."!.$z.C:...\......u.5...!Px..f...M.._..m.....rY.tW$(._......{..kr..De.Z:.kP.)[E2'e..eU..**......s...toMz.?.`z...IlE.U..3..%WJ..t.A.._...*...f.b.....AEP`.y.....r4...v.%..G.....2\......r._.s.s.Q\..Ju..e.......G... ..C..>.#.j....'r.!t...z7H5.?%...%.Q=..u...B.2.L.]^L....`...S.y&.... V$.<z...CE2......^..p ...!.#3.P..T.yS;..W.rL...G.)0....&.b.O..n}EHy.0.&.w.}.2V.J..Dc.....;.w........E...e.C...U.*.V.{...f.......6.:.o.I.Lx7.oV...}/%2n....l\..({...g;I..:`.=.J/..H..rA.$..........WE..a......@...0..7\....>nR.m...7XsB.......YB.TX..c...z."B.#..p.f.r0.C-Z&.n3"$&..Z.[..{...JU. gb..E5.....%.A.K.Y.".........,*+.IJ...(%.[j.4.Uv3...).....q..s|.>...|.,.......6..?.....F.\N:...@j,.MC..J....t...P\6.Y...~12...F&.M.....i..V......K`./^.....CF.d.....c...9.LR..L_e!...n
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33744
                  Entropy (8bit):7.994807603036677
                  Encrypted:true
                  SSDEEP:768:1baFrxc/vLJJyVfALgcYTL77yLB5O4oa5DMr9j9bsS:1bcxc7JJyrcYb+bOv9j9bs
                  MD5:2AFB7747DC6786940FF4CCFA9B8815F4
                  SHA1:904D1ABD3826BE7F5D697138857E2C38E4076D1F
                  SHA-256:EFADB643800F60455B2C0512D5AF1CF6A7B2B337CBABCB7C9C37293B21A4195D
                  SHA-512:70456F6C96A0E45188447245E0DF640EB2470980A76362AFE7FFF9EEBF3090FBCE57A783AD37653ACF16AF528B6A60879D42A31C0560079F7780DBE064D02351
                  Malicious:true
                  Preview:B.s.?...b..0oj_.v5..pq......D./P.......y{...K.@.bW...}....>st..5...x.....ok"V:0....!.y.\,....io@uH.}.6.-.Y...(.OQ..k..!..S%..Lz<....;.p...IK.........^P:.!"..k......i&OLW....$@(.........f.X..L...L?r..d...Q....1.t.?v?., ..`..?.f...~.........m)y......\.JS.h.v$.R.f%....7. .....}..w..-;..7&....M."........I.T.+/JH....H...(..^E.....qq...i...WRt...N.4...S.....3.!..q..cZ...C..y.h..p..Zu.o..o)C.T..F2\D~.p..W&..;6'.iNc.5...'.7..a.;..S......+.zt.X..|..A^qQ4.Lp;O.........X..-....u!...DR...=......I.g..4-.u.I).....\.v.~Ew.$[..........r"..x.RC.Z......^..:3.bd.w2L[.q.r...I.. .......m/..S..?.DMz/\P6H.V..()KDi..-h!..@..V1..y7...m.Yz.3.wK....Y[...-.2........&\.c...l........I.Y=..z.Z...+.'.It......d...6.~.1.mp...*...q.uk..P9..x.3O..A.P*...C.|.......r.%..$......s.....<......I..A..JAy@B..N.G.M..}...i..^.t.t.,Wiw.z..7a.kI..e.0w..1.6..*wag.e..#....P.F..HS...;yBF|...B.0K..1.....xI..a.WK{{...V...R].,.EC0.....C.3`<...M?.`...d...^.E\...3....p.I0|....K.<...&k.j#.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33764
                  Entropy (8bit):7.995178553097767
                  Encrypted:true
                  SSDEEP:768:zjTsIRDomDb6VSIVq65hXmJyVP0d2LkelzOGBZ+0I4v9V:zjTslcMSIcq9A2gel6GF
                  MD5:4CFCBCBE1F2E99CC661BF48EAAA37F09
                  SHA1:1DFEA719BB3242AA465E05408D054186FD8C8B04
                  SHA-256:765B7B38A022A86D10613E8F9892C4F3350404E864D432553F46A81664B3A4F7
                  SHA-512:3AEF9105FA0217BD2D956EB6099FDFF3F5DB72714A6FD7BDE77BB114E1A6A20B66F0DCCDE284A03FE10685A829D443E80582C1038948DA33079786343B076385
                  Malicious:true
                  Preview: "=......A.......Tb...Ct.b...0)=6C.ZY=....k..wl*.D.|....9.%......C..z.1.rFB..~..:..I..".w.E.N[..N.b]!0...........WRs.7..;.+.S....Y...K..K...<....2..!Js.4............:8.e.h(...H..x.W....|Z....3...Gx.`z...:.h.%..y......;..1.kI.0........x.fT..x.h.3.|[.7<.....+q[.?,N.d.."}|5...wI...A...."Zx.....=...n.O...YK..8.v..G.#.&.M?=H..QM?...yB.`.+.`v.Q....o.u.X.%'w.q6.XY>X....8.d.v......8V....Gj..]l.-=.......$..+...U....D\0eP?/.q.'k!........Sad..p......J..u...R...2...i.o......1..>;}..%>.e.{.....mb...?......|ABv"....o.Tc....W..@.....I.B.00T..2..]K.O.*......n...E...y._6......=~4..1.9....[}...7Y.I....&L^^..]..[}....t..y.........9...BjY...Q~..bk..V..1._<.J.....N.(.P.....E..*.mjF....~.vz6'.<....1.X.g.K...:....4py=..$...4YZ..r.....ra.y%..........V..(....L.M..W.[..$..H...........M..gP]...".=....c.b..X.?.%....@rMI...,.h\..@..b.6.....a.yr.._.Yl.DR.."...o.I.d...E.,.f....nG..p.3.p,...../h...?.v.B.>!0..d...q/...}.J.`.?..M..`A..l........](.D.*c......T.3...^.e....r.R..sU.)
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33776
                  Entropy (8bit):7.993757122605708
                  Encrypted:true
                  SSDEEP:768:2tF256VD6jIYgjSeaqZdNr+toffxdw6gc+HIyaXQ6:2tFeoWI1l1hffxdw6g9H3A
                  MD5:9B5A9CA8B3253C228D1D72269DF04AEE
                  SHA1:C3AEB53FBFF31AF11BDB2F3D78B5B2ED2C9B89FA
                  SHA-256:32D6D7C750A671296CE64518585E66D9CCFDDCDC0FC2F620D024D93F571591D4
                  SHA-512:3A1E3E95D0AAC89E0191C12951CED631BC54966BFDEABBC026086B4CE103E058C6479FB7B3663AAAB9D6A773B67EA7B1DC061D997904F87F95E1BBAA23EC9002
                  Malicious:true
                  Preview:.0~.......w_.'w.-..o.J..|"_w.v......Q..7.R..6.......R...;nj..V...+T.a..?...{..)8LT.fW.8...'8C.U..Hn...r.^..+....>.|..I...2.s..et...........'l.q...ik>yZ`L....H...i.{yx..8*P.....l.m...*.'Q.>:.....d..T..H..Z\.:R....1...$r..r..e-........D.+..a..6'....F..@y....&..Y...E.?.....^...DH.........lc..,cv.(.~W.qG..Z...99.69\.JZ..o.L.B.5......o..f..!I...a.O.TK.....<.j.h..`y.!8fS..p.t.;|.c@3b-.C..FJ.....K.1::...x.....!F.U..9..'`..{.d.s.QZ...u..V.n...Q/...8....S^..cQ....x.J..CW,W.......a ........Z.UQ.\..))..-...#.jA.l]Z5N..$.].7..s...b.`'+.k.Y.....0).=..<&!.;..lW..V..(..*..._3=".S.6.............H...D.WVVl....'u.:..+.k..X..........B,....M.p3Fn..2...C..&^f.l.Z..SN.U..u..~n.dpM,...B..sZ^......a....1t.M3....:/l.........A8&4.I/..>K:....o.wiY.K...xp.e...7BQ...xet...y]d:...W......^_..m...........:.p^..o..I..LO.b`.C..K(I.".[.....*"0F|...{k...+..mpF.].P.....3.U.M;.((X?b...:.j..&..1...md.....G}.Ik.w4H+.CQ...#.3$DbA.."\.]6b...T.X.d.(.:"Q.$.U......"..9s....."..K..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33886
                  Entropy (8bit):7.994566777108
                  Encrypted:true
                  SSDEEP:768:I+8ZSPF0QmIxPfN3Obu+9TOWQIF0odxB/:I+8ZSd043OqakS0oN
                  MD5:2FA5B03C93C6AE8878E048112779B60C
                  SHA1:CC5453CC98D45C9602B2F484255DBEB6E3CD7C4C
                  SHA-256:09A614AC0190EE9AAE20BF4FAB7E1035D5FD90A964EE0B8010B5FCBE5F515075
                  SHA-512:07904D5958C67545D98866A8740DCF8FFEB3F7C34515A002E0B5FA0206BD8D4D859AFF085BB9217884AA0B147A472FA09397A13EA50F15F2E4ED600745E59C5A
                  Malicious:true
                  Preview:&.|&....B...hzJ.0~APM..VE9.0.b._.F....n._.ll.*z..0)...8f......<". .."h...\.>a~.\.F........>t.J...i".....am..7....[..P.x...8.j.o.[]x......!....wF8B...f...7..o..Y~.B/y.t..WlC.. ..d..s...-..Q#...0~,}...k.1...>/B.....Lb....*.x.z.U..lw_<........YYY.hj^Gh.5. .......#.0..$O..S...2.E2p...+f)..o..g.vN!..).!.1...+.O...!.f...1...A!s...;...#._.^,qU#..2..N....\T.w..XBMG.......~..#.v..#..V.o.}n.T.[.t.5U..Qfj...uk$..'N5....x.Op...V.mcQ.......::.R8qil.+f6-.vO..=.b.{o...<..........$.#... j......a....+.V....g/.~F.3.rB..H.q......b;....|.H..h...tGB....$...(a..c...l8... P.....\.F.2......h`@...v.QD..j...$.x.T..l..Q... *Zp......@:.WuY..7..f....sp..]...l.9..q......%OW...N.#.o..upB.dB...}.m.Z...r:3D.Y.....-b.[....o.x.G.C.h.Pye....).D.]e...v...{.'K....g[....g..N{.`..$......&.M...^.;Y.*....bq.GI..L.Az.X..,..".<.e.......p..6C...<.F.......8..>8.u.`..B........C.)..Y...6=[.+&..U2D...4P..%..w>~.:..6.3n._W..E.i1...O..l...rnb..vA........_.K.$TS*....w.....&gQ...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33886
                  Entropy (8bit):7.994964013900695
                  Encrypted:true
                  SSDEEP:768:pnoP4j8oydAVUoO/q99IjQWjK5w/rolUqdsWMBxM8gtdKUUvt:pnoP4jlifMTIcbw/CUXWwxM8gfut
                  MD5:E28CBEC04A5402B2DF32977655CE56E1
                  SHA1:02F8D700528FF65943DA60C50CE102508638CB43
                  SHA-256:A1080A74C9132711AB829634D3B6BF4D90F911E676F0E161B599E2CB7F388B5E
                  SHA-512:3D003BEC11205C3171171E8A1FB4A6B433BAF2E1389A426BEFEB5D3C7054DCF818D2C32219D2B275B22334E17573F3F81116EC2D766E7BAF197CEC15B3ADD216
                  Malicious:true
                  Preview:.C.^Y L......[....q...V...&.+.h/r.qo79bJ..rl.v...J~.T{.7F.A..A..rt.0.Ik..............#...E.........iv0...........S|.*.$......\Q\...............y....0.$..&r m."C..?.^.f.c........e.&..<.BAm...L..5Cvm.w$.|..8.Tw]....2(.o...+.......D.).g...?.&.~.9f..a{(.......OW.u....Ax...R..b.9.8..B..q.I..^t........u.k8.}....<..p!..V.Y.Q..J.w.rr@TX$.._.w..p.z.f..=..."l.^..."J.[..w.[.\.^..(...&c.b]...$..qo.-[.;9..K.#..VA...FS..~y./.*!x...c.....AK...G..y.......P......(..7.:.Q.T...1..x.?.K..r.2......R.4.\.1"...=$..T..`?.....^[.......3.n..;...|b.5.i....)V..6...[...G........n.h#..j^/.JN.).Q.L*... .1RX..A..Uo..+G....B1....S....C6.Jx...8./../]./JjI......:...n..w.......B..s^.D[......c}w.x.nY..:..}..g..4......kc0T......v...T_@.q5...W"<.....#.\.e$..f....Z....E.....0.t.7d:'.$h.JN.d.O.oH..F.bs\..).f,D..'.l..MD.-..Of9....O...q$..*.!%......?]....ZC..~.M.......]9.a9P. ......o..L.+<..I...s8.OxN.?..o..)4.+.t....].q..QZ.s.....)Q.....k.M|.3..h.)c....'&.-....W..F.n..5....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34000
                  Entropy (8bit):7.993136488035534
                  Encrypted:true
                  SSDEEP:768:O2JPWZXLHf4AAr1zYZijsLXBzBmkAf++xmu0S6:O2JPWJL/erO0gLXBzBg++xPF
                  MD5:08AB9EC8A6D841CEF1CB0994A141F03F
                  SHA1:A44508A9EFC86DF3E057CBD04119AE4A5C789786
                  SHA-256:F1E3005AA0BD04B0AC646FD88EA58A1040B36084CC662BD3AC2AE797BCB3E420
                  SHA-512:821F05E10FF01E2BD4624D9B9D0C1B9DADDDB4C5318EF0B125C9DB544CF8ADD6A0E48EB4B8C5868421CF045AFD3C030918D292256692E3A300D19B6D6D8CCC3E
                  Malicious:true
                  Preview:..O.^...9+z.H.Q..wt.e...g1...Y[.%.Nr0..sL..7.a......:...o8+.@x^..].......O...n........0V,......w...8&0.3.........J*.73.j..Pa.\.m...(..8"...s..]\........Kc.\...{...Z$|..E.4.N5.s...SJ.a..1.....6[......#...eD`E..........9.*teI..E.......4.$U2...C.1]"|..%...>JN.Z.@.n".......Cb..EZ.C.'.T.+a.wo6.......s.....yme&4........b....9.....G......4.....Lpb.. _..-.A..@.wH)_.....\.....k.z:......p......ut.."....R..L......5.&.PC.j.$....p....R8a+.\*..&>.....Dj}.(.........4...K.......s.8..0Tq........N}f.N..&Q...I8S..1.........e.e>f=2.T...._...Is.*.n..n...n..[.`..R ....8....FC....n.ZK'..Qz;,.[....(...y?f6...[........}s..S.O.J....O.P.m.~.p......}."F....O..Z..?..H.........G.R(.....c.pb....<`yF#....B..!2..])..O..$.UMIS".;..ek..u...r...t.h.u.DL.........oz...U..)4.+..s...}..m.J........_...L...>r..<...h.A..:H...^..'..1=..B.IY...{...e.Lc.J8..e..VNh.q.t~..1R...2.nh....?...3u3..{l....cz.$A^.....3.O..F..l..1.....h....$.kR.P..a..L..hc....\d..9.fO*~.....F..}...a
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34138
                  Entropy (8bit):7.99446258495454
                  Encrypted:true
                  SSDEEP:768:4HbaKKaBuMuXHQ67P163P2asiuYZ52RyOhg2OrVbIADSz:4BKaBf+HQ67P8oiuY8lhgv5b
                  MD5:03B35DFB365F4FB45F51A5DEA824ED9C
                  SHA1:83F880D3699F604F20D8D96C8B0DEC359007EE01
                  SHA-256:F4AA728333494810EB6F53436965E588E950D813EF0C5330D8499E17DE21FB95
                  SHA-512:A33EC6C20DFB675766701BCAD71FF565AEE74FC2E766EF53E40425E53C0424F32793D303776F59CC9C093FD113EF813E2CD587265D98C804EBF6F64F45A41270
                  Malicious:true
                  Preview:p.....t^.k.S.Q=..\.5.Qlu[.w....Itj...JI.V....r.`..tl.q.?v..;.......,...{N....).B..{."..%.EX...s..y...W.G....V.Z.....X...E.+1.q../l.).d...a...&.B.P.m...Be....../....'#.M...7."R...s.u.2WG.VW...g.....%xUO.1!^...KQ....a.y.w....9q..T..aB.~...8.....-.'6....(.e..Y....oW..C.....&.qK..aA34.x|...y.h3.c.!.....Ym..OL.[..t..k.-...m.".oM.z.Ya.A..5|......8.Y.b...Q8h...bH..b..*......L_9..........B.lq...:.....T...%:.Z..g4.to.A.U}....}."-2I....:.c......D.a....z..f.{7n..._b....r$..4/......(.p'.l5..4.I..T..w.n.di]..$....n(.#...f.Z..3..n.p[>uX2v`.)T......J.6.....w{.+.%....a..`=..E2.X.52..?.g.....4...F.*.....P..qj...\4...`...'...D.G.J..MX$Ej.&.m8......@.kb..HsB.p....V.{.......'(..:1.3.+.|sT........._)7.)....\*.f....$.......W.("..+.>.,.5{.0.I....b.....eV....9..RF....[......&LP....8(...a...w=........,.dx ....}..a...."...m..j.k.T./..x.~#U@V.<..o......5.....E`.....Vuf...F4;a..#.:.......8.._.VO...jm9.......4.s+6a......E..b...;`b.0w.v......-|.F....$@...(?.y..\
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34148
                  Entropy (8bit):7.994990002483461
                  Encrypted:true
                  SSDEEP:768:qt82OwfmMHhsH5TAa9jAnVikKBl6KQK+IYuzuYJ:q6k145hhAnokKB6K+IpzuY
                  MD5:B11F5B17AB888DB212BAAFCBBF5D5372
                  SHA1:40BD32AD776D77C5C0B4CF32DCB97626A3CAEDB0
                  SHA-256:EA0CC0EE2EA9EE31F8B0544AFF77E2490352F73870E31270285989830B2FB123
                  SHA-512:26A3954D7B964B84037051D4BA0E2A08BB1329CE21B9267C9044BF8FD819FD331A14B65029CF0D6B25FDE04422B2406B88344FFAA17D428B7A82163E890DB7B4
                  Malicious:true
                  Preview:...E...p.o.\...\-...o........t9...N.PF.{.x.......n..IA.[7._...B..k(....a.....?.E..AF)...G......g=........E]..ip..#...f...9.d..6.$NB&P.F....)......h.4.....#^.".3a....>2{..e_...B.a.s 1...M..n%..=c*(...9a.Bl..7..'.-lkv1..|......b...5".v'Y#w...(cW....#......Z.;vKUu..KNPq..V......=9.f.R..o...1[M&...rZ...@.6N_. }. .SGO.....&i.;g...Ns.:...RNPDb*......G..4ha....-..j...i...........2.....<Op.|^..m..t.>...0...3e~..\...Y...o.O.K...`.,;.!F.>. x.c..K.....;...5..tW...#...I.2v.n*.....G...tQC....._.v.W.Hs..DM.../)...u(2.C}..o7....=..z..L....Er/.4...........sk..b.....*.1 .C?...6...O.....%.c.%..W._....x..u..F.kI..N..w.+.F{6....u.%..6.e.CY\.!Z..e.g......eA....X.,.s...=...U.......r..&..k.O/o"..y...1...a0a...X..p.$....h.f...DY..G....z.C...RCiPJ.au....q.$({.<g..T.]....k..t..!l"......V.DK....... ..$..3q..--...vZB.@.M...:%..v..6..>...J........6..?.c.L./.._J.ev0...H.z...y...........arj6?.A..?u`..4.&z.4.4......>..h].R........R].z.g.r.U6!.S.Y.]......:....,..Q....P
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33208
                  Entropy (8bit):7.994507614632388
                  Encrypted:true
                  SSDEEP:768:A6SGQN2CzBnaEZ4JlXPWawqLMf914jlEPYH20a:AQuzBaEZkXsuFQYH8
                  MD5:FB346ED9FDBED07EA6718207258A43C0
                  SHA1:B4569A608A4D90ED494A859025B02DD943091E34
                  SHA-256:A75DD95CC2D235A0446979356A65142535AEE1A7696CF7E16B07802F38FE8F83
                  SHA-512:DE6759E35454D3183305AF895B25EA012AEF07905A8F3C34ED9CDE016E7BD7C5FDEED44B90B718B2E77F89B04BD3B5A61240253CA377A48BBB8CE8C8DBC77F42
                  Malicious:true
                  Preview:.,3}/c.$..u..*..r!.J........>......z....R......$C.E....=.3...3..&.........p;.....K9.k...T..R.w#..y..Gi..$.PPa.Z@t...W`T)k..x.{o.e.zX....2.T.........XL..h....;I..)...:s.g.a.tuk.4.%S..E(G.3.~....0.................d.7.+Ie..+......ZQB..<{.R{...N.%....u.....-.z...X.....J.Nx....W........=...J.2...J.yH+..h.d.o U..fx{.\x...D..Ay.2....$....P#.....OI......#;..OpD.Y.8....(....d.0...K@..>:Q...v.b.p..U.8..q.|#...W.'....8ej...(.T.C.....CY.{.:.3......h..H.....u.....z..._..fC.0'`...e1.b.}._RG..`..T....=....@....3.6.....U.#7?..E[:.;t\.u,...0.^i._K>.c.."/....(4..X..p..rO......2....%..g.~C.{.5.W=.R...+.3.....i0..r..s....+z....H`.w.....d....s..&&.......5....c.8.......f.S/m,A.....e...H.w.b..F.QSHg.........U5.6..;.B...Jg..jj(..>.VEW.]..=....7...t...%@..I.,.3K....+00?...}p..}..<.G.s.=)..q.....+KD...;.p.V.Mn.......<.../HR...s.....,ue...H.N.c~...#.K.pq..........p...>z.W.@,."......~.....QL'. ).v..5...7yQ..V .-.r.n.......lY...1]..K...F.....-..ee+.${.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33208
                  Entropy (8bit):7.994667839826571
                  Encrypted:true
                  SSDEEP:768:a1vieNIBzDmCiS7Z+WKlYu7IFcjfFwVBFHCDmbB/1VaUA5B7JNq:aV38mCi6RMI+jfFwVrHCOXaU
                  MD5:8D2C11053B5A4B7BAD788FE81B99ECBF
                  SHA1:B3BBB0504CAD154021FD01249A6A509F36B3E417
                  SHA-256:805306FB180436AB24E537E573FE9C90956EC20ACD1EEF725B36C26B334938F9
                  SHA-512:48844C0F0668D69C853694BB8531DEA90A0EE33368E2659D0AF51B849FE26CAA0D295EECC63F38E03067148A87BA23F2FAD190F1370ED0006480CE3F8CDD43E6
                  Malicious:true
                  Preview:.;.B.Yu.%)\.....u=.=.!..|..)M2.lk...;.e...b..&O.....,.b.'...sf"D....l.it<.d.d.h$..........*.<.....*.K?.1.L....`.Owzy.+B....'..=...l.U!.%c..a.........-l.<~...c..`...c.......(.%....._...o.Sn......;....(.n)......".........)......Y.......}..1'3h_..\.].9?eO..1..P.6...p...f...n_`......e.W`...v(.?..@Rm..ut.."xB~.-Go.1.......*..y,..Ja.N....$.#-.....t.5E..."+...>G...jW(..M.....k..^......o..0....Z>.4.9.Z]qqL.....v3..l36......Wy..(....S...0...i.kT..8....!..........$..+.....g.B.,..A{PXg.1..=..EF<.....j...w.M.}h..3.n.D"..Yg.a...d.....Y..I#.t......d...1L...A...-.Z.u.4/.fnDx......A.c...@.{.q...hJ{;..o..h:@..[.Pr.........-........@..._r.O....B....2{.I.d..|...9..].d9....x...k."..'.!rp.._....../.........J.v.<Q.$s@..J.....r.?.(...cR.S?..d.e......81....@.....)U....Q.H..'........M.|:>)...ud.#...'y..o..J....c..$Z.xv.[....K.?..$n....(..w..`B.E.QY..>.h.kh.o.2...l.;Q{....J.#..*.i.......2...].n."V...=.(..u...H....l.....X.\w.F."7...f.s..T.6..f.....4~.K)N
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35484
                  Entropy (8bit):7.994425047734504
                  Encrypted:true
                  SSDEEP:768:xmQjPsVyNqBTtkwOFxWlfAP3i9aBzysf6XXaq5WQr9F5fs9LvfgRugxAkcMPsxDt:MQjPsVRWBxWiP3xLsqfYv5fs9L6uursn
                  MD5:21483219410FFD509AA65ED1022058B0
                  SHA1:51E7243512E8B473C30D1B6567651741E2DE0472
                  SHA-256:FE2C22FFCD17B401E57020155FC074C0D9A982B2F777A0B5E798B219206AE77A
                  SHA-512:46D22BA534B03F9ACEA1CC219472CDE41424ADEF251AC9FB2EB356958DB4FE87D86EDFFCFA602E9FFA45E05EE1C0D068A6B1297C29EEEA9561620110D37C3879
                  Malicious:true
                  Preview:.1.....{..........Sqvni3....5.).....F..i.9......3zG....b........)......T.I...W.E.G...@.}.....W.4...[.Lm?A.....n8.?{E..s.3.p.:.MK)n#....-..M....._g/@.n$xd...b......n..._.......-...P.k.z.....$~..F..C......^-....x-.O...}...[....H...x.+....gT.f.....%6..0.W..{....M.._.+...1.91.-f.YY..Z:!....`-.+.........S.........G.>.[C.JL.=...qR.............}....O..LwN...Q..i'...v...J.?U.nh......69...~...^.....s.~N......x.....~k. ...9gA_..'B..d..m....b.gG.$......k..k!).....U8q^}.. .....I1...Y...x>e.B..q....tx..5.+...k....[.!Y.Q.-2%p...;...m.g........1[ek...U.....(o"5...?|.;...J-Q..p..3...JOg.ZP.k.P..\.q.,P.s.q..|...Bp.qO.f?.C....`e.+g.X.l.#......{.X7.D.sa/..).\....C.By..[G-...V....Av. kQ.M....E.....TDJ.E.H... t.g-.....^z..DE[W......n@.......-.q...8.o.......1U-.d......J&T..4].....Eb.J..r.g..../Bw.M.....E".u.co.i...fE......=0.!+..MIK.a..fj.(.L.....Q..y.......q..d..!g40..P7...~..[.+.}.0!.../x.+.q..n.^.=<..&....O...mQ.6)py.L...bFl.&N:....Z.q..CK.G.3/...k..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35484
                  Entropy (8bit):7.9953048116458625
                  Encrypted:true
                  SSDEEP:768:EUPClaJIuxds9iJBkQUywf471/rBVxYDX6vUCHD7ppYsztxyjH0EV:EFmIaO9kkyRx/rvxYD6vUCHDbYszt0LD
                  MD5:13ADAFFB12E3C7AD2B20B0543CFD3894
                  SHA1:30D128542D140C3D9559086E2B78B5873458AB79
                  SHA-256:B3EDD929163882308C25D261935FADE4C77842C5E6895E7B48A14999C24910ED
                  SHA-512:5DB5DFC8FC7EF75A750A793F697F0F6D208A6010559095E179A736DCC0AB6399535B5BF095C6FE4A4C3165642286348F9D11333095537885F07176AAE17ABFE5
                  Malicious:true
                  Preview:J.......~.j.a............^..Sxo.m.......!..8..A....h.).V./.l......].H....o...TV"R.x...e.......v...J...8....^p.I...{..i.|gh.,..9HT..?.pQ.}7.......U{.i....<.p..@.Z..........m'..S....(..5..w...'....jw......I...C'..Z./...`5....=....':...gLJ.z_1..=.p.p@>.L..&e%N..~.v...).d1...r.Q,7...~A...r.+{.P]...3`$_.....?u..M.6..O..I.OR.yG.Qf.>....g{....].P..N!a./b).,.z*.s...{.....9..]&.q......u.....UXJ..^..-.`...R...h......#'..v8..*..&O.8nq.4.*\%...+.......@.m.a.....>..g....;.dJ..X.UG....x2I....q._)...u.......V...b.*5.%.M....ssALT.."vV.....x..3..W~(<.[...w.:..3..6........W;-}w.B<.........K...s....f.{....]...~.9..I>.....|h.%.V...YeE +tY......4.\....p.v..-.m.+.l......n.L..Z...D..q.+.m7.dq.. .7..^J^.......}7.t..R2^.E......u.LS{..I.a..........5.U._.4....].....N}..z1......u.N......L....h...,.I..Q.8.Y..x.xp.&Ic..m.......l.H....h...P..(_u..kf/."^......p7._.9.....^...........ro.s......bUK>....Uj..7.d.....NN.3Ks.j1.G..BeJ.c.........k..1.:.E..Y.{D7-Q.`..%Dx.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35362
                  Entropy (8bit):7.995006902856133
                  Encrypted:true
                  SSDEEP:768:F1xgub0HTRn7wHl8gaRsJD/OmvGkeHP2DkLzmORo:PqzuFuaVWCGkeHP2RO+
                  MD5:7A24B345727DD978CDB9C58E7C46A2AE
                  SHA1:D654FEC001E9C6915F2C0C07BA45F13BFDF4230F
                  SHA-256:4E089F9053D01BDAB2A9D8CACC156951B209408EDA29391F0E796939F99570C2
                  SHA-512:C7813F95B66634B861389F1B47D0579ED7B29DF23D46EEE512973EF1DED0CB1224C0463A84FC6AD2EA61631C05DC8C33C7B98FB52AB3647550B25DAF7B78BC9F
                  Malicious:true
                  Preview:E)........#..[.=$>..[.O.'.%..=QB@z...6.u.........[....Y....L~....G...dD.$....8.._&R....l[EST.1Z..t....Q...)......q....{...{...-Gh.e..c&.F..:.C...E..w.[\...5...B.0..D.=.....{..Z.|H*..Q2..A./u....w...:.2..J..Ug]....7.....zk.Jto*..B..a.|....P.....n...J..$g!.s..X.pe...P..(.y.l..VD....f......X1.$k7.,.2...I`!.T.u.L|..I.!....|.1.g...5..l...48.N..N....mhE.."...E6!s.'F.B.I.C..h.1.n.-.r.GL.SU.........K...Z.4><...+..Fa...k..l.h.:m.B......G..7{jJ....v..,0.tO....}....V{....._O...A.....]4.PH.(=F.9.......M.m.r.]...UWq.Uu._..X...r...+..."...3..>iP5^0..7XN.|..ls......6B..q.M...8*.'..k....`..~X..B.......Z...e.S..We_+.....m...].."*)..#.N.VQ..F..BH.cq.M$.8.k^...H.K......R.cYstY[..cR...odZ>..;U{K...y'.....-SyW.s....Y;....Z.....4G......%....t).._.r.v"SS.-..[..6.o.].pLMjg.p&#..e......3..._.A.....i~..JM`a.d..*.z.D.....:..S"...;......r|h....+!/...hj.....c...[.$H.......B.\( ...r...i..VJ...YC..7.Y ......N.....`........*.)8.....F...Q...T....N...2..k.{..}V.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33652
                  Entropy (8bit):7.994150230124864
                  Encrypted:true
                  SSDEEP:768:a1LOAi2FkUGwzSaOAPeYkqtW1IRhRi74v/F1bwvpacJ4p2tEYEVB5fF5+zX:SOnob9TO63E2hdv/3kry22VPz+
                  MD5:74D3E0B960092398A2542DE878D6FE9C
                  SHA1:02739FA6844BBCD315987473DE5B235607ADF894
                  SHA-256:50F875B46AEBD00B09B50B77F704796C092717A2A74D5A2A219DE2E23257BBEA
                  SHA-512:5FA9F77CDA86E29DB7C0902CB0F1418F372C61FFAC947B90C3BFFCD5EFB9429FAAB333AFB3BEC4C72BB0F5E6663B514EBD871BA1FD1AD4BEFAFFAEB5242CFA7A
                  Malicious:true
                  Preview:..0I..h/..r...L....YDr.f..:....x.W...b.._9...5.z|.U..*..Y]%zF...............J..v...Q.....'....r...-..[.D.`p..j..r...x.H...dEnv.w._..=)}}6..'.=.C8....O.....kxPJo.1l...\.8.W..s.)p....l.aW. .{.|_.v.....>.>..AAP+o.Q7...D.3.P{...v.(.]w.J.Z........f9..{.q .~.E^.....1>A.../..[. '.q....*.{K..vVC...qY......M.=_?t_.[.3...L.?d=.}.$R.t.h.$.k.......\....`.F.2;..rh...\..l..O........9E........Z.Q.&...`B.p..........8U.$NE9wz.}....f.. ..11.........|.....K...2.#.....w5......0...J........$#TdiB.A.b..FWc....].GQ..=J.=..........."...t.......].E.d._;.OO..s...H....^w.12........)..P.M.A..F.!v.\.....{P......V;..Z...|.]=:).Y9!.3E...X....~...0M.....,n..H...4.z..8..=....#..M.}...y%.q.R...A[..8{.n...u3.q$......V.7....pEho.O.X..E(?..q.H.o.d......[.>6.;=.,E..\Ir...3........R...oqp.ca.f.9<..w..Vm.E..$..K..F...m..s9P.(..We......M.........>........>.`..r..b....8z%..b...hS.yct..M...Dr...l...."@........_.S.<D;<..D..U.&.....O.#!r.._....c.w..`.u...*....`.q.C...2....{B
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):33652
                  Entropy (8bit):7.994164767268958
                  Encrypted:true
                  SSDEEP:768:1fUWlzUJg+L2AOYy9BLc6Kq0spRELxqLhFRbuB5m5J+6LMaO:1RoJLL2JvDLc6TpRuCFRbOm5UCy
                  MD5:58AD6A8748F3D79698071140D521EBBE
                  SHA1:EC6896141C9346156859FD92C71D5C671A174B4C
                  SHA-256:13A78F8C5D27D5978219C37E2090FAA9530FA3D77A10CE905EC009654C3F5AC5
                  SHA-512:F133C7B711C3A8EEDAD9048CF0CCA956BF598ECA8F761F460FDF45848A0AD599F3087FB045BFE2F9BED30F750CFAFCEF57C3240D79E3BD038053C26DA1D50EB1
                  Malicious:true
                  Preview:r@.&....C......0Co..`".4`S....##.W..<..W..w}.4....0.CD...w.X.d...0..9.-n.0.}...K..U...%..N..^.(..[2...._x.....p.%+..&.h9]....aC....-m.....%F...........`AX.S....Mo..z#d..Iz.......D$.....9...../......XE...;....!L,.^....B.:.......".a..B..V[..-9.J.E)..j..q.[B.......w...f..f_./..:F....3!........x. ]..$.`...~.S..9.).tG...V...,4.....(T.........K....T.Q.C.6...8.._.:j{...tn!...~lq:...A.Q.4v.@......R:8n"u.r=c........=<...p[qg.O...w.e`z.F.n.L.1..c.$\....O..q`.w.@;.i!..%2...;..V.J...g.L,.p.[.@.@w..^V.?......E.e...eR....&_....C.....g.....vE..D.f.y.}...T..D.....awr.r<.O..N..).F.....[j..........kU.R....$..#.xA....P.......^...?..g.6.` ..#....c.o.O..8P...s..Dul7@...........mTL......`...;.....+0m..P-...z_3...X....U....[..0.fs[...T.;..}..s....C'K+?.B..Oxqj5F..6P.5G.........Ws..q.6......Sz..{......>.:..\.,.=lx.......u.k.......].@~,...Ss)Lfx.v.c....:.j....D@.....O."..K..s.Y..:.....YpX....N...xk?..9.<p.Z...+...E.......T,....d...'J........aOdx./.&.....c
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34000
                  Entropy (8bit):7.99475801957768
                  Encrypted:true
                  SSDEEP:768:3N0tKabi1dMvNBUrRQuZG/0ZPofKAM7YMw+/F9m7:StdkuBUrTGiAcYwq
                  MD5:0DFED4E694AF59594090BCD71F48A517
                  SHA1:DCC77871ED0DBC57F83EC851946404DAB6C6EB40
                  SHA-256:6FFC48CE6076BE0D540AEEC83929842E6EBFDBA4A83AC147E4F6AD28F811D448
                  SHA-512:DE55A787854C439FCBBCFECFA1CD8E8095848DC41E4EB7CCC49A2670008322C06E5713EA2997AE2A111F8382D03DD0870FDF8164F8A0495A5924064246F31BB8
                  Malicious:true
                  Preview:.2*.e...L...+..I.$...d...F....I...x.....T]..W...0R..E..>.u.........:....0"\...$!.i.}.#c.*..p.s...Q.a...8l.HN.#'V.N.(.C}..'.D{....D7......I/....ql..._.1p".AoHV.+2.U6M..5L.S..^J..gD.#]4...@.,.7Y.-.....e....V..&..=.l.;>..QU.V.<x}\.Mz...i.". .....,..1?6g%....??...u..>.u...T.7...g..."s....p..E}.IoW......n..<..F.'.L..v......N...f.l0m....N......P........./R.......N_.....E5..Y..wX...J".....i..@gj`...'z..|%..t..%...Rw.Q=r\.&/....B.......*..?r..)fA~).m.......{.0b.3z.....F.b}s...5.....~|.a.k.3)w..H..'@.X.w....^[..-.Q.....D/vS...r0C.....J+q.6>.DdW.y..YA..77-.g...&w...L|.].....,..%@.,....J.1.\.j..P?.T.5..5A.h.>H.L.KG..8..."...*T...7...?./..X..T...k..2\.y.J....l......u...t.......+...C$5Kh.}[-.a7V|..[....V..j..o.r#.Nf..h.a..y.!........\r..!a....E.(hM.z.z.L9..Y...D..%.:...L.G(.~...1o.r8..y.rUk.....Q..Lo.....01.C.L..J....^....{h.u|V.q..$.;A....#..a}..I_k..w.<....t......0...(.L'..(.Ir.....6Zy..S2z...$.g2...U.6cO.X.;;............z...d"Y0.#
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34000
                  Entropy (8bit):7.995029676567278
                  Encrypted:true
                  SSDEEP:768:x/i5ATFLWQESCv/1xWh1WL9GG6+O7xNhAYFfCz1bCHxhTQZdtzNpZ:065PpTi9jO7x319Cz1bCRRQZj
                  MD5:892FDDA94907FC6EA82B97187F20BF23
                  SHA1:DEE28881B3B445B1D2D58CECBCB0DE8B3CFE44E6
                  SHA-256:3AE701184A7C1AF76AE7E0AD7F78F9FD53C8866D8541AF87E53BED23FE040605
                  SHA-512:3309C72B6995A3778CE73E1AD2371E82A38057979DF56E436360834C3ADB547053EFAD528C7185288CC3304DC2FED50E6763A9A1895909A4B98FA80A762850BC
                  Malicious:true
                  Preview:.gl'H%..p3.j.b.j..[-.x.x....$>.<"C.sZG....d.nj....Rg.-.O.......... UE.,..#..*1.*.b..P9.o.Hxc.zL.-.,.V..I..I.{......N).x.!...+r#H..+X..Wrp.o.~!T.....DV.q.g...>..W.AZ..;(..[p.T.l.Qd..W..y7......Z..q.-..J....8\..I1.w..-%...y......od..x.+.....l}....T.\r .H.x.d...V\.f....!...M....../....a......P.a..9.[..-.H.bN.#.wv..q...g].j..........$....vk\..z.....&4.....9.?V...~.*...R.M.Vn..& !..ul.L.[.Q....".N.z...\..k..+..8..I.S..m..P.S|..8^[H9"....a..b.........2...}I...._..i...o0.g...F......%....y..\...;...?w.a...........oe..T...L..Q..D.Z.....qG.z$c.`q...P...H0..D......IfK"T.=.........d..(........m4.s...\....G........e..|......7....u..&.aS.bN.F'.!.kF.]x...*r.=....s..../.'.ul<.T...92.U..G..V...3..'..<..|.#....W.`o...[.......`..tC...S......i1.../~<?..vp.Tvj~... .J.L:J#a..wJ.......\.....:!H-...+..N.Gf-.1Vj...;.]........"h....h...,..\`...._. ..f.>.D.}/g.v..C....N=Xy..Ud.Wn...Z.D.T.A....Y.....G....#...1.Y&,h_>?..$.Z.KK...U...<[..{.1.6....Qy.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34658
                  Entropy (8bit):7.994162726109321
                  Encrypted:true
                  SSDEEP:768:4ZHs92vSYyY471yzpBuvR1GS4w5n2foBfbvpwqw:4psASYOxcpcvb74w52fC7
                  MD5:4DA8A5C6CFDF62DDDB5418EDCDE84A0A
                  SHA1:C0706464C503233A70376DDF0E25C4A93EBB7B60
                  SHA-256:65018E6034820A3C3C4D1A454E7A1AD013A24FDD019197ACB049CB85D5BD6AD7
                  SHA-512:BDE350C0CE4C0A98B4787CB72339620227C0437A3BA8E35C9501A25FC914D94B084BD9F4EE90E2829E74ADA616447DEB7BF035F660501BFFE8955595C11AD5A1
                  Malicious:true
                  Preview:.&.L..X.:w..l....~.d..6...f.b..g.2U....p.......g?........-.b....Y......&..#.....k...w9..@.k...E....ax.zR....GS'..r......jM.1~O&...../(..:'E@....^..W+.....*...e#......X.w...m.....gnW.F......(Qj>2..6h=...}_}./..:.U.4f...^]UC...+.:...8L.......E.vUR...\Al....eF....Q.WU...f..yi...H.R.DF.>j......b.Q.=p...0.6.\.}.u.1.\..'9.s..nq.s.'..g......xF.KlZ3..r..^p.PL.=.</ZR...3c......ky[..ex.&...g.V*|./!/...|U+w}......T.C..I....+....5=p..dVw....2.P..7..i..?.6..@.F../..6......F;....%].nv.6..]...f.:.jOC.f.\..5|.}].....^.PE3."s.O......%..e... D...".K....-Am.....a....RF.zV..3..(.l._"..D6.p^g...;74ti.t.a..f.w.f`....{.0U.N...T..9..87.6......R}..H."..Q...$.5d.......Oy..L=..,....m...R.;..z..OJ.#.s..0........4P..U..^_...J.P.......9.U.F..o^`P..z..cPC<....O.....'......Qs..../Z.<....=....%...{..J.y...7.......h.;..2...+x..W.b..1...#..m.....s....'}.n.b.2....D<....{.......b.z...=."...x.H...C.....K.'."4.{-.n{...*.Y.\.......o...7~.l..b...S*.5J..........;L.....V.^:
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34630
                  Entropy (8bit):7.994406769585354
                  Encrypted:true
                  SSDEEP:768:QNv7uPkVSIkDPJWYMFO5Unjd6yqR+9VciyiiJIU+Bt09nyy6:Qx6TFD8YMFrnjQho9Gi7igzS
                  MD5:4775973A26F9793D16B5504F095DE1EF
                  SHA1:DF38BE414A95D83978664627440039621CEDD07E
                  SHA-256:32B2F542A5250D27FAEF249679022F59570816C85D85CAC966179C2E277F170C
                  SHA-512:A3F21E2530941E20A0919B06F026D2EBF414AB735962D799BC8646178330512899886B9C8D55958C03623CABC7DA462E2CF7A3D4AF1AAD7B2BB1418AAF83EDCF
                  Malicious:true
                  Preview:......N)e.LXfb..S..-v.$...`^.r_..F..e..p..x.f...-T4~tve_Sh.qZ9......)i.#.Y.."M.lQP.kT..b{d..........n..S.w.`J.=....c.A]....KrE..e.d.j.6s.F.=.....[...\......1.M1.2?8Y....X..r.&..m.|..&.y.7...A.nQ...c.N.........D......rk....o.f`G.LJ....ra.....5H..S..?~.*.1&..Xl...x.e..>..$..%..~#w.}..hQ......8.ms..WJ.E.dj.OpkZ%....m..A..Ym.-/..f..C...O......8,...#k..z.C.^NU..$.\......@4b.m.#...i.!2..=...{b.uC.~.S.gZ9.G.._.Q..];....m.a.. [@.K..b..xu.{..J>.2.LO.8.l.......vt...y6AfxI..c.g..m.....<.B.D......U*?'...*.Z../w..Z.a....u.]../ag.G.h.S.u.;.[.0....p'.-.j.i~...a.Q..E.e.'>..c...6uT.R...XAm+..n.|..."mk.a.A.4aB....qI...:......v..+s...Pa.Y..R..CL.$..l..F..|..e..t.}7%._.~.m..nm...q.d..b..~+...u.G...{.B."..DW1 ..y..._.w.j&.....2..c.H0...x.qY.R%..U..."K.|pam....J.Nw.{.......@.7....Q&:...*.=Zr5..c...*...0.}.....G..j.....]j.un..9k.....1..rA}..O..v$.-...}M....K./x...A..F.O..;Vwj....C.n.f..7..J;.......uV...'b4.Z.S..C;Dz..f.%.......-..H.l3....5K..*...R....4.x
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34658
                  Entropy (8bit):7.995267387596381
                  Encrypted:true
                  SSDEEP:768:n+gkhQRxwMXCn7oBRoezBFCoqkXOUOcTTumT7ypMxJF3:n+gkO/y7iRXFDZX2eCmT7ypMxH
                  MD5:D095D11569050954024702ACA09AA1FE
                  SHA1:3E92641A8ACF50236B91AFD83873F8D565749EF7
                  SHA-256:3DC5CEC8826A824569A3AA2361EA2E2029D6A18C6326E0FA597717A3233E2D30
                  SHA-512:B139A3224240A59622B5B256DF08B4D6FBC1076F0DE002CBD9C85BF11DFC7330BD9C5C8E1557442097FBA9B9EDA5BA47046EF24A591109CEBD52E9DA300ABA78
                  Malicious:true
                  Preview:..Z...w.......J..1"7.f.../.u.w...^..:.....k....u.3.D..'$.......i.9M...G..[k..n_<...N:vJ....g.p.}.'v.........mv3.-..I.4:.c.E..d...!........6.n.o..wZ.<6...@vk.v.....<,..B.#....~.|..;.*;4.w.e&.c>..=r.H/...3....{v.m......y..P..z..g......j....L'.W.}:........p....Q.}......[a...yHd..]7ZV.<?).c...I.w...&.....f.....!....G.u>..) N....\l..,,..\...K.S..1u?......D...b<. q.5..w.Xi......f...GH...w..GS..']...S5\....;3.&....X..|.D.de..j._h~]..1.....g\O..l.........{iLF.......b.1..EB...f......@...J.m.d....hE:...o...)..t"..I......_...e..y.>...<.b.QL3$"r.i.....Q...j.1..}..4..._.d.....>^2..Q.-....$.0+.....B...>.h.s....e7...1...Wf..p.Z/...\LQ.......E0.8....g.t....t.P.8!\y.....w.[4f........Hn...u..ul.SB.k.z.....?..s.:.@..Y....Y.?.w..9\....N...;...dR.d1.iqv....Q......5...i;....c.qg..^Q.[T.a.V..n..6....Y....C.>.v.U..0. ..n......u.@Z..G...S.n8.G.lP.Lb...n.(B?.3Q.q....>|6..Kg1.]r\....8+..CE7.....p0..x..#..{<v.8.D..=.4.+.......z.m..J.)...........<@...w0\...|... ..?#.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35018
                  Entropy (8bit):7.9946507634262325
                  Encrypted:true
                  SSDEEP:768:Wj2vz7qtNmWNTS8+4cbUsphRmznvKLWIBmanqk1a5:Wqvz6mwTH+4cAs1m7sWI1P
                  MD5:EF7EBB8A3DF435FA7B0F239192A8BA01
                  SHA1:AC2466EB3D21F87B36A363502C585C2140A3148E
                  SHA-256:EE2312077A6E4AF3A035FE43A71785710A26B4FB9128C81B98C21B7A7C9D6530
                  SHA-512:99A317FEDD7FC24DD6F620D07821339EAC357CC385CF2D09A42986CFBA38FEF00E1F768CDA94F5491CA1904268AEB7D87969436E4357BA6669AF07DE683EBD07
                  Malicious:true
                  Preview:..B].. .^,..z.{).<6%...[&....L....XjEp.9..r..u..k.%...L..q_..g.S..R...[g........i.'...E.*.V...d.N./.n.A.oI...b.0;...6.i...L..._?...:bDu#........x^=....X......H..U..x6...uqlON.9..M..d'.C-........V.k9......_..56...&....:...7s.XI'[.......;.%T>.xT.#.'G......L...?.............j....IQ..s..r..!....C....M...`.....Jn%Dc......>&n.....;.. ...\b={:H'..V.Y.z../.i.j.].u>.sY.LG.#.t.0.$.....R...........B.E.kFl.......L..E..'....d.....^.y}wF..<....A.....@C..~(....!....s.:.:..._X..k..{...G^.......bp..S.....g!P.&m.....j.4.mD..#....[BWS..Y.........\....F.)T.P...P.H...C...!..r.\.bk......s...3w..t.B.?h..>Rt......N.4.#.....C .....9nv...}..].?8..0..&..~.6/....b......R...cH.7^.nE.......|...-....:..b?..........O....z....Ht.O.Dc.!RH}+,..Q...F+3w=_1Z..D...{..uV....>#..=../.R..z.`...6o.l.%...965?...4.?g..s..Vf..iSb..o.M.a..\....92.>.2.KN..&....S.)......>.. ..e}.5...j.~!a....-l.....#..t%B.L.$.Q5.....B..6.Y.GJ396.g...24a.Os'zx..J/@.....zA...(..C.....n...gE
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):35018
                  Entropy (8bit):7.9947292679752495
                  Encrypted:true
                  SSDEEP:768:CEjkmwDY1DGI+FmJDzRxGuZSvqlHbYxvzt1SaWkAD9bbgbkMX:FcE1DIFmJDzfTSKHUxrt1PJw3skM
                  MD5:F410BFBF4977393054CCB196C11A52E6
                  SHA1:25CD420DB365C1E1BD8DCD39F5288B75326E4C21
                  SHA-256:594661E0D346F2A5EDFC764007374A9F0DC7EAC02C8A1C9348FAF110FFE62ED9
                  SHA-512:64485C3B8028029AA30A46182C67E54B29AE19C851D89FD654A65B70CE721495DED6ACA06A68670A0DEDF52E98AEC47CD7B7C1C1FA2A8C6527690A68BB305F3D
                  Malicious:true
                  Preview:.Z...X.8..<.30Fz,...1![.H..;..J.M;YQ.....[.&.F.W6.o%P.?S..."~.........s?..'..q7.....S.>._..<`7...#Y...7r..7.?...,...2j. ).*.sS<..].:W.G....F...@Z....T...5>.-C#.J(....&.P.{..3kQ.s...o.....?....Ez...Y..I.`..T.....Z?...E.P.6..x...."N.v.."."+J...C./.~8.~.a..A.~.U..&.kO.@.u....V:....~.4n....*.7U..3Pd......ih..K"u..4./...~.....NV..<....... ..:...\8.'.b...8....g#...j.m..f..q........=!......w..S.X.....b..gP...w.......v3s`r....+Mp..G..R...f...UZR..M....e.1...U.]*.Y>] fet(f..#.. ...S.wyp^...i.`.....O..........}((.I.h..-^n-.W..#.jl..X[PyK.......$(..S.....GI!.xk......Q..|..o......Ds.\(...N../c~..>52.hQ#d.D.2.....Lw.....GS..u.\...z........E*T..D......!..:4u.S..&w.O.D...j..S1.............)F....R...p......[..KD...5..J.q.#H.F...kfQE.O\...6....{>..<t......).b.3......"......v....A.. .".1......e..D$.p.b6(.$Q:n.1..ZX"....`u.~..\...:.. ..H.~..zS...n...g..P.O..EB?q...w.&....*c..............AU..U;gN.C`\U`r.*.6C.F.X=....-...`eZ.3..[...{$....N..s..N..*..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34898
                  Entropy (8bit):7.994303765658075
                  Encrypted:true
                  SSDEEP:768:vtVjeAzcm/Khh/UmSzDLPUyAoDAKg2S69UzHbv:njeBtDUmuzUADT9byz7
                  MD5:096350812CF8C22411771B0042FA2E0D
                  SHA1:09B4D04EA7E05FA457C7F2F47AB1E95F0E317CE4
                  SHA-256:1A2C21D0BD7000E24E8B4408B0DB44575D57AEC28D3D98FF4E15B5CD616F81AB
                  SHA-512:328E5097B7C29DD7947A5FB0F603F2B50C787643033EF28104FBDE2020F72DDAF56A6CED3734A25B9B8E1C71281AD1319DF11C7093681DDCA41C88F6191FCB07
                  Malicious:true
                  Preview:...m.M..S.....j..f..T.4.KH.fq......s...}....R5..Yd......y.%2.....:.x..7...1E...}%..4 ....)9p?T......Ti.Pir.,.(....1r..m.b........vh{lcd........5.gx.....c.....-...0.b..U.h..Si...4.{....U..`...!...d.O.V.-..Mc2U......-.0.....U....t?.!.C.%9.l.`..........>.Z'...pF..0h.Z......C.l...di[.C......V....2...<C%..:..g........^.....%".UT)Q.TZ<.A.gO.(y2L..L..p..~Mm(B...V.A&../9w./.....c-..x.?.F.X,G.>I.?....#2..:..Xw.......B.> .w.n.{.....cr.m.:.....L..V..L...'W.y.9.]&.0X.s=.M>.\..9:g..4...U.:.v.>.6.+..FLJK..>.....|C..2...1...#....-.W.....J.....i..f.J.Kt..L...n..lX...JP..<L..W<...{..o..-.c.7|jp.w. ..d..@...;...A.z..CM/.2!yX..?J...1O.....#..W*..-....v..+.st+.......H3...7/;...uZ.A.*YQ...<...m...........p..B_`".8..7v.@.^...z..f......?.zE..$AH.........)M;..f.......YkI..)f.IN.\&n.^..0.]!.jn..#...........O"....=7I..d..B...u).....Z!DO3.}+...0j$....O.uQ.6.F.p..,.."....zF{.,...>HNnt.....'.7..m..J0F..t,.=.S.l...c......b.O. F..R..4..V.D.j.g..r.F.7.`.D<jJMN.%-...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34898
                  Entropy (8bit):7.994626392820203
                  Encrypted:true
                  SSDEEP:768:qgyZapWuvpLA1v/W8FCsNRu1QS88pq91KCBRI9Na5X46b3LiKhKb15F9VLKX/G6n:NyZaMaLA1v/RFCsNRFnzwCrga46b+KhO
                  MD5:3154CBD4687BF28D86240B7D0B3DAA15
                  SHA1:4CF597E03315BBE993D30B104D14B38A318A137D
                  SHA-256:6B98695C196DEBAF0E6C12EB4F811DB75A208B6E43B9EA18735AA5E18A9A4D70
                  SHA-512:01714241A2ABC939C68535E902741AF1EE2E8FF8DA31DC97B9AA70349CE9C1FA1F26D5646C37C09C3F4350A81DDAEED8AD9BAEBD4C5D89C1522305F7207F04DA
                  Malicious:true
                  Preview:t........(.u(6XE!i..v.O..7`.Y..`.<...........q`..%.=.J^V...#...<...).|...w.eE^y...e..$.4?5....1...t.*..R..F..../.]b.I.K...u.)w'.q..E....U...r..8..#.<pm..0.R{.X..g....*o..A.l.3*.o.|j}Ym...} .3.<.F.......`.......^7.m.c{....|....sa@.1..[............]......;....'.....qN.....>..4.kwV#..6...'..r...%.9...1......3."`d.,./.e*(..u.....:.......~t.."-....5.@...R.b7G.Y..DA...0L.P..2..xK.O....h..gT.D...S.*....K.....L....;..~....F7o...2..T..7M..B....p*.....A...]...V..&h..V.....J.....b...R.,^r(..Q}.ZF.._|t2C.s*`Z....7...#.q.P>..qJF.[. .n..6..E.#n....,{AH.:7aX....2|....Qw..hy...r..B..2xF...n..F.Aj.g..Ael..<.B.>.....Fn.6%e..$<.k..2kX<D.M-......n.X.j..1!{..5 )|.f.[.P.6j.......Vu...a\o.".G........i..w.i.d+...Y5.\..P)m.f.....i..;.\......=..o..a..........o...8B.KN...d.........X.2...h..'.L.}.X..|.qXU(.......>&.n6...+..fvi.-.;*.........(...../mnFh.............Z.3.....rl...s/^.9.|0j...Q..N.G.GF.5.wW.0{.<[@6..iQ.>kt....S#l..&U.`..8....J...~.s.J...T.h'....5
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30250
                  Entropy (8bit):7.993998399554326
                  Encrypted:true
                  SSDEEP:768:z/XGZumQIn7sfg3ybPjYXVLSwK7fTBgGz6A3Cv1GG6:z/XGZumQM0gCYVLSpxgy9iGG
                  MD5:5D4BDEF71CC9897D28FC8B3B02F0D9AB
                  SHA1:DDB265B0BA9249317308C3141D4AE34DF13556A6
                  SHA-256:986E5A9E6877BF363AB86E404BCD135259594438B23421826D97D636FBAC825A
                  SHA-512:B4A08222804A8CA234257956B5A2734E8BD9C9307F8C1028F161C2542CCF5247C43225280A8AC0915ABFEE3BB7148A93F6B7FAF56D7688617C88F8B57219FD2D
                  Malicious:true
                  Preview:kb=..!c.....AL..Kr..wtx@..|.K..+t.i^.&).+...9..a1yI.'3..&v.Z...>.=.=.|=.q>N...8..M.....Q4+e{..S....w....\.k....I.g<.UO...-Y...c5..d....V>........[........|<.<.8.y....)W...PM.I.t.....Y...}..^..yyS..p.-..}1.e...z.e..L.X.M.v{C.....T.(..;Ela&....:..]e~^..]../.8Z..Px....7t*_.t*8...}.B.....6bz.*...h..<\.|..H.`.~...=.;.1......M..`z.._QB..n..b._tb)..k....t.>.l.x5....@\v.....i...0 .*.#Zk..CV6 .\.....U.._..,X:..bRM../.....-.. .S..L.y;.(..g'..tW..N#8<....b...|9_......'QF..d...u.&.V...R....-M..b..:..9...6#...G$..v...\...y-8.zs..=.(....g..I...D.`.?.J....n..{.......E....Y...{..<nHR\n....Bv.i.c%.Z....a."r.....9..h@..>...gv..."d.d...U..M...Y.......kP~~x.}H.......(T......-n..."c.m.Cf....&S...Z...D...{.(.....ad..?.v!.xeyG.s....%`.@@.._.|..l...7_......-J...A...4..[y....)..9....6......t.U....J~.a1..j. /=....&......Y..=....aL........$...^.6.,..%.6k..K..Q....=......M...{...,P.......3....^.4...d.j..@......l4N.VMc.t.{..v\}.c...*.X3.BQ 0......|......|.w.T
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30306
                  Entropy (8bit):7.993920180513045
                  Encrypted:true
                  SSDEEP:768:C2GiLfyzvcvJpW4eBHtQByyzdfAy61w+yx:C+gAqwwyzdfj
                  MD5:474085C8B9C78FE2C4323B29C04BC5D6
                  SHA1:F5165B71F8508365A48D4E6908D7C86BB9E77B5C
                  SHA-256:FFDE6CA0127B45631285D0E765762A784FCE4925F9C70480414D287BC1F53622
                  SHA-512:FB37D93C5DDD6B93A025EF3846F27A11014FA3CF668AACDF4DF574499ECE6E6C82D58F52FBBBA0D720F0A666BFE052BD05EACFC7F23D50181FA9464C75BBE454
                  Malicious:true
                  Preview:l....Q.n0.... .....QE.....r`...V.rk.K..rF~.T[s......^d".A....<....}.z..S.....1...(..1u.../.:.>.[,.9....V.....{.Ru..C..........4Hv.&..T5g.-....c.......&eVl...`d....q....P.-R.R.......V.25.o.}.....k..@v..........j.....3..h`..37f.........jG......d.t:?.c?...>i...G..-...n..l............6.a.ig.N..3!..3.....s...x.g..9.Q.G......N..@.Z,\.<..zk.-o{nq1....&..G..GaN....^.D....U.%.`vvh.rT#%.A.a...|.pS.....2..\...5.`..&/XyT.......7.w$7..-._..o.A.V6I;H..@$.K....d......c...Ib.:.a.,....Q.....B..i.^T$...P.,U.R.0d.?....FB....s.!.I.g..yFo^...(...k^.....b.z....e..GUM.....?R9 .d.}..g.B5.9^.+....>.[./........#f.....>........5.....1..[.9...'o,d...5..I.../.H..e./..h.......+`A.sk..hf.x.y..4........x...v.,?'#k...[+.`..GW.W../....z./....DY.&..LB.....l...u.G!....6..Z....q.....KZ..S .w..t.`..<W... F.*k....u$g.$s....m.K).....*YS..}......SO.b........d.;:+.|.%....mI.....*rKD..Y\y.M.(.......I....o.7....:....X'f.W..:............$....xZ7...]5.Wa..K)R.O7.9f?
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30306
                  Entropy (8bit):7.993920180513045
                  Encrypted:true
                  SSDEEP:768:C2GiLfyzvcvJpW4eBHtQByyzdfAy61w+yx:C+gAqwwyzdfj
                  MD5:474085C8B9C78FE2C4323B29C04BC5D6
                  SHA1:F5165B71F8508365A48D4E6908D7C86BB9E77B5C
                  SHA-256:FFDE6CA0127B45631285D0E765762A784FCE4925F9C70480414D287BC1F53622
                  SHA-512:FB37D93C5DDD6B93A025EF3846F27A11014FA3CF668AACDF4DF574499ECE6E6C82D58F52FBBBA0D720F0A666BFE052BD05EACFC7F23D50181FA9464C75BBE454
                  Malicious:true
                  Preview:l....Q.n0.... .....QE.....r`...V.rk.K..rF~.T[s......^d".A....<....}.z..S.....1...(..1u.../.:.>.[,.9....V.....{.Ru..C..........4Hv.&..T5g.-....c.......&eVl...`d....q....P.-R.R.......V.25.o.}.....k..@v..........j.....3..h`..37f.........jG......d.t:?.c?...>i...G..-...n..l............6.a.ig.N..3!..3.....s...x.g..9.Q.G......N..@.Z,\.<..zk.-o{nq1....&..G..GaN....^.D....U.%.`vvh.rT#%.A.a...|.pS.....2..\...5.`..&/XyT.......7.w$7..-._..o.A.V6I;H..@$.K....d......c...Ib.:.a.,....Q.....B..i.^T$...P.,U.R.0d.?....FB....s.!.I.g..yFo^...(...k^.....b.z....e..GUM.....?R9 .d.}..g.B5.9^.+....>.[./........#f.....>........5.....1..[.9...'o,d...5..I.../.H..e./..h.......+`A.sk..hf.x.y..4........x...v.,?'#k...[+.`..GW.W../....z./....DY.&..LB.....l...u.G!....6..Z....q.....KZ..S .w..t.`..<W... F.*k....u$g.$s....m.K).....*YS..}......SO.b........d.;:+.|.%....mI.....*rKD..Y\y.M.(.......I....o.7....:....X'f.W..:............$....xZ7...]5.Wa..K)R.O7.9f?
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30306
                  Entropy (8bit):7.993920180513045
                  Encrypted:true
                  SSDEEP:768:C2GiLfyzvcvJpW4eBHtQByyzdfAy61w+yx:C+gAqwwyzdfj
                  MD5:474085C8B9C78FE2C4323B29C04BC5D6
                  SHA1:F5165B71F8508365A48D4E6908D7C86BB9E77B5C
                  SHA-256:FFDE6CA0127B45631285D0E765762A784FCE4925F9C70480414D287BC1F53622
                  SHA-512:FB37D93C5DDD6B93A025EF3846F27A11014FA3CF668AACDF4DF574499ECE6E6C82D58F52FBBBA0D720F0A666BFE052BD05EACFC7F23D50181FA9464C75BBE454
                  Malicious:true
                  Preview:l....Q.n0.... .....QE.....r`...V.rk.K..rF~.T[s......^d".A....<....}.z..S.....1...(..1u.../.:.>.[,.9....V.....{.Ru..C..........4Hv.&..T5g.-....c.......&eVl...`d....q....P.-R.R.......V.25.o.}.....k..@v..........j.....3..h`..37f.........jG......d.t:?.c?...>i...G..-...n..l............6.a.ig.N..3!..3.....s...x.g..9.Q.G......N..@.Z,\.<..zk.-o{nq1....&..G..GaN....^.D....U.%.`vvh.rT#%.A.a...|.pS.....2..\...5.`..&/XyT.......7.w$7..-._..o.A.V6I;H..@$.K....d......c...Ib.:.a.,....Q.....B..i.^T$...P.,U.R.0d.?....FB....s.!.I.g..yFo^...(...k^.....b.z....e..GUM.....?R9 .d.}..g.B5.9^.+....>.[./........#f.....>........5.....1..[.9...'o,d...5..I.../.H..e./..h.......+`A.sk..hf.x.y..4........x...v.,?'#k...[+.`..GW.W../....z./....DY.&..LB.....l...u.G!....6..Z....q.....KZ..S .w..t.`..<W... F.*k....u$g.$s....m.K).....*YS..}......SO.b........d.;:+.|.%....mI.....*rKD..Y\y.M.(.......I....o.7....:....X'f.W..:............$....xZ7...]5.Wa..K)R.O7.9f?
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30320
                  Entropy (8bit):7.9937413465047635
                  Encrypted:true
                  SSDEEP:768:edEB9ntNLm+b+HgXwi9SOKePX8Q8eVGYV3H:edEBRie+HgXf9PKGz80bV
                  MD5:B6183E0FB144A6F9017C51E4341548C7
                  SHA1:4868AF4F9104E3869BE3434A5E1D95F61D3952C6
                  SHA-256:7DC279C51875499AE1C0BE85A7790A1A7D9028D877FDAC8285001F6D427A4AE4
                  SHA-512:3295F86BE462CCC453161760A34D195091DC36F63EE4088C4DD126D2C2DE42FB46C9C5346F9987E44FB653804AD76E37C63ADB19CF1F8FC7852D1D0484881E28
                  Malicious:true
                  Preview:1........j......l........L...H...|J.?..=..=...>NMogA.$....8....!v...#.9....W..J.....A...<....+...4.\...t..q.d...F...^.dr..l..+.Uw.....A..xP...H/...dl6#x.iK...z x..O..........K0+v..E..X"....B.\...WN.T..A\..cg.;E...T|....*.......-.|....Xv.TJ......~-.Xh.....I.O.Mv...a... ..w.hl<...9.........C}..QU.^.q...5.R... ....h.hghE#.w....b2.....Y..........T.n6eN(.e.(.`?.Q..A.k...(.0...:.T()....g....!...}^..a...U....a{.a0t....e.Qm..1+L"...2..C>j.K.'.f}B...e..*n....sB*..+>x@.....8*..w.R&..e.....+fO...0bc..7...K*..79.>....]...Q.N....n...aLS.K......_PK.#h7...u.,4F~...$x.T....p.+..)2r..=.w..-+..T.c.:....}.^....E..K...-0..nR.lL..`).BoO.U.....p.d......s......C.r...n.wy$....+....v!.H..7..."..5..A..VQm=m."....4@g]N.\....m..>..........v..Yx.Pw..8..........o.]}.G..". .?.?`...$....."</.n.F...B..!..@..G.....j....0T..8..>Y......'.8w..F.".}.|6..JA..I.L0.....w..O..24.x"..v...F.Rf.,^..hAV..(.U.<../,..k2.=.yy...B...RwK..i......\.j2^.E.}....b.b........+?{..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30320
                  Entropy (8bit):7.9937413465047635
                  Encrypted:true
                  SSDEEP:768:edEB9ntNLm+b+HgXwi9SOKePX8Q8eVGYV3H:edEBRie+HgXf9PKGz80bV
                  MD5:B6183E0FB144A6F9017C51E4341548C7
                  SHA1:4868AF4F9104E3869BE3434A5E1D95F61D3952C6
                  SHA-256:7DC279C51875499AE1C0BE85A7790A1A7D9028D877FDAC8285001F6D427A4AE4
                  SHA-512:3295F86BE462CCC453161760A34D195091DC36F63EE4088C4DD126D2C2DE42FB46C9C5346F9987E44FB653804AD76E37C63ADB19CF1F8FC7852D1D0484881E28
                  Malicious:true
                  Preview:1........j......l........L...H...|J.?..=..=...>NMogA.$....8....!v...#.9....W..J.....A...<....+...4.\...t..q.d...F...^.dr..l..+.Uw.....A..xP...H/...dl6#x.iK...z x..O..........K0+v..E..X"....B.\...WN.T..A\..cg.;E...T|....*.......-.|....Xv.TJ......~-.Xh.....I.O.Mv...a... ..w.hl<...9.........C}..QU.^.q...5.R... ....h.hghE#.w....b2.....Y..........T.n6eN(.e.(.`?.Q..A.k...(.0...:.T()....g....!...}^..a...U....a{.a0t....e.Qm..1+L"...2..C>j.K.'.f}B...e..*n....sB*..+>x@.....8*..w.R&..e.....+fO...0bc..7...K*..79.>....]...Q.N....n...aLS.K......_PK.#h7...u.,4F~...$x.T....p.+..)2r..=.w..-+..T.c.:....}.^....E..K...-0..nR.lL..`).BoO.U.....p.d......s......C.r...n.wy$....+....v!.H..7..."..5..A..VQm=m."....4@g]N.\....m..>..........v..Yx.Pw..8..........o.]}.G..". .?.?`...$....."</.n.F...B..!..@..G.....j....0T..8..>Y......'.8w..F.".}.|6..JA..I.L0.....w..O..24.x"..v...F.Rf.,^..hAV..(.U.<../,..k2.=.yy...B...RwK..i......\.j2^.E.}....b.b........+?{..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):30320
                  Entropy (8bit):7.9937413465047635
                  Encrypted:true
                  SSDEEP:768:edEB9ntNLm+b+HgXwi9SOKePX8Q8eVGYV3H:edEBRie+HgXf9PKGz80bV
                  MD5:B6183E0FB144A6F9017C51E4341548C7
                  SHA1:4868AF4F9104E3869BE3434A5E1D95F61D3952C6
                  SHA-256:7DC279C51875499AE1C0BE85A7790A1A7D9028D877FDAC8285001F6D427A4AE4
                  SHA-512:3295F86BE462CCC453161760A34D195091DC36F63EE4088C4DD126D2C2DE42FB46C9C5346F9987E44FB653804AD76E37C63ADB19CF1F8FC7852D1D0484881E28
                  Malicious:true
                  Preview:1........j......l........L...H...|J.?..=..=...>NMogA.$....8....!v...#.9....W..J.....A...<....+...4.\...t..q.d...F...^.dr..l..+.Uw.....A..xP...H/...dl6#x.iK...z x..O..........K0+v..E..X"....B.\...WN.T..A\..cg.;E...T|....*.......-.|....Xv.TJ......~-.Xh.....I.O.Mv...a... ..w.hl<...9.........C}..QU.^.q...5.R... ....h.hghE#.w....b2.....Y..........T.n6eN(.e.(.`?.Q..A.k...(.0...:.T()....g....!...}^..a...U....a{.a0t....e.Qm..1+L"...2..C>j.K.'.f}B...e..*n....sB*..+>x@.....8*..w.R&..e.....+fO...0bc..7...K*..79.>....]...Q.N....n...aLS.K......_PK.#h7...u.,4F~...$x.T....p.+..)2r..=.w..-+..T.c.:....}.^....E..K...-0..nR.lL..`).BoO.U.....p.d......s......C.r...n.wy$....+....v!.H..7..."..5..A..VQm=m."....4@g]N.\....m..>..........v..Yx.Pw..8..........o.]}.G..". .?.?`...$....."</.n.F...B..!..@..G.....j....0T..8..>Y......'.8w..F.".}.|6..JA..I.L0.....w..O..24.x"..v...F.Rf.,^..hAV..(.U.<../,..k2.=.yy...B...RwK..i......\.j2^.E.}....b.b........+?{..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):987
                  Entropy (8bit):7.781347581262504
                  Encrypted:false
                  SSDEEP:24:EFDfyFEJMbZHSboLoi2HkAnHxjODsHHReZ20Il843Kg:GD2YMobYo3HRnHE69V7
                  MD5:C90CC145A0D2AA69A671DDD9CE95B789
                  SHA1:B717428D169A945F3637C106F7DC96C574EAE956
                  SHA-256:8B8DBC08F5255AE85B0B08866C6BC61EB8FAF2BDD36AD833C811B14091B805E9
                  SHA-512:16074C58DC3C1581DC02B4CC67C5BEAB0FF091789DA9B851ADD1D4B732D67D1C9A4FF48E775C2C69A422E152A30306F145DB0EB1983680F539B3CCBA4DCD4FB3
                  Malicious:false
                  Preview:!{.,.v.....JsG...B....k..;.+..YS.T.V..u.........T..)...f.o.....%4x.}....&.xZ.x=.D!..g.F;K&.?...y..!....>..!...........*d4Ee~.YVX. .........FZ.-rn.i.k.M...\7t.o....hi.qyLB...>..3.s.db...3`.Q...n..E..4...(..#...;W-.$.N....".R?*...D.......uux/)WX.X....~..iO.....3mD.H.d.....MP..........K..+.#.J....DH9XU..C.?$.c"..m.Y.O..|...qLp.:V.:.x...[zUq'..szak...u....z..b.Y8....0...n.}..y.de.&........>m.v..4.}A=.)SF.o.Q[.^...KQ,.. .5.k....+....^;......js}?JM.t0..1J..ai...y.......n>.M....<.UkO...{QJw1..8p.j.I..l.....I..UD`..Hd.S..&....).......C-.].t..o.Lz.p.&.:X....;...]..<"...Dqh.G$.1...0..6...(.i.e...SK[.c6.....e.....r.."...7D./<Q.rwJ...vJ....?/D....>..N....3.(...c..D..De;........39..M....K*....f...C.#..s..\..)....S.3.%...p..H...G!..S.\.X.K..'.5...w...3z(..<...{...e[.z.4..?.F...y.$.3..\WZ5^.....9.....K..T.v?...Gn....D....?Qd......n.|.:R.o........M;...........\....n.$.....(..|.~j.-....uw.>...q..!B..].'................;...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):987
                  Entropy (8bit):7.781347581262504
                  Encrypted:false
                  SSDEEP:24:EFDfyFEJMbZHSboLoi2HkAnHxjODsHHReZ20Il843Kg:GD2YMobYo3HRnHE69V7
                  MD5:C90CC145A0D2AA69A671DDD9CE95B789
                  SHA1:B717428D169A945F3637C106F7DC96C574EAE956
                  SHA-256:8B8DBC08F5255AE85B0B08866C6BC61EB8FAF2BDD36AD833C811B14091B805E9
                  SHA-512:16074C58DC3C1581DC02B4CC67C5BEAB0FF091789DA9B851ADD1D4B732D67D1C9A4FF48E775C2C69A422E152A30306F145DB0EB1983680F539B3CCBA4DCD4FB3
                  Malicious:false
                  Preview:!{.,.v.....JsG...B....k..;.+..YS.T.V..u.........T..)...f.o.....%4x.}....&.xZ.x=.D!..g.F;K&.?...y..!....>..!...........*d4Ee~.YVX. .........FZ.-rn.i.k.M...\7t.o....hi.qyLB...>..3.s.db...3`.Q...n..E..4...(..#...;W-.$.N....".R?*...D.......uux/)WX.X....~..iO.....3mD.H.d.....MP..........K..+.#.J....DH9XU..C.?$.c"..m.Y.O..|...qLp.:V.:.x...[zUq'..szak...u....z..b.Y8....0...n.}..y.de.&........>m.v..4.}A=.)SF.o.Q[.^...KQ,.. .5.k....+....^;......js}?JM.t0..1J..ai...y.......n>.M....<.UkO...{QJw1..8p.j.I..l.....I..UD`..Hd.S..&....).......C-.].t..o.Lz.p.&.:X....;...]..<"...Dqh.G$.1...0..6...(.i.e...SK[.c6.....e.....r.."...7D./<Q.rwJ...vJ....?/D....>..N....3.(...c..D..De;........39..M....K*....f...C.#..s..\..)....S.3.%...p..H...G!..S.\.X.K..'.5...w...3z(..<...{...e[.z.4..?.F...y.$.3..\WZ5^.....9.....K..T.v?...Gn....D....?Qd......n.|.:R.o........M;...........\....n.$.....(..|.~j.-....uw.>...q..!B..].'................;...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):987
                  Entropy (8bit):7.781347581262504
                  Encrypted:false
                  SSDEEP:24:EFDfyFEJMbZHSboLoi2HkAnHxjODsHHReZ20Il843Kg:GD2YMobYo3HRnHE69V7
                  MD5:C90CC145A0D2AA69A671DDD9CE95B789
                  SHA1:B717428D169A945F3637C106F7DC96C574EAE956
                  SHA-256:8B8DBC08F5255AE85B0B08866C6BC61EB8FAF2BDD36AD833C811B14091B805E9
                  SHA-512:16074C58DC3C1581DC02B4CC67C5BEAB0FF091789DA9B851ADD1D4B732D67D1C9A4FF48E775C2C69A422E152A30306F145DB0EB1983680F539B3CCBA4DCD4FB3
                  Malicious:false
                  Preview:!{.,.v.....JsG...B....k..;.+..YS.T.V..u.........T..)...f.o.....%4x.}....&.xZ.x=.D!..g.F;K&.?...y..!....>..!...........*d4Ee~.YVX. .........FZ.-rn.i.k.M...\7t.o....hi.qyLB...>..3.s.db...3`.Q...n..E..4...(..#...;W-.$.N....".R?*...D.......uux/)WX.X....~..iO.....3mD.H.d.....MP..........K..+.#.J....DH9XU..C.?$.c"..m.Y.O..|...qLp.:V.:.x...[zUq'..szak...u....z..b.Y8....0...n.}..y.de.&........>m.v..4.}A=.)SF.o.Q[.^...KQ,.. .5.k....+....^;......js}?JM.t0..1J..ai...y.......n>.M....<.UkO...{QJw1..8p.j.I..l.....I..UD`..Hd.S..&....).......C-.].t..o.Lz.p.&.:X....;...]..<"...Dqh.G$.1...0..6...(.i.e...SK[.c6.....e.....r.."...7D./<Q.rwJ...vJ....?/D....>..N....3.(...c..D..De;........39..M....K*....f...C.#..s..\..)....S.3.%...p..H...G!..S.\.X.K..'.5...w...3z(..<...{...e[.z.4..?.F...y.$.3..\WZ5^.....9.....K..T.v?...Gn....D....?Qd......n.|.:R.o........M;...........\....n.$.....(..|.~j.-....uw.>...q..!B..].'................;...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:modified
                  Size (bytes):387
                  Entropy (8bit):7.303664739800981
                  Encrypted:false
                  SSDEEP:6:EOZzehGrDsDqoVTR53PNezpBcyCnf6zmhxfTL4Vq4HUZYDhc:EOZzepVVtBP0zpBcyCnSzmhBJeq
                  MD5:53C9CD26778E4C5AE4B4D42C05FDBF78
                  SHA1:F3EB23A4BF2EB958EF4336A68BDE634709A48EB1
                  SHA-256:27E0CEE46588AEBB6E0ADE757228C8F3B4F22FEDA9100E8A3403CBB3B64AFF8B
                  SHA-512:BAF67F639D2551162171DC703D5D202DE7976B982D8DFD57F4378BD5CD7C7DFABD1D1929CFB9E9E6BCBDF919542B329CFA65D60F987C8CB602E2F7123DAF1488
                  Malicious:false
                  Preview:...'u.....W.xD=.k...v.......&....w.>{.=......d.F..(L}.o....w.U..#...MW......YljiErr;.."..~4... .I.c]. 'O..a.6.Hc....X..Q. .T.$:.Fl.$.'.......pIq...9...D....@..S..q...`6E...9....wV.R#y.\y.Bp.>/...r;.....(..'(+B.......W:.1F_!.8.e,...../&..^ ..L..4k.YUH"_(9P...|l..-MIzVg.e..................K\E..n.\.(.L2]I.EQYX.).s.%.......@....J..T.)M.a.j.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):387
                  Entropy (8bit):7.303664739800981
                  Encrypted:false
                  SSDEEP:6:EOZzehGrDsDqoVTR53PNezpBcyCnf6zmhxfTL4Vq4HUZYDhc:EOZzepVVtBP0zpBcyCnSzmhBJeq
                  MD5:53C9CD26778E4C5AE4B4D42C05FDBF78
                  SHA1:F3EB23A4BF2EB958EF4336A68BDE634709A48EB1
                  SHA-256:27E0CEE46588AEBB6E0ADE757228C8F3B4F22FEDA9100E8A3403CBB3B64AFF8B
                  SHA-512:BAF67F639D2551162171DC703D5D202DE7976B982D8DFD57F4378BD5CD7C7DFABD1D1929CFB9E9E6BCBDF919542B329CFA65D60F987C8CB602E2F7123DAF1488
                  Malicious:false
                  Preview:...'u.....W.xD=.k...v.......&....w.>{.=......d.F..(L}.o....w.U..#...MW......YljiErr;.."..~4... .I.c]. 'O..a.6.Hc....X..Q. .T.$:.Fl.$.'.......pIq...9...D....@..S..q...`6E...9....wV.R#y.\y.Bp.>/...r;.....(..'(+B.......W:.1F_!.8.e,...../&..^ ..L..4k.YUH"_(9P...|l..-MIzVg.e..................K\E..n.\.(.L2]I.EQYX.).s.%.......@....J..T.)M.a.j.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):387
                  Entropy (8bit):7.303664739800981
                  Encrypted:false
                  SSDEEP:6:EOZzehGrDsDqoVTR53PNezpBcyCnf6zmhxfTL4Vq4HUZYDhc:EOZzepVVtBP0zpBcyCnSzmhBJeq
                  MD5:53C9CD26778E4C5AE4B4D42C05FDBF78
                  SHA1:F3EB23A4BF2EB958EF4336A68BDE634709A48EB1
                  SHA-256:27E0CEE46588AEBB6E0ADE757228C8F3B4F22FEDA9100E8A3403CBB3B64AFF8B
                  SHA-512:BAF67F639D2551162171DC703D5D202DE7976B982D8DFD57F4378BD5CD7C7DFABD1D1929CFB9E9E6BCBDF919542B329CFA65D60F987C8CB602E2F7123DAF1488
                  Malicious:false
                  Preview:...'u.....W.xD=.k...v.......&....w.>{.=......d.F..(L}.o....w.U..#...MW......YljiErr;.."..~4... .I.c]. 'O..a.6.Hc....X..Q. .T.$:.Fl.$.'.......pIq...9...D....@..S..q...`6E...9....wV.R#y.\y.Bp.>/...r;.....(..'(+B.......W:.1F_!.8.e,...../&..^ ..L..4k.YUH"_(9P...|l..-MIzVg.e..................K\E..n.\.(.L2]I.EQYX.).s.%.......@....J..T.)M.a.j.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):771
                  Entropy (8bit):7.667827761092059
                  Encrypted:false
                  SSDEEP:24:aBhQ3RXQy2Xw9x24U5NDs+wrSfeawxeVsL8nAEW:oQ3RXr64eW+we3w+sAnW
                  MD5:C3726017A2A44CEC90E8B3396CE367D6
                  SHA1:675522AB7FA04CEDE2078FC0647355693DF342DB
                  SHA-256:A1660F4657FEE22396CFC6C430A2F6DAFD25830FF58BC54124685AAA32EEC129
                  SHA-512:C7A3E3788595721667366CF40DA482BDC62F67156DD4639706AAD61DE7FA3F8D80141F6A61C872399A3C0DC8E305337B031B48AEADA9832223BF8D804C3F37FA
                  Malicious:false
                  Preview:.J...Y'...$.8.laM............tb..5>..+....`#rvy......*H..l...qU.........%k\..F......?.U...8..{!......\.....=....H./....7...y.tZ.0.KJ.A.>L.{.....0.l\.$Mt.tb.& d)........E..."....-.8.b9.}F......*.7.M...#.=....[..%m.....Lw..2...J..)...g.s.g......."..UC..P.a..^#...h.{.C%.s._....&.I.....5?...Hq.b.N/T.3]..2#b....$[.A.3..Bf+B....8.iW....0.I0.E.oy@:00...X...fR9... .~.I-..F.6.........{.. :y)dC.....u.....6s.0[1:..MY..qy..-.....K...y.zppKx.....Me.V.z.......[..>eC.@.FZ............w.z.J|3`..J......y...=9.:4....K...+!.....>;.E5.w.@8..Q.....G[.`.}M|f.f...../.(..u).... ..U.....L.T7....d..5y......)..i.io.....Dc...8.>#.>*:..M......8..6!.vp..>Y..Hj.....c...........8............/_.b..z.f...3..Sm]$..v...a...e.W..R.J........c...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):771
                  Entropy (8bit):7.667827761092059
                  Encrypted:false
                  SSDEEP:24:aBhQ3RXQy2Xw9x24U5NDs+wrSfeawxeVsL8nAEW:oQ3RXr64eW+we3w+sAnW
                  MD5:C3726017A2A44CEC90E8B3396CE367D6
                  SHA1:675522AB7FA04CEDE2078FC0647355693DF342DB
                  SHA-256:A1660F4657FEE22396CFC6C430A2F6DAFD25830FF58BC54124685AAA32EEC129
                  SHA-512:C7A3E3788595721667366CF40DA482BDC62F67156DD4639706AAD61DE7FA3F8D80141F6A61C872399A3C0DC8E305337B031B48AEADA9832223BF8D804C3F37FA
                  Malicious:false
                  Preview:.J...Y'...$.8.laM............tb..5>..+....`#rvy......*H..l...qU.........%k\..F......?.U...8..{!......\.....=....H./....7...y.tZ.0.KJ.A.>L.{.....0.l\.$Mt.tb.& d)........E..."....-.8.b9.}F......*.7.M...#.=....[..%m.....Lw..2...J..)...g.s.g......."..UC..P.a..^#...h.{.C%.s._....&.I.....5?...Hq.b.N/T.3]..2#b....$[.A.3..Bf+B....8.iW....0.I0.E.oy@:00...X...fR9... .~.I-..F.6.........{.. :y)dC.....u.....6s.0[1:..MY..qy..-.....K...y.zppKx.....Me.V.z.......[..>eC.@.FZ............w.z.J|3`..J......y...=9.:4....K...+!.....>;.E5.w.@8..Q.....G[.`.}M|f.f...../.(..u).... ..U.....L.T7....d..5y......)..i.io.....Dc...8.>#.>*:..M......8..6!.vp..>Y..Hj.....c...........8............/_.b..z.f...3..Sm]$..v...a...e.W..R.J........c...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):771
                  Entropy (8bit):7.667827761092059
                  Encrypted:false
                  SSDEEP:24:aBhQ3RXQy2Xw9x24U5NDs+wrSfeawxeVsL8nAEW:oQ3RXr64eW+we3w+sAnW
                  MD5:C3726017A2A44CEC90E8B3396CE367D6
                  SHA1:675522AB7FA04CEDE2078FC0647355693DF342DB
                  SHA-256:A1660F4657FEE22396CFC6C430A2F6DAFD25830FF58BC54124685AAA32EEC129
                  SHA-512:C7A3E3788595721667366CF40DA482BDC62F67156DD4639706AAD61DE7FA3F8D80141F6A61C872399A3C0DC8E305337B031B48AEADA9832223BF8D804C3F37FA
                  Malicious:false
                  Preview:.J...Y'...$.8.laM............tb..5>..+....`#rvy......*H..l...qU.........%k\..F......?.U...8..{!......\.....=....H./....7...y.tZ.0.KJ.A.>L.{.....0.l\.$Mt.tb.& d)........E..."....-.8.b9.}F......*.7.M...#.=....[..%m.....Lw..2...J..)...g.s.g......."..UC..P.a..^#...h.{.C%.s._....&.I.....5?...Hq.b.N/T.3]..2#b....$[.A.3..Bf+B....8.iW....0.I0.E.oy@:00...X...fR9... .~.I-..F.6.........{.. :y)dC.....u.....6s.0[1:..MY..qy..-.....K...y.zppKx.....Me.V.z.......[..>eC.@.FZ............w.z.J|3`..J......y...=9.:4....K...+!.....>;.E5.w.@8..Q.....G[.`.}M|f.f...../.(..u).... ..U.....L.T7....d..5y......)..i.io.....Dc...8.>#.>*:..M......8..6!.vp..>Y..Hj.....c...........8............/_.b..z.f...3..Sm]$..v...a...e.W..R.J........c...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1003
                  Entropy (8bit):7.733061712608813
                  Encrypted:false
                  SSDEEP:24:Y61pLLUe+vo2m6VVQGiCD385Ng9ERttNktQg:YmpLgeGo2PQPnrgn
                  MD5:FABCE8CEDCCAAB4844FF531759DC597D
                  SHA1:5778FB5BC79D2C0DD9EFB6007303D3C81834B24D
                  SHA-256:3B58552115BE88378FF8BB43914F630A2CD6DC47B082AAA3617E1A573CA00577
                  SHA-512:E396E4A9F11B85D823A8B462747CB89FE79338DD09A735411E9BBD1D14064E996100DE762ECA3C76038FBE622483633C549198B5460F14C7D77FC5B293CB4EEF
                  Malicious:false
                  Preview:&..5:......'UV..#..=..O}[@f.|....<_.i.f.m..~.%i'.WMu\..h....A.Z.G...d..E.....<........df....Wyz.4..-...>.....s..2...QF.tca....0.q....mn\;Ex..xkf...bB..S.B<.F}.R...*.h..._h}....k.....K..A.G(E..Ms..0..l.45.'.......VDo~.....=..CB*.q./..p$..<...T^w...1m.E..v...m.e%c....Hf.q.).....<.m...?..4.*...Fs.TQ..i>2..cY......MT........d.8.....k_S.......i...._.9\V}.t.3.8..4@.|o....5...|R..w.7m.Y..%pSRB.x-..qmRY.....E....E..d.n.6o.....(g .5|6.........+.Nw{lA(2..:.oS...m..u\...;#....n...K|.V9...vUQqI.T.*.n.d(.#..E).... fv..G......?..w..#./__.x.+.P...\......zx........Q.O..`....m.Z..lJ^3).$ej......U..j....8..*-Lt/..4.YU......?M.(N\$.P...J).ai.r..`.U...N...?.y.@{hw..... .P..\[p...8.!...^.op.L....M^..4.[f<M.....n..\<Yf...........}S<.%......c.M.....A..we..#....Jz..]f.`.......,....M....9d..L7..|.D..h....Y.`.....KG.N...Em.....4.....)..`.......s...._..".Z..c.k...........K.........] ....".....~.y...d.....d..._..Q..qz.2.Q......3.........K...............@....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1003
                  Entropy (8bit):7.733061712608813
                  Encrypted:false
                  SSDEEP:24:Y61pLLUe+vo2m6VVQGiCD385Ng9ERttNktQg:YmpLgeGo2PQPnrgn
                  MD5:FABCE8CEDCCAAB4844FF531759DC597D
                  SHA1:5778FB5BC79D2C0DD9EFB6007303D3C81834B24D
                  SHA-256:3B58552115BE88378FF8BB43914F630A2CD6DC47B082AAA3617E1A573CA00577
                  SHA-512:E396E4A9F11B85D823A8B462747CB89FE79338DD09A735411E9BBD1D14064E996100DE762ECA3C76038FBE622483633C549198B5460F14C7D77FC5B293CB4EEF
                  Malicious:false
                  Preview:&..5:......'UV..#..=..O}[@f.|....<_.i.f.m..~.%i'.WMu\..h....A.Z.G...d..E.....<........df....Wyz.4..-...>.....s..2...QF.tca....0.q....mn\;Ex..xkf...bB..S.B<.F}.R...*.h..._h}....k.....K..A.G(E..Ms..0..l.45.'.......VDo~.....=..CB*.q./..p$..<...T^w...1m.E..v...m.e%c....Hf.q.).....<.m...?..4.*...Fs.TQ..i>2..cY......MT........d.8.....k_S.......i...._.9\V}.t.3.8..4@.|o....5...|R..w.7m.Y..%pSRB.x-..qmRY.....E....E..d.n.6o.....(g .5|6.........+.Nw{lA(2..:.oS...m..u\...;#....n...K|.V9...vUQqI.T.*.n.d(.#..E).... fv..G......?..w..#./__.x.+.P...\......zx........Q.O..`....m.Z..lJ^3).$ej......U..j....8..*-Lt/..4.YU......?M.(N\$.P...J).ai.r..`.U...N...?.y.@{hw..... .P..\[p...8.!...^.op.L....M^..4.[f<M.....n..\<Yf...........}S<.%......c.M.....A..we..#....Jz..]f.`.......,....M....9d..L7..|.D..h....Y.`.....KG.N...Em.....4.....)..`.......s...._..".Z..c.k...........K.........] ....".....~.y...d.....d..._..Q..qz.2.Q......3.........K...............@....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1003
                  Entropy (8bit):7.733061712608813
                  Encrypted:false
                  SSDEEP:24:Y61pLLUe+vo2m6VVQGiCD385Ng9ERttNktQg:YmpLgeGo2PQPnrgn
                  MD5:FABCE8CEDCCAAB4844FF531759DC597D
                  SHA1:5778FB5BC79D2C0DD9EFB6007303D3C81834B24D
                  SHA-256:3B58552115BE88378FF8BB43914F630A2CD6DC47B082AAA3617E1A573CA00577
                  SHA-512:E396E4A9F11B85D823A8B462747CB89FE79338DD09A735411E9BBD1D14064E996100DE762ECA3C76038FBE622483633C549198B5460F14C7D77FC5B293CB4EEF
                  Malicious:false
                  Preview:&..5:......'UV..#..=..O}[@f.|....<_.i.f.m..~.%i'.WMu\..h....A.Z.G...d..E.....<........df....Wyz.4..-...>.....s..2...QF.tca....0.q....mn\;Ex..xkf...bB..S.B<.F}.R...*.h..._h}....k.....K..A.G(E..Ms..0..l.45.'.......VDo~.....=..CB*.q./..p$..<...T^w...1m.E..v...m.e%c....Hf.q.).....<.m...?..4.*...Fs.TQ..i>2..cY......MT........d.8.....k_S.......i...._.9\V}.t.3.8..4@.|o....5...|R..w.7m.Y..%pSRB.x-..qmRY.....E....E..d.n.6o.....(g .5|6.........+.Nw{lA(2..:.oS...m..u\...;#....n...K|.V9...vUQqI.T.*.n.d(.#..E).... fv..G......?..w..#./__.x.+.P...\......zx........Q.O..`....m.Z..lJ^3).$ej......U..j....8..*-Lt/..4.YU......?M.(N\$.P...J).ai.r..`.U...N...?.y.@{hw..... .P..\[p...8.!...^.op.L....M^..4.[f<M.....n..\<Yf...........}S<.%......c.M.....A..we..#....Jz..]f.`.......,....M....9d..L7..|.D..h....Y.`.....KG.N...Em.....4.....)..`.......s...._..".Z..c.k...........K.........] ....".....~.y...d.....d..._..Q..qz.2.Q......3.........K...............@....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14202
                  Entropy (8bit):7.985946015740671
                  Encrypted:false
                  SSDEEP:192:nubmGUlVQvqLaPXqjVWP8NmGRodE6Obv2oWHukghsjUUFy7P3ODCVjs2HFOFPG5u:aC2vqLa/vPmZW2h7z7vO+jsOAGY
                  MD5:0269FCB8947B17C0E6C32AC725C6E56A
                  SHA1:A6D6B5CC86B477BBC3F8963582EB468B6765A88E
                  SHA-256:C074F28D7AFBAF5B6A1421B4E69EE50E6A1160362D5F572B534790541944FAE8
                  SHA-512:7680D06039FC6405EC47E61409EDC17F5B7D5C91DD9189885C3F8711A2EDB20DF87D8D233B9EB9A238E05AE1A19E3855E75A15102C583B57899ABD3414CAA4D8
                  Malicious:false
                  Preview:..+.Tb.....,Ud.g-.W..Tl.c\:....eP..0e[>WB..y...*\.G.v_:.....!y._|.9..p.t?......m....^.i...=.....P....De^..xbfG.$K....G.ju..0..5..X....l...r.q........(.FH.6.S0..X........`.C=..[R...).ii..l.....M.. ..K.-..DR.JG....'.h;'...0..8k.x!...n..B...IZ....M`#..{...M.q.]. ...K... V.*[MlP...b.[.)<tL...b*..h;,S.n%.K.8....pQ....eWEH..\.5.WYUa.s...5\.q..u~..y.>R.uV...ghf=#...z..P'..:...A..[../;g.u.V.z~....".R....2$.s.7........C...Y.).....3....#.j........$.....F...6.Z...."PD..^W.........u.>!I_.b..M.M.d\.b..8WXu..T./....`.............. M...f...[.7...8[...2(n....J.....+`..o...tN;BW.Q..Ek...|./ES..J.~$.X.w....#...*..f='{P.G,.,s.H........q.-..L......5...E..b...V{o......b.........3....\........H..q.Z.,..+75....i..o.......R..y..Bl.....cl.3BK....W.......a..bbmV/..Vj.22.b..X..kM.T..}..q...:...iH.B....m../..,..-.#.d.<..B0.J.......0z.a..*W.../..........f...UP..6..J,Tq.i...[..a+.r<@).g..k...n..;..1Q.A.~_..?.J........b..l..t5xW.i..?fZ...........k.Of33......#....%.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14202
                  Entropy (8bit):7.985946015740671
                  Encrypted:false
                  SSDEEP:192:nubmGUlVQvqLaPXqjVWP8NmGRodE6Obv2oWHukghsjUUFy7P3ODCVjs2HFOFPG5u:aC2vqLa/vPmZW2h7z7vO+jsOAGY
                  MD5:0269FCB8947B17C0E6C32AC725C6E56A
                  SHA1:A6D6B5CC86B477BBC3F8963582EB468B6765A88E
                  SHA-256:C074F28D7AFBAF5B6A1421B4E69EE50E6A1160362D5F572B534790541944FAE8
                  SHA-512:7680D06039FC6405EC47E61409EDC17F5B7D5C91DD9189885C3F8711A2EDB20DF87D8D233B9EB9A238E05AE1A19E3855E75A15102C583B57899ABD3414CAA4D8
                  Malicious:false
                  Preview:..+.Tb.....,Ud.g-.W..Tl.c\:....eP..0e[>WB..y...*\.G.v_:.....!y._|.9..p.t?......m....^.i...=.....P....De^..xbfG.$K....G.ju..0..5..X....l...r.q........(.FH.6.S0..X........`.C=..[R...).ii..l.....M.. ..K.-..DR.JG....'.h;'...0..8k.x!...n..B...IZ....M`#..{...M.q.]. ...K... V.*[MlP...b.[.)<tL...b*..h;,S.n%.K.8....pQ....eWEH..\.5.WYUa.s...5\.q..u~..y.>R.uV...ghf=#...z..P'..:...A..[../;g.u.V.z~....".R....2$.s.7........C...Y.).....3....#.j........$.....F...6.Z...."PD..^W.........u.>!I_.b..M.M.d\.b..8WXu..T./....`.............. M...f...[.7...8[...2(n....J.....+`..o...tN;BW.Q..Ek...|./ES..J.~$.X.w....#...*..f='{P.G,.,s.H........q.-..L......5...E..b...V{o......b.........3....\........H..q.Z.,..+75....i..o.......R..y..Bl.....cl.3BK....W.......a..bbmV/..Vj.22.b..X..kM.T..}..q...:...iH.B....m../..,..-.#.d.<..B0.J.......0z.a..*W.../..........f...UP..6..J,Tq.i...[..a+.r<@).g..k...n..;..1Q.A.~_..?.J........b..l..t5xW.i..?fZ...........k.Of33......#....%.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):14202
                  Entropy (8bit):7.985946015740671
                  Encrypted:false
                  SSDEEP:192:nubmGUlVQvqLaPXqjVWP8NmGRodE6Obv2oWHukghsjUUFy7P3ODCVjs2HFOFPG5u:aC2vqLa/vPmZW2h7z7vO+jsOAGY
                  MD5:0269FCB8947B17C0E6C32AC725C6E56A
                  SHA1:A6D6B5CC86B477BBC3F8963582EB468B6765A88E
                  SHA-256:C074F28D7AFBAF5B6A1421B4E69EE50E6A1160362D5F572B534790541944FAE8
                  SHA-512:7680D06039FC6405EC47E61409EDC17F5B7D5C91DD9189885C3F8711A2EDB20DF87D8D233B9EB9A238E05AE1A19E3855E75A15102C583B57899ABD3414CAA4D8
                  Malicious:false
                  Preview:..+.Tb.....,Ud.g-.W..Tl.c\:....eP..0e[>WB..y...*\.G.v_:.....!y._|.9..p.t?......m....^.i...=.....P....De^..xbfG.$K....G.ju..0..5..X....l...r.q........(.FH.6.S0..X........`.C=..[R...).ii..l.....M.. ..K.-..DR.JG....'.h;'...0..8k.x!...n..B...IZ....M`#..{...M.q.]. ...K... V.*[MlP...b.[.)<tL...b*..h;,S.n%.K.8....pQ....eWEH..\.5.WYUa.s...5\.q..u~..y.>R.uV...ghf=#...z..P'..:...A..[../;g.u.V.z~....".R....2$.s.7........C...Y.).....3....#.j........$.....F...6.Z...."PD..^W.........u.>!I_.b..M.M.d\.b..8WXu..T./....`.............. M...f...[.7...8[...2(n....J.....+`..o...tN;BW.Q..Ek...|./ES..J.~$.X.w....#...*..f='{P.G,.,s.H........q.-..L......5...E..b...V{o......b.........3....\........H..q.Z.,..+75....i..o.......R..y..Bl.....cl.3BK....W.......a..bbmV/..Vj.22.b..X..kM.T..}..q...:...iH.B....m../..,..-.#.d.<..B0.J.......0z.a..*W.../..........f...UP..6..J,Tq.i...[..a+.r<@).g..k...n..;..1Q.A.~_..?.J........b..l..t5xW.i..?fZ...........k.Of33......#....%.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):2009
                  Entropy (8bit):7.904084657650794
                  Encrypted:false
                  SSDEEP:48:GRVOGdrKLb7C9IymluWX5DeeEXunCM4q12AMfVHK:GHOQ8C+LX5Deefnf4qyF
                  MD5:80FFE46CA435B19EC9DBAE5A55D52924
                  SHA1:63D295A63587C41F9AA9AD707E3350E79B073230
                  SHA-256:6BD1DBA2C6CE12DB866075003049EA07D5730E68477D02F8C8D7AC85302A3A18
                  SHA-512:9CBF3248CBFEA078BFC0F8F48B5F27CC855598C1C509765EC0CC057D1FC9DBB9B4B430C6F76D331DE5605E874D980F06983C671EF3800078B582DEDB816516EC
                  Malicious:false
                  Preview:..s.Zd.,....../..@.. B.b\o=.y.]Sy.`(.../e....K.Q$..|.9P.PJ...tXy.s.....:......e..(M.!..T(..Y.....q.0...aN.]I.....F.DT.>...H....y..aS|5D.b|.+..M&.X.X.N.iX..+...4\{.....Z....E.....\,ku,.e.+.C9.`G.;.c..97.....m.Q..J.wp$.....&Cr......i....,H....S..B..G{.dV.[.,..T.0.kl.-.mY....*...l..3.t(L.a].E.e./z...u....3.A%I.f0U..9...$.M..<.-?&{pr.r..zAw..z...n.Y.YE.+.{....5..=a..*..3C....s..^..+.1..<.."......(.. -.}=....)....?..(.`0..m+.o..Um....%......~..:.t...1.r..i.37Iu.Nx.R1...;...x.O5;....H|SX0\.*X...+..|_.k...C.?.-......Y..0...Q8{.~.}.,....w.aA.0...#i......V..._.......Z..+..o.m..$.4....<...ow..w<..*.....Kk;..H..u..y :...../D....}.......U.(...&..S.....J..p....u@?"]7.eW.....=..t./..*..._.8M.@..^.....F*..z4}B......w....oc....sS|.f..'XG.).GK[X....z.>..Y..P.#.....<.:...]...:.u<.+.~|p.".v%[..+...c....?>x.....;.q#>.@....c.....]%w...'Z@L..5$...u=:n..[..d..........b.`.S...T.B.nw..I?;{......t*.%.x.$..o).G..=c..b.q..\.'...5..3L2...[.aJ..^...@$H..B.o..-.....t<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):2009
                  Entropy (8bit):7.904084657650794
                  Encrypted:false
                  SSDEEP:48:GRVOGdrKLb7C9IymluWX5DeeEXunCM4q12AMfVHK:GHOQ8C+LX5Deefnf4qyF
                  MD5:80FFE46CA435B19EC9DBAE5A55D52924
                  SHA1:63D295A63587C41F9AA9AD707E3350E79B073230
                  SHA-256:6BD1DBA2C6CE12DB866075003049EA07D5730E68477D02F8C8D7AC85302A3A18
                  SHA-512:9CBF3248CBFEA078BFC0F8F48B5F27CC855598C1C509765EC0CC057D1FC9DBB9B4B430C6F76D331DE5605E874D980F06983C671EF3800078B582DEDB816516EC
                  Malicious:false
                  Preview:..s.Zd.,....../..@.. B.b\o=.y.]Sy.`(.../e....K.Q$..|.9P.PJ...tXy.s.....:......e..(M.!..T(..Y.....q.0...aN.]I.....F.DT.>...H....y..aS|5D.b|.+..M&.X.X.N.iX..+...4\{.....Z....E.....\,ku,.e.+.C9.`G.;.c..97.....m.Q..J.wp$.....&Cr......i....,H....S..B..G{.dV.[.,..T.0.kl.-.mY....*...l..3.t(L.a].E.e./z...u....3.A%I.f0U..9...$.M..<.-?&{pr.r..zAw..z...n.Y.YE.+.{....5..=a..*..3C....s..^..+.1..<.."......(.. -.}=....)....?..(.`0..m+.o..Um....%......~..:.t...1.r..i.37Iu.Nx.R1...;...x.O5;....H|SX0\.*X...+..|_.k...C.?.-......Y..0...Q8{.~.}.,....w.aA.0...#i......V..._.......Z..+..o.m..$.4....<...ow..w<..*.....Kk;..H..u..y :...../D....}.......U.(...&..S.....J..p....u@?"]7.eW.....=..t./..*..._.8M.@..^.....F*..z4}B......w....oc....sS|.f..'XG.).GK[X....z.>..Y..P.#.....<.:...]...:.u<.+.~|p.".v%[..+...c....?>x.....;.q#>.@....c.....]%w...'Z@L..5$...u=:n..[..d..........b.`.S...T.B.nw..I?;{......t*.%.x.$..o).G..=c..b.q..\.'...5..3L2...[.aJ..^...@$H..B.o..-.....t<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):2009
                  Entropy (8bit):7.904084657650794
                  Encrypted:false
                  SSDEEP:48:GRVOGdrKLb7C9IymluWX5DeeEXunCM4q12AMfVHK:GHOQ8C+LX5Deefnf4qyF
                  MD5:80FFE46CA435B19EC9DBAE5A55D52924
                  SHA1:63D295A63587C41F9AA9AD707E3350E79B073230
                  SHA-256:6BD1DBA2C6CE12DB866075003049EA07D5730E68477D02F8C8D7AC85302A3A18
                  SHA-512:9CBF3248CBFEA078BFC0F8F48B5F27CC855598C1C509765EC0CC057D1FC9DBB9B4B430C6F76D331DE5605E874D980F06983C671EF3800078B582DEDB816516EC
                  Malicious:false
                  Preview:..s.Zd.,....../..@.. B.b\o=.y.]Sy.`(.../e....K.Q$..|.9P.PJ...tXy.s.....:......e..(M.!..T(..Y.....q.0...aN.]I.....F.DT.>...H....y..aS|5D.b|.+..M&.X.X.N.iX..+...4\{.....Z....E.....\,ku,.e.+.C9.`G.;.c..97.....m.Q..J.wp$.....&Cr......i....,H....S..B..G{.dV.[.,..T.0.kl.-.mY....*...l..3.t(L.a].E.e./z...u....3.A%I.f0U..9...$.M..<.-?&{pr.r..zAw..z...n.Y.YE.+.{....5..=a..*..3C....s..^..+.1..<.."......(.. -.}=....)....?..(.`0..m+.o..Um....%......~..:.t...1.r..i.37Iu.Nx.R1...;...x.O5;....H|SX0\.*X...+..|_.k...C.?.-......Y..0...Q8{.~.}.,....w.aA.0...#i......V..._.......Z..+..o.m..$.4....<...ow..w<..*.....Kk;..H..u..y :...../D....}.......U.(...&..S.....J..p....u@?"]7.eW.....=..t./..*..._.8M.@..^.....F*..z4}B......w....oc....sS|.f..'XG.).GK[X....z.>..Y..P.#.....<.:...]...:.u<.+.~|p.".v%[..+...c....?>x.....;.q#>.@....c.....]%w...'Z@L..5$...u=:n..[..d..........b.`.S...T.B.nw..I?;{......t*.%.x.$..o).G..=c..b.q..\.'...5..3L2...[.aJ..^...@$H..B.o..-.....t<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2067
                  Entropy (8bit):7.8961049332868605
                  Encrypted:false
                  SSDEEP:48:WWnq2TGrt19H9uz7ym1QxY0Z8hluq/bpNy5kaxXiGyv4aFcXDHC8MJYx:vnqjrt1X47y7b+DpA6axXivgeYMS
                  MD5:8852C8D583EF7EBB78DDB1FD871B4742
                  SHA1:E01C8746B8B4CDF7946AB746540AF8C9F7BE1E3A
                  SHA-256:3B6545227C7B1ADFA3047736DB46EC903BD670DD45A9D20E232B1DD577C81DEB
                  SHA-512:BF695C96BD3243B59C337B3A5C08B683876B4FCBE4C62E6E8573D3803F5566D570B9B89FAC8F7B88206154ACEB4E11A506A44117DAA81E239B0234B1DDB501DB
                  Malicious:false
                  Preview:.....IQx..8[K.........Rn.oE"..0...tS.^..t.0.O..^.u....."....O.Y.+*TCL`.s...Z.&......^..}o.55^.W.9p..M...{..%...L(^.=...j.(..e.^..]......e..-;..h.E...~I .l!....w...!..D.....H...8..%.>W.....R..!Q..Cqi.,w+.&.Pp.%..:s..UM..Z.p...I..aF..q.......1}.HQD.;LU.};.r..3E..v.A.;MI.........._...WO..&(.~.; x^..&...-.m...@..wR:)!e...C.XE@..J...4.f.'*...].Q.&.z3.=..L....z.$...._Z...R.....%.]'...LxJ....\.G.'v=J...3...d.xgO...D.H5Z..a..............|)..x.(]-a.\...X...........(..i..K.......=....!GUCxR.`.....}...}%.../..H?."...!. .g.......D.h.1.~............J.CK.-r...\........&d.u6...D.`.............6...............a...G^fS..-RAT....Z.!..;F`.rZR...<...'u.;%.T..cP14.v.R..<..[.O-.qH.).h:O../.v...a.!FH.F.4q.;.Y..J:..yFq.{.....7[..\...f......QPw.q.e>."..r..e...<Z./R.O.3b..F.e.3.. .B........'.*...HF...:.[...,..F...}2zFY......a.l]#fl7...6...x....3E...=.. J.g(....B..%)....k..J.".Tb..pL.......|..i..2.......g.F.8._..S......O_...."e|.../...c....H.P7s..sj...5.j.j\..b..e..#v...IrH..`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2067
                  Entropy (8bit):7.8961049332868605
                  Encrypted:false
                  SSDEEP:48:WWnq2TGrt19H9uz7ym1QxY0Z8hluq/bpNy5kaxXiGyv4aFcXDHC8MJYx:vnqjrt1X47y7b+DpA6axXivgeYMS
                  MD5:8852C8D583EF7EBB78DDB1FD871B4742
                  SHA1:E01C8746B8B4CDF7946AB746540AF8C9F7BE1E3A
                  SHA-256:3B6545227C7B1ADFA3047736DB46EC903BD670DD45A9D20E232B1DD577C81DEB
                  SHA-512:BF695C96BD3243B59C337B3A5C08B683876B4FCBE4C62E6E8573D3803F5566D570B9B89FAC8F7B88206154ACEB4E11A506A44117DAA81E239B0234B1DDB501DB
                  Malicious:false
                  Preview:.....IQx..8[K.........Rn.oE"..0...tS.^..t.0.O..^.u....."....O.Y.+*TCL`.s...Z.&......^..}o.55^.W.9p..M...{..%...L(^.=...j.(..e.^..]......e..-;..h.E...~I .l!....w...!..D.....H...8..%.>W.....R..!Q..Cqi.,w+.&.Pp.%..:s..UM..Z.p...I..aF..q.......1}.HQD.;LU.};.r..3E..v.A.;MI.........._...WO..&(.~.; x^..&...-.m...@..wR:)!e...C.XE@..J...4.f.'*...].Q.&.z3.=..L....z.$...._Z...R.....%.]'...LxJ....\.G.'v=J...3...d.xgO...D.H5Z..a..............|)..x.(]-a.\...X...........(..i..K.......=....!GUCxR.`.....}...}%.../..H?."...!. .g.......D.h.1.~............J.CK.-r...\........&d.u6...D.`.............6...............a...G^fS..-RAT....Z.!..;F`.rZR...<...'u.;%.T..cP14.v.R..<..[.O-.qH.).h:O../.v...a.!FH.F.4q.;.Y..J:..yFq.{.....7[..\...f......QPw.q.e>."..r..e...<Z./R.O.3b..F.e.3.. .B........'.*...HF...:.[...,..F...}2zFY......a.l]#fl7...6...x....3E...=.. J.g(....B..%)....k..J.".Tb..pL.......|..i..2.......g.F.8._..S......O_...."e|.../...c....H.P7s..sj...5.j.j\..b..e..#v...IrH..`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2067
                  Entropy (8bit):7.8961049332868605
                  Encrypted:false
                  SSDEEP:48:WWnq2TGrt19H9uz7ym1QxY0Z8hluq/bpNy5kaxXiGyv4aFcXDHC8MJYx:vnqjrt1X47y7b+DpA6axXivgeYMS
                  MD5:8852C8D583EF7EBB78DDB1FD871B4742
                  SHA1:E01C8746B8B4CDF7946AB746540AF8C9F7BE1E3A
                  SHA-256:3B6545227C7B1ADFA3047736DB46EC903BD670DD45A9D20E232B1DD577C81DEB
                  SHA-512:BF695C96BD3243B59C337B3A5C08B683876B4FCBE4C62E6E8573D3803F5566D570B9B89FAC8F7B88206154ACEB4E11A506A44117DAA81E239B0234B1DDB501DB
                  Malicious:false
                  Preview:.....IQx..8[K.........Rn.oE"..0...tS.^..t.0.O..^.u....."....O.Y.+*TCL`.s...Z.&......^..}o.55^.W.9p..M...{..%...L(^.=...j.(..e.^..]......e..-;..h.E...~I .l!....w...!..D.....H...8..%.>W.....R..!Q..Cqi.,w+.&.Pp.%..:s..UM..Z.p...I..aF..q.......1}.HQD.;LU.};.r..3E..v.A.;MI.........._...WO..&(.~.; x^..&...-.m...@..wR:)!e...C.XE@..J...4.f.'*...].Q.&.z3.=..L....z.$...._Z...R.....%.]'...LxJ....\.G.'v=J...3...d.xgO...D.H5Z..a..............|)..x.(]-a.\...X...........(..i..K.......=....!GUCxR.`.....}...}%.../..H?."...!. .g.......D.h.1.~............J.CK.-r...\........&d.u6...D.`.............6...............a...G^fS..-RAT....Z.!..;F`.rZR...<...'u.;%.T..cP14.v.R..<..[.O-.qH.).h:O../.v...a.!FH.F.4q.;.Y..J:..yFq.{.....7[..\...f......QPw.q.e>."..r..e...<Z./R.O.3b..F.e.3.. .B........'.*...HF...:.[...,..F...}2zFY......a.l]#fl7...6...x....3E...=.. J.g(....B..%)....k..J.".Tb..pL.......|..i..2.......g.F.8._..S......O_...."e|.../...c....H.P7s..sj...5.j.j\..b..e..#v...IrH..`
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):761441
                  Entropy (8bit):7.999798007383305
                  Encrypted:true
                  SSDEEP:12288:wt6JL6vmAfPZKDOoYFtn0HFCF9Nc/9NZuMyiJo0oqClUcJrXOUZgvhCwVkYEw6:onvmmZKDVYP0HMN+juMyjqClIRvhKw
                  MD5:AE68811276D66D313A0ECD18CDEE8250
                  SHA1:78ED69D1D0BDB7E3E10FF464D08243030325F220
                  SHA-256:C49A67BEBAC3845B9DD8C7AAD48056C025352B1969A3FBEE90B00016E4881882
                  SHA-512:DB70748D83CEFEAC7E3C869E928DE0C565C79E05F621C646A470A34B57FA4D3F71D1F0E26755C2264FEE065319E02B24E47A5A490E0C7757E13DABEF65F1800E
                  Malicious:true
                  Preview:v/y.z..w...c....a:..S.Z.._...g.%..G.>....=.p..>&>eWF..C..`..."....."./zDx.vj.b.#.r..`...b.....<\...Xq_...T.`..`..:.j'.nn5..S.\].8..z......1N.:....@....51'!I.}...J....#.;.2.;..A2...d.F.I.....?.wW..P.;..Cn.&..7...O=........tD#.V-.!.....(.Rz.K..C?&..mC._..u..u.i.A.c|O.F0....CO..H\....4.....8$..EP7E.v.....<..O....P..vT1w....S:....7[..S.z(...`r..k...!..a.....N.N.=d'-.ep....*e..$...{I9.-......}&.7]..@)...!..q....y5>.c0...V...E-.vK}...d]......Y..S....}.<...jo..k..e.WHz|.........#....t`.<nF.'.&..G.E....HoA;...Q...f......"uR.8..W..J?.<.b. ...t.....B......x.......m5...H.c|(..v....7 A...{...=r...`CfS..OT....;x...-?.[~.j...L....N%]@..-..\.)]/...H.%71.......l/q.nrD.[.....*qY..W.YtT)..9.Jq..e$......!On.U6Wk..z.f|G7>....fI....vq.A..B|...]Y.g...0S8....BF*b.'........./."..d.~G.k.e.5........e.y......,..k.......~s.........a~q.6..|E..Y\|.'..+.z.....f..{.6.'^....Jx.@.7..J?.).......4.0..M.....v.).]@.......#K.....4.$.I.....'@....^h..&.]`..>....-.K..Y..3(...ty.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):761441
                  Entropy (8bit):7.999798007383305
                  Encrypted:true
                  SSDEEP:12288:wt6JL6vmAfPZKDOoYFtn0HFCF9Nc/9NZuMyiJo0oqClUcJrXOUZgvhCwVkYEw6:onvmmZKDVYP0HMN+juMyjqClIRvhKw
                  MD5:AE68811276D66D313A0ECD18CDEE8250
                  SHA1:78ED69D1D0BDB7E3E10FF464D08243030325F220
                  SHA-256:C49A67BEBAC3845B9DD8C7AAD48056C025352B1969A3FBEE90B00016E4881882
                  SHA-512:DB70748D83CEFEAC7E3C869E928DE0C565C79E05F621C646A470A34B57FA4D3F71D1F0E26755C2264FEE065319E02B24E47A5A490E0C7757E13DABEF65F1800E
                  Malicious:true
                  Preview:v/y.z..w...c....a:..S.Z.._...g.%..G.>....=.p..>&>eWF..C..`..."....."./zDx.vj.b.#.r..`...b.....<\...Xq_...T.`..`..:.j'.nn5..S.\].8..z......1N.:....@....51'!I.}...J....#.;.2.;..A2...d.F.I.....?.wW..P.;..Cn.&..7...O=........tD#.V-.!.....(.Rz.K..C?&..mC._..u..u.i.A.c|O.F0....CO..H\....4.....8$..EP7E.v.....<..O....P..vT1w....S:....7[..S.z(...`r..k...!..a.....N.N.=d'-.ep....*e..$...{I9.-......}&.7]..@)...!..q....y5>.c0...V...E-.vK}...d]......Y..S....}.<...jo..k..e.WHz|.........#....t`.<nF.'.&..G.E....HoA;...Q...f......"uR.8..W..J?.<.b. ...t.....B......x.......m5...H.c|(..v....7 A...{...=r...`CfS..OT....;x...-?.[~.j...L....N%]@..-..\.)]/...H.%71.......l/q.nrD.[.....*qY..W.YtT)..9.Jq..e$......!On.U6Wk..z.f|G7>....fI....vq.A..B|...]Y.g...0S8....BF*b.'........./."..d.~G.k.e.5........e.y......,..k.......~s.........a~q.6..|E..Y\|.'..+.z.....f..{.6.'^....Jx.@.7..J?.).......4.0..M.....v.).]@.......#K.....4.$.I.....'@....^h..&.]`..>....-.K..Y..3(...ty.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):761441
                  Entropy (8bit):7.999798007383305
                  Encrypted:true
                  SSDEEP:12288:wt6JL6vmAfPZKDOoYFtn0HFCF9Nc/9NZuMyiJo0oqClUcJrXOUZgvhCwVkYEw6:onvmmZKDVYP0HMN+juMyjqClIRvhKw
                  MD5:AE68811276D66D313A0ECD18CDEE8250
                  SHA1:78ED69D1D0BDB7E3E10FF464D08243030325F220
                  SHA-256:C49A67BEBAC3845B9DD8C7AAD48056C025352B1969A3FBEE90B00016E4881882
                  SHA-512:DB70748D83CEFEAC7E3C869E928DE0C565C79E05F621C646A470A34B57FA4D3F71D1F0E26755C2264FEE065319E02B24E47A5A490E0C7757E13DABEF65F1800E
                  Malicious:true
                  Preview:v/y.z..w...c....a:..S.Z.._...g.%..G.>....=.p..>&>eWF..C..`..."....."./zDx.vj.b.#.r..`...b.....<\...Xq_...T.`..`..:.j'.nn5..S.\].8..z......1N.:....@....51'!I.}...J....#.;.2.;..A2...d.F.I.....?.wW..P.;..Cn.&..7...O=........tD#.V-.!.....(.Rz.K..C?&..mC._..u..u.i.A.c|O.F0....CO..H\....4.....8$..EP7E.v.....<..O....P..vT1w....S:....7[..S.z(...`r..k...!..a.....N.N.=d'-.ep....*e..$...{I9.-......}&.7]..@)...!..q....y5>.c0...V...E-.vK}...d]......Y..S....}.<...jo..k..e.WHz|.........#....t`.<nF.'.&..G.E....HoA;...Q...f......"uR.8..W..J?.<.b. ...t.....B......x.......m5...H.c|(..v....7 A...{...=r...`CfS..OT....;x...-?.[~.j...L....N%]@..-..\.)]/...H.%71.......l/q.nrD.[.....*qY..W.YtT)..9.Jq..e$......!On.U6Wk..z.f|G7>....fI....vq.A..B|...]Y.g...0S8....BF*b.'........./."..d.~G.k.e.5........e.y......,..k.......~s.........a~q.6..|E..Y\|.'..+.z.....f..{.6.'^....Jx.@.7..J?.).......4.0..M.....v.).]@.......#K.....4.$.I.....'@....^h..&.]`..>....-.K..Y..3(...ty.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):280081
                  Entropy (8bit):7.9993701186834025
                  Encrypted:true
                  SSDEEP:6144:2Q8wgxznRVRgA26hu5CcEl1bI65b2HdqE7FUSivgep7hM3vC:26glRV5gb0My22SiBp7WvC
                  MD5:3198EC8BE722DE1AF3FC6C01A46F2563
                  SHA1:2F8F427FCC3C88F60DA157022F264359757B070F
                  SHA-256:45B1C7538922C1638259B31FA93A213484214A0C4933EF1F8D5547F7082582BD
                  SHA-512:D04CFE78987187CC6C154DD270AB501A2F80335D88F0105B75BB3784153F316FBCED736A65DE735F7DBFFFA02A68CAC9BE1B2EB07371F4E0BBE8CC12084A149D
                  Malicious:true
                  Preview:ksh.X.5Tq6e.`+\D.M...H.l..d:..1...E"._m.W6.NN.E.f...:...].<.n[g7..:.E...)(..&..@.]2O3..JN..N..t.X.}>.5=^@....LG-..o+..P.3.D.6..46.4}.....;.D.}..........\m.v...C.........n..Wk-...Z}...9.0Y.&..e6Y.....l_..Pk.i.....M..#...l..{.v..x..$.1.B.E..... ."......R./|...]3...R.gB.jX?..W...c.W.ibA....gz...f/...T._...B...N6....4)A....^.7....-....yi+..Nzy....%...\..NR.0G.&.3Kab,!.......K.....gt..X.~.Ba...A,...-.Y.v.......e......0..../..|pT.)F....&....2.\.@(.j.{..j.FK{...:#.{..;e%..p....T._.M..bK..R....P_.....!.vD.....&#g<k.y..WSE.b)k6.,.i./...uZ.u4..t".....1-x\&6.x..`...2M.@.AU..8..r...?...K....x...:.0...Q..nS.B(..c.......T..:..i....-v9Q9*.Y..w.v.e..`..KOI..x.\2O...Hd9......%.+.8w.... M.c6.X/T.A.a....7O....(..v.[IM)....<..P.:.....^.w...B.c...d.BP...J_..#%zQ.7..:..\....jEP...7...s...."!......'...i.l.j.g-..3w.*^y...q.=.E.S...g........#].~D...........}.e..&.....?...L..j...d.|fo.....G.K7uR...?.QXk.S.p..o.~..E....~...TR....T.$..V..s.j..n..[.b;.8........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):280081
                  Entropy (8bit):7.9993701186834025
                  Encrypted:true
                  SSDEEP:6144:2Q8wgxznRVRgA26hu5CcEl1bI65b2HdqE7FUSivgep7hM3vC:26glRV5gb0My22SiBp7WvC
                  MD5:3198EC8BE722DE1AF3FC6C01A46F2563
                  SHA1:2F8F427FCC3C88F60DA157022F264359757B070F
                  SHA-256:45B1C7538922C1638259B31FA93A213484214A0C4933EF1F8D5547F7082582BD
                  SHA-512:D04CFE78987187CC6C154DD270AB501A2F80335D88F0105B75BB3784153F316FBCED736A65DE735F7DBFFFA02A68CAC9BE1B2EB07371F4E0BBE8CC12084A149D
                  Malicious:true
                  Preview:ksh.X.5Tq6e.`+\D.M...H.l..d:..1...E"._m.W6.NN.E.f...:...].<.n[g7..:.E...)(..&..@.]2O3..JN..N..t.X.}>.5=^@....LG-..o+..P.3.D.6..46.4}.....;.D.}..........\m.v...C.........n..Wk-...Z}...9.0Y.&..e6Y.....l_..Pk.i.....M..#...l..{.v..x..$.1.B.E..... ."......R./|...]3...R.gB.jX?..W...c.W.ibA....gz...f/...T._...B...N6....4)A....^.7....-....yi+..Nzy....%...\..NR.0G.&.3Kab,!.......K.....gt..X.~.Ba...A,...-.Y.v.......e......0..../..|pT.)F....&....2.\.@(.j.{..j.FK{...:#.{..;e%..p....T._.M..bK..R....P_.....!.vD.....&#g<k.y..WSE.b)k6.,.i./...uZ.u4..t".....1-x\&6.x..`...2M.@.AU..8..r...?...K....x...:.0...Q..nS.B(..c.......T..:..i....-v9Q9*.Y..w.v.e..`..KOI..x.\2O...Hd9......%.+.8w.... M.c6.X/T.A.a....7O....(..v.[IM)....<..P.:.....^.w...B.c...d.BP...J_..#%zQ.7..:..\....jEP...7...s...."!......'...i.l.j.g-..3w.*^y...q.=.E.S...g........#].~D...........}.e..&.....?...L..j...d.|fo.....G.K7uR...?.QXk.S.p..o.~..E....~...TR....T.$..V..s.j..n..[.b;.8........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):280081
                  Entropy (8bit):7.9993701186834025
                  Encrypted:true
                  SSDEEP:6144:2Q8wgxznRVRgA26hu5CcEl1bI65b2HdqE7FUSivgep7hM3vC:26glRV5gb0My22SiBp7WvC
                  MD5:3198EC8BE722DE1AF3FC6C01A46F2563
                  SHA1:2F8F427FCC3C88F60DA157022F264359757B070F
                  SHA-256:45B1C7538922C1638259B31FA93A213484214A0C4933EF1F8D5547F7082582BD
                  SHA-512:D04CFE78987187CC6C154DD270AB501A2F80335D88F0105B75BB3784153F316FBCED736A65DE735F7DBFFFA02A68CAC9BE1B2EB07371F4E0BBE8CC12084A149D
                  Malicious:true
                  Preview:ksh.X.5Tq6e.`+\D.M...H.l..d:..1...E"._m.W6.NN.E.f...:...].<.n[g7..:.E...)(..&..@.]2O3..JN..N..t.X.}>.5=^@....LG-..o+..P.3.D.6..46.4}.....;.D.}..........\m.v...C.........n..Wk-...Z}...9.0Y.&..e6Y.....l_..Pk.i.....M..#...l..{.v..x..$.1.B.E..... ."......R./|...]3...R.gB.jX?..W...c.W.ibA....gz...f/...T._...B...N6....4)A....^.7....-....yi+..Nzy....%...\..NR.0G.&.3Kab,!.......K.....gt..X.~.Ba...A,...-.Y.v.......e......0..../..|pT.)F....&....2.\.@(.j.{..j.FK{...:#.{..;e%..p....T._.M..bK..R....P_.....!.vD.....&#g<k.y..WSE.b)k6.,.i./...uZ.u4..t".....1-x\&6.x..`...2M.@.AU..8..r...?...K....x...:.0...Q..nS.B(..c.......T..:..i....-v9Q9*.Y..w.v.e..`..KOI..x.\2O...Hd9......%.+.8w.... M.c6.X/T.A.a....7O....(..v.[IM)....<..P.:.....^.w...B.c...d.BP...J_..#%zQ.7..:..\....jEP...7...s...."!......'...i.l.j.g-..3w.*^y...q.=.E.S...g........#].~D...........}.e..&.....?...L..j...d.|fo.....G.K7uR...?.QXk.S.p..o.~..E....~...TR....T.$..V..s.j..n..[.b;.8........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:SysEx File - Fostex
                  Category:dropped
                  Size (bytes):2878
                  Entropy (8bit):7.930247102469913
                  Encrypted:false
                  SSDEEP:48:/NZWQ76hGQgluz0GR49HNLw2CEODXKbNdkhjUoBHIY07aXVX6NHvNkW1arvaZ/ri:/QRfqtqEuO6jLf0aXVqNHvN/1aTEA
                  MD5:0AA5D141A5EA6F2D1AB248BD4C75A72A
                  SHA1:42656F57446F5053A601589B5EADFAECB2875720
                  SHA-256:C4DB9E8AA1DBCA858006900FAF4A1FE0A2964DD1628D4EA23E5D3C5946A75192
                  SHA-512:CEE7F922ADA8FFD1BCE413B1EEDDF324D237B5996829E324035A6AAD07A60CA3CB40D11810B82BE0380EF5B8579CB4AAC43C0F811B0BC32A25B6CD26E24C53DD
                  Malicious:true
                  Preview:.Qn.LzI!vG).....= ....P..|...+.9.u[.}..t.......[jt..4....7..$...m.i>.k..2..r|.jA.1P.Z..O.).^ .....H.L'j.<.!).'..3.).f..g.3L..P......svq.%p..9..`s.a...%..b]....O.H.$I9b_....z.&......1x......Tg.,. '.)rN..:.1O...g.8.$M.H.......c.Z.t..8.....[.P........|.}.V..).;....\c(Qj..Q.Dz.."_.*..:.9..Y...rT..Xb/"h.7|Y.Z....L..I.pB.B..=.-teU=...LpG.m..Uq..h.8.7&IRd.2.7tl4..So...zU.V_..-@...d.W....f..c..rA..!Z*J.....k..[.....!.q.>u....5@..x.bQ..s...b.y....Mp..a.Y.....%.%.f.....KW?.%.5....)d.;...>m.h.Oe..d._..S..y.tz.,...f.h7...,+..`...0z.v*.m..g..=^...+&.8...>..A.dQ..Mh.W.V!..lca.M..3v...5Y.s....2.....b.).......I.Qg..4.(..`f.5`.3..*=+."..0.....>..-Itn..;a....1.....J...l...(.;.\bk....|<..dgRj.E.....G2.d. W..%G._...0._/....g..D>.?x6......{...fl...&.r..K.....T$]z.&....z..8A....._..>.....-..9..6.....Ds...x.\Q~.X.CN.p..p.....H+...[.... YP.($}.....(KU.Q..f_...^.G[.w......8..;.....s.t..Bg...h~.i........'....F.Oe.f.sr...J.!...7...............~C.........N.}8
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:SysEx File - Fostex
                  Category:dropped
                  Size (bytes):2878
                  Entropy (8bit):7.930247102469913
                  Encrypted:false
                  SSDEEP:48:/NZWQ76hGQgluz0GR49HNLw2CEODXKbNdkhjUoBHIY07aXVX6NHvNkW1arvaZ/ri:/QRfqtqEuO6jLf0aXVqNHvN/1aTEA
                  MD5:0AA5D141A5EA6F2D1AB248BD4C75A72A
                  SHA1:42656F57446F5053A601589B5EADFAECB2875720
                  SHA-256:C4DB9E8AA1DBCA858006900FAF4A1FE0A2964DD1628D4EA23E5D3C5946A75192
                  SHA-512:CEE7F922ADA8FFD1BCE413B1EEDDF324D237B5996829E324035A6AAD07A60CA3CB40D11810B82BE0380EF5B8579CB4AAC43C0F811B0BC32A25B6CD26E24C53DD
                  Malicious:true
                  Preview:.Qn.LzI!vG).....= ....P..|...+.9.u[.}..t.......[jt..4....7..$...m.i>.k..2..r|.jA.1P.Z..O.).^ .....H.L'j.<.!).'..3.).f..g.3L..P......svq.%p..9..`s.a...%..b]....O.H.$I9b_....z.&......1x......Tg.,. '.)rN..:.1O...g.8.$M.H.......c.Z.t..8.....[.P........|.}.V..).;....\c(Qj..Q.Dz.."_.*..:.9..Y...rT..Xb/"h.7|Y.Z....L..I.pB.B..=.-teU=...LpG.m..Uq..h.8.7&IRd.2.7tl4..So...zU.V_..-@...d.W....f..c..rA..!Z*J.....k..[.....!.q.>u....5@..x.bQ..s...b.y....Mp..a.Y.....%.%.f.....KW?.%.5....)d.;...>m.h.Oe..d._..S..y.tz.,...f.h7...,+..`...0z.v*.m..g..=^...+&.8...>..A.dQ..Mh.W.V!..lca.M..3v...5Y.s....2.....b.).......I.Qg..4.(..`f.5`.3..*=+."..0.....>..-Itn..;a....1.....J...l...(.;.\bk....|<..dgRj.E.....G2.d. W..%G._...0._/....g..D>.?x6......{...fl...&.r..K.....T$]z.&....z..8A....._..>.....-..9..6.....Ds...x.\Q~.X.CN.p..p.....H+...[.... YP.($}.....(KU.Q..f_...^.G[.w......8..;.....s.t..Bg...h~.i........'....F.Oe.f.sr...J.!...7...............~C.........N.}8
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:SysEx File - Fostex
                  Category:dropped
                  Size (bytes):2878
                  Entropy (8bit):7.930247102469913
                  Encrypted:false
                  SSDEEP:48:/NZWQ76hGQgluz0GR49HNLw2CEODXKbNdkhjUoBHIY07aXVX6NHvNkW1arvaZ/ri:/QRfqtqEuO6jLf0aXVqNHvN/1aTEA
                  MD5:0AA5D141A5EA6F2D1AB248BD4C75A72A
                  SHA1:42656F57446F5053A601589B5EADFAECB2875720
                  SHA-256:C4DB9E8AA1DBCA858006900FAF4A1FE0A2964DD1628D4EA23E5D3C5946A75192
                  SHA-512:CEE7F922ADA8FFD1BCE413B1EEDDF324D237B5996829E324035A6AAD07A60CA3CB40D11810B82BE0380EF5B8579CB4AAC43C0F811B0BC32A25B6CD26E24C53DD
                  Malicious:true
                  Preview:.Qn.LzI!vG).....= ....P..|...+.9.u[.}..t.......[jt..4....7..$...m.i>.k..2..r|.jA.1P.Z..O.).^ .....H.L'j.<.!).'..3.).f..g.3L..P......svq.%p..9..`s.a...%..b]....O.H.$I9b_....z.&......1x......Tg.,. '.)rN..:.1O...g.8.$M.H.......c.Z.t..8.....[.P........|.}.V..).;....\c(Qj..Q.Dz.."_.*..:.9..Y...rT..Xb/"h.7|Y.Z....L..I.pB.B..=.-teU=...LpG.m..Uq..h.8.7&IRd.2.7tl4..So...zU.V_..-@...d.W....f..c..rA..!Z*J.....k..[.....!.q.>u....5@..x.bQ..s...b.y....Mp..a.Y.....%.%.f.....KW?.%.5....)d.;...>m.h.Oe..d._..S..y.tz.,...f.h7...,+..`...0z.v*.m..g..=^...+&.8...>..A.dQ..Mh.W.V!..lca.M..3v...5Y.s....2.....b.).......I.Qg..4.(..`f.5`.3..*=+."..0.....>..-Itn..;a....1.....J...l...(.;.\bk....|<..dgRj.E.....G2.d. W..%G._...0._/....g..D>.?x6......{...fl...&.r..K.....T$]z.&....z..8A....._..>.....-..9..6.....Ds...x.\Q~.X.CN.p..p.....H+...[.... YP.($}.....(KU.Q..f_...^.G[.w......8..;.....s.t..Bg...h~.i........'....F.Oe.f.sr...J.!...7...............~C.........N.}8
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2250
                  Entropy (8bit):7.9001004663532655
                  Encrypted:false
                  SSDEEP:48:JtSaqORYLBQpRsPTltmkPdFe4gd0TjJibG4uiGA:eaNYLapRSPez0TjkbGH
                  MD5:B6B60981F5050D57F6439796F1F934D6
                  SHA1:A33D41FA65CC34B83F586CDC57FF663442034053
                  SHA-256:EC3BCABFA637F0DE531FDAB42570345762A500ADC98BBB5A2D31CF163E4E32C9
                  SHA-512:0A97DCD619519364875E5C177AFAD560D9800E92DF13D9E829A6BD3F5842D51C899950C81112607F5758E993A94FF19FDCDF5B95654C5EE2A56BDF90E7C470ED
                  Malicious:false
                  Preview:.;FO....F.6.=.G..z...<.<0g.D...6..W1..N...7;64o.S.v.....~*.6>..V`EV+Z.Q.;....a......(.M..YEt/>5.....(.eD...XE.BJ.....h,1...[.....0....C.R..[....*.....B.*.}Y.e...F....I1AS./|....)>.S...+..........s..&...I.....>O.TS...s..\...k ........).aar.....L.......`'Q.....{.9...SeY.g.A.2..[..;q.d._.K.;X...........^..X.....w..I...4c>.9..M...TtcdwP4.......K ...\><....W...FY-7T..E..a..z...r>.>7.b.....3...4.xw.{.5,E.. V$..`T.n..&-..1..#<i.H......a].\.|3..\....2u.7....F.CB..x7Iw..6..kl......}....0%o..........\B.>])... 6x.V...AUT.............4...wmc.E..,.D.[1..:q.e`.[n./po1g4....&.s.4....c.,..yv#..9....].QCb...{.[..............{(N:>....9.....n..L.....v.(.w/OR+....|..i..=..n........[.]d.k..d.jp8.y-.....:b.7(0b.2.||.i3R..<.k...l..>.zo..Q{.he.Z..m...n..QI.......#..7?......@|p./!}..O.df)+...^'.....a0.............xQ.joP...}..1............u....Iq....<%1lt..../Q*.....C@..W..k...m..5Iu@n..sT.3..h.L....p..UP.d..\..5t.@.......z.u..y.!.;lW.O..h0.<..'..V:AV..&73..p.`...<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2250
                  Entropy (8bit):7.9001004663532655
                  Encrypted:false
                  SSDEEP:48:JtSaqORYLBQpRsPTltmkPdFe4gd0TjJibG4uiGA:eaNYLapRSPez0TjkbGH
                  MD5:B6B60981F5050D57F6439796F1F934D6
                  SHA1:A33D41FA65CC34B83F586CDC57FF663442034053
                  SHA-256:EC3BCABFA637F0DE531FDAB42570345762A500ADC98BBB5A2D31CF163E4E32C9
                  SHA-512:0A97DCD619519364875E5C177AFAD560D9800E92DF13D9E829A6BD3F5842D51C899950C81112607F5758E993A94FF19FDCDF5B95654C5EE2A56BDF90E7C470ED
                  Malicious:false
                  Preview:.;FO....F.6.=.G..z...<.<0g.D...6..W1..N...7;64o.S.v.....~*.6>..V`EV+Z.Q.;....a......(.M..YEt/>5.....(.eD...XE.BJ.....h,1...[.....0....C.R..[....*.....B.*.}Y.e...F....I1AS./|....)>.S...+..........s..&...I.....>O.TS...s..\...k ........).aar.....L.......`'Q.....{.9...SeY.g.A.2..[..;q.d._.K.;X...........^..X.....w..I...4c>.9..M...TtcdwP4.......K ...\><....W...FY-7T..E..a..z...r>.>7.b.....3...4.xw.{.5,E.. V$..`T.n..&-..1..#<i.H......a].\.|3..\....2u.7....F.CB..x7Iw..6..kl......}....0%o..........\B.>])... 6x.V...AUT.............4...wmc.E..,.D.[1..:q.e`.[n./po1g4....&.s.4....c.,..yv#..9....].QCb...{.[..............{(N:>....9.....n..L.....v.(.w/OR+....|..i..=..n........[.]d.k..d.jp8.y-.....:b.7(0b.2.||.i3R..<.k...l..>.zo..Q{.he.Z..m...n..QI.......#..7?......@|p./!}..O.df)+...^'.....a0.............xQ.joP...}..1............u....Iq....<%1lt..../Q*.....C@..W..k...m..5Iu@n..sT.3..h.L....p..UP.d..\..5t.@.......z.u..y.!.;lW.O..h0.<..'..V:AV..&73..p.`...<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2250
                  Entropy (8bit):7.9001004663532655
                  Encrypted:false
                  SSDEEP:48:JtSaqORYLBQpRsPTltmkPdFe4gd0TjJibG4uiGA:eaNYLapRSPez0TjkbGH
                  MD5:B6B60981F5050D57F6439796F1F934D6
                  SHA1:A33D41FA65CC34B83F586CDC57FF663442034053
                  SHA-256:EC3BCABFA637F0DE531FDAB42570345762A500ADC98BBB5A2D31CF163E4E32C9
                  SHA-512:0A97DCD619519364875E5C177AFAD560D9800E92DF13D9E829A6BD3F5842D51C899950C81112607F5758E993A94FF19FDCDF5B95654C5EE2A56BDF90E7C470ED
                  Malicious:false
                  Preview:.;FO....F.6.=.G..z...<.<0g.D...6..W1..N...7;64o.S.v.....~*.6>..V`EV+Z.Q.;....a......(.M..YEt/>5.....(.eD...XE.BJ.....h,1...[.....0....C.R..[....*.....B.*.}Y.e...F....I1AS./|....)>.S...+..........s..&...I.....>O.TS...s..\...k ........).aar.....L.......`'Q.....{.9...SeY.g.A.2..[..;q.d._.K.;X...........^..X.....w..I...4c>.9..M...TtcdwP4.......K ...\><....W...FY-7T..E..a..z...r>.>7.b.....3...4.xw.{.5,E.. V$..`T.n..&-..1..#<i.H......a].\.|3..\....2u.7....F.CB..x7Iw..6..kl......}....0%o..........\B.>])... 6x.V...AUT.............4...wmc.E..,.D.[1..:q.e`.[n./po1g4....&.s.4....c.,..yv#..9....].QCb...{.[..............{(N:>....9.....n..L.....v.(.w/OR+....|..i..=..n........[.]d.k..d.jp8.y-.....:b.7(0b.2.||.i3R..<.k...l..>.zo..Q{.he.Z..m...n..QI.......#..7?......@|p./!}..O.df)+...^'.....a0.............xQ.joP...}..1............u....Iq....<%1lt..../Q*.....C@..W..k...m..5Iu@n..sT.3..h.L....p..UP.d..\..5t.@.......z.u..y.!.;lW.O..h0.<..'..V:AV..&73..p.`...<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1816
                  Entropy (8bit):7.885497163716465
                  Encrypted:false
                  SSDEEP:48:DrRzxULpd3lBWFFeeg/JJXcSIhyhef/n/GD3To:3lepllMGXJJcOMn/GD3k
                  MD5:BE58F988F3D3CC9FB5CBC60CFA92D921
                  SHA1:630A44C1E9B34F76A69DACC13E2DDE921EB66E1B
                  SHA-256:828846EC69D80548B1A07099DAA3E10970711855F892A8A8A03CA07916E54EF7
                  SHA-512:29D716DDC105A065D0FF6E2E8233ED52B09F7CF28940DEA4EE5B9302F2173D718937ACE21EDE2241F26BDEDF083D624A6A1ECAAC5C40388AAE7B5106B48EEB77
                  Malicious:false
                  Preview:'..A.....>........]..t.y..M..7Z.cH..Z6?..j.....{U..t.....%..@g..w.{.!...l.Q49_.."...;..i..v...B.t@.}..'Y/<."....5.y............^.(.......o..y.j........+.3..:..f..e....s"....."7..A.j..z....?n=........<."l.'R0@qh...7].i{,....).TX.......J.....,._..t..A9.bsu..6.ZtJ.s.....}.G.k8.T..Q"......k..S.AwD{.....(...-y.Y........'._l....sr+...../FZ.....*|_..2...{3.;...J..........Q....5a4... ..?.M/....0u{.L.B.....SW.hG~.D....J..@DS-.g/\......c..}>...P........c...x'....E.M).....>74...n.....xHu.....pEu-.t.."..@..Q.,!.~....2.q/VEDM|X=....;..%n..<J@+.......\.=<1.kU.7)..?..L..r.(.a....#...\9.....h'EWz.|...H..r..b.../.....D=..8.w..ir.Y.^...%l...d.:.+...Gm...$..E.3!.d....&........N..Y......._^..gv....o(z.).O0...5M.O.}...J..$......;..?..H.^i.F..;{b.e.A|'.k...\.;.u..-.....A:..!..k.<...X C.......p..m..}h...K...g...fc.`..Q.....iO...uN{tq...G....G..b.a7dc.....*...rF.ht...J....>.gb5....6.....W{.....$..Ke.{..0n}im....=q{.7.Q.".[w..g.oe.E...p..-.P!.....4..vgu.@.u...mn..9.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1816
                  Entropy (8bit):7.885497163716465
                  Encrypted:false
                  SSDEEP:48:DrRzxULpd3lBWFFeeg/JJXcSIhyhef/n/GD3To:3lepllMGXJJcOMn/GD3k
                  MD5:BE58F988F3D3CC9FB5CBC60CFA92D921
                  SHA1:630A44C1E9B34F76A69DACC13E2DDE921EB66E1B
                  SHA-256:828846EC69D80548B1A07099DAA3E10970711855F892A8A8A03CA07916E54EF7
                  SHA-512:29D716DDC105A065D0FF6E2E8233ED52B09F7CF28940DEA4EE5B9302F2173D718937ACE21EDE2241F26BDEDF083D624A6A1ECAAC5C40388AAE7B5106B48EEB77
                  Malicious:false
                  Preview:'..A.....>........]..t.y..M..7Z.cH..Z6?..j.....{U..t.....%..@g..w.{.!...l.Q49_.."...;..i..v...B.t@.}..'Y/<."....5.y............^.(.......o..y.j........+.3..:..f..e....s"....."7..A.j..z....?n=........<."l.'R0@qh...7].i{,....).TX.......J.....,._..t..A9.bsu..6.ZtJ.s.....}.G.k8.T..Q"......k..S.AwD{.....(...-y.Y........'._l....sr+...../FZ.....*|_..2...{3.;...J..........Q....5a4... ..?.M/....0u{.L.B.....SW.hG~.D....J..@DS-.g/\......c..}>...P........c...x'....E.M).....>74...n.....xHu.....pEu-.t.."..@..Q.,!.~....2.q/VEDM|X=....;..%n..<J@+.......\.=<1.kU.7)..?..L..r.(.a....#...\9.....h'EWz.|...H..r..b.../.....D=..8.w..ir.Y.^...%l...d.:.+...Gm...$..E.3!.d....&........N..Y......._^..gv....o(z.).O0...5M.O.}...J..$......;..?..H.^i.F..;{b.e.A|'.k...\.;.u..-.....A:..!..k.<...X C.......p..m..}h...K...g...fc.`..Q.....iO...uN{tq...G....G..b.a7dc.....*...rF.ht...J....>.gb5....6.....W{.....$..Ke.{..0n}im....=q{.7.Q.".[w..g.oe.E...p..-.P!.....4..vgu.@.u...mn..9.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1816
                  Entropy (8bit):7.885497163716465
                  Encrypted:false
                  SSDEEP:48:DrRzxULpd3lBWFFeeg/JJXcSIhyhef/n/GD3To:3lepllMGXJJcOMn/GD3k
                  MD5:BE58F988F3D3CC9FB5CBC60CFA92D921
                  SHA1:630A44C1E9B34F76A69DACC13E2DDE921EB66E1B
                  SHA-256:828846EC69D80548B1A07099DAA3E10970711855F892A8A8A03CA07916E54EF7
                  SHA-512:29D716DDC105A065D0FF6E2E8233ED52B09F7CF28940DEA4EE5B9302F2173D718937ACE21EDE2241F26BDEDF083D624A6A1ECAAC5C40388AAE7B5106B48EEB77
                  Malicious:false
                  Preview:'..A.....>........]..t.y..M..7Z.cH..Z6?..j.....{U..t.....%..@g..w.{.!...l.Q49_.."...;..i..v...B.t@.}..'Y/<."....5.y............^.(.......o..y.j........+.3..:..f..e....s"....."7..A.j..z....?n=........<."l.'R0@qh...7].i{,....).TX.......J.....,._..t..A9.bsu..6.ZtJ.s.....}.G.k8.T..Q"......k..S.AwD{.....(...-y.Y........'._l....sr+...../FZ.....*|_..2...{3.;...J..........Q....5a4... ..?.M/....0u{.L.B.....SW.hG~.D....J..@DS-.g/\......c..}>...P........c...x'....E.M).....>74...n.....xHu.....pEu-.t.."..@..Q.,!.~....2.q/VEDM|X=....;..%n..<J@+.......\.=<1.kU.7)..?..L..r.(.a....#...\9.....h'EWz.|...H..r..b.../.....D=..8.w..ir.Y.^...%l...d.:.+...Gm...$..E.3!.d....&........N..Y......._^..gv....o(z.).O0...5M.O.}...J..$......;..?..H.^i.F..;{b.e.A|'.k...\.;.u..-.....A:..!..k.<...X C.......p..m..}h...K...g...fc.`..Q.....iO...uN{tq...G....G..b.a7dc.....*...rF.ht...J....>.gb5....6.....W{.....$..Ke.{..0n}im....=q{.7.Q.".[w..g.oe.E...p..-.P!.....4..vgu.@.u...mn..9.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5530
                  Entropy (8bit):7.956729393611497
                  Encrypted:false
                  SSDEEP:96:R6s1yfmH9zuPkY/OL9R5U2TKp5uEKUE0UnAmd+16PHLpEe5vMPO1Wp4eV2KodMyF:weyfmde/MU2EE0UlLKeUOkp4eHox
                  MD5:C7772292D3E3822967CE8F2E0F0B0B72
                  SHA1:889AECE4BFA659A2DCAD6B901BC902C67FB0BB86
                  SHA-256:3F1FF5DE3D0DF520276149958B51C62449F3CF4EB455D3F7BD8284E95DE8B690
                  SHA-512:8C7D795417F8F60FB078E52E1D85D5C71947CD7CA2BAB24C8DF41AB25B13044C3E6C388D5F2FF5E68E5EB5151AF17EF900556F1B7A4195938E07FAA683B40BBD
                  Malicious:false
                  Preview:.xP?H...@**.g..%.....z.........Lg..En....B1.kZ`....y\..cs.\x...bE......P1]<+N..N......u.'..t........!aP].H....\g....k.....$tN\*@...c>.X....G...m.P).Z..g....C./.t...z..).U........1o..'.[.n..q7.......z..w(Xie:.{!Jn...[;Y4..\...R^e<;..........@j...........'%Ap.S......]..u..i....G\q.f...^....o.?.......Q;..T]\.r,<....tBI..d6..m...RK..1G....C}...6.HQ....QKo6....N.."58..;..[u;.........S...e.N...y....T..s..[.C*...5.a...u.}0.Ei....?....4....#..U.2L...........s.6.(.......:}..d(.i...?f9JH_..2..q..\..f..7..d.........7ceV...@...........~<W.X...m..~8.,J.Y1.V{..........\..$.].v.. A..F.O:./.E..i...(h.:.......l<.y.O.....K.B.l......=..6.s.d...$@...J....p..q.XW.0...!)..........d..b...w.9.p..G..o.&..w+I...2 ..6.}X....GE..wz2....Hi....KW......i.e....^[O._n}...[.$..?...........R{..R.I.4.".fm4/.....dNC1....,..<cZ.rXp.rH........O4...3.d.Q,.|..../...d..I......B.5..<..\."..V..+...u.FbQ.0N..c-.........m..:..qmI.g~.W...^...?.2)~j.y..].Y.R......"..yW..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5530
                  Entropy (8bit):7.956729393611497
                  Encrypted:false
                  SSDEEP:96:R6s1yfmH9zuPkY/OL9R5U2TKp5uEKUE0UnAmd+16PHLpEe5vMPO1Wp4eV2KodMyF:weyfmde/MU2EE0UlLKeUOkp4eHox
                  MD5:C7772292D3E3822967CE8F2E0F0B0B72
                  SHA1:889AECE4BFA659A2DCAD6B901BC902C67FB0BB86
                  SHA-256:3F1FF5DE3D0DF520276149958B51C62449F3CF4EB455D3F7BD8284E95DE8B690
                  SHA-512:8C7D795417F8F60FB078E52E1D85D5C71947CD7CA2BAB24C8DF41AB25B13044C3E6C388D5F2FF5E68E5EB5151AF17EF900556F1B7A4195938E07FAA683B40BBD
                  Malicious:false
                  Preview:.xP?H...@**.g..%.....z.........Lg..En....B1.kZ`....y\..cs.\x...bE......P1]<+N..N......u.'..t........!aP].H....\g....k.....$tN\*@...c>.X....G...m.P).Z..g....C./.t...z..).U........1o..'.[.n..q7.......z..w(Xie:.{!Jn...[;Y4..\...R^e<;..........@j...........'%Ap.S......]..u..i....G\q.f...^....o.?.......Q;..T]\.r,<....tBI..d6..m...RK..1G....C}...6.HQ....QKo6....N.."58..;..[u;.........S...e.N...y....T..s..[.C*...5.a...u.}0.Ei....?....4....#..U.2L...........s.6.(.......:}..d(.i...?f9JH_..2..q..\..f..7..d.........7ceV...@...........~<W.X...m..~8.,J.Y1.V{..........\..$.].v.. A..F.O:./.E..i...(h.:.......l<.y.O.....K.B.l......=..6.s.d...$@...J....p..q.XW.0...!)..........d..b...w.9.p..G..o.&..w+I...2 ..6.}X....GE..wz2....Hi....KW......i.e....^[O._n}...[.$..?...........R{..R.I.4.".fm4/.....dNC1....,..<cZ.rXp.rH........O4...3.d.Q,.|..../...d..I......B.5..<..\."..V..+...u.FbQ.0N..c-.........m..:..qmI.g~.W...^...?.2)~j.y..].Y.R......"..yW..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5530
                  Entropy (8bit):7.956729393611497
                  Encrypted:false
                  SSDEEP:96:R6s1yfmH9zuPkY/OL9R5U2TKp5uEKUE0UnAmd+16PHLpEe5vMPO1Wp4eV2KodMyF:weyfmde/MU2EE0UlLKeUOkp4eHox
                  MD5:C7772292D3E3822967CE8F2E0F0B0B72
                  SHA1:889AECE4BFA659A2DCAD6B901BC902C67FB0BB86
                  SHA-256:3F1FF5DE3D0DF520276149958B51C62449F3CF4EB455D3F7BD8284E95DE8B690
                  SHA-512:8C7D795417F8F60FB078E52E1D85D5C71947CD7CA2BAB24C8DF41AB25B13044C3E6C388D5F2FF5E68E5EB5151AF17EF900556F1B7A4195938E07FAA683B40BBD
                  Malicious:false
                  Preview:.xP?H...@**.g..%.....z.........Lg..En....B1.kZ`....y\..cs.\x...bE......P1]<+N..N......u.'..t........!aP].H....\g....k.....$tN\*@...c>.X....G...m.P).Z..g....C./.t...z..).U........1o..'.[.n..q7.......z..w(Xie:.{!Jn...[;Y4..\...R^e<;..........@j...........'%Ap.S......]..u..i....G\q.f...^....o.?.......Q;..T]\.r,<....tBI..d6..m...RK..1G....C}...6.HQ....QKo6....N.."58..;..[u;.........S...e.N...y....T..s..[.C*...5.a...u.}0.Ei....?....4....#..U.2L...........s.6.(.......:}..d(.i...?f9JH_..2..q..\..f..7..d.........7ceV...@...........~<W.X...m..~8.,J.Y1.V{..........\..$.].v.. A..F.O:./.E..i...(h.:.......l<.y.O.....K.B.l......=..6.s.d...$@...J....p..q.XW.0...!)..........d..b...w.9.p..G..o.&..w+I...2 ..6.}X....GE..wz2....Hi....KW......i.e....^[O._n}...[.$..?...........R{..R.I.4.".fm4/.....dNC1....,..<cZ.rXp.rH........O4...3.d.Q,.|..../...d..I......B.5..<..\."..V..+...u.FbQ.0N..c-.........m..:..qmI.g~.W...^...?.2)~j.y..].Y.R......"..yW..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3233
                  Entropy (8bit):7.93752530003197
                  Encrypted:false
                  SSDEEP:48:PdmkaVgJaGCSCdQAgoz96/kFmRZ1GtYWC7/6CbhwN+Ba48bVSPpQVS3:Pdmk+gJLTMQSzQ/kFmRZ16j818bsQg
                  MD5:86896A874FED4694A7A42DCC359F1F99
                  SHA1:E663CB1B5569F38B380732A9D67FCEC81FE57F29
                  SHA-256:3F5DE8F4BC3BCBA253F962A1BB0F503A588C81EF08BAFECE3E45F4B78C493639
                  SHA-512:7FBDF5377B09DB77E193EDFEADC9839D343B98F28DD200044493F3E388B9614B6ABBD008188B36C11D4CAF21EE76C3690A12183623ACF4EDC63E0302C8CBFD38
                  Malicious:false
                  Preview:.f...a15w.r.'.....O.....*v.]....x.;.zr...=..+)k...W-....m.Kn.dT.7...V.._hI{...B..,f...{wC....H.8.B......0gF.f[Y.'..r...Z*...~..~...j..II~......p..[..K..N.\!..J.V...uF.@.b.......>....\........~'......:2G.H.3.>......zM'.....1R..1k.G...2R.#..L..y(P.y(..t.M..2.....dUjS^.....o....H..v.j.... %.Zo...F.2}.sA.g... ..q [:.YQ...B.N7N..@.<.q.7..gF.i.......}.. ....C.z.C0......<uZ....<k....d(.>V=..07.N..I@)A.m...86..5!..=....jny.Y...g..tv..R|4..:.......B>.;......QYuE1.|r...8w.....9.?.+S.H".`......)u6...+....t.dPf..D........fK.....i;..d.^$.C...Y......HP.*E............0....1.YV..J>..Yc..M`.J...$+...Q...;.X................|........b.#.t....Y......@...0.]_.....7>.i...|.jW....3.MO.1.b.\.a..)1...m..e.2.n>....se.~p.G..l...cr........W....F~..0.p.v%I ..0Up.dC"....&...J._P:.{+3..TH.gb.x.Y...l&.....K......k....h..5....7.....]t.(6..JA....F.o.z....O5.oO.f.m.\.....l...LN.Z...D..\,...bJ...)(.vu..1.....Y.....R=......n.PpI..O..1....5fm....DI.S..a......p...$n...g.......04.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3233
                  Entropy (8bit):7.93752530003197
                  Encrypted:false
                  SSDEEP:48:PdmkaVgJaGCSCdQAgoz96/kFmRZ1GtYWC7/6CbhwN+Ba48bVSPpQVS3:Pdmk+gJLTMQSzQ/kFmRZ16j818bsQg
                  MD5:86896A874FED4694A7A42DCC359F1F99
                  SHA1:E663CB1B5569F38B380732A9D67FCEC81FE57F29
                  SHA-256:3F5DE8F4BC3BCBA253F962A1BB0F503A588C81EF08BAFECE3E45F4B78C493639
                  SHA-512:7FBDF5377B09DB77E193EDFEADC9839D343B98F28DD200044493F3E388B9614B6ABBD008188B36C11D4CAF21EE76C3690A12183623ACF4EDC63E0302C8CBFD38
                  Malicious:false
                  Preview:.f...a15w.r.'.....O.....*v.]....x.;.zr...=..+)k...W-....m.Kn.dT.7...V.._hI{...B..,f...{wC....H.8.B......0gF.f[Y.'..r...Z*...~..~...j..II~......p..[..K..N.\!..J.V...uF.@.b.......>....\........~'......:2G.H.3.>......zM'.....1R..1k.G...2R.#..L..y(P.y(..t.M..2.....dUjS^.....o....H..v.j.... %.Zo...F.2}.sA.g... ..q [:.YQ...B.N7N..@.<.q.7..gF.i.......}.. ....C.z.C0......<uZ....<k....d(.>V=..07.N..I@)A.m...86..5!..=....jny.Y...g..tv..R|4..:.......B>.;......QYuE1.|r...8w.....9.?.+S.H".`......)u6...+....t.dPf..D........fK.....i;..d.^$.C...Y......HP.*E............0....1.YV..J>..Yc..M`.J...$+...Q...;.X................|........b.#.t....Y......@...0.]_.....7>.i...|.jW....3.MO.1.b.\.a..)1...m..e.2.n>....se.~p.G..l...cr........W....F~..0.p.v%I ..0Up.dC"....&...J._P:.{+3..TH.gb.x.Y...l&.....K......k....h..5....7.....]t.(6..JA....F.o.z....O5.oO.f.m.\.....l...LN.Z...D..\,...bJ...)(.vu..1.....Y.....R=......n.PpI..O..1....5fm....DI.S..a......p...$n...g.......04.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3233
                  Entropy (8bit):7.93752530003197
                  Encrypted:false
                  SSDEEP:48:PdmkaVgJaGCSCdQAgoz96/kFmRZ1GtYWC7/6CbhwN+Ba48bVSPpQVS3:Pdmk+gJLTMQSzQ/kFmRZ16j818bsQg
                  MD5:86896A874FED4694A7A42DCC359F1F99
                  SHA1:E663CB1B5569F38B380732A9D67FCEC81FE57F29
                  SHA-256:3F5DE8F4BC3BCBA253F962A1BB0F503A588C81EF08BAFECE3E45F4B78C493639
                  SHA-512:7FBDF5377B09DB77E193EDFEADC9839D343B98F28DD200044493F3E388B9614B6ABBD008188B36C11D4CAF21EE76C3690A12183623ACF4EDC63E0302C8CBFD38
                  Malicious:false
                  Preview:.f...a15w.r.'.....O.....*v.]....x.;.zr...=..+)k...W-....m.Kn.dT.7...V.._hI{...B..,f...{wC....H.8.B......0gF.f[Y.'..r...Z*...~..~...j..II~......p..[..K..N.\!..J.V...uF.@.b.......>....\........~'......:2G.H.3.>......zM'.....1R..1k.G...2R.#..L..y(P.y(..t.M..2.....dUjS^.....o....H..v.j.... %.Zo...F.2}.sA.g... ..q [:.YQ...B.N7N..@.<.q.7..gF.i.......}.. ....C.z.C0......<uZ....<k....d(.>V=..07.N..I@)A.m...86..5!..=....jny.Y...g..tv..R|4..:.......B>.;......QYuE1.|r...8w.....9.?.+S.H".`......)u6...+....t.dPf..D........fK.....i;..d.^$.C...Y......HP.*E............0....1.YV..J>..Yc..M`.J...$+...Q...;.X................|........b.#.t....Y......@...0.]_.....7>.i...|.jW....3.MO.1.b.\.a..)1...m..e.2.n>....se.~p.G..l...cr........W....F~..0.p.v%I ..0Up.dC"....&...J._P:.{+3..TH.gb.x.Y...l&.....K......k....h..5....7.....]t.(6..JA....F.o.z....O5.oO.f.m.\.....l...LN.Z...D..\,...bJ...)(.vu..1.....Y.....R=......n.PpI..O..1....5fm....DI.S..a......p...$n...g.......04.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):78063
                  Entropy (8bit):7.997601569917824
                  Encrypted:true
                  SSDEEP:1536:qHp9LBnMyPncV3PdaaHH9aq/eP1dDx0bpBgadF+ancn+Aw:qJ9dnKVdZ9tetdDx0bpeajt9A
                  MD5:09C02DEC43DA5EEBE3800BEC12FC6DA2
                  SHA1:BA455272BDDE641F6D510B36564F91E59DB77186
                  SHA-256:99AB2477267D502777B2DDE7084E0CE800A613EBE31A1BBB821E24CD249A03DE
                  SHA-512:CFF4F31BE9D5863ECAFFC83507102FCFA444BCE4484386B319ADEBEFACDEC712C3043868CE55D83D2F7A1DDF320F17982D42216C9ADE04DC1E7748EC342D469C
                  Malicious:true
                  Preview:..>4a......|..f+.9.h..\.K..hZz.Y...6.0=.>...s.S....l...W.n..3z.|..?J..W.x..CF:yk!g=....3.N...ed..o.R...T.....N..2$.^.....6w.B.5.#.(......!.........9...&0.;.R..].b..OG......H.....~.2{...B..4.....Z..4Gl..C...oN....}A_.6l5....Dl...........%....,..E|..U..l.....lgL4.a.<...p......>..............n..^.4...+E..1.U...\}..o../.*.......0X........b..qUt.3..}{....e..o."..L.>...?d..QL ..rn..x.c.Z...~.I....\J]Y.b-{..N3.'...@bh...r~.I...6.~..f.....+......G..R..1".C........r[..h9....k.\i..~.H...pT.x..b.i.".....y|#.<3.+I.....p..@hL8./[.*....P.l..[1..NvN:U]B. ...'"....%......h{U.L..8...?...<3..w..r.?GC}.....(..&m&/(>A..pGQ".6-.r6u+...2..P.Y.g`A....%.B.i..A3..$..[.X....9Y.dx.|..!..=...j....\{. y...4...j..y.y....'9......rK.P..........a....N..}%....}Yj.54>._.w..._p{g:.m.jl.]...p.._s..GE...}.4........?^..w.....s^..?....9.X.v...3.:/.g.._U...A..;..diu:......)....I..j$..&.5....QU..fT@...mV(d..!....k.....k.i...f..]........n.0.Q'...pf.M....C...q..O....7..G;q>
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):758313
                  Entropy (8bit):7.9997351757098265
                  Encrypted:true
                  SSDEEP:12288:iCydisQCEDLD78JNHfa3E52X9zjlY/khANZgoA5QVGTeZiQ2gynyxEcRUk28Z5NS:iCydihCE3kJs3EQjKcigoA5RNfEwk2IS
                  MD5:A3BD056F89D561A5D1AA7B3DC568B8D3
                  SHA1:8A946BA1B972A5B35B288DF4202151CFC2C2800E
                  SHA-256:C8A21F7210185D3EB78F42F338DF604435C3A9A376DD08AFB4330095F27E48C6
                  SHA-512:33E1D16EE398371DAD6FF41AC7E3C222093E45C09DE4BB4AFC7B8C393FB85CC1BD7E90EC0E743BBC345AC0496FEAE839872D9BEE497B4F82C532FD4C2A45D09E
                  Malicious:true
                  Preview: O#q....=...'N...YQ.<..........5..r&..).=.......2.M...........K,..m.=o9...5...}.P...]......../.(.g...`..eq{....e..d...T.....%.#.|A..1...0..q..A..bC.d.....,G.2.q.s31...=.....ph.j.....H.W.]....pDn..#.8y4......X...p.:eU.........g.u.T...|W...,$....`...2..5A.t.tz,..f..YS.......@..t..5....$v..b:.'N.00..W....=`..^N.."!TF%...S.........m..:...[....e.|.w..S.v.[Z...q?\...c..syq.N....4]..d].d....?.....f.n?...:N.a.!,k.).T.b.....c6y...~.ZIp.U..#2=.......7f-...6...u......+'g../...F..zbYK. _@...|..&...@k....u..|.t.E>..,.~...dM....1v.l.......L0.+E....${9..T8s.>/....p.9FQk.UAD.,_...vr|,h.TP...n.0..$[z'..f..J./...m..1..X9..dG.z..........@M.A@..e.%.......#..2R..{K.g.O./.........{..'...T....e.N.>?tNV.$U....d~am.7...5)9..M.!..k5......C6....F...oJ..'...;._.l..;........'.?...F...@o..Q..I.j"..rG.....R.r.;....W......Vx..p..5...YA".ECh.....)..&........Z..E[/...Vh.&e.......V...}'..M....y".<P....b2w....4(...;.......rA.....f .......k+...U..47....K.'.gj..}]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):173457
                  Entropy (8bit):7.998860985553712
                  Encrypted:true
                  SSDEEP:3072:cWgGvOh+ZJCIusNXcuOVLGKgLAMTlJQnoQ4RWaXPYceimqixr+TMl+yNPgotqMWr:yGWgZkmiF5gjzQoQSxQ8TE+yNYo4MP
                  MD5:C3E84FB43116FFDA5265C34634958206
                  SHA1:712F4AF160F237BB859EC35524F45780BB471564
                  SHA-256:5A44247EF6421E5ABB011B5D5C1C360D0565C0EAFE1D6A3C10D91E12C3F41539
                  SHA-512:18BBD781CA99E3E18B66308BCEA4F24A9CB72EF3F5412A0E7A237519B220501B95334DADFD40129D407D4DDA72BB5F81B272ABD540562BAC92B639C9DDE10E57
                  Malicious:true
                  Preview:....1..O...CV......X..c......Y...Ckk..f.l...Z.\...l+......U.N|.}.....h..?...I.PU.....2.I>r........p5..t.tf..G...u.M.....Z.^.._..i.?...N..F....P..!..S.S....l.8......*5}....K...S..X.t.GN.f>.Q..X.7\.......}..b.nGN.3.....K05WQ.p........Z._...#f..tjn.@.... .l..Z......t.../.r..d. *~%.g4{..pd.....%....@.t..;Y......S....o.....E..s..(o...0?...^.....e....(..h.9..N.+%7......<X.. .t....).H.T=.7O....u9.:....C'......^........MI&N.....P..?8}sA.)..5!..%[A.9.=."A.\..K,.=.....e..>........N..oYt..go....op.../].5E....!..x....O ..6.y...r.*.........s.q.0.`.]98HP.hz#.'bE.....gf...h...WM}.....6......%.'.."d_.(...\t._...8,....3.....-K.l3.w.i.7B.]Z.5..>iw..iS.O.d.0..~..%........nr...Y..=..v.....S..][.B...(.lv.."........3-...U.A.I...B....nU..._U..CK-D.4..H..87.z...5...=.(.P....Cg."V..%....!..gk..L....A>),...eo........5.....|.gpd....+..aB..%.L..J...0%..k.......C.\;:.:..l`.........:P.a..N..@.w....E.P.FV..[Q......0JE.{..........c.4....~.D.....Q..cS.`...-.1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):173457
                  Entropy (8bit):7.998860985553712
                  Encrypted:true
                  SSDEEP:3072:cWgGvOh+ZJCIusNXcuOVLGKgLAMTlJQnoQ4RWaXPYceimqixr+TMl+yNPgotqMWr:yGWgZkmiF5gjzQoQSxQ8TE+yNYo4MP
                  MD5:C3E84FB43116FFDA5265C34634958206
                  SHA1:712F4AF160F237BB859EC35524F45780BB471564
                  SHA-256:5A44247EF6421E5ABB011B5D5C1C360D0565C0EAFE1D6A3C10D91E12C3F41539
                  SHA-512:18BBD781CA99E3E18B66308BCEA4F24A9CB72EF3F5412A0E7A237519B220501B95334DADFD40129D407D4DDA72BB5F81B272ABD540562BAC92B639C9DDE10E57
                  Malicious:true
                  Preview:....1..O...CV......X..c......Y...Ckk..f.l...Z.\...l+......U.N|.}.....h..?...I.PU.....2.I>r........p5..t.tf..G...u.M.....Z.^.._..i.?...N..F....P..!..S.S....l.8......*5}....K...S..X.t.GN.f>.Q..X.7\.......}..b.nGN.3.....K05WQ.p........Z._...#f..tjn.@.... .l..Z......t.../.r..d. *~%.g4{..pd.....%....@.t..;Y......S....o.....E..s..(o...0?...^.....e....(..h.9..N.+%7......<X.. .t....).H.T=.7O....u9.:....C'......^........MI&N.....P..?8}sA.)..5!..%[A.9.=."A.\..K,.=.....e..>........N..oYt..go....op.../].5E....!..x....O ..6.y...r.*.........s.q.0.`.]98HP.hz#.'bE.....gf...h...WM}.....6......%.'.."d_.(...\t._...8,....3.....-K.l3.w.i.7B.]Z.5..>iw..iS.O.d.0..~..%........nr...Y..=..v.....S..][.B...(.lv.."........3-...U.A.I...B....nU..._U..CK-D.4..H..87.z...5...=.(.P....Cg."V..%....!..gk..L....A>),...eo........5.....|.gpd....+..aB..%.L..J...0%..k.......C.\;:.:..l`.........:P.a..N..@.w....E.P.FV..[Q......0JE.{..........c.4....~.D.....Q..cS.`...-.1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):173457
                  Entropy (8bit):7.998860985553712
                  Encrypted:true
                  SSDEEP:3072:cWgGvOh+ZJCIusNXcuOVLGKgLAMTlJQnoQ4RWaXPYceimqixr+TMl+yNPgotqMWr:yGWgZkmiF5gjzQoQSxQ8TE+yNYo4MP
                  MD5:C3E84FB43116FFDA5265C34634958206
                  SHA1:712F4AF160F237BB859EC35524F45780BB471564
                  SHA-256:5A44247EF6421E5ABB011B5D5C1C360D0565C0EAFE1D6A3C10D91E12C3F41539
                  SHA-512:18BBD781CA99E3E18B66308BCEA4F24A9CB72EF3F5412A0E7A237519B220501B95334DADFD40129D407D4DDA72BB5F81B272ABD540562BAC92B639C9DDE10E57
                  Malicious:true
                  Preview:....1..O...CV......X..c......Y...Ckk..f.l...Z.\...l+......U.N|.}.....h..?...I.PU.....2.I>r........p5..t.tf..G...u.M.....Z.^.._..i.?...N..F....P..!..S.S....l.8......*5}....K...S..X.t.GN.f>.Q..X.7\.......}..b.nGN.3.....K05WQ.p........Z._...#f..tjn.@.... .l..Z......t.../.r..d. *~%.g4{..pd.....%....@.t..;Y......S....o.....E..s..(o...0?...^.....e....(..h.9..N.+%7......<X.. .t....).H.T=.7O....u9.:....C'......^........MI&N.....P..?8}sA.)..5!..%[A.9.=."A.\..K,.=.....e..>........N..oYt..go....op.../].5E....!..x....O ..6.y...r.*.........s.q.0.`.]98HP.hz#.'bE.....gf...h...WM}.....6......%.'.."d_.(...\t._...8,....3.....-K.l3.w.i.7B.]Z.5..>iw..iS.O.d.0..~..%........nr...Y..=..v.....S..][.B...(.lv.."........3-...U.A.I...B....nU..._U..CK-D.4..H..87.z...5...=.(.P....Cg."V..%....!..gk..L....A>),...eo........5.....|.gpd....+..aB..%.L..J...0%..k.......C.\;:.:..l`.........:P.a..N..@.w....E.P.FV..[Q......0JE.{..........c.4....~.D.....Q..cS.`...-.1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM)
                  Category:dropped
                  Size (bytes):15562
                  Entropy (8bit):7.989383035602789
                  Encrypted:false
                  SSDEEP:384:NLpJfMR5mFP9NATqO03kiwnMp95fooSSCXZBGURVrn5uljQ09QJx:39rNm03vwnM/5fwXr0ljQBx
                  MD5:C88D5467FF65C6068D4BAA7A5B25EDF3
                  SHA1:CE31A870615BCE6F1DAD4E212235BBE476F533FB
                  SHA-256:0C4E5A42B9FCF7A1B2D1BD2AC18A30805C4C23E8206FA5B40C4B0862904A0B3C
                  SHA-512:3ED67F38E576AFB0C1AA3696A6A5EDE1D80EA259A8814D2FF00064A5103D79064BC5341E764B4C0A69C1DE167543A369A14B7F49D32D763DE274999A43A9995A
                  Malicious:false
                  Preview:.aT.......ws..O...x....z.......P.....L.Tq.2.U.u.&.....N...S?....?...{>....t.W.Gj..%)U..S5.qfX;......!..^F..?!6j.'v..HY..d.U.q4..&a.I...O:..H{...+1..........5..B.............o..v.R.E...Y...SQV.....ED~...Aw..,p..#.....zon.0..(.VB...2-...@m..H....>..1...n.O...T........f..{..@..L...>..cw.*..p.l.....l....]Dz.j(s*;.wj.c..y..H....h.....L..O:..d...\T....u.....6n.D...8.....b|.C.]....u.M'xJt..._..3... ...8...T...;..{2....k....}d..<k6.3.#.fi......d..~*\.....M.@........,...\ob..|K.f..e.b....ElS.....En...#..@...&..#E.RL........R.ls..%?....IS.\R..L.\7.B..#y..6I3.................lf..?.....-..N.B._;..J1....?\....f....i.).O0.9..E..-L...@;.}..K.=.@.....g&........).....c.E...k3.X7#.=.....>Ew.*...w...... .J.W......Z......zC..Z..E....I.u........C...y.....g...`<..!b.4..E..jrR5.;.o-.|.c1.l<...F..=........#............(X.....=k.>.v..5`....$w2..L...a.*..D...w.|d\.=....=...-u..<ph.............+...CL..jq...Eh#$.k`.J.T^..3.x..a..)M..S..~_k.E.`.".KG...<..=!........u...6
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM)
                  Category:dropped
                  Size (bytes):15562
                  Entropy (8bit):7.989383035602789
                  Encrypted:false
                  SSDEEP:384:NLpJfMR5mFP9NATqO03kiwnMp95fooSSCXZBGURVrn5uljQ09QJx:39rNm03vwnM/5fwXr0ljQBx
                  MD5:C88D5467FF65C6068D4BAA7A5B25EDF3
                  SHA1:CE31A870615BCE6F1DAD4E212235BBE476F533FB
                  SHA-256:0C4E5A42B9FCF7A1B2D1BD2AC18A30805C4C23E8206FA5B40C4B0862904A0B3C
                  SHA-512:3ED67F38E576AFB0C1AA3696A6A5EDE1D80EA259A8814D2FF00064A5103D79064BC5341E764B4C0A69C1DE167543A369A14B7F49D32D763DE274999A43A9995A
                  Malicious:false
                  Preview:.aT.......ws..O...x....z.......P.....L.Tq.2.U.u.&.....N...S?....?...{>....t.W.Gj..%)U..S5.qfX;......!..^F..?!6j.'v..HY..d.U.q4..&a.I...O:..H{...+1..........5..B.............o..v.R.E...Y...SQV.....ED~...Aw..,p..#.....zon.0..(.VB...2-...@m..H....>..1...n.O...T........f..{..@..L...>..cw.*..p.l.....l....]Dz.j(s*;.wj.c..y..H....h.....L..O:..d...\T....u.....6n.D...8.....b|.C.]....u.M'xJt..._..3... ...8...T...;..{2....k....}d..<k6.3.#.fi......d..~*\.....M.@........,...\ob..|K.f..e.b....ElS.....En...#..@...&..#E.RL........R.ls..%?....IS.\R..L.\7.B..#y..6I3.................lf..?.....-..N.B._;..J1....?\....f....i.).O0.9..E..-L...@;.}..K.=.@.....g&........).....c.E...k3.X7#.=.....>Ew.*...w...... .J.W......Z......zC..Z..E....I.u........C...y.....g...`<..!b.4..E..jrR5.;.o-.|.c1.l<...F..=........#............(X.....=k.>.v..5`....$w2..L...a.*..D...w.|d\.=....=...-u..<ph.............+...CL..jq...Eh#$.k`.J.T^..3.x..a..)M..S..~_k.E.`.".KG...<..=!........u...6
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM)
                  Category:dropped
                  Size (bytes):15562
                  Entropy (8bit):7.989383035602789
                  Encrypted:false
                  SSDEEP:384:NLpJfMR5mFP9NATqO03kiwnMp95fooSSCXZBGURVrn5uljQ09QJx:39rNm03vwnM/5fwXr0ljQBx
                  MD5:C88D5467FF65C6068D4BAA7A5B25EDF3
                  SHA1:CE31A870615BCE6F1DAD4E212235BBE476F533FB
                  SHA-256:0C4E5A42B9FCF7A1B2D1BD2AC18A30805C4C23E8206FA5B40C4B0862904A0B3C
                  SHA-512:3ED67F38E576AFB0C1AA3696A6A5EDE1D80EA259A8814D2FF00064A5103D79064BC5341E764B4C0A69C1DE167543A369A14B7F49D32D763DE274999A43A9995A
                  Malicious:false
                  Preview:.aT.......ws..O...x....z.......P.....L.Tq.2.U.u.&.....N...S?....?...{>....t.W.Gj..%)U..S5.qfX;......!..^F..?!6j.'v..HY..d.U.q4..&a.I...O:..H{...+1..........5..B.............o..v.R.E...Y...SQV.....ED~...Aw..,p..#.....zon.0..(.VB...2-...@m..H....>..1...n.O...T........f..{..@..L...>..cw.*..p.l.....l....]Dz.j(s*;.wj.c..y..H....h.....L..O:..d...\T....u.....6n.D...8.....b|.C.]....u.M'xJt..._..3... ...8...T...;..{2....k....}d..<k6.3.#.fi......d..~*\.....M.@........,...\ob..|K.f..e.b....ElS.....En...#..@...&..#E.RL........R.ls..%?....IS.\R..L.\7.B..#y..6I3.................lf..?.....-..N.B._;..J1....?\....f....i.).O0.9..E..-L...@;.}..K.=.@.....g&........).....c.E...k3.X7#.=.....>Ew.*...w...... .J.W......Z......zC..Z..E....I.u........C...y.....g...`<..!b.4..E..jrR5.;.o-.|.c1.l<...F..=........#............(X.....=k.>.v..5`....$w2..L...a.*..D...w.|d\.=....=...-u..<ph.............+...CL..jq...Eh#$.k`.J.T^..3.x..a..)M..S..~_k.E.`.".KG...<..=!........u...6
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1206
                  Entropy (8bit):7.805578010244723
                  Encrypted:false
                  SSDEEP:24:6BFQDpJ/GT6DVXm+QLfgIzGKot3W48rVUnaK+IFBaycpEROkgwOWV:2aDpJrDNm5LYCGKot3d8GnnB7c6om
                  MD5:654E2FBCDD7253415781432FE0F006C4
                  SHA1:3E523B19A052F96CE0F8CC99CD46BDEAE69E9858
                  SHA-256:F0B066B070824776D9A5A3629309FF2AD103D99E0583A45228C1A8EC69780EF9
                  SHA-512:06A9D925D83C7D24473B12A4BE0022953CDE3E49D053F8AB214B6F4EDF5C3C61AC96BF38044D069BEE159B093188456891FB897E5CF412401D0C58615C9EA7C3
                  Malicious:false
                  Preview:@4m.~7.hE.s.....>..o..+...&.....7....4.iv.V..G.s#.-.c.?'.%..4..D...8@4.._-]..k9..H..`...jf.X..{.-...h..../a:......]%{n.....(uF?..IJi..cI.Q..w.'....x.7.h.W5.c..Ho......*6..e.`....zpM..8l.2.......X.4.^.._...d-..v..B5....8.Z,..I.o..>.....rY.1..K.|.."..S......".Kk.Wk....^U..8.\.)m.....b*...:.Oi..@.rj7&.f..6...#,.pZ..._..]76)......"13u....`M?.2...4..i.s......u...G[.%w..;...a../4.../....l.v9.`.C.QY!...].T....)..t.\.pH<].y\.Mi.@@.(....e..k,[Q...|..xfx.RV).A.Y..yX.L.w.W...q..Y.a9.x..L.`. W./Xs...%^&..\J.....2Rj$C{K.m5......^.....!.0p..e..Dij.L...Lm..E..+.>N..6...c$.e......5xx..?....R#.f.K.b..fC..U..........f......_n.pMW.?4<k..s3kW.y..d... ..;}....!,...H,.S.=.....M..!...OlZ...NN..T..Z.l.6^R.........tS....rr...1\Gw..5..7.<.....M.S0.7..{V.tj.P.l.2e.r....?......`.{.c....xV.. 8_.?Tu.'...2..>.O.g...:d.W.!1........C.M..k.Z.+K?5z1f:..m!a]!W.......tY#.3.......O.8.:.GY.+...@........c...C{..|z....C..Z..C..O..=QK.,.!.......E....YT;Z..f.,...gr..`H.e.....>R.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1206
                  Entropy (8bit):7.805578010244723
                  Encrypted:false
                  SSDEEP:24:6BFQDpJ/GT6DVXm+QLfgIzGKot3W48rVUnaK+IFBaycpEROkgwOWV:2aDpJrDNm5LYCGKot3d8GnnB7c6om
                  MD5:654E2FBCDD7253415781432FE0F006C4
                  SHA1:3E523B19A052F96CE0F8CC99CD46BDEAE69E9858
                  SHA-256:F0B066B070824776D9A5A3629309FF2AD103D99E0583A45228C1A8EC69780EF9
                  SHA-512:06A9D925D83C7D24473B12A4BE0022953CDE3E49D053F8AB214B6F4EDF5C3C61AC96BF38044D069BEE159B093188456891FB897E5CF412401D0C58615C9EA7C3
                  Malicious:false
                  Preview:@4m.~7.hE.s.....>..o..+...&.....7....4.iv.V..G.s#.-.c.?'.%..4..D...8@4.._-]..k9..H..`...jf.X..{.-...h..../a:......]%{n.....(uF?..IJi..cI.Q..w.'....x.7.h.W5.c..Ho......*6..e.`....zpM..8l.2.......X.4.^.._...d-..v..B5....8.Z,..I.o..>.....rY.1..K.|.."..S......".Kk.Wk....^U..8.\.)m.....b*...:.Oi..@.rj7&.f..6...#,.pZ..._..]76)......"13u....`M?.2...4..i.s......u...G[.%w..;...a../4.../....l.v9.`.C.QY!...].T....)..t.\.pH<].y\.Mi.@@.(....e..k,[Q...|..xfx.RV).A.Y..yX.L.w.W...q..Y.a9.x..L.`. W./Xs...%^&..\J.....2Rj$C{K.m5......^.....!.0p..e..Dij.L...Lm..E..+.>N..6...c$.e......5xx..?....R#.f.K.b..fC..U..........f......_n.pMW.?4<k..s3kW.y..d... ..;}....!,...H,.S.=.....M..!...OlZ...NN..T..Z.l.6^R.........tS....rr...1\Gw..5..7.<.....M.S0.7..{V.tj.P.l.2e.r....?......`.{.c....xV.. 8_.?Tu.'...2..>.O.g...:d.W.!1........C.M..k.Z.+K?5z1f:..m!a]!W.......tY#.3.......O.8.:.GY.+...@........c...C{..|z....C..Z..C..O..=QK.,.!.......E....YT;Z..f.,...gr..`H.e.....>R.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1206
                  Entropy (8bit):7.805578010244723
                  Encrypted:false
                  SSDEEP:24:6BFQDpJ/GT6DVXm+QLfgIzGKot3W48rVUnaK+IFBaycpEROkgwOWV:2aDpJrDNm5LYCGKot3d8GnnB7c6om
                  MD5:654E2FBCDD7253415781432FE0F006C4
                  SHA1:3E523B19A052F96CE0F8CC99CD46BDEAE69E9858
                  SHA-256:F0B066B070824776D9A5A3629309FF2AD103D99E0583A45228C1A8EC69780EF9
                  SHA-512:06A9D925D83C7D24473B12A4BE0022953CDE3E49D053F8AB214B6F4EDF5C3C61AC96BF38044D069BEE159B093188456891FB897E5CF412401D0C58615C9EA7C3
                  Malicious:false
                  Preview:@4m.~7.hE.s.....>..o..+...&.....7....4.iv.V..G.s#.-.c.?'.%..4..D...8@4.._-]..k9..H..`...jf.X..{.-...h..../a:......]%{n.....(uF?..IJi..cI.Q..w.'....x.7.h.W5.c..Ho......*6..e.`....zpM..8l.2.......X.4.^.._...d-..v..B5....8.Z,..I.o..>.....rY.1..K.|.."..S......".Kk.Wk....^U..8.\.)m.....b*...:.Oi..@.rj7&.f..6...#,.pZ..._..]76)......"13u....`M?.2...4..i.s......u...G[.%w..;...a../4.../....l.v9.`.C.QY!...].T....)..t.\.pH<].y\.Mi.@@.(....e..k,[Q...|..xfx.RV).A.Y..yX.L.w.W...q..Y.a9.x..L.`. W./Xs...%^&..\J.....2Rj$C{K.m5......^.....!.0p..e..Dij.L...Lm..E..+.>N..6...c$.e......5xx..?....R#.f.K.b..fC..U..........f......_n.pMW.?4<k..s3kW.y..d... ..;}....!,...H,.S.=.....M..!...OlZ...NN..T..Z.l.6^R.........tS....rr...1\Gw..5..7.<.....M.S0.7..{V.tj.P.l.2e.r....?......`.{.c....xV.. 8_.?Tu.'...2..>.O.g...:d.W.!1........C.M..k.Z.+K?5z1f:..m!a]!W.......tY#.3.......O.8.:.GY.+...@........c...C{..|z....C..Z..C..O..=QK.,.!.......E....YT;Z..f.,...gr..`H.e.....>R.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):3406
                  Entropy (8bit):7.9423248629773315
                  Encrypted:false
                  SSDEEP:96:uoJheg6MeDo7/CLbAxBpgmMWRJF2lQXqGBhNoJ:/be0gA9gm3EQl
                  MD5:623402719CAEB843DF6F810F6EA2297E
                  SHA1:7CC61174EBB3FFCE45B8D7937D3551AD05741AA9
                  SHA-256:2DF580014B9C49A8683C67D952138CDB0D2753A1C505F28EA190A61CCB792664
                  SHA-512:265829D40D5C147DD1BE92DF277F064F10A3C6771851B6D345C0D963A9CC1370D67DC15C6DB716E4EE15CBF76048668AB1AC5453F99FBDE72446CE8EA718D6CB
                  Malicious:false
                  Preview:.r.0.....v.`.m.f...#.P.z..P....a.ovQ._..q...NA. ....d`.cx..........w9...n..._.t...D..f.i.dkv.>....='mBt.z..x...g...\F.#.....Cs.3Jl.>.nr..S..|./&.[O.^.H'O.m.....o.X.b....H.m.b..r=z..=...>..!G\9..3?..).9......c..w..)6.1.....c...f......J.Z.s...8:1#.|...2..^.>.Rh.....R.B..t..SZ....'6C ...>.I...o...y ..J..k..F].8......d':]...P.k.M.$'4....q.h|...i....IbHE......+.............{.=.~.*...yZ2..`,.....J.y_.n%6f..BZ!M..2..,...U.4x..6(.v;!.Ac]k:3";L..g.P...0.`#..8.m.U..O...$........GWS.D;.....[y...A1.O..."Pk.0..4k.R...SO7..'t......`...I......../1]W.c...%..g;..h...z....JP8..c........eF.....a.'..,..'.R8.S.{.C..s..........O......U..TbV...kg<...Cf3.P.X.w....m......s.z.L.B.......(....;.....,.Qx.8e.~.'R..?=...}...i.o.u9vq=;m...........G)]zC<-.$\..>D.D...&e...*.Z~.#a.e.@.....^.....x.Qsu...t.f..).5......J'....0.'...v.O.0..k../..Bv.i.K......`...PM.pc...WE.../...w..._.e.p.....E...).>..7....gt....TCS(.;.......7....e.V......dA...7.O......8.|/Ic%...d#..%....E...e...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):806815
                  Entropy (8bit):7.999777737625906
                  Encrypted:true
                  SSDEEP:12288:dhAYVvkv7zZDa3lL5yxyFWHOZqMejin+M6clWG0N8b/7LJEjTL/6rc:dGYUBD8LsxyxZ4cN08nNEj3
                  MD5:7C2696DEDF8F7B19C8DE518A4755B563
                  SHA1:D911E31313563610F1F8BABCFCFAB0AC6A6AEBCA
                  SHA-256:101D83BDB3418D61835B6E40118C4E4D8E3E9732A3621D1E751EE03585E258BE
                  SHA-512:1B843AD7C04917FEB86E85534FC1A6964FD13329F5B8685B80E3E7DDB2621208972E604883C821E10829559E7FE714ED9B23179C90DEBD2A23B6C3C65EF3FF3A
                  Malicious:true
                  Preview::..0..!.y!...\0.=?.L...2..,jy:G..V\M\..........E..C..7..zn..-m...w.2._..>QDW\_...c..=.}..0`t..2..H.7.%.yf.N"..X.,.Q.P:....?.O$. ..E..m.&0...!..(..2...T...fG......#.h. .y.d%...MG..[......6........w.^..Y..cw5...... ..\K.).....x,F........=./...#.3..W,.]...e..J.S.Z.xh. ....3.....%. .{...zZ...#.....q...o.....?W.u..QCn...k].2.j...cj.~.:../n"...b..z_.QB...$?..9..~....H}..8`:.....\./q...A.^P^.. C^......;KW...-.*,=.....&s.e`.L..5bgJ.>t._koy&uJ4...!q..fm.C$.....x.-.....a.9.&i.b.....)....s.1.<M-.G.....v.M."..6u.....k......Wg.....p...S....C..ut.3@#..`.='..s.<....h`.O.'..Z...5....2r...0.Cik..o.a..!6..{I......z9.(.a.].^...WH.&....y.g.....!S^.3....k1.q.w:99R..cC.g.@R..&....w....D..N.....J.j.|.......tzJ.........T..6i`.8.?o.P...\...$:j..o7.d....c...7.....Vh.i.b..q....J1..3c...}.7..x..........N.....I..i.yH,Z....l[.lp*u{...#...]T.<.--. \!.$......+P...U......z._.Ej.dn...W...c.`.......8P.N<:....>..#.vyv2!..........[..@."...&G].}..&`;3u..)+...p..}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):806815
                  Entropy (8bit):7.999777737625906
                  Encrypted:true
                  SSDEEP:12288:dhAYVvkv7zZDa3lL5yxyFWHOZqMejin+M6clWG0N8b/7LJEjTL/6rc:dGYUBD8LsxyxZ4cN08nNEj3
                  MD5:7C2696DEDF8F7B19C8DE518A4755B563
                  SHA1:D911E31313563610F1F8BABCFCFAB0AC6A6AEBCA
                  SHA-256:101D83BDB3418D61835B6E40118C4E4D8E3E9732A3621D1E751EE03585E258BE
                  SHA-512:1B843AD7C04917FEB86E85534FC1A6964FD13329F5B8685B80E3E7DDB2621208972E604883C821E10829559E7FE714ED9B23179C90DEBD2A23B6C3C65EF3FF3A
                  Malicious:true
                  Preview::..0..!.y!...\0.=?.L...2..,jy:G..V\M\..........E..C..7..zn..-m...w.2._..>QDW\_...c..=.}..0`t..2..H.7.%.yf.N"..X.,.Q.P:....?.O$. ..E..m.&0...!..(..2...T...fG......#.h. .y.d%...MG..[......6........w.^..Y..cw5...... ..\K.).....x,F........=./...#.3..W,.]...e..J.S.Z.xh. ....3.....%. .{...zZ...#.....q...o.....?W.u..QCn...k].2.j...cj.~.:../n"...b..z_.QB...$?..9..~....H}..8`:.....\./q...A.^P^.. C^......;KW...-.*,=.....&s.e`.L..5bgJ.>t._koy&uJ4...!q..fm.C$.....x.-.....a.9.&i.b.....)....s.1.<M-.G.....v.M."..6u.....k......Wg.....p...S....C..ut.3@#..`.='..s.<....h`.O.'..Z...5....2r...0.Cik..o.a..!6..{I......z9.(.a.].^...WH.&....y.g.....!S^.3....k1.q.w:99R..cC.g.@R..&....w....D..N.....J.j.|.......tzJ.........T..6i`.8.?o.P...\...$:j..o7.d....c...7.....Vh.i.b..q....J1..3c...}.7..x..........N.....I..i.yH,Z....l[.lp*u{...#...]T.<.--. \!.$......+P...U......z._.Ej.dn...W...c.`.......8P.N<:....>..#.vyv2!..........[..@."...&G].}..&`;3u..)+...p..}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):806815
                  Entropy (8bit):7.999777737625906
                  Encrypted:true
                  SSDEEP:12288:dhAYVvkv7zZDa3lL5yxyFWHOZqMejin+M6clWG0N8b/7LJEjTL/6rc:dGYUBD8LsxyxZ4cN08nNEj3
                  MD5:7C2696DEDF8F7B19C8DE518A4755B563
                  SHA1:D911E31313563610F1F8BABCFCFAB0AC6A6AEBCA
                  SHA-256:101D83BDB3418D61835B6E40118C4E4D8E3E9732A3621D1E751EE03585E258BE
                  SHA-512:1B843AD7C04917FEB86E85534FC1A6964FD13329F5B8685B80E3E7DDB2621208972E604883C821E10829559E7FE714ED9B23179C90DEBD2A23B6C3C65EF3FF3A
                  Malicious:true
                  Preview::..0..!.y!...\0.=?.L...2..,jy:G..V\M\..........E..C..7..zn..-m...w.2._..>QDW\_...c..=.}..0`t..2..H.7.%.yf.N"..X.,.Q.P:....?.O$. ..E..m.&0...!..(..2...T...fG......#.h. .y.d%...MG..[......6........w.^..Y..cw5...... ..\K.).....x,F........=./...#.3..W,.]...e..J.S.Z.xh. ....3.....%. .{...zZ...#.....q...o.....?W.u..QCn...k].2.j...cj.~.:../n"...b..z_.QB...$?..9..~....H}..8`:.....\./q...A.^P^.. C^......;KW...-.*,=.....&s.e`.L..5bgJ.>t._koy&uJ4...!q..fm.C$.....x.-.....a.9.&i.b.....)....s.1.<M-.G.....v.M."..6u.....k......Wg.....p...S....C..ut.3@#..`.='..s.<....h`.O.'..Z...5....2r...0.Cik..o.a..!6..{I......z9.(.a.].^...WH.&....y.g.....!S^.3....k1.q.w:99R..cC.g.@R..&....w....D..N.....J.j.|.......tzJ.........T..6i`.8.?o.P...\...$:j..o7.d....c...7.....Vh.i.b..q....J1..3c...}.7..x..........N.....I..i.yH,Z....l[.lp*u{...#...]T.<.--. \!.$......+P...U......z._.Ej.dn...W...c.`.......8P.N<:....>..#.vyv2!..........[..@."...&G].}..&`;3u..)+...p..}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):206119
                  Entropy (8bit):7.999076564655488
                  Encrypted:true
                  SSDEEP:6144:DUve5AeL0leZsKyyWAZzbMtIno8dAsEXGWCF35g:Dme5AeYleZsKyspQ10iXGWCFJg
                  MD5:336FF0879C1F4F2EB7703E9A5B561B3F
                  SHA1:6C65A71B0FB0F23A6EA3916EF9BC5BF261150B2F
                  SHA-256:52BC578170EE1FDC25A703C968A2E42076A8A76A4F88B37A6DD20AD4C1E4ACA2
                  SHA-512:94061742BC0227B558EB80AF07AA6706E0504067EFAE32FCB36DD25F28F0EC88178A45856FAF0CD00667665AA162337F4BB25720148E11B1BF1AB9903E7A619E
                  Malicious:true
                  Preview:.B...;....U.O.}.G.....+..S.y.@!...+..C.:......9.}6..PW|.4cxL&X.....:.7r...E......SI...K..%.e7p3x8U_y..6...2}.[6..;.8.....Y.=.f3Z.)...A'..x...?.O..M*.d.X....u..W.[n...':L..S.3/.[/P<..ot..T....`8.H9"..\}.q...~\ ..IA.z...,...]...5i...4..Q.+...fV.r.f9..\\.....h.......+[.8.....CB"H^..X.%j..={.UD........y......b..!d.zf._B,...#&n....I?..*'...%..g....q.G.n...]J'...1...N,QR....../e....8<*...S.....FP.z.x.3...Z..:}.l,.....<b.e..n..2.M..B.....:z.2.A@.....=...;.0.....I..o.a....H!...o....H".%..@jR..[.u....L?.G;)..+9....K...S..5lr......%)I]N.^...,.....f.T.#...s.&.!.B......z.....%oQ``R..>Q.I...Zif..6.@.....{..*cl-..\r..F.K..EAt..BR.V.......1........sC3%..G.4=d=.........?\R..O...$.#g.8.;..}..pL@N.!G8.....)7...,~.......s...I.E..S&.Lj...Z.R....R.......k.N..j..f.}.P.s...Ge...F&>1X...o...R./b..%p.c.,..1.........FZ"..d...`q....>G..Y7..%..9......8..)......>..'..dC.......g.\....Aw.bwD@..|s|"..2.J....ka.*...L..?Z..%... ..9..C.../......:?+.....].xY.`.......b3
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):206119
                  Entropy (8bit):7.999076564655488
                  Encrypted:true
                  SSDEEP:6144:DUve5AeL0leZsKyyWAZzbMtIno8dAsEXGWCF35g:Dme5AeYleZsKyspQ10iXGWCFJg
                  MD5:336FF0879C1F4F2EB7703E9A5B561B3F
                  SHA1:6C65A71B0FB0F23A6EA3916EF9BC5BF261150B2F
                  SHA-256:52BC578170EE1FDC25A703C968A2E42076A8A76A4F88B37A6DD20AD4C1E4ACA2
                  SHA-512:94061742BC0227B558EB80AF07AA6706E0504067EFAE32FCB36DD25F28F0EC88178A45856FAF0CD00667665AA162337F4BB25720148E11B1BF1AB9903E7A619E
                  Malicious:true
                  Preview:.B...;....U.O.}.G.....+..S.y.@!...+..C.:......9.}6..PW|.4cxL&X.....:.7r...E......SI...K..%.e7p3x8U_y..6...2}.[6..;.8.....Y.=.f3Z.)...A'..x...?.O..M*.d.X....u..W.[n...':L..S.3/.[/P<..ot..T....`8.H9"..\}.q...~\ ..IA.z...,...]...5i...4..Q.+...fV.r.f9..\\.....h.......+[.8.....CB"H^..X.%j..={.UD........y......b..!d.zf._B,...#&n....I?..*'...%..g....q.G.n...]J'...1...N,QR....../e....8<*...S.....FP.z.x.3...Z..:}.l,.....<b.e..n..2.M..B.....:z.2.A@.....=...;.0.....I..o.a....H!...o....H".%..@jR..[.u....L?.G;)..+9....K...S..5lr......%)I]N.^...,.....f.T.#...s.&.!.B......z.....%oQ``R..>Q.I...Zif..6.@.....{..*cl-..\r..F.K..EAt..BR.V.......1........sC3%..G.4=d=.........?\R..O...$.#g.8.;..}..pL@N.!G8.....)7...,~.......s...I.E..S&.Lj...Z.R....R.......k.N..j..f.}.P.s...Ge...F&>1X...o...R./b..%p.c.,..1.........FZ"..d...`q....>G..Y7..%..9......8..)......>..'..dC.......g.\....Aw.bwD@..|s|"..2.J....ka.*...L..?Z..%... ..9..C.../......:?+.....].xY.`.......b3
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):206119
                  Entropy (8bit):7.999076564655488
                  Encrypted:true
                  SSDEEP:6144:DUve5AeL0leZsKyyWAZzbMtIno8dAsEXGWCF35g:Dme5AeYleZsKyspQ10iXGWCFJg
                  MD5:336FF0879C1F4F2EB7703E9A5B561B3F
                  SHA1:6C65A71B0FB0F23A6EA3916EF9BC5BF261150B2F
                  SHA-256:52BC578170EE1FDC25A703C968A2E42076A8A76A4F88B37A6DD20AD4C1E4ACA2
                  SHA-512:94061742BC0227B558EB80AF07AA6706E0504067EFAE32FCB36DD25F28F0EC88178A45856FAF0CD00667665AA162337F4BB25720148E11B1BF1AB9903E7A619E
                  Malicious:true
                  Preview:.B...;....U.O.}.G.....+..S.y.@!...+..C.:......9.}6..PW|.4cxL&X.....:.7r...E......SI...K..%.e7p3x8U_y..6...2}.[6..;.8.....Y.=.f3Z.)...A'..x...?.O..M*.d.X....u..W.[n...':L..S.3/.[/P<..ot..T....`8.H9"..\}.q...~\ ..IA.z...,...]...5i...4..Q.+...fV.r.f9..\\.....h.......+[.8.....CB"H^..X.%j..={.UD........y......b..!d.zf._B,...#&n....I?..*'...%..g....q.G.n...]J'...1...N,QR....../e....8<*...S.....FP.z.x.3...Z..:}.l,.....<b.e..n..2.M..B.....:z.2.A@.....=...;.0.....I..o.a....H!...o....H".%..@jR..[.u....L?.G;)..+9....K...S..5lr......%)I]N.^...,.....f.T.#...s.&.!.B......z.....%oQ``R..>Q.I...Zif..6.@.....{..*cl-..\r..F.K..EAt..BR.V.......1........sC3%..G.4=d=.........?\R..O...$.#g.8.;..}..pL@N.!G8.....)7...,~.......s...I.E..S&.Lj...Z.R....R.......k.N..j..f.}.P.s...Ge...F&>1X...o...R./b..%p.c.,..1.........FZ"..d...`q....>G..Y7..%..9......8..)......>..'..dC.......g.\....Aw.bwD@..|s|"..2.J....ka.*...L..?Z..%... ..9..C.../......:?+.....].xY.`.......b3
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM)
                  Category:dropped
                  Size (bytes):170
                  Entropy (8bit):6.2380070371341985
                  Encrypted:false
                  SSDEEP:3:Uwl0KdbD8Ye+mypn5br8TY9Tair0D/DsSs+uMt26yT78HaXWdHNUinWgjA2l9ll:vJbgrlyp5EYIi4HjuMt2zfMHrWgjD
                  MD5:2B2CC236489E22B4AAABFFB9975D3D73
                  SHA1:C380ABE411B2EB8073526025D94D831E9597F191
                  SHA-256:7F9F45FB3B2252B9BFFA738CDEEEB3F3602DA04C8815620BA543C5D41BA18038
                  SHA-512:1C9379436BF5643D426084FE68352E217FE0B73D73BD6DBBC3B5C5DAA026C21246AD57A83CD4486D92BF203F5DDDF82FF69F06CC119123D0F40CFB81C0091C03
                  Malicious:false
                  Preview:.....K..!.O.;.1.....{.]04b].e]x._k..Z....}s.w?*...N.R....y.Q..7L.....HH&........e...D..L,..s.............F..SF....d.H.+..z..g8"(|..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM)
                  Category:dropped
                  Size (bytes):170
                  Entropy (8bit):6.2380070371341985
                  Encrypted:false
                  SSDEEP:3:Uwl0KdbD8Ye+mypn5br8TY9Tair0D/DsSs+uMt26yT78HaXWdHNUinWgjA2l9ll:vJbgrlyp5EYIi4HjuMt2zfMHrWgjD
                  MD5:2B2CC236489E22B4AAABFFB9975D3D73
                  SHA1:C380ABE411B2EB8073526025D94D831E9597F191
                  SHA-256:7F9F45FB3B2252B9BFFA738CDEEEB3F3602DA04C8815620BA543C5D41BA18038
                  SHA-512:1C9379436BF5643D426084FE68352E217FE0B73D73BD6DBBC3B5C5DAA026C21246AD57A83CD4486D92BF203F5DDDF82FF69F06CC119123D0F40CFB81C0091C03
                  Malicious:false
                  Preview:.....K..!.O.;.1.....{.]04b].e]x._k..Z....}s.w?*...N.R....y.Q..7L.....HH&........e...D..L,..s.............F..SF....d.H.+..z..g8"(|..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:DOS executable (COM)
                  Category:dropped
                  Size (bytes):170
                  Entropy (8bit):6.2380070371341985
                  Encrypted:false
                  SSDEEP:3:Uwl0KdbD8Ye+mypn5br8TY9Tair0D/DsSs+uMt26yT78HaXWdHNUinWgjA2l9ll:vJbgrlyp5EYIi4HjuMt2zfMHrWgjD
                  MD5:2B2CC236489E22B4AAABFFB9975D3D73
                  SHA1:C380ABE411B2EB8073526025D94D831E9597F191
                  SHA-256:7F9F45FB3B2252B9BFFA738CDEEEB3F3602DA04C8815620BA543C5D41BA18038
                  SHA-512:1C9379436BF5643D426084FE68352E217FE0B73D73BD6DBBC3B5C5DAA026C21246AD57A83CD4486D92BF203F5DDDF82FF69F06CC119123D0F40CFB81C0091C03
                  Malicious:false
                  Preview:.....K..!.O.;.1.....{.]04b].e]x._k..Z....}s.w?*...N.R....y.Q..7L.....HH&........e...D..L,..s.............F..SF....d.H.+..z..g8"(|..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):161
                  Entropy (8bit):6.058361295141319
                  Encrypted:false
                  SSDEEP:3:8IOOO4WyJyn758Z28FBRnzAWWwt5MHg3gM0Thf4MSTocmE72l9ll:8IOO/WIc7iZ7FB/SHg3P0GTZmE+
                  MD5:32C49604F4229D49DB6CB708F13492D2
                  SHA1:9AFCB0A8B67BD72CA301682586731AEC7448CBCD
                  SHA-256:5DB4EA6A008C4AF3BCA327A5627E8F692859FA46498AED53D631706248CE077D
                  SHA-512:A771311945577107A19C976515F45A284D7B352C0B8660959503E5B87A133A6836E6D50005ED7CC5E96D5C90E68BD5135C54FD38FB4BFDB87408043196BC9B05
                  Malicious:false
                  Preview:....>f..TnHM.o..p.7...}'..+x....$s....S.T.5uu.OJ......B.%..Y.6..........wH..(;..b,I,*./..e^C.K..>f.....}. sP...S..j.>7o.>..._........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):161
                  Entropy (8bit):6.058361295141319
                  Encrypted:false
                  SSDEEP:3:8IOOO4WyJyn758Z28FBRnzAWWwt5MHg3gM0Thf4MSTocmE72l9ll:8IOO/WIc7iZ7FB/SHg3P0GTZmE+
                  MD5:32C49604F4229D49DB6CB708F13492D2
                  SHA1:9AFCB0A8B67BD72CA301682586731AEC7448CBCD
                  SHA-256:5DB4EA6A008C4AF3BCA327A5627E8F692859FA46498AED53D631706248CE077D
                  SHA-512:A771311945577107A19C976515F45A284D7B352C0B8660959503E5B87A133A6836E6D50005ED7CC5E96D5C90E68BD5135C54FD38FB4BFDB87408043196BC9B05
                  Malicious:false
                  Preview:....>f..TnHM.o..p.7...}'..+x....$s....S.T.5uu.OJ......B.%..Y.6..........wH..(;..b,I,*./..e^C.K..>f.....}. sP...S..j.>7o.>..._........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):161
                  Entropy (8bit):6.058361295141319
                  Encrypted:false
                  SSDEEP:3:8IOOO4WyJyn758Z28FBRnzAWWwt5MHg3gM0Thf4MSTocmE72l9ll:8IOO/WIc7iZ7FB/SHg3P0GTZmE+
                  MD5:32C49604F4229D49DB6CB708F13492D2
                  SHA1:9AFCB0A8B67BD72CA301682586731AEC7448CBCD
                  SHA-256:5DB4EA6A008C4AF3BCA327A5627E8F692859FA46498AED53D631706248CE077D
                  SHA-512:A771311945577107A19C976515F45A284D7B352C0B8660959503E5B87A133A6836E6D50005ED7CC5E96D5C90E68BD5135C54FD38FB4BFDB87408043196BC9B05
                  Malicious:false
                  Preview:....>f..TnHM.o..p.7...}'..+x....$s....S.T.5uu.OJ......B.%..Y.6..........wH..(;..b,I,*./..e^C.K..>f.....}. sP...S..j.>7o.>..._........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7377
                  Entropy (8bit):7.972455038399331
                  Encrypted:false
                  SSDEEP:192:x2VCvy82leesDIk4TtrAPb2iLQf+LNRbnuyjQPCb9q3:08ceeGFWok2Rbnu6m
                  MD5:3F52319621297A1D9462D6530DC23124
                  SHA1:BE49DB0CB5DD5092B510F5D5CECAA5847CE70340
                  SHA-256:8E7520E6045AC77C717145B890FFB0DC104783B870CB69B6D50E3C19CB6ABAC8
                  SHA-512:A720066C4FCB76081C07E9BBE7FEC43106F1CB0B42D0063C938F924F5E04C3241279427ACE49C488B22CB8D5DC4D61C8370F07D7EE40C42FA0EC413D25891E8B
                  Malicious:false
                  Preview:...r...Z...b.=lX. ....Tx@.Y..QgN.=.......4....s?.......]!C.....i......>.r.......L.~d..E0.........6-G.W..s-...a9@...cZ|...H..u..v...Io=z6<.~.U......I.t....2...."+........_.=....9..fR....jL.>u...ZU#]$`.v.my.inp..D...qN..S.b(rqg..W=s..;e~.v...........<..~Vg.U.=N...U....Z.%....5...4.6EE.Wg..V.....i.4..T/.A.Hhyu...._..u.....N.i..r.m...5.x.Y..yF....d..<.o..;%P..*......u).n.{..K.S1F\.P.b!.!V........*5.&Z.4.9W.U.&..T.N...p$q.....mnUD6....&6i...?d.....&.1Z..l,~....t..=..x.x.. .e.$.|..JtC.n..c.2d.....Ef.-PN.!...v.YK.........t..j...:.DfwI}..J..%..".....E..u....u....LdFt../.{1.J..#.z....iP..J...w.....7..q@..R.0...\y.O.......j-...F....3...W..rS.q.;&t..;.eS.4.~....vh..!..J.. ..b.Uh|.SO.y....<{..{....1nB.....:3....O.#.....^[4.uJO>.:.\...rPE...z.e.(..SY.>....,.0.Q;.-+m.....ic.v.....g.9u...=kcm...7...~....._.+..VQ}..o.@..sh1.E....RY..el.dM.........G...Wy.7...U$.?.1........+..&.6W{....."EUXS.....mx...Y....I(y6. ..y....4..Wo.8%...1g.#_#Va
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7377
                  Entropy (8bit):7.972455038399331
                  Encrypted:false
                  SSDEEP:192:x2VCvy82leesDIk4TtrAPb2iLQf+LNRbnuyjQPCb9q3:08ceeGFWok2Rbnu6m
                  MD5:3F52319621297A1D9462D6530DC23124
                  SHA1:BE49DB0CB5DD5092B510F5D5CECAA5847CE70340
                  SHA-256:8E7520E6045AC77C717145B890FFB0DC104783B870CB69B6D50E3C19CB6ABAC8
                  SHA-512:A720066C4FCB76081C07E9BBE7FEC43106F1CB0B42D0063C938F924F5E04C3241279427ACE49C488B22CB8D5DC4D61C8370F07D7EE40C42FA0EC413D25891E8B
                  Malicious:false
                  Preview:...r...Z...b.=lX. ....Tx@.Y..QgN.=.......4....s?.......]!C.....i......>.r.......L.~d..E0.........6-G.W..s-...a9@...cZ|...H..u..v...Io=z6<.~.U......I.t....2...."+........_.=....9..fR....jL.>u...ZU#]$`.v.my.inp..D...qN..S.b(rqg..W=s..;e~.v...........<..~Vg.U.=N...U....Z.%....5...4.6EE.Wg..V.....i.4..T/.A.Hhyu...._..u.....N.i..r.m...5.x.Y..yF....d..<.o..;%P..*......u).n.{..K.S1F\.P.b!.!V........*5.&Z.4.9W.U.&..T.N...p$q.....mnUD6....&6i...?d.....&.1Z..l,~....t..=..x.x.. .e.$.|..JtC.n..c.2d.....Ef.-PN.!...v.YK.........t..j...:.DfwI}..J..%..".....E..u....u....LdFt../.{1.J..#.z....iP..J...w.....7..q@..R.0...\y.O.......j-...F....3...W..rS.q.;&t..;.eS.4.~....vh..!..J.. ..b.Uh|.SO.y....<{..{....1nB.....:3....O.#.....^[4.uJO>.:.\...rPE...z.e.(..SY.>....,.0.Q;.-+m.....ic.v.....g.9u...=kcm...7...~....._.+..VQ}..o.@..sh1.E....RY..el.dM.........G...Wy.7...U$.?.1........+..&.6W{....."EUXS.....mx...Y....I(y6. ..y....4..Wo.8%...1g.#_#Va
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7377
                  Entropy (8bit):7.972455038399331
                  Encrypted:false
                  SSDEEP:192:x2VCvy82leesDIk4TtrAPb2iLQf+LNRbnuyjQPCb9q3:08ceeGFWok2Rbnu6m
                  MD5:3F52319621297A1D9462D6530DC23124
                  SHA1:BE49DB0CB5DD5092B510F5D5CECAA5847CE70340
                  SHA-256:8E7520E6045AC77C717145B890FFB0DC104783B870CB69B6D50E3C19CB6ABAC8
                  SHA-512:A720066C4FCB76081C07E9BBE7FEC43106F1CB0B42D0063C938F924F5E04C3241279427ACE49C488B22CB8D5DC4D61C8370F07D7EE40C42FA0EC413D25891E8B
                  Malicious:false
                  Preview:...r...Z...b.=lX. ....Tx@.Y..QgN.=.......4....s?.......]!C.....i......>.r.......L.~d..E0.........6-G.W..s-...a9@...cZ|...H..u..v...Io=z6<.~.U......I.t....2...."+........_.=....9..fR....jL.>u...ZU#]$`.v.my.inp..D...qN..S.b(rqg..W=s..;e~.v...........<..~Vg.U.=N...U....Z.%....5...4.6EE.Wg..V.....i.4..T/.A.Hhyu...._..u.....N.i..r.m...5.x.Y..yF....d..<.o..;%P..*......u).n.{..K.S1F\.P.b!.!V........*5.&Z.4.9W.U.&..T.N...p$q.....mnUD6....&6i...?d.....&.1Z..l,~....t..=..x.x.. .e.$.|..JtC.n..c.2d.....Ef.-PN.!...v.YK.........t..j...:.DfwI}..J..%..".....E..u....u....LdFt../.{1.J..#.z....iP..J...w.....7..q@..R.0...\y.O.......j-...F....3...W..rS.q.;&t..;.eS.4.~....vh..!..J.. ..b.Uh|.SO.y....<{..{....1nB.....:3....O.#.....^[4.uJO>.:.\...rPE...z.e.(..SY.>....,.0.Q;.-+m.....ic.v.....g.9u...=kcm...7...~....._.+..VQ}..o.@..sh1.E....RY..el.dM.........G...Wy.7...U$.?.1........+..&.6W{....."EUXS.....mx...Y....I(y6. ..y....4..Wo.8%...1g.#_#Va
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1946
                  Entropy (8bit):7.874687617499043
                  Encrypted:false
                  SSDEEP:48:HX+Fwy+3JpEhrHigV2fkmWVt3Bf6OaCswrXDHWHc:HX+Wy+3JpuFGkmWj3x6OAqH
                  MD5:5AFABB20DDB6F807C2A2FA8B60DD6DBE
                  SHA1:7D2C53724422C12AEC60C8180D6F9E2FE77829CA
                  SHA-256:9B9C8DA9975454A729256524B3C2342AABB3C9A2F0A2D03149D5623CA9E87444
                  SHA-512:07F6C2469E502083F5C168072EFACEE09975DFB5B0CC530D2678EACD6427BD6289BE3F9E665880262FA7205CB6284A45104B7237409D882AD4BAEC655605A9CC
                  Malicious:false
                  Preview:c"Q.|..n.:.k......}9.m-..K....-`Fm...[...e..Z.Mkk..|.%...n.[..c...........#..L.`.8.e.~|.K.XT@n.)..B.JE....,=....qK....-.QQ...N.y&.B...k.C.P...|.[.$.t.J...X...,P.....~Vw....NH.Q....A.Up0.V......1.Y5x.T..c.o...l..~+.c..%....?...B......W1%I7.+....\$.u..k....b..i......(.~......F..F.B..r:..O......?C.T.......h......V'.....e?......Kgyj..9+4.9.+..;.D..7a.a_A.+P....+O..,...g..,..j~w...VBp,B...].3IN.t=Tw....K.."..;.Y..%j...'z.l..lo...Y...P....l..0..N...W.:(n._IS.?........b.....d],..?.g.r2..#...&orL2..y......r|....u......Z..8c.M.G<....y...{.......%.\mO F1...b[f.W....9....c.FN..7...gY.&.... .G.A...=t$.Wbza\'`^....r...A..gy.B.A.....uj.V.z6.!..>..k..../...~jL.Kk%8.e.zytr.o.qa.U....>..Y^p/...'.........i4t......f.<z.....'.S_0:c..K........'....r.4.L....L...ka.Ev..%.4...HN...5M.;.ln./.<~.....#..(...vK.....\.2.MVP9..0..K1.....W.c.G....O......._`+/.|.e.O...n...9D..y^..U*N_.N.......&..`w.Gy$.H.^Y..?.a..d..gmY'o...q..*....u{...cT.^....kH[..[....p.T....~dL.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1946
                  Entropy (8bit):7.874687617499043
                  Encrypted:false
                  SSDEEP:48:HX+Fwy+3JpEhrHigV2fkmWVt3Bf6OaCswrXDHWHc:HX+Wy+3JpuFGkmWj3x6OAqH
                  MD5:5AFABB20DDB6F807C2A2FA8B60DD6DBE
                  SHA1:7D2C53724422C12AEC60C8180D6F9E2FE77829CA
                  SHA-256:9B9C8DA9975454A729256524B3C2342AABB3C9A2F0A2D03149D5623CA9E87444
                  SHA-512:07F6C2469E502083F5C168072EFACEE09975DFB5B0CC530D2678EACD6427BD6289BE3F9E665880262FA7205CB6284A45104B7237409D882AD4BAEC655605A9CC
                  Malicious:false
                  Preview:c"Q.|..n.:.k......}9.m-..K....-`Fm...[...e..Z.Mkk..|.%...n.[..c...........#..L.`.8.e.~|.K.XT@n.)..B.JE....,=....qK....-.QQ...N.y&.B...k.C.P...|.[.$.t.J...X...,P.....~Vw....NH.Q....A.Up0.V......1.Y5x.T..c.o...l..~+.c..%....?...B......W1%I7.+....\$.u..k....b..i......(.~......F..F.B..r:..O......?C.T.......h......V'.....e?......Kgyj..9+4.9.+..;.D..7a.a_A.+P....+O..,...g..,..j~w...VBp,B...].3IN.t=Tw....K.."..;.Y..%j...'z.l..lo...Y...P....l..0..N...W.:(n._IS.?........b.....d],..?.g.r2..#...&orL2..y......r|....u......Z..8c.M.G<....y...{.......%.\mO F1...b[f.W....9....c.FN..7...gY.&.... .G.A...=t$.Wbza\'`^....r...A..gy.B.A.....uj.V.z6.!..>..k..../...~jL.Kk%8.e.zytr.o.qa.U....>..Y^p/...'.........i4t......f.<z.....'.S_0:c..K........'....r.4.L....L...ka.Ev..%.4...HN...5M.;.ln./.<~.....#..(...vK.....\.2.MVP9..0..K1.....W.c.G....O......._`+/.|.e.O...n...9D..y^..U*N_.N.......&..`w.Gy$.H.^Y..?.a..d..gmY'o...q..*....u{...cT.^....kH[..[....p.T....~dL.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1946
                  Entropy (8bit):7.874687617499043
                  Encrypted:false
                  SSDEEP:48:HX+Fwy+3JpEhrHigV2fkmWVt3Bf6OaCswrXDHWHc:HX+Wy+3JpuFGkmWj3x6OAqH
                  MD5:5AFABB20DDB6F807C2A2FA8B60DD6DBE
                  SHA1:7D2C53724422C12AEC60C8180D6F9E2FE77829CA
                  SHA-256:9B9C8DA9975454A729256524B3C2342AABB3C9A2F0A2D03149D5623CA9E87444
                  SHA-512:07F6C2469E502083F5C168072EFACEE09975DFB5B0CC530D2678EACD6427BD6289BE3F9E665880262FA7205CB6284A45104B7237409D882AD4BAEC655605A9CC
                  Malicious:false
                  Preview:c"Q.|..n.:.k......}9.m-..K....-`Fm...[...e..Z.Mkk..|.%...n.[..c...........#..L.`.8.e.~|.K.XT@n.)..B.JE....,=....qK....-.QQ...N.y&.B...k.C.P...|.[.$.t.J...X...,P.....~Vw....NH.Q....A.Up0.V......1.Y5x.T..c.o...l..~+.c..%....?...B......W1%I7.+....\$.u..k....b..i......(.~......F..F.B..r:..O......?C.T.......h......V'.....e?......Kgyj..9+4.9.+..;.D..7a.a_A.+P....+O..,...g..,..j~w...VBp,B...].3IN.t=Tw....K.."..;.Y..%j...'z.l..lo...Y...P....l..0..N...W.:(n._IS.?........b.....d],..?.g.r2..#...&orL2..y......r|....u......Z..8c.M.G<....y...{.......%.\mO F1...b[f.W....9....c.FN..7...gY.&.... .G.A...=t$.Wbza\'`^....r...A..gy.B.A.....uj.V.z6.!..>..k..../...~jL.Kk%8.e.zytr.o.qa.U....>..Y^p/...'.........i4t......f.<z.....'.S_0:c..K........'....r.4.L....L...ka.Ev..%.4...HN...5M.;.ln./.<~.....#..(...vK.....\.2.MVP9..0..K1.....W.c.G....O......._`+/.|.e.O...n...9D..y^..U*N_.N.......&..`w.Gy$.H.^Y..?.a..d..gmY'o...q..*....u{...cT.^....kH[..[....p.T....~dL.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):568
                  Entropy (8bit):7.506158985330953
                  Encrypted:false
                  SSDEEP:12:i/ywb9xlb9dhOouAU/TrkePiCfoQnUQ9IYPzgctKK81Az93TllC:i3F9dhOPxX1PiCUQ9180KQTl
                  MD5:6C694977FA0FB5802AD8E6F2A39C65C9
                  SHA1:E6A418A526CFB7F53F24DADF9975BF3B33BB9397
                  SHA-256:5EC6742D687DA75155AD5DEDFA50028DBC91E1FD2FE43E52BE43CA8EA651C8FC
                  SHA-512:E9688D462F38D78B72328D32EA2346EF1EB956CF7C2F82BBD6F538517EABD7ECC37D62330EB6925F3F09AE29BE28BE3BC7B329FB476252A87C2CE2B58813D9F3
                  Malicious:false
                  Preview:.V...w....cz.a.s.)$.....&si.n...A..}....KB........:F..9}.1TSyZ...v.8..[.w.7X...7.......-.......r...x.4.4&t...o.U.kr.7..=....-.;v@.l...55..8.x..v9].N.r..8.K....0T!PS.....9....}.....Ip.3..>..GQ$A.A.... .V..m.iT.&@.....7so.uw..,.{Y&.8.'.n..u..L...a.}.E..f.].I.. .@.....j...@......|^8.S...J..Wb........v.8(rbINHg...Z.05..P.Qz...G...l....o.Q.D.``4....m...q.-....P.j%.^.....O.i.x2 .....(.I...NU...xW/..0N..%%..j$.+r..).Xm.........E.7.>.U...T..U.7..f{....;\.........@.egB...Tcnijpw<#$....M,...s.3Ls.@21...g...0...3e{...a........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):568
                  Entropy (8bit):7.506158985330953
                  Encrypted:false
                  SSDEEP:12:i/ywb9xlb9dhOouAU/TrkePiCfoQnUQ9IYPzgctKK81Az93TllC:i3F9dhOPxX1PiCUQ9180KQTl
                  MD5:6C694977FA0FB5802AD8E6F2A39C65C9
                  SHA1:E6A418A526CFB7F53F24DADF9975BF3B33BB9397
                  SHA-256:5EC6742D687DA75155AD5DEDFA50028DBC91E1FD2FE43E52BE43CA8EA651C8FC
                  SHA-512:E9688D462F38D78B72328D32EA2346EF1EB956CF7C2F82BBD6F538517EABD7ECC37D62330EB6925F3F09AE29BE28BE3BC7B329FB476252A87C2CE2B58813D9F3
                  Malicious:false
                  Preview:.V...w....cz.a.s.)$.....&si.n...A..}....KB........:F..9}.1TSyZ...v.8..[.w.7X...7.......-.......r...x.4.4&t...o.U.kr.7..=....-.;v@.l...55..8.x..v9].N.r..8.K....0T!PS.....9....}.....Ip.3..>..GQ$A.A.... .V..m.iT.&@.....7so.uw..,.{Y&.8.'.n..u..L...a.}.E..f.].I.. .@.....j...@......|^8.S...J..Wb........v.8(rbINHg...Z.05..P.Qz...G...l....o.Q.D.``4....m...q.-....P.j%.^.....O.i.x2 .....(.I...NU...xW/..0N..%%..j$.+r..).Xm.........E.7.>.U...T..U.7..f{....;\.........@.egB...Tcnijpw<#$....M,...s.3Ls.@21...g...0...3e{...a........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):568
                  Entropy (8bit):7.506158985330953
                  Encrypted:false
                  SSDEEP:12:i/ywb9xlb9dhOouAU/TrkePiCfoQnUQ9IYPzgctKK81Az93TllC:i3F9dhOPxX1PiCUQ9180KQTl
                  MD5:6C694977FA0FB5802AD8E6F2A39C65C9
                  SHA1:E6A418A526CFB7F53F24DADF9975BF3B33BB9397
                  SHA-256:5EC6742D687DA75155AD5DEDFA50028DBC91E1FD2FE43E52BE43CA8EA651C8FC
                  SHA-512:E9688D462F38D78B72328D32EA2346EF1EB956CF7C2F82BBD6F538517EABD7ECC37D62330EB6925F3F09AE29BE28BE3BC7B329FB476252A87C2CE2B58813D9F3
                  Malicious:false
                  Preview:.V...w....cz.a.s.)$.....&si.n...A..}....KB........:F..9}.1TSyZ...v.8..[.w.7X...7.......-.......r...x.4.4&t...o.U.kr.7..=....-.;v@.l...55..8.x..v9].N.r..8.K....0T!PS.....9....}.....Ip.3..>..GQ$A.A.... .V..m.iT.&@.....7so.uw..,.{Y&.8.'.n..u..L...a.}.E..f.].I.. .@.....j...@......|^8.S...J..Wb........v.8(rbINHg...Z.05..P.Qz...G...l....o.Q.D.``4....m...q.-....P.j%.^.....O.i.x2 .....(.I...NU...xW/..0N..%%..j$.+r..).Xm.........E.7.>.U...T..U.7..f{....;\.........@.egB...Tcnijpw<#$....M,...s.3Ls.@21...g...0...3e{...a........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):3594
                  Entropy (8bit):7.9376346274702865
                  Encrypted:false
                  SSDEEP:96:asi8ZwyBq/MGLJpX7cbKrVreWt+sMZ9se5P:Fnjk/hHomppIR9sM
                  MD5:2EBE067F093C50A90E8857182CE21B53
                  SHA1:36E4BA57F7260BFE647FA1E0E864A817375042B9
                  SHA-256:D9CEDA78052D9B0E53002880A33152F2730F1FCC64D072F125A63830D007BDD4
                  SHA-512:DA938F0ADC41ACF3E3BF07EE28AFBC91EBDFB3A75A183B3A59788629CC4D3D468B29D741471BDF4C264C1E6D7D7C3B687B4C7D8DD45974400499A5C1C233ADD8
                  Malicious:false
                  Preview:.<.*y.d.wO[...v........l..B...(.[E.ef..aL..y.S...0...|......j=....D......x..{.+....v.6.+.exH7U.(..W[.....%....N.x-....D...o..Q.n O....X...........Ccf.^m.......9....,.(..[.qe.A../..L..G..7..-aRl......o+7n].b......)...1.#1...S.j,.}......r.....".....#.Xb;*\...;...t.....A3..-.n..3...*....hG...%9G.^...Y..D.. a./..%...0A.s.....p.?.=.B&&z... ......%....x.(.G...*..#.9-..I.......x.....g..P&s.a3QK.....z$...".;.P..Y..R...p.X....aL...j?..:QM..aM...(-....-i...]"...+ ...[..H.........WcA...#.].S)....Qw...\.zk.6.R.......y.|.`i.`....\b.....z..Q..g..-..<....uMyB..t....%..w..M..L....>.._eG.[A.3...v..T..o........vun....`.k.....g.~.=.E..3p.w.^.`..{.s.'.........wP0....J....0..aG....6t+..F.G..e.-.[.....~..U..Q.nqljVnU.A...C8...T...a..JHK.[..Pe`.. 7.F...p.A...J.g.#.....Bf........*..........Y..TB{.......PI........#..%?....=..h'F......'D:[8...=.......:D..<f<....~)d.. ..W.....k..rs322.~.......%7..........>.....g..eY..(t..TO7.....W.04..&n....^*m.....nZ..$..V'n.h+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):3594
                  Entropy (8bit):7.9376346274702865
                  Encrypted:false
                  SSDEEP:96:asi8ZwyBq/MGLJpX7cbKrVreWt+sMZ9se5P:Fnjk/hHomppIR9sM
                  MD5:2EBE067F093C50A90E8857182CE21B53
                  SHA1:36E4BA57F7260BFE647FA1E0E864A817375042B9
                  SHA-256:D9CEDA78052D9B0E53002880A33152F2730F1FCC64D072F125A63830D007BDD4
                  SHA-512:DA938F0ADC41ACF3E3BF07EE28AFBC91EBDFB3A75A183B3A59788629CC4D3D468B29D741471BDF4C264C1E6D7D7C3B687B4C7D8DD45974400499A5C1C233ADD8
                  Malicious:false
                  Preview:.<.*y.d.wO[...v........l..B...(.[E.ef..aL..y.S...0...|......j=....D......x..{.+....v.6.+.exH7U.(..W[.....%....N.x-....D...o..Q.n O....X...........Ccf.^m.......9....,.(..[.qe.A../..L..G..7..-aRl......o+7n].b......)...1.#1...S.j,.}......r.....".....#.Xb;*\...;...t.....A3..-.n..3...*....hG...%9G.^...Y..D.. a./..%...0A.s.....p.?.=.B&&z... ......%....x.(.G...*..#.9-..I.......x.....g..P&s.a3QK.....z$...".;.P..Y..R...p.X....aL...j?..:QM..aM...(-....-i...]"...+ ...[..H.........WcA...#.].S)....Qw...\.zk.6.R.......y.|.`i.`....\b.....z..Q..g..-..<....uMyB..t....%..w..M..L....>.._eG.[A.3...v..T..o........vun....`.k.....g.~.=.E..3p.w.^.`..{.s.'.........wP0....J....0..aG....6t+..F.G..e.-.[.....~..U..Q.nqljVnU.A...C8...T...a..JHK.[..Pe`.. 7.F...p.A...J.g.#.....Bf........*..........Y..TB{.......PI........#..%?....=..h'F......'D:[8...=.......:D..<f<....~)d.. ..W.....k..rs322.~.......%7..........>.....g..eY..(t..TO7.....W.04..&n....^*m.....nZ..$..V'n.h+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):3594
                  Entropy (8bit):7.9376346274702865
                  Encrypted:false
                  SSDEEP:96:asi8ZwyBq/MGLJpX7cbKrVreWt+sMZ9se5P:Fnjk/hHomppIR9sM
                  MD5:2EBE067F093C50A90E8857182CE21B53
                  SHA1:36E4BA57F7260BFE647FA1E0E864A817375042B9
                  SHA-256:D9CEDA78052D9B0E53002880A33152F2730F1FCC64D072F125A63830D007BDD4
                  SHA-512:DA938F0ADC41ACF3E3BF07EE28AFBC91EBDFB3A75A183B3A59788629CC4D3D468B29D741471BDF4C264C1E6D7D7C3B687B4C7D8DD45974400499A5C1C233ADD8
                  Malicious:false
                  Preview:.<.*y.d.wO[...v........l..B...(.[E.ef..aL..y.S...0...|......j=....D......x..{.+....v.6.+.exH7U.(..W[.....%....N.x-....D...o..Q.n O....X...........Ccf.^m.......9....,.(..[.qe.A../..L..G..7..-aRl......o+7n].b......)...1.#1...S.j,.}......r.....".....#.Xb;*\...;...t.....A3..-.n..3...*....hG...%9G.^...Y..D.. a./..%...0A.s.....p.?.=.B&&z... ......%....x.(.G...*..#.9-..I.......x.....g..P&s.a3QK.....z$...".;.P..Y..R...p.X....aL...j?..:QM..aM...(-....-i...]"...+ ...[..H.........WcA...#.].S)....Qw...\.zk.6.R.......y.|.`i.`....\b.....z..Q..g..-..<....uMyB..t....%..w..M..L....>.._eG.[A.3...v..T..o........vun....`.k.....g.~.=.E..3p.w.^.`..{.s.'.........wP0....J....0..aG....6t+..F.G..e.-.[.....~..U..Q.nqljVnU.A...C8...T...a..JHK.[..Pe`.. 7.F...p.A...J.g.#.....Bf........*..........Y..TB{.......PI........#..%?....=..h'F......'D:[8...=.......:D..<f<....~)d.. ..W.....k..rs322.~.......%7..........>.....g..eY..(t..TO7.....W.04..&n....^*m.....nZ..$..V'n.h+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):306
                  Entropy (8bit):6.9657264153428216
                  Encrypted:false
                  SSDEEP:6:o5HJxLuyrcNNipYEXGxEqgItMjlWZEmv2+39d8g0tZAz5oVEL:o5HJxLuyYNNdEXQHkMu+3r2r+CEL
                  MD5:56F6131D35604C8C70C702C965436B6D
                  SHA1:5781C6B97674EEE4F7E5FB71B3A5ADC4C3D1F3E5
                  SHA-256:080B451097332AB882390ACA6598FDDE7D012F6CC6A1C1C4BAC0DA996C7437FD
                  SHA-512:57B38DCDAC22E94FA33762651568362281C5DC00B87890D44AFB9AFF6C853A153132B64AA358099B25480870DAA14B797BF74576AB47DDB2E7A5B384D4627D23
                  Malicious:false
                  Preview:.~r..e..........r.[...u{..X...b4.%...T...'..6o.O...g.-.:.......' ....6..c,....)7wq..........7.H>4,....{....-lF...kE.Hp..W.lb.N..".>G...S..q..$.|...[..3.3..._.;.Cf..+.no.X"$.#.......".......#B..........yJ&.........f.."..2.k.W..:..IJ!.w.3r.....c../.]...I...@.,cr.j2.|.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):306
                  Entropy (8bit):6.9657264153428216
                  Encrypted:false
                  SSDEEP:6:o5HJxLuyrcNNipYEXGxEqgItMjlWZEmv2+39d8g0tZAz5oVEL:o5HJxLuyYNNdEXQHkMu+3r2r+CEL
                  MD5:56F6131D35604C8C70C702C965436B6D
                  SHA1:5781C6B97674EEE4F7E5FB71B3A5ADC4C3D1F3E5
                  SHA-256:080B451097332AB882390ACA6598FDDE7D012F6CC6A1C1C4BAC0DA996C7437FD
                  SHA-512:57B38DCDAC22E94FA33762651568362281C5DC00B87890D44AFB9AFF6C853A153132B64AA358099B25480870DAA14B797BF74576AB47DDB2E7A5B384D4627D23
                  Malicious:false
                  Preview:.~r..e..........r.[...u{..X...b4.%...T...'..6o.O...g.-.:.......' ....6..c,....)7wq..........7.H>4,....{....-lF...kE.Hp..W.lb.N..".>G...S..q..$.|...[..3.3..._.;.Cf..+.no.X"$.#.......".......#B..........yJ&.........f.."..2.k.W..:..IJ!.w.3r.....c../.]...I...@.,cr.j2.|.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):306
                  Entropy (8bit):6.9657264153428216
                  Encrypted:false
                  SSDEEP:6:o5HJxLuyrcNNipYEXGxEqgItMjlWZEmv2+39d8g0tZAz5oVEL:o5HJxLuyYNNdEXQHkMu+3r2r+CEL
                  MD5:56F6131D35604C8C70C702C965436B6D
                  SHA1:5781C6B97674EEE4F7E5FB71B3A5ADC4C3D1F3E5
                  SHA-256:080B451097332AB882390ACA6598FDDE7D012F6CC6A1C1C4BAC0DA996C7437FD
                  SHA-512:57B38DCDAC22E94FA33762651568362281C5DC00B87890D44AFB9AFF6C853A153132B64AA358099B25480870DAA14B797BF74576AB47DDB2E7A5B384D4627D23
                  Malicious:false
                  Preview:.~r..e..........r.[...u{..X...b4.%...T...'..6o.O...g.-.:.......' ....6..c,....)7wq..........7.H>4,....{....-lF...kE.Hp..W.lb.N..".>G...S..q..$.|...[..3.3..._.;.Cf..+.no.X"$.#.......".......#B..........yJ&.........f.."..2.k.W..:..IJ!.w.3r.....c../.]...I...@.,cr.j2.|.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2287
                  Entropy (8bit):7.909877963936639
                  Encrypted:false
                  SSDEEP:48:4j/3xH6dOAG3P892EfFTL3c1lcv6vaksPuxM1r9kb9Xvy3fkSM+:4j/h2k3Pc2EfF/klcvKBsPacpkxifN
                  MD5:E61F117180FD9DBACFB6DF84C8A18C82
                  SHA1:61927FEA3C5C1E8AEBD4A12130B4C72141B96E2E
                  SHA-256:2E6F2FFEDA7881B5B0EA8AF5B90226C072F910A6F1391551D63E75A36C31B41C
                  SHA-512:F3D606B0AD904B434015C9516CEDEDE0F414F29871CC0299361FA830EAF71D3DBC226AF07D8545EFE1A6FA47D3B9EA2B0E21B27609011859B400EC903002C83E
                  Malicious:false
                  Preview:.G.F..>j\Lb......E..uBJA.^.#f.asW..H.!In_j....GZ.L...88..K.o. ......dg[.7.......7........t.y......KBw.7.`&..U..+P...u.0#.r!.K.jk.....XGw"..xTM.W/f(../.b.}..M...m.*..d.....e..{...9......~....P...6l........._H...9.].Z......kbi..q...#`.fyU;.....d..-..........R?.f.3.u^.Y..n...[.-.(...he..."..7.K4e...1P.5$E..v....z'(.....b...j..5...9...~.&........X...k.I..e.8..(.ff..@x...B-jD.pY.k.<Ei...saL....R. q.^.%.>.....k.9.q..b...a.+A'....MU/H{Q..Em..~...f...&...-........%....:N...Ux...G.#W.f.-.&..`..<,.....pP........#W'0..j=.....>9j..r=M,>{..r8y...[...D...B.).>.G\S3..l..F9.....oT..%...Op..d..r.Z1..).\j.......Q...2..].....t|.])..|..|.n!...Q.S..Y...=.c.~G..~UeF..WT....[....UQ.0........A.*a.....s9nG.o.z...(e..}...Z{...L.{...P.(p...j..8K......Z.i....ze....^\..QQ...A...<......3.6u .y ...~l.|...2nVf.e+.Z'9\#..|B[\.....t.....>..'.....pO"]5.{....@...}tB..j.b..F...:..N..TS..E,(p..{...3..$.M0.....z..N..!.^.9te...7..a]..2..q.h.Zr2..W9W|d....N.N..F.O...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2287
                  Entropy (8bit):7.909877963936639
                  Encrypted:false
                  SSDEEP:48:4j/3xH6dOAG3P892EfFTL3c1lcv6vaksPuxM1r9kb9Xvy3fkSM+:4j/h2k3Pc2EfF/klcvKBsPacpkxifN
                  MD5:E61F117180FD9DBACFB6DF84C8A18C82
                  SHA1:61927FEA3C5C1E8AEBD4A12130B4C72141B96E2E
                  SHA-256:2E6F2FFEDA7881B5B0EA8AF5B90226C072F910A6F1391551D63E75A36C31B41C
                  SHA-512:F3D606B0AD904B434015C9516CEDEDE0F414F29871CC0299361FA830EAF71D3DBC226AF07D8545EFE1A6FA47D3B9EA2B0E21B27609011859B400EC903002C83E
                  Malicious:false
                  Preview:.G.F..>j\Lb......E..uBJA.^.#f.asW..H.!In_j....GZ.L...88..K.o. ......dg[.7.......7........t.y......KBw.7.`&..U..+P...u.0#.r!.K.jk.....XGw"..xTM.W/f(../.b.}..M...m.*..d.....e..{...9......~....P...6l........._H...9.].Z......kbi..q...#`.fyU;.....d..-..........R?.f.3.u^.Y..n...[.-.(...he..."..7.K4e...1P.5$E..v....z'(.....b...j..5...9...~.&........X...k.I..e.8..(.ff..@x...B-jD.pY.k.<Ei...saL....R. q.^.%.>.....k.9.q..b...a.+A'....MU/H{Q..Em..~...f...&...-........%....:N...Ux...G.#W.f.-.&..`..<,.....pP........#W'0..j=.....>9j..r=M,>{..r8y...[...D...B.).>.G\S3..l..F9.....oT..%...Op..d..r.Z1..).\j.......Q...2..].....t|.])..|..|.n!...Q.S..Y...=.c.~G..~UeF..WT....[....UQ.0........A.*a.....s9nG.o.z...(e..}...Z{...L.{...P.(p...j..8K......Z.i....ze....^\..QQ...A...<......3.6u .y ...~l.|...2nVf.e+.Z'9\#..|B[\.....t.....>..'.....pO"]5.{....@...}tB..j.b..F...:..N..TS..E,(p..{...3..$.M0.....z..N..!.^.9te...7..a]..2..q.h.Zr2..W9W|d....N.N..F.O...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2287
                  Entropy (8bit):7.909877963936639
                  Encrypted:false
                  SSDEEP:48:4j/3xH6dOAG3P892EfFTL3c1lcv6vaksPuxM1r9kb9Xvy3fkSM+:4j/h2k3Pc2EfF/klcvKBsPacpkxifN
                  MD5:E61F117180FD9DBACFB6DF84C8A18C82
                  SHA1:61927FEA3C5C1E8AEBD4A12130B4C72141B96E2E
                  SHA-256:2E6F2FFEDA7881B5B0EA8AF5B90226C072F910A6F1391551D63E75A36C31B41C
                  SHA-512:F3D606B0AD904B434015C9516CEDEDE0F414F29871CC0299361FA830EAF71D3DBC226AF07D8545EFE1A6FA47D3B9EA2B0E21B27609011859B400EC903002C83E
                  Malicious:false
                  Preview:.G.F..>j\Lb......E..uBJA.^.#f.asW..H.!In_j....GZ.L...88..K.o. ......dg[.7.......7........t.y......KBw.7.`&..U..+P...u.0#.r!.K.jk.....XGw"..xTM.W/f(../.b.}..M...m.*..d.....e..{...9......~....P...6l........._H...9.].Z......kbi..q...#`.fyU;.....d..-..........R?.f.3.u^.Y..n...[.-.(...he..."..7.K4e...1P.5$E..v....z'(.....b...j..5...9...~.&........X...k.I..e.8..(.ff..@x...B-jD.pY.k.<Ei...saL....R. q.^.%.>.....k.9.q..b...a.+A'....MU/H{Q..Em..~...f...&...-........%....:N...Ux...G.#W.f.-.&..`..<,.....pP........#W'0..j=.....>9j..r=M,>{..r8y...[...D...B.).>.G\S3..l..F9.....oT..%...Op..d..r.Z1..).\j.......Q...2..].....t|.])..|..|.n!...Q.S..Y...=.c.~G..~UeF..WT....[....UQ.0........A.*a.....s9nG.o.z...(e..}...Z{...L.{...P.(p...j..8K......Z.i....ze....^\..QQ...A...<......3.6u .y ...~l.|...2nVf.e+.Z'9\#..|B[\.....t.....>..'.....pO"]5.{....@...}tB..j.b..F...:..N..TS..E,(p..{...3..$.M0.....z..N..!.^.9te...7..a]..2..q.h.Zr2..W9W|d....N.N..F.O...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):599
                  Entropy (8bit):7.51432604031809
                  Encrypted:false
                  SSDEEP:12:Y0BkxdkCv38a5QQsaHJPIo5k4rvcwwxRZc6Wmhy2:Y0Bqxv3rsaHdAwwNc2y
                  MD5:EBD95D24B6A50C461D1C395B0B74C8EE
                  SHA1:AB8FD7BE4BAEBB3D8B00FBFEEFF714876CD87A63
                  SHA-256:481ED2BE80566AB7195D40DEE1C3FB96CAD75FEE95FCBB0F4F2D320BB8A23324
                  SHA-512:5DB27DF1F2169FFAED19B2F1115CB3EC28280444AC9A6371482ACA04A7E47729F4C801ADBBDCEAE16CD42C91071BC287463CEA02B13536A15CDB4EE0D9A54211
                  Malicious:false
                  Preview:T..(.......@....o...o..j...p.v..q.G;mIh....r..v.e..`8,|.u....f...q.`[..Y..<>..9q...z..D...}m....e..[.]'S...W...6;p..7>X..x~.B...q_...o.g.;..tc.{..E...t.........o./.P.=.d.F.+..|y...3..G..@/V|..bc.:|.sk.\N.GC.*..5....@........{........y./...*5:.b...T..I..C.J.?h...;s..3..Q.i.Q..s.......SC...U6.2.3q.y.{.l..!..p.j...)rjzsMn'..T.*}......O.........b"D.....P.....j.t........6...[b.LH...z....;np..h....I...M}...E....k..,..C '.G.Ii.......V6.iv...E..Y.....1...PN.E"..U.5.l../.g!...O........Ej......b...M.%..d|+4.W....yb.,.........C.l.qWo..>h..K........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):599
                  Entropy (8bit):7.51432604031809
                  Encrypted:false
                  SSDEEP:12:Y0BkxdkCv38a5QQsaHJPIo5k4rvcwwxRZc6Wmhy2:Y0Bqxv3rsaHdAwwNc2y
                  MD5:EBD95D24B6A50C461D1C395B0B74C8EE
                  SHA1:AB8FD7BE4BAEBB3D8B00FBFEEFF714876CD87A63
                  SHA-256:481ED2BE80566AB7195D40DEE1C3FB96CAD75FEE95FCBB0F4F2D320BB8A23324
                  SHA-512:5DB27DF1F2169FFAED19B2F1115CB3EC28280444AC9A6371482ACA04A7E47729F4C801ADBBDCEAE16CD42C91071BC287463CEA02B13536A15CDB4EE0D9A54211
                  Malicious:false
                  Preview:T..(.......@....o...o..j...p.v..q.G;mIh....r..v.e..`8,|.u....f...q.`[..Y..<>..9q...z..D...}m....e..[.]'S...W...6;p..7>X..x~.B...q_...o.g.;..tc.{..E...t.........o./.P.=.d.F.+..|y...3..G..@/V|..bc.:|.sk.\N.GC.*..5....@........{........y./...*5:.b...T..I..C.J.?h...;s..3..Q.i.Q..s.......SC...U6.2.3q.y.{.l..!..p.j...)rjzsMn'..T.*}......O.........b"D.....P.....j.t........6...[b.LH...z....;np..h....I...M}...E....k..,..C '.G.Ii.......V6.iv...E..Y.....1...PN.E"..U.5.l../.g!...O........Ej......b...M.%..d|+4.W....yb.,.........C.l.qWo..>h..K........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):599
                  Entropy (8bit):7.51432604031809
                  Encrypted:false
                  SSDEEP:12:Y0BkxdkCv38a5QQsaHJPIo5k4rvcwwxRZc6Wmhy2:Y0Bqxv3rsaHdAwwNc2y
                  MD5:EBD95D24B6A50C461D1C395B0B74C8EE
                  SHA1:AB8FD7BE4BAEBB3D8B00FBFEEFF714876CD87A63
                  SHA-256:481ED2BE80566AB7195D40DEE1C3FB96CAD75FEE95FCBB0F4F2D320BB8A23324
                  SHA-512:5DB27DF1F2169FFAED19B2F1115CB3EC28280444AC9A6371482ACA04A7E47729F4C801ADBBDCEAE16CD42C91071BC287463CEA02B13536A15CDB4EE0D9A54211
                  Malicious:false
                  Preview:T..(.......@....o...o..j...p.v..q.G;mIh....r..v.e..`8,|.u....f...q.`[..Y..<>..9q...z..D...}m....e..[.]'S...W...6;p..7>X..x~.B...q_...o.g.;..tc.{..E...t.........o./.P.=.d.F.+..|y...3..G..@/V|..bc.:|.sk.\N.GC.*..5....@........{........y./...*5:.b...T..I..C.J.?h...;s..3..Q.i.Q..s.......SC...U6.2.3q.y.{.l..!..p.j...)rjzsMn'..T.*}......O.........b"D.....P.....j.t........6...[b.LH...z....;np..h....I...M}...E....k..,..C '.G.Ii.......V6.iv...E..Y.....1...PN.E"..U.5.l../.g!...O........Ej......b...M.%..d|+4.W....yb.,.........C.l.qWo..>h..K........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):549
                  Entropy (8bit):7.5416562815116714
                  Encrypted:false
                  SSDEEP:12:Ko4q7PZIv8rmgk62CSNiqVI0GZbBMwmQ/jTc/:d37hStn+RLmQ/jT
                  MD5:0CD815C545650C02B82410E09124FA65
                  SHA1:EF21816D97797B0E44B875731DF97500E0F38406
                  SHA-256:7913570DD7980B878A6CF26D7753AE154A4B874729DC18CE81EF7E645D984C94
                  SHA-512:4658F45C8F2EEE5EEAF7D8429DD3653AF25B5E0C33AE07874CAAFCB8468D112E99310436B58BC53611759C4CD948E54C95963EC622C64B1BAC988C9C985F9F55
                  Malicious:false
                  Preview:"....'.>.V-P..0.7.....?.R)..&.(.u.l.65`].2..;/..:.._...j..+.....<..-.>.I.=...o........R....6iu...G.a<.(Y...."....`.PM.".D..s.|..|...e.Sm....|.....7.....gh...nr..W.0G{a......F.fc\R...L...?V..P......g...3`.P.Oh....*...&..s.c3.U.7T..1....T6Fl.U..O......mo...M.c.E.0>.~2...fn..z...Nk.}.".x..#....1.F.$.?.\..9.._..{....X..dCI.k+...8...3g.q........f..A..w.O.,O.).2.v......M...qqo.. j...J...*.UT..$.%>H.7.}.......Gk]...*..[+..Zu...\.............o?k.F.[....QC.3#.....yv.{...#.j...fN.......C.......D.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):549
                  Entropy (8bit):7.5416562815116714
                  Encrypted:false
                  SSDEEP:12:Ko4q7PZIv8rmgk62CSNiqVI0GZbBMwmQ/jTc/:d37hStn+RLmQ/jT
                  MD5:0CD815C545650C02B82410E09124FA65
                  SHA1:EF21816D97797B0E44B875731DF97500E0F38406
                  SHA-256:7913570DD7980B878A6CF26D7753AE154A4B874729DC18CE81EF7E645D984C94
                  SHA-512:4658F45C8F2EEE5EEAF7D8429DD3653AF25B5E0C33AE07874CAAFCB8468D112E99310436B58BC53611759C4CD948E54C95963EC622C64B1BAC988C9C985F9F55
                  Malicious:false
                  Preview:"....'.>.V-P..0.7.....?.R)..&.(.u.l.65`].2..;/..:.._...j..+.....<..-.>.I.=...o........R....6iu...G.a<.(Y...."....`.PM.".D..s.|..|...e.Sm....|.....7.....gh...nr..W.0G{a......F.fc\R...L...?V..P......g...3`.P.Oh....*...&..s.c3.U.7T..1....T6Fl.U..O......mo...M.c.E.0>.~2...fn..z...Nk.}.".x..#....1.F.$.?.\..9.._..{....X..dCI.k+...8...3g.q........f..A..w.O.,O.).2.v......M...qqo.. j...J...*.UT..$.%>H.7.}.......Gk]...*..[+..Zu...\.............o?k.F.[....QC.3#.....yv.{...#.j...fN.......C.......D.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):549
                  Entropy (8bit):7.5416562815116714
                  Encrypted:false
                  SSDEEP:12:Ko4q7PZIv8rmgk62CSNiqVI0GZbBMwmQ/jTc/:d37hStn+RLmQ/jT
                  MD5:0CD815C545650C02B82410E09124FA65
                  SHA1:EF21816D97797B0E44B875731DF97500E0F38406
                  SHA-256:7913570DD7980B878A6CF26D7753AE154A4B874729DC18CE81EF7E645D984C94
                  SHA-512:4658F45C8F2EEE5EEAF7D8429DD3653AF25B5E0C33AE07874CAAFCB8468D112E99310436B58BC53611759C4CD948E54C95963EC622C64B1BAC988C9C985F9F55
                  Malicious:false
                  Preview:"....'.>.V-P..0.7.....?.R)..&.(.u.l.65`].2..;/..:.._...j..+.....<..-.>.I.=...o........R....6iu...G.a<.(Y...."....`.PM.".D..s.|..|...e.Sm....|.....7.....gh...nr..W.0G{a......F.fc\R...L...?V..P......g...3`.P.Oh....*...&..s.c3.U.7T..1....T6Fl.U..O......mo...M.c.E.0>.~2...fn..z...Nk.}.".x..#....1.F.$.?.\..9.._..{....X..dCI.k+...8...3g.q........f..A..w.O.,O.).2.v......M...qqo.. j...J...*.UT..$.%>H.7.}.......Gk]...*..[+..Zu...\.............o?k.F.[....QC.3#.....yv.{...#.j...fN.......C.......D.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):697
                  Entropy (8bit):7.584173160772218
                  Encrypted:false
                  SSDEEP:12:1X1D7EXYIPvSO7s1gWbIDk2Ro6kLHTkYKhlUkDb5GsnBkcRKlrt+PfAj:UxPKQeHUo2i6kLHIYKTff5GXcIl6fA
                  MD5:50021A7F8CA0A510C0B886E42557132A
                  SHA1:1B5E6C242C03C9E944763224C7B7CB9888540B5C
                  SHA-256:26182D0E4ADA40691062B72CE16C31C7B8075295C06E95E78F7B8BC477E990FB
                  SHA-512:029079037709BE2FE75E6F379F757593D1FCBDBCF9299F8CF97697C6D71C5B117051F6CBBE238C746A31EBEB68BEBD462AFD44DD8B5B41B5DC6D73A9B5D8B726
                  Malicious:false
                  Preview:.K.........a......j...B,..^...&..........e ..z...M....a_.x/.Nt/S......1...3.5..AV.....9.1.<...o.mY..s.lg.R..0..O.V....P...B.k.5.....Gg.>...H....Z .R....5#...k2oD....(gd%..%.W.m.+.-.b-5..................d.8.7....Te/...-.)....X0...@....R...(iHW...Ow.b.a....7..$.R.YIG...D......>...l......._F.eb@Yb6..._.d...\0......;Z"..t..<.....E(aD.A.%..2O.....n..h.......%.]~.Y\3V-?..6<...3)v.R...Z....T.}2v...*..@q.s..|*......H|.{H..ZG(.s.>k0Z...#...mG..k.;|.5..@.w.9i......X\.....].Z.vlG...^.(~.A.&.J.........R.wk.<.........S9.,..(..N/_...-...9jg.....u.d.*@....SZ..K.3.s9..na.c...........~..q4A..\.......4..o.e..Y2.S.-x.[.l..|.RF..!.M.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):697
                  Entropy (8bit):7.584173160772218
                  Encrypted:false
                  SSDEEP:12:1X1D7EXYIPvSO7s1gWbIDk2Ro6kLHTkYKhlUkDb5GsnBkcRKlrt+PfAj:UxPKQeHUo2i6kLHIYKTff5GXcIl6fA
                  MD5:50021A7F8CA0A510C0B886E42557132A
                  SHA1:1B5E6C242C03C9E944763224C7B7CB9888540B5C
                  SHA-256:26182D0E4ADA40691062B72CE16C31C7B8075295C06E95E78F7B8BC477E990FB
                  SHA-512:029079037709BE2FE75E6F379F757593D1FCBDBCF9299F8CF97697C6D71C5B117051F6CBBE238C746A31EBEB68BEBD462AFD44DD8B5B41B5DC6D73A9B5D8B726
                  Malicious:false
                  Preview:.K.........a......j...B,..^...&..........e ..z...M....a_.x/.Nt/S......1...3.5..AV.....9.1.<...o.mY..s.lg.R..0..O.V....P...B.k.5.....Gg.>...H....Z .R....5#...k2oD....(gd%..%.W.m.+.-.b-5..................d.8.7....Te/...-.)....X0...@....R...(iHW...Ow.b.a....7..$.R.YIG...D......>...l......._F.eb@Yb6..._.d...\0......;Z"..t..<.....E(aD.A.%..2O.....n..h.......%.]~.Y\3V-?..6<...3)v.R...Z....T.}2v...*..@q.s..|*......H|.{H..ZG(.s.>k0Z...#...mG..k.;|.5..@.w.9i......X\.....].Z.vlG...^.(~.A.&.J.........R.wk.<.........S9.,..(..N/_...-...9jg.....u.d.*@....SZ..K.3.s9..na.c...........~..q4A..\.......4..o.e..Y2.S.-x.[.l..|.RF..!.M.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):697
                  Entropy (8bit):7.584173160772218
                  Encrypted:false
                  SSDEEP:12:1X1D7EXYIPvSO7s1gWbIDk2Ro6kLHTkYKhlUkDb5GsnBkcRKlrt+PfAj:UxPKQeHUo2i6kLHIYKTff5GXcIl6fA
                  MD5:50021A7F8CA0A510C0B886E42557132A
                  SHA1:1B5E6C242C03C9E944763224C7B7CB9888540B5C
                  SHA-256:26182D0E4ADA40691062B72CE16C31C7B8075295C06E95E78F7B8BC477E990FB
                  SHA-512:029079037709BE2FE75E6F379F757593D1FCBDBCF9299F8CF97697C6D71C5B117051F6CBBE238C746A31EBEB68BEBD462AFD44DD8B5B41B5DC6D73A9B5D8B726
                  Malicious:false
                  Preview:.K.........a......j...B,..^...&..........e ..z...M....a_.x/.Nt/S......1...3.5..AV.....9.1.<...o.mY..s.lg.R..0..O.V....P...B.k.5.....Gg.>...H....Z .R....5#...k2oD....(gd%..%.W.m.+.-.b-5..................d.8.7....Te/...-.)....X0...@....R...(iHW...Ow.b.a....7..$.R.YIG...D......>...l......._F.eb@Yb6..._.d...\0......;Z"..t..<.....E(aD.A.%..2O.....n..h.......%.]~.Y\3V-?..6<...3)v.R...Z....T.}2v...*..@q.s..|*......H|.{H..ZG(.s.>k0Z...#...mG..k.;|.5..@.w.9i......X\.....].Z.vlG...^.(~.A.&.J.........R.wk.<.........S9.,..(..N/_...-...9jg.....u.d.*@....SZ..K.3.s9..na.c...........~..q4A..\.......4..o.e..Y2.S.-x.[.l..|.RF..!.M.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):337637792
                  Entropy (8bit):7.6091229696312075
                  Encrypted:false
                  SSDEEP:6291456:TGcNICCKMJRSTq5ZjK1+VVL5/JY1bbMTopZ:7NWJXG4Vtg4k
                  MD5:1C33960EB72096BBFED326B639D3A4A3
                  SHA1:5D09AA72D95EAF3BFCC37AC18FDABE37B3F4195D
                  SHA-256:AD1BE081979B2E2A5634047B09D75D8DAFBED2B65A51666AAF013598C9BB8139
                  SHA-512:589DF6C15FB83FE11D38CB1EA7781A1F9B5CFCCF7D88CD0143E3AB72F4D7B8A4B751AEC11B620046FFF83BDA81C7C3146B7D207F75418BC67DB90F24B8266BE7
                  Malicious:false
                  Preview:Lsu.2.....E...q.^G.m. s.W... .._).N4.L4..P.4...9..n..|a.@.........1T....@C*...T.. B3(`Y=Y...&...[jo35.+..(d.l.{P6..5Xl....q........).@......cr.^=......_...c/..E..]D..uI....ry..-...#.....S.)..Gj$.......s).S;..e. .tc..H.p./....pL.....)......\.},|....TEy3..^.!..H...............J.~..ymv. r...~O.M..j..L..,..qF~`4Y.B6......1Y.l|.oA.<.C.fQ....I9.oK4.8.G8.^Cf....Ijg..<WQ.y!).z...`X.{*...E=..+7.K.......n. ....W...{..D.&.c\.M..hR.^.X..-...7pA._7g..8.l..1.#k......k...K2U.4!u..q.@.=R...wo.7.8........j|@.w.N.1.;z.^.......s ..6.(..TXf.}.,...E.......y@2...`.CT...........x>..D....yi.C.6...*....... .....;....eK...h._..u).8..@X\...........q....j, ..O...m.G.. ......=.....*&m..^..Tr+.......=.B.Tf.T.S.y.k....5*d.=...Q..K0u.B.h`?x... ....b.m.N3.8...W.x...X1o.W..IL....C.^..R..Yi.<%..;7h.BC.$...=........^n....z......9...1*#.zSY...\a..#%}..H..@..0O...d..P.;|.B..0I.. .V.Y.s.W..R.t..E5n.9t..y..*.'..@Br...f ..c..x.d,..V.Ng.+...tj..H0j....r.:.x2.Q....v.......C..N.}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):337637792
                  Entropy (8bit):7.6091229696312075
                  Encrypted:false
                  SSDEEP:6291456:TGcNICCKMJRSTq5ZjK1+VVL5/JY1bbMTopZ:7NWJXG4Vtg4k
                  MD5:1C33960EB72096BBFED326B639D3A4A3
                  SHA1:5D09AA72D95EAF3BFCC37AC18FDABE37B3F4195D
                  SHA-256:AD1BE081979B2E2A5634047B09D75D8DAFBED2B65A51666AAF013598C9BB8139
                  SHA-512:589DF6C15FB83FE11D38CB1EA7781A1F9B5CFCCF7D88CD0143E3AB72F4D7B8A4B751AEC11B620046FFF83BDA81C7C3146B7D207F75418BC67DB90F24B8266BE7
                  Malicious:false
                  Preview:Lsu.2.....E...q.^G.m. s.W... .._).N4.L4..P.4...9..n..|a.@.........1T....@C*...T.. B3(`Y=Y...&...[jo35.+..(d.l.{P6..5Xl....q........).@......cr.^=......_...c/..E..]D..uI....ry..-...#.....S.)..Gj$.......s).S;..e. .tc..H.p./....pL.....)......\.},|....TEy3..^.!..H...............J.~..ymv. r...~O.M..j..L..,..qF~`4Y.B6......1Y.l|.oA.<.C.fQ....I9.oK4.8.G8.^Cf....Ijg..<WQ.y!).z...`X.{*...E=..+7.K.......n. ....W...{..D.&.c\.M..hR.^.X..-...7pA._7g..8.l..1.#k......k...K2U.4!u..q.@.=R...wo.7.8........j|@.w.N.1.;z.^.......s ..6.(..TXf.}.,...E.......y@2...`.CT...........x>..D....yi.C.6...*....... .....;....eK...h._..u).8..@X\...........q....j, ..O...m.G.. ......=.....*&m..^..Tr+.......=.B.Tf.T.S.y.k....5*d.=...Q..K0u.B.h`?x... ....b.m.N3.8...W.x...X1o.W..IL....C.^..R..Yi.<%..;7h.BC.$...=........^n....z......9...1*#.zSY...\a..#%}..H..@..0O...d..P.;|.B..0I.. .V.Y.s.W..R.t..E5n.9t..y..*.'..@Br...f ..c..x.d,..V.Ng.+...tj..H0j....r.:.x2.Q....v.......C..N.}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):804
                  Entropy (8bit):7.690494483467728
                  Encrypted:false
                  SSDEEP:12:WQFTfvlyg42KNnGMAVFWkhZ70SB9a/gVY72TGMhKJGrdwisKoUK6noeu3SoqgI:XFjvIgnK9NmxnjBKgiLMh7GPnMoeuNq
                  MD5:48FBC58722A0A54583F18C8C590D2AA2
                  SHA1:0530FDDB0C06D5C832DAF32ACDF7682FB4853386
                  SHA-256:FD7AD2B4F7B672AD6953BC2524251A0A621E49DABC08B7B13C643E37B662DB31
                  SHA-512:568264DDF3E0A6EF5C7AA1E1D6E94BD5AF97BACED7FC1D7C49A88F013FA76243275AAA13A6EF98E58F6E475D22EFFFBD9908ED58106215CA26DDE4DA09EC3022
                  Malicious:false
                  Preview:T..bu..U.S:.D.(.W.."...yp..D...+..>B....2...u}....In..J.....E...;...tA...%_}kJ=.......8X...d...!g.!;.<..H.%..-...H.y!.0L.T(.-.....9.!.&.h...e....b.F..*.w....[....C...f....$.)...b...8.......~..$o(F..UZ...Z.p.....u...0$..R1....p0tC......d|...K...0K..s..{.$...'.......=wR...9..2S..2.1C.]Ra.#. ....".(Y5..{...#J_2Ux.W....]..C....V.-q..)...$.25....KU]..f...n....(......../....2?].....M.....S+.l.a...N......g...pL.).....%.e....."Z'.'.....G...95`10..-B..%(....U.JZ..k.>v.a9Q..:g..q..E...........O.a.....&.%"j&..M.....~..cg.^..t.|....?..)B...n...!1..'H..VV.......^`...G.......}y....0t.....P..J.....j..y..X*...G....4.....f...m......Q..l..q17u.c.....@..1..........x.~h.{.V.,p.z.J............../2.....0..<..a..........^...-.aG....W.:.H.....gjkC..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):804
                  Entropy (8bit):7.690494483467728
                  Encrypted:false
                  SSDEEP:12:WQFTfvlyg42KNnGMAVFWkhZ70SB9a/gVY72TGMhKJGrdwisKoUK6noeu3SoqgI:XFjvIgnK9NmxnjBKgiLMh7GPnMoeuNq
                  MD5:48FBC58722A0A54583F18C8C590D2AA2
                  SHA1:0530FDDB0C06D5C832DAF32ACDF7682FB4853386
                  SHA-256:FD7AD2B4F7B672AD6953BC2524251A0A621E49DABC08B7B13C643E37B662DB31
                  SHA-512:568264DDF3E0A6EF5C7AA1E1D6E94BD5AF97BACED7FC1D7C49A88F013FA76243275AAA13A6EF98E58F6E475D22EFFFBD9908ED58106215CA26DDE4DA09EC3022
                  Malicious:false
                  Preview:T..bu..U.S:.D.(.W.."...yp..D...+..>B....2...u}....In..J.....E...;...tA...%_}kJ=.......8X...d...!g.!;.<..H.%..-...H.y!.0L.T(.-.....9.!.&.h...e....b.F..*.w....[....C...f....$.)...b...8.......~..$o(F..UZ...Z.p.....u...0$..R1....p0tC......d|...K...0K..s..{.$...'.......=wR...9..2S..2.1C.]Ra.#. ....".(Y5..{...#J_2Ux.W....]..C....V.-q..)...$.25....KU]..f...n....(......../....2?].....M.....S+.l.a...N......g...pL.).....%.e....."Z'.'.....G...95`10..-B..%(....U.JZ..k.>v.a9Q..:g..q..E...........O.a.....&.%"j&..M.....~..cg.^..t.|....?..)B...n...!1..'H..VV.......^`...G.......}y....0t.....P..J.....j..y..X*...G....4.....f...m......Q..l..q17u.c.....@..1..........x.~h.{.V.,p.z.J............../2.....0..<..a..........^...-.aG....W.:.H.....gjkC..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):804
                  Entropy (8bit):7.690494483467728
                  Encrypted:false
                  SSDEEP:12:WQFTfvlyg42KNnGMAVFWkhZ70SB9a/gVY72TGMhKJGrdwisKoUK6noeu3SoqgI:XFjvIgnK9NmxnjBKgiLMh7GPnMoeuNq
                  MD5:48FBC58722A0A54583F18C8C590D2AA2
                  SHA1:0530FDDB0C06D5C832DAF32ACDF7682FB4853386
                  SHA-256:FD7AD2B4F7B672AD6953BC2524251A0A621E49DABC08B7B13C643E37B662DB31
                  SHA-512:568264DDF3E0A6EF5C7AA1E1D6E94BD5AF97BACED7FC1D7C49A88F013FA76243275AAA13A6EF98E58F6E475D22EFFFBD9908ED58106215CA26DDE4DA09EC3022
                  Malicious:false
                  Preview:T..bu..U.S:.D.(.W.."...yp..D...+..>B....2...u}....In..J.....E...;...tA...%_}kJ=.......8X...d...!g.!;.<..H.%..-...H.y!.0L.T(.-.....9.!.&.h...e....b.F..*.w....[....C...f....$.)...b...8.......~..$o(F..UZ...Z.p.....u...0$..R1....p0tC......d|...K...0K..s..{.$...'.......=wR...9..2S..2.1C.]Ra.#. ....".(Y5..{...#J_2Ux.W....]..C....V.-q..)...$.25....KU]..f...n....(......../....2?].....M.....S+.l.a...N......g...pL.).....%.e....."Z'.'.....G...95`10..-B..%(....U.JZ..k.>v.a9Q..:g..q..E...........O.a.....&.%"j&..M.....~..cg.^..t.|....?..)B...n...!1..'H..VV.......^`...G.......}y....0t.....P..J.....j..y..X*...G....4.....f...m......Q..l..q17u.c.....@..1..........x.~h.{.V.,p.z.J............../2.....0..<..a..........^...-.aG....W.:.H.....gjkC..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):529
                  Entropy (8bit):7.507567435245275
                  Encrypted:false
                  SSDEEP:12:ccXSnDm9Vdc96SRwrno0zkhHTaNpU+S5hrd5do9Si0mZ8Uw5nkDpJh3C:NSDm5cBRwzrczysrd5do9Si0Gw5nkD3l
                  MD5:1E749455A8814C93006A9E9814CF3550
                  SHA1:E7BB0166A813CC3EA5396513673D583639BB0966
                  SHA-256:E9AFED56F68F20AC14FCF22B1347B025F9F3F929BB63A6896B764C0C18C10591
                  SHA-512:3CDC3B095BFEE04A764846F48B3BF7B752BA6A4AC63BBB9CB1EBA0F0EBC83E64165423BDDCF52D688DD32DC4AB57696A04798382B114A0BD1DC9ADE348EED60C
                  Malicious:false
                  Preview:i..A2...zIV.!9.....,.+.-|.......b.....\.{.|UH[...N......w..x..,..a.....Uo..%.^..k..^.7.>x&.K...~..3.U.....%_...#+w.....:......{f..Z.X\Zx.A}.....s...o.J..].`..r..4#<.0.O.&)W...E..v..Yk..z.g.*.+z/. ....0..3O..!.......A.=..r... .PD.,FKR...LI^..t.uh.v.#...;.E.A.c.)y.)..,.6.....T.=O.4t..'.C..Eq...(/..u.n.1.v......{..G.Nz6.<..p..D.a....zn6.'.g.."..w.?..y.....s..Ea...f6"`..vv.;...FH...+.|.."k....:.%...L.....Y.Uq........z._...cMJ.O..s..j0VI40..H9.r..~..-p.af.z<...8[...f........q...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):529
                  Entropy (8bit):7.507567435245275
                  Encrypted:false
                  SSDEEP:12:ccXSnDm9Vdc96SRwrno0zkhHTaNpU+S5hrd5do9Si0mZ8Uw5nkDpJh3C:NSDm5cBRwzrczysrd5do9Si0Gw5nkD3l
                  MD5:1E749455A8814C93006A9E9814CF3550
                  SHA1:E7BB0166A813CC3EA5396513673D583639BB0966
                  SHA-256:E9AFED56F68F20AC14FCF22B1347B025F9F3F929BB63A6896B764C0C18C10591
                  SHA-512:3CDC3B095BFEE04A764846F48B3BF7B752BA6A4AC63BBB9CB1EBA0F0EBC83E64165423BDDCF52D688DD32DC4AB57696A04798382B114A0BD1DC9ADE348EED60C
                  Malicious:false
                  Preview:i..A2...zIV.!9.....,.+.-|.......b.....\.{.|UH[...N......w..x..,..a.....Uo..%.^..k..^.7.>x&.K...~..3.U.....%_...#+w.....:......{f..Z.X\Zx.A}.....s...o.J..].`..r..4#<.0.O.&)W...E..v..Yk..z.g.*.+z/. ....0..3O..!.......A.=..r... .PD.,FKR...LI^..t.uh.v.#...;.E.A.c.)y.)..,.6.....T.=O.4t..'.C..Eq...(/..u.n.1.v......{..G.Nz6.<..p..D.a....zn6.'.g.."..w.?..y.....s..Ea...f6"`..vv.;...FH...+.|.."k....:.%...L.....Y.Uq........z._...cMJ.O..s..j0VI40..H9.r..~..-p.af.z<...8[...f........q...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):529
                  Entropy (8bit):7.507567435245275
                  Encrypted:false
                  SSDEEP:12:ccXSnDm9Vdc96SRwrno0zkhHTaNpU+S5hrd5do9Si0mZ8Uw5nkDpJh3C:NSDm5cBRwzrczysrd5do9Si0Gw5nkD3l
                  MD5:1E749455A8814C93006A9E9814CF3550
                  SHA1:E7BB0166A813CC3EA5396513673D583639BB0966
                  SHA-256:E9AFED56F68F20AC14FCF22B1347B025F9F3F929BB63A6896B764C0C18C10591
                  SHA-512:3CDC3B095BFEE04A764846F48B3BF7B752BA6A4AC63BBB9CB1EBA0F0EBC83E64165423BDDCF52D688DD32DC4AB57696A04798382B114A0BD1DC9ADE348EED60C
                  Malicious:false
                  Preview:i..A2...zIV.!9.....,.+.-|.......b.....\.{.|UH[...N......w..x..,..a.....Uo..%.^..k..^.7.>x&.K...~..3.U.....%_...#+w.....:......{f..Z.X\Zx.A}.....s...o.J..].`..r..4#<.0.O.&)W...E..v..Yk..z.g.*.+z/. ....0..3O..!.......A.=..r... .PD.,FKR...LI^..t.uh.v.#...;.E.A.c.)y.)..,.6.....T.=O.4t..'.C..Eq...(/..u.n.1.v......{..G.Nz6.<..p..D.a....zn6.'.g.."..w.?..y.....s..Ea...f6"`..vv.;...FH...+.|.."k....:.%...L.....Y.Uq........z._...cMJ.O..s..j0VI40..H9.r..~..-p.af.z<...8[...f........q...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):935
                  Entropy (8bit):7.72522180237773
                  Encrypted:false
                  SSDEEP:24:F9f7iqIqhuaIpu2sAQRCSG0NaG6Du+3QFXlVN0k2UCwSQ:PWa4uZISGRDDu+32XlVgwS
                  MD5:977589D86538D778C8C9BC8722ABF265
                  SHA1:723451AA7FEEF4A3C277ACDD292E938F9B02D2A9
                  SHA-256:11EE2E547E764C9EF1D0E10AC0C0528F19DB5619627AAA54920A8C83C5E80F02
                  SHA-512:FBA435A8A49C8B70AF50FB3A492ED84047AB926DABDE15577181AA6CA01E2687680A9655FC702617424A819FFDD01463673198228F3F426E17018E9B53814702
                  Malicious:false
                  Preview:..-^Z_.A......Ec.J]..~..+g..|....t&.H.R5.Vq.C..P..t....ul........b..V.jKp.x[PYCs.\..;k.....<.5F!f.9.-.9MyE.N..Z.B.b.|4><w......~._.o.X.#..e.R.E.sX..,.....i.Bw.I.{.jG:x.....c}.e>.rV8D..!P.U*.=`...uS...R.D.CK0R<...xf.?j...~^....Dqm..#..y.X...gb1@......m...2.n0cqG.:...GM.BO.C.)W.4mc..OLi.n.S.B......>.q..uU1Y.N+i...AC...~....P1...1..e......d?W.0.Bo=.T....o...aSM./^....ay#../..%Y6...>..5...)qR..~OC...+..T9............\.6...z*..6..~...4.*m+.....-.,.]...R.......D/.T@......J......k.i..[..T.a...0..a...n... .%....q..."n..>|..qk....Y..S.G?.y..I.}.0....=.q..)^.ia.b.!w1......aH.f..]}.r.J...V...42....U.e..v.$...~T*p..;...qh..../..q. ka....g..=..U.DY~...(....w..|.MZ..N+...#Y../....4...0MO\.M.#....7...X.Vt.?..#X..}.....-..5...T!...5^...B..F........*.....}.7....6..e...*...z5...O.v..\.0.................htr.J..Y..v.....H4l.....o..W.-^ |.....A..X.....v)............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):935
                  Entropy (8bit):7.72522180237773
                  Encrypted:false
                  SSDEEP:24:F9f7iqIqhuaIpu2sAQRCSG0NaG6Du+3QFXlVN0k2UCwSQ:PWa4uZISGRDDu+32XlVgwS
                  MD5:977589D86538D778C8C9BC8722ABF265
                  SHA1:723451AA7FEEF4A3C277ACDD292E938F9B02D2A9
                  SHA-256:11EE2E547E764C9EF1D0E10AC0C0528F19DB5619627AAA54920A8C83C5E80F02
                  SHA-512:FBA435A8A49C8B70AF50FB3A492ED84047AB926DABDE15577181AA6CA01E2687680A9655FC702617424A819FFDD01463673198228F3F426E17018E9B53814702
                  Malicious:false
                  Preview:..-^Z_.A......Ec.J]..~..+g..|....t&.H.R5.Vq.C..P..t....ul........b..V.jKp.x[PYCs.\..;k.....<.5F!f.9.-.9MyE.N..Z.B.b.|4><w......~._.o.X.#..e.R.E.sX..,.....i.Bw.I.{.jG:x.....c}.e>.rV8D..!P.U*.=`...uS...R.D.CK0R<...xf.?j...~^....Dqm..#..y.X...gb1@......m...2.n0cqG.:...GM.BO.C.)W.4mc..OLi.n.S.B......>.q..uU1Y.N+i...AC...~....P1...1..e......d?W.0.Bo=.T....o...aSM./^....ay#../..%Y6...>..5...)qR..~OC...+..T9............\.6...z*..6..~...4.*m+.....-.,.]...R.......D/.T@......J......k.i..[..T.a...0..a...n... .%....q..."n..>|..qk....Y..S.G?.y..I.}.0....=.q..)^.ia.b.!w1......aH.f..]}.r.J...V...42....U.e..v.$...~T*p..;...qh..../..q. ka....g..=..U.DY~...(....w..|.MZ..N+...#Y../....4...0MO\.M.#....7...X.Vt.?..#X..}.....-..5...T!...5^...B..F........*.....}.7....6..e...*...z5...O.v..\.0.................htr.J..Y..v.....H4l.....o..W.-^ |.....A..X.....v)............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):935
                  Entropy (8bit):7.72522180237773
                  Encrypted:false
                  SSDEEP:24:F9f7iqIqhuaIpu2sAQRCSG0NaG6Du+3QFXlVN0k2UCwSQ:PWa4uZISGRDDu+32XlVgwS
                  MD5:977589D86538D778C8C9BC8722ABF265
                  SHA1:723451AA7FEEF4A3C277ACDD292E938F9B02D2A9
                  SHA-256:11EE2E547E764C9EF1D0E10AC0C0528F19DB5619627AAA54920A8C83C5E80F02
                  SHA-512:FBA435A8A49C8B70AF50FB3A492ED84047AB926DABDE15577181AA6CA01E2687680A9655FC702617424A819FFDD01463673198228F3F426E17018E9B53814702
                  Malicious:false
                  Preview:..-^Z_.A......Ec.J]..~..+g..|....t&.H.R5.Vq.C..P..t....ul........b..V.jKp.x[PYCs.\..;k.....<.5F!f.9.-.9MyE.N..Z.B.b.|4><w......~._.o.X.#..e.R.E.sX..,.....i.Bw.I.{.jG:x.....c}.e>.rV8D..!P.U*.=`...uS...R.D.CK0R<...xf.?j...~^....Dqm..#..y.X...gb1@......m...2.n0cqG.:...GM.BO.C.)W.4mc..OLi.n.S.B......>.q..uU1Y.N+i...AC...~....P1...1..e......d?W.0.Bo=.T....o...aSM./^....ay#../..%Y6...>..5...)qR..~OC...+..T9............\.6...z*..6..~...4.*m+.....-.,.]...R.......D/.T@......J......k.i..[..T.a...0..a...n... .%....q..."n..>|..qk....Y..S.G?.y..I.}.0....=.q..)^.ia.b.!w1......aH.f..]}.r.J...V...42....U.e..v.$...~T*p..;...qh..../..q. ka....g..=..U.DY~...(....w..|.MZ..N+...#Y../....4...0MO\.M.#....7...X.Vt.?..#X..}.....-..5...T!...5^...B..F........*.....}.7....6..e...*...z5...O.v..\.0.................htr.J..Y..v.....H4l.....o..W.-^ |.....A..X.....v)............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):874
                  Entropy (8bit):7.718762380950773
                  Encrypted:false
                  SSDEEP:24:GFNb/r6QkTb548k299EA4yh9fZr/59jVAA:kF/sTb+8XnEARLhrh9r
                  MD5:8DBC8497029B86819A581693899D2E39
                  SHA1:3F04476985B5459D6FCAEF2C9D0E5B84EC79BA8C
                  SHA-256:E88A959ED59955F2E9956C6B7C1D02C4038663D90B9C322FF848B7DFAA520530
                  SHA-512:CCEA16BEAF2902598CA8E9175E46CD908677CD02ACBF7438FB86F3452E2092A7A3C7A3F6D78D4A3B9E160FA35E6DB0411E46EA41CD8EFDA99E1A06DBF96D5FB8
                  Malicious:false
                  Preview:3.....9.~..O..b.!.:.:.._}...B Y..[.w..".M\.h.l^Or./..es?o..#9..l..L..:.pgg....0........p...,0....j/...$..E...A..bl......Ci...A...ea..q:.R.q.Km..k....O.U.w"-...3G.4x...,.b|..W..L..et6..i.2....6...K.C8...K...&.f5A..[.M...0.W#..J..#..bh.H.=..a....\. .=..<.....K....C<9}..49|..C.uY0.....b`s..............86kae.x..*.a8....o.9*~.Z..?....=.s..5[o...*.]Z....1.9...(..e.Y..I.....9.n.{......aLp...(*...\%.uf....-%.n.QTO.@#...d........U!}.U.,#.A...k.}-..L.]9...<...N.;.BI...:.....v....~..].N....3..d8.. ......2..2....%.|........`...<.......91.~T.<=........m....W....J....u$.V\.\.a. s..+=.jqX...i....w.t...v.n...{F....Q...k.b..8..`7..tc.......P9].A.(.B.O.E.i.H...M..FA.F+i..(Wr.N.fk.........{..[.V....?mtZ.^b(..n...x.s.......d...H....x.."./..?Rk........Y.X..9......,.._./...mm..(..l2....X.i$\#...3.y...-..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):874
                  Entropy (8bit):7.718762380950773
                  Encrypted:false
                  SSDEEP:24:GFNb/r6QkTb548k299EA4yh9fZr/59jVAA:kF/sTb+8XnEARLhrh9r
                  MD5:8DBC8497029B86819A581693899D2E39
                  SHA1:3F04476985B5459D6FCAEF2C9D0E5B84EC79BA8C
                  SHA-256:E88A959ED59955F2E9956C6B7C1D02C4038663D90B9C322FF848B7DFAA520530
                  SHA-512:CCEA16BEAF2902598CA8E9175E46CD908677CD02ACBF7438FB86F3452E2092A7A3C7A3F6D78D4A3B9E160FA35E6DB0411E46EA41CD8EFDA99E1A06DBF96D5FB8
                  Malicious:false
                  Preview:3.....9.~..O..b.!.:.:.._}...B Y..[.w..".M\.h.l^Or./..es?o..#9..l..L..:.pgg....0........p...,0....j/...$..E...A..bl......Ci...A...ea..q:.R.q.Km..k....O.U.w"-...3G.4x...,.b|..W..L..et6..i.2....6...K.C8...K...&.f5A..[.M...0.W#..J..#..bh.H.=..a....\. .=..<.....K....C<9}..49|..C.uY0.....b`s..............86kae.x..*.a8....o.9*~.Z..?....=.s..5[o...*.]Z....1.9...(..e.Y..I.....9.n.{......aLp...(*...\%.uf....-%.n.QTO.@#...d........U!}.U.,#.A...k.}-..L.]9...<...N.;.BI...:.....v....~..].N....3..d8.. ......2..2....%.|........`...<.......91.~T.<=........m....W....J....u$.V\.\.a. s..+=.jqX...i....w.t...v.n...{F....Q...k.b..8..`7..tc.......P9].A.(.B.O.E.i.H...M..FA.F+i..(Wr.N.fk.........{..[.V....?mtZ.^b(..n...x.s.......d...H....x.."./..?Rk........Y.X..9......,.._./...mm..(..l2....X.i$\#...3.y...-..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):874
                  Entropy (8bit):7.718762380950773
                  Encrypted:false
                  SSDEEP:24:GFNb/r6QkTb548k299EA4yh9fZr/59jVAA:kF/sTb+8XnEARLhrh9r
                  MD5:8DBC8497029B86819A581693899D2E39
                  SHA1:3F04476985B5459D6FCAEF2C9D0E5B84EC79BA8C
                  SHA-256:E88A959ED59955F2E9956C6B7C1D02C4038663D90B9C322FF848B7DFAA520530
                  SHA-512:CCEA16BEAF2902598CA8E9175E46CD908677CD02ACBF7438FB86F3452E2092A7A3C7A3F6D78D4A3B9E160FA35E6DB0411E46EA41CD8EFDA99E1A06DBF96D5FB8
                  Malicious:false
                  Preview:3.....9.~..O..b.!.:.:.._}...B Y..[.w..".M\.h.l^Or./..es?o..#9..l..L..:.pgg....0........p...,0....j/...$..E...A..bl......Ci...A...ea..q:.R.q.Km..k....O.U.w"-...3G.4x...,.b|..W..L..et6..i.2....6...K.C8...K...&.f5A..[.M...0.W#..J..#..bh.H.=..a....\. .=..<.....K....C<9}..49|..C.uY0.....b`s..............86kae.x..*.a8....o.9*~.Z..?....=.s..5[o...*.]Z....1.9...(..e.Y..I.....9.n.{......aLp...(*...\%.uf....-%.n.QTO.@#...d........U!}.U.,#.A...k.}-..L.]9...<...N.;.BI...:.....v....~..].N....3..d8.. ......2..2....%.|........`...<.......91.~T.<=........m....W....J....u$.V\.\.a. s..+=.jqX...i....w.t...v.n...{F....Q...k.b..8..`7..tc.......P9].A.(.B.O.E.i.H...M..FA.F+i..(Wr.N.fk.........{..[.V....?mtZ.^b(..n...x.s.......d...H....x.."./..?Rk........Y.X..9......,.._./...mm..(..l2....X.i$\#...3.y...-..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):388
                  Entropy (8bit):7.299661101516088
                  Encrypted:false
                  SSDEEP:12:sXL+xwZNg08OfqNBu3IKpxZLrryU83w6gS7vCuqarn4R:sXL+xx9NY3IKFKv3w6gST
                  MD5:466B3234F44905C29B12B2A95B083C6D
                  SHA1:260B37407AECC8AA062096F0BE82919D88D83571
                  SHA-256:7CCA81415134BB999403D231879577A7E339E7444031A6FDD403028DA24E32D8
                  SHA-512:9CA6BB927B6AC0690213E0ECD289FD0D6981933F59ECCCFE4D88BB7E12F2846D8F4AC2A217A6B1CB99B5B14A67291C10688ADF606A01DD3FF0832DBAC3D0DF31
                  Malicious:false
                  Preview:..&.....2.TB+U....!..G..0..p*...Lq......T.....2yO/_8..TI6.$..\.d.<.?R3}..+....e....a.WeX.!.. .....~=...G/.o.D....L.....>..C.X.....M.........A1h.9.....D._.....rd.Sh.q.-.....f...].{..J..Y..X...+D..{.kY.W.R`.$].5.@....3...q2.la)3..0..=e..&.....c.>...Q.rJ"HAQ..........nS..N.oy.e. .I............ZT..K..,V.....1d...$...}6Ax...*.m....5.1.....g.J........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):388
                  Entropy (8bit):7.299661101516088
                  Encrypted:false
                  SSDEEP:12:sXL+xwZNg08OfqNBu3IKpxZLrryU83w6gS7vCuqarn4R:sXL+xx9NY3IKFKv3w6gST
                  MD5:466B3234F44905C29B12B2A95B083C6D
                  SHA1:260B37407AECC8AA062096F0BE82919D88D83571
                  SHA-256:7CCA81415134BB999403D231879577A7E339E7444031A6FDD403028DA24E32D8
                  SHA-512:9CA6BB927B6AC0690213E0ECD289FD0D6981933F59ECCCFE4D88BB7E12F2846D8F4AC2A217A6B1CB99B5B14A67291C10688ADF606A01DD3FF0832DBAC3D0DF31
                  Malicious:false
                  Preview:..&.....2.TB+U....!..G..0..p*...Lq......T.....2yO/_8..TI6.$..\.d.<.?R3}..+....e....a.WeX.!.. .....~=...G/.o.D....L.....>..C.X.....M.........A1h.9.....D._.....rd.Sh.q.-.....f...].{..J..Y..X...+D..{.kY.W.R`.$].5.@....3...q2.la)3..0..=e..&.....c.>...Q.rJ"HAQ..........nS..N.oy.e. .I............ZT..K..,V.....1d...$...}6Ax...*.m....5.1.....g.J........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):388
                  Entropy (8bit):7.299661101516088
                  Encrypted:false
                  SSDEEP:12:sXL+xwZNg08OfqNBu3IKpxZLrryU83w6gS7vCuqarn4R:sXL+xx9NY3IKFKv3w6gST
                  MD5:466B3234F44905C29B12B2A95B083C6D
                  SHA1:260B37407AECC8AA062096F0BE82919D88D83571
                  SHA-256:7CCA81415134BB999403D231879577A7E339E7444031A6FDD403028DA24E32D8
                  SHA-512:9CA6BB927B6AC0690213E0ECD289FD0D6981933F59ECCCFE4D88BB7E12F2846D8F4AC2A217A6B1CB99B5B14A67291C10688ADF606A01DD3FF0832DBAC3D0DF31
                  Malicious:false
                  Preview:..&.....2.TB+U....!..G..0..p*...Lq......T.....2yO/_8..TI6.$..\.d.<.?R3}..+....e....a.WeX.!.. .....~=...G/.o.D....L.....>..C.X.....M.........A1h.9.....D._.....rd.Sh.q.-.....f...].{..J..Y..X...+D..{.kY.W.R`.$].5.@....3...q2.la)3..0..=e..&.....c.>...Q.rJ"HAQ..........nS..N.oy.e. .I............ZT..K..,V.....1d...$...}6Ax...*.m....5.1.....g.J........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):259
                  Entropy (8bit):6.811150496589181
                  Encrypted:false
                  SSDEEP:6:Js4+WuiBQXJYLNEHkgw6CCkOQzVAaK5Y:VRBQXWyZoCkJaav
                  MD5:82088A1B6297CA37359E458049861B08
                  SHA1:53F8867EF8D3E75DA8204FBAD1F1FE8893991D3C
                  SHA-256:87C4B36E77953AD9F6B1CF845B480A13C3B5F5694757CE739610DAE7F22F5BF8
                  SHA-512:4F0D75114E715606BA11DC59C1B249D6DE5B8A0BCB6D48C1DC24E45E2112558FF0BA0430AF59029923C25FDE1F2F8FA906EC831D2140B166AA1C48B586531C77
                  Malicious:false
                  Preview:.2S+.;.h.\.~].}..}...'.b.._....h.K.Uh#t.......)....;.......7*."....`........'[.g.$.X.{.m.........|...I.S~..V.{q5....I....x....:...%..Q...cG.'.m....Dx.O&(...c........o0......h:Dw.J..Z.........1.&"....DD....n.&H...zp.U..........c...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):259
                  Entropy (8bit):6.811150496589181
                  Encrypted:false
                  SSDEEP:6:Js4+WuiBQXJYLNEHkgw6CCkOQzVAaK5Y:VRBQXWyZoCkJaav
                  MD5:82088A1B6297CA37359E458049861B08
                  SHA1:53F8867EF8D3E75DA8204FBAD1F1FE8893991D3C
                  SHA-256:87C4B36E77953AD9F6B1CF845B480A13C3B5F5694757CE739610DAE7F22F5BF8
                  SHA-512:4F0D75114E715606BA11DC59C1B249D6DE5B8A0BCB6D48C1DC24E45E2112558FF0BA0430AF59029923C25FDE1F2F8FA906EC831D2140B166AA1C48B586531C77
                  Malicious:false
                  Preview:.2S+.;.h.\.~].}..}...'.b.._....h.K.Uh#t.......)....;.......7*."....`........'[.g.$.X.{.m.........|...I.S~..V.{q5....I....x....:...%..Q...cG.'.m....Dx.O&(...c........o0......h:Dw.J..Z.........1.&"....DD....n.&H...zp.U..........c...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):259
                  Entropy (8bit):6.811150496589181
                  Encrypted:false
                  SSDEEP:6:Js4+WuiBQXJYLNEHkgw6CCkOQzVAaK5Y:VRBQXWyZoCkJaav
                  MD5:82088A1B6297CA37359E458049861B08
                  SHA1:53F8867EF8D3E75DA8204FBAD1F1FE8893991D3C
                  SHA-256:87C4B36E77953AD9F6B1CF845B480A13C3B5F5694757CE739610DAE7F22F5BF8
                  SHA-512:4F0D75114E715606BA11DC59C1B249D6DE5B8A0BCB6D48C1DC24E45E2112558FF0BA0430AF59029923C25FDE1F2F8FA906EC831D2140B166AA1C48B586531C77
                  Malicious:false
                  Preview:.2S+.;.h.\.~].}..}...'.b.._....h.K.Uh#t.......)....;.......7*."....`........'[.g.$.X.{.m.........|...I.S~..V.{q5....I....x....:...%..Q...cG.'.m....Dx.O&(...c........o0......h:Dw.J..Z.........1.&"....DD....n.&H...zp.U..........c...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:24:ixR9X+wPQ5Kj8gI13PWHEGOTHX8jJuYksTetZ1zCwNzZaBVglLGdH9e3EXrfOvLC:gZhdwBGK30uDzFasC9rT
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):338947180
                  Entropy (8bit):7.10089495490019
                  Encrypted:false
                  SSDEEP:3145728:dvwOB9O92CBOwoNY0QTPvWoCOA6v/Tm1/2l5uuxaaf0LYHOm2uwZqCi1LbY19It:dTB9+2KOXK3K6v/42l5naLLpmIA
                  MD5:F9ADB07ED68B8E8F144BABDB34B42294
                  SHA1:F727528D921F69F86AA47802035F25E6223982E0
                  SHA-256:C94CE27A9A5ACF232484967EF6570F91BD9609761B1193E54F7CD0E66BDE89F1
                  SHA-512:ED3414C58109CABD7378E9A4F528386AA438DC58CE4A732EE41FBAF51BC0D4BF869DB62F11CBF3861E153C34DA7F77B405BDB2A3091C7FC6F30BA28BDBB92FEA
                  Malicious:false
                  Preview:8.qZ.]^..U.@..-...'8K..AP..&C'^.U^X.........z:F.9..V..Q........OKH.M.wG.c3..r....j.V...P...T...L......$...9?.....S........noV`=..)%.WJB.h/Q.v...V.......(.p:..#.q|.....n.\.M .|b*..y.7..B...@.5..1.d..4W..t.I.|......J...(..M.VX.RM...?A......l..}&v0.!.X.-nzB>I0.......l..@X....&....E;6>U....1..] .Q..y.t.`.=.....#...;\.G..a&C...z.h....6......H.?,S.\..dY.e....E.F..."gP.....g....g.'b...k.z;..._.t&.Z...V.C7...fT..rN..*..\..?....Ny/>.4F.44.H.M..W.+...5.O....{........\.H........9...X.Z...........a..;70n^4..)...J..A....g......~..jt..3,...~p....O.I.../.....;e....(....N(..H...2..Q.-3......g...94c.....&s..b...?.[...UWKF.UEr{.D..{..^.|.fh.....^.&.r.......<Tg!.2.t."..|`.".S....[.q.iI#.R..q..Bj........q<.l......."C..+.1]....z.j....<Y.v..%T....g..j.^{.C...F....oz"..;....W.t..7.j.X.x...;......N\6..q.|dm0.{P.q.d.l!.......SlD...........z.9.TT.{'............s%. J..Gu.["......$..U..jcY.O...3...5..+A..1.e&..Eh.m..eD.........j.y..R.~&s.....J..N.w
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):338947180
                  Entropy (8bit):7.10089495490019
                  Encrypted:false
                  SSDEEP:3145728:dvwOB9O92CBOwoNY0QTPvWoCOA6v/Tm1/2l5uuxaaf0LYHOm2uwZqCi1LbY19It:dTB9+2KOXK3K6v/42l5naLLpmIA
                  MD5:F9ADB07ED68B8E8F144BABDB34B42294
                  SHA1:F727528D921F69F86AA47802035F25E6223982E0
                  SHA-256:C94CE27A9A5ACF232484967EF6570F91BD9609761B1193E54F7CD0E66BDE89F1
                  SHA-512:ED3414C58109CABD7378E9A4F528386AA438DC58CE4A732EE41FBAF51BC0D4BF869DB62F11CBF3861E153C34DA7F77B405BDB2A3091C7FC6F30BA28BDBB92FEA
                  Malicious:false
                  Preview:8.qZ.]^..U.@..-...'8K..AP..&C'^.U^X.........z:F.9..V..Q........OKH.M.wG.c3..r....j.V...P...T...L......$...9?.....S........noV`=..)%.WJB.h/Q.v...V.......(.p:..#.q|.....n.\.M .|b*..y.7..B...@.5..1.d..4W..t.I.|......J...(..M.VX.RM...?A......l..}&v0.!.X.-nzB>I0.......l..@X....&....E;6>U....1..] .Q..y.t.`.=.....#...;\.G..a&C...z.h....6......H.?,S.\..dY.e....E.F..."gP.....g....g.'b...k.z;..._.t&.Z...V.C7...fT..rN..*..\..?....Ny/>.4F.44.H.M..W.+...5.O....{........\.H........9...X.Z...........a..;70n^4..)...J..A....g......~..jt..3,...~p....O.I.../.....;e....(....N(..H...2..Q.-3......g...94c.....&s..b...?.[...UWKF.UEr{.D..{..^.|.fh.....^.&.r.......<Tg!.2.t."..|`.".S....[.q.iI#.R..q..Bj........q<.l......."C..+.1]....z.j....<Y.v..%T....g..j.^{.C...F....oz"..;....W.t..7.j.X.x...;......N\6..q.|dm0.{P.q.d.l!.......SlD...........z.9.TT.{'............s%. J..Gu.["......$..U..jcY.O...3...5..+A..1.e&..Eh.m..eD.........j.y..R.~&s.....J..N.w
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):411840
                  Entropy (8bit):7.999534044367031
                  Encrypted:true
                  SSDEEP:
                  MD5:A456DC5FEFA87237D3128AF2C39E738E
                  SHA1:56F40110707E950D66FD39D4A10ED9665A188F94
                  SHA-256:A9C93CC868454FAA22E62521F066E3AD8A34023C85ED4E52F72427C02181D79E
                  SHA-512:5390E14369FACBABEDFB03CB79B66C0A737C63B89F288667FD71846986DDAF5501FF6BA9D90128AF16C7B19492FECA696B09C3D0CBE97D332414C015E04D7397
                  Malicious:true
                  Preview:..@..{..../..rd<.r..u....1a..k.2...O.R...........,W..,ZX.f..b.....&....F....:.A".4.?.%ly..4....o.........+z2.......^{..D..`...'.|..9.0...44..Q....$y..uU...K;`..g.Y..\&...0Q...jP...1..n.O....N.y..1..7...="..?....C...j....-.......3.wx...X....P...L.....2.;0...2a:..........j.).k.z..d4...^6..5U.f..t.a.,E..d;n..`.rk...[l....Z&6..g......E......s.t..3...!.x.Eq.....r.h.k;.t.x.....7...1......W...x(7.cCN.......1.&....e.y..U..!...mt.E.2...@..i..f...I.'..w.....H..N..j..\v6...[Vhs..Z....Uf.TJ?...... ..d)..[v.|....=+..........{..@.n...:.P.~.+.V.X...i}.[.....X..F....!../.b...jF........H;...Q..?m+.01uh0..G.v..W.zJ.\..uc...&.*.r.[.....{..6.B...MBi.....:."..f4.....Oql.+*..J...[..L.#.%>..q.a....4b....7.._t...Ns.i..a_I....ED.M.i.\.{3.V<.%.>].=..@.U....e..5|?0..u{@&.f..h.-..Vj.A...6\!....W.=..H..\...^r...Mx.u!..=.)..t..->....9.t.Q1~....e.....,PE.....;.-..m.UD.@l....../LZ..5P..]..b....\.`.....$.n....](;..._......i.-.3..,8.+B..f8....n....x;..B3J.nLcW{....M....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):411840
                  Entropy (8bit):7.999534044367031
                  Encrypted:true
                  SSDEEP:
                  MD5:A456DC5FEFA87237D3128AF2C39E738E
                  SHA1:56F40110707E950D66FD39D4A10ED9665A188F94
                  SHA-256:A9C93CC868454FAA22E62521F066E3AD8A34023C85ED4E52F72427C02181D79E
                  SHA-512:5390E14369FACBABEDFB03CB79B66C0A737C63B89F288667FD71846986DDAF5501FF6BA9D90128AF16C7B19492FECA696B09C3D0CBE97D332414C015E04D7397
                  Malicious:true
                  Preview:..@..{..../..rd<.r..u....1a..k.2...O.R...........,W..,ZX.f..b.....&....F....:.A".4.?.%ly..4....o.........+z2.......^{..D..`...'.|..9.0...44..Q....$y..uU...K;`..g.Y..\&...0Q...jP...1..n.O....N.y..1..7...="..?....C...j....-.......3.wx...X....P...L.....2.;0...2a:..........j.).k.z..d4...^6..5U.f..t.a.,E..d;n..`.rk...[l....Z&6..g......E......s.t..3...!.x.Eq.....r.h.k;.t.x.....7...1......W...x(7.cCN.......1.&....e.y..U..!...mt.E.2...@..i..f...I.'..w.....H..N..j..\v6...[Vhs..Z....Uf.TJ?...... ..d)..[v.|....=+..........{..@.n...:.P.~.+.V.X...i}.[.....X..F....!../.b...jF........H;...Q..?m+.01uh0..G.v..W.zJ.\..uc...&.*.r.[.....{..6.B...MBi.....:."..f4.....Oql.+*..J...[..L.#.%>..q.a....4b....7.._t...Ns.i..a_I....ED.M.i.\.{3.V<.%.>].=..@.U....e..5|?0..u{@&.f..h.-..Vj.A...6\!....W.=..H..\...^r...Mx.u!..=.)..t..->....9.t.Q1~....e.....,PE.....;.-..m.UD.@l....../LZ..5P..]..b....\.`.....$.n....](;..._......i.-.3..,8.+B..f8....n....x;..B3J.nLcW{....M....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):411840
                  Entropy (8bit):7.999534044367031
                  Encrypted:true
                  SSDEEP:
                  MD5:A456DC5FEFA87237D3128AF2C39E738E
                  SHA1:56F40110707E950D66FD39D4A10ED9665A188F94
                  SHA-256:A9C93CC868454FAA22E62521F066E3AD8A34023C85ED4E52F72427C02181D79E
                  SHA-512:5390E14369FACBABEDFB03CB79B66C0A737C63B89F288667FD71846986DDAF5501FF6BA9D90128AF16C7B19492FECA696B09C3D0CBE97D332414C015E04D7397
                  Malicious:true
                  Preview:..@..{..../..rd<.r..u....1a..k.2...O.R...........,W..,ZX.f..b.....&....F....:.A".4.?.%ly..4....o.........+z2.......^{..D..`...'.|..9.0...44..Q....$y..uU...K;`..g.Y..\&...0Q...jP...1..n.O....N.y..1..7...="..?....C...j....-.......3.wx...X....P...L.....2.;0...2a:..........j.).k.z..d4...^6..5U.f..t.a.,E..d;n..`.rk...[l....Z&6..g......E......s.t..3...!.x.Eq.....r.h.k;.t.x.....7...1......W...x(7.cCN.......1.&....e.y..U..!...mt.E.2...@..i..f...I.'..w.....H..N..j..\v6...[Vhs..Z....Uf.TJ?...... ..d)..[v.|....=+..........{..@.n...:.P.~.+.V.X...i}.[.....X..F....!../.b...jF........H;...Q..?m+.01uh0..G.v..W.zJ.\..uc...&.*.r.[.....{..6.B...MBi.....:."..f4.....Oql.+*..J...[..L.#.%>..q.a....4b....7.._t...Ns.i..a_I....ED.M.i.\.{3.V<.%.>].=..@.U....e..5|?0..u{@&.f..h.-..Vj.A...6\!....W.=..H..\...^r...Mx.u!..=.)..t..->....9.t.Q1~....e.....,PE.....;.-..m.UD.@l....../LZ..5P..]..b....\.`.....$.n....](;..._......i.-.3..,8.+B..f8....n....x;..B3J.nLcW{....M....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671636
                  Entropy (8bit):7.999713847827368
                  Encrypted:true
                  SSDEEP:
                  MD5:0D1083FA750248B61EF25B1FF5E2CBCE
                  SHA1:F66959A3EEF96AA777FD8412459C8B51C9F5A294
                  SHA-256:4FABA021821EE680B9422BB87D498E51B5F9C702966F096ED910F7986148444B
                  SHA-512:2845198F3F6C756C33D4063A15A7B114F9756C5082870ABA960E2E213FE57E9E53769618C63B6D3455F144D3C7D8D901AFAB37FA5B6A545A67C108F4875E6360
                  Malicious:true
                  Preview:%.d......-.[.s'ie.3..a...........a.Ts...Ez.4..M.>...C..Y-*.'P.Dw..2...}.z...gf.hPP......a..-.?....].iiT..|..a..R.......}B..R........}.)2....O.j!."...x8.f.A.m52.....*..3.tF{..6...\"....d.......js.d..#.g.sM]0j......`.....s.S.+.\RA.Lmv....`'..E..,2.....F.......;.-..../...).gk.u4..d..i..C.(.B.....E..2...v#P2.?V...F.-Q#1.....k....@.c.?.3."T.(..igp2h...CH...>......joI.|n.....LK....C".......[|..D[o+.n..Q9w...>..g.^....C..'~......R....a..)..R1&LXWm..@.nn......kz.?..5_S:...j.....Ho....'.#0.~s>lB.I(.@.&..U...#...7..2....b..'..$N..-.u.;wc..1...3..}3..."..@...............J..d....Z.DId...5.....o.....D.T.H...e.e.~...7b.&.2...Z?..'...A.@j......v]q....O.H1Hu.?SF,<...@.....3.'.Yf.p[.jzi[.U.....W........i....3.v.E(..,x......M..@..i.kA.......a=j...k...h...`>J.U................M..*.6.v.]Vi&.H.B.f.....6......9......[...L.....7...d.T.....[}.M.`.D.77\.5..../.....%4.7.v......j..U...X,.^...U.)6..#7.e...D.g?N..h...Mg..{$........8.h..5.!..k........V....]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671636
                  Entropy (8bit):7.999713847827368
                  Encrypted:true
                  SSDEEP:
                  MD5:0D1083FA750248B61EF25B1FF5E2CBCE
                  SHA1:F66959A3EEF96AA777FD8412459C8B51C9F5A294
                  SHA-256:4FABA021821EE680B9422BB87D498E51B5F9C702966F096ED910F7986148444B
                  SHA-512:2845198F3F6C756C33D4063A15A7B114F9756C5082870ABA960E2E213FE57E9E53769618C63B6D3455F144D3C7D8D901AFAB37FA5B6A545A67C108F4875E6360
                  Malicious:true
                  Preview:%.d......-.[.s'ie.3..a...........a.Ts...Ez.4..M.>...C..Y-*.'P.Dw..2...}.z...gf.hPP......a..-.?....].iiT..|..a..R.......}B..R........}.)2....O.j!."...x8.f.A.m52.....*..3.tF{..6...\"....d.......js.d..#.g.sM]0j......`.....s.S.+.\RA.Lmv....`'..E..,2.....F.......;.-..../...).gk.u4..d..i..C.(.B.....E..2...v#P2.?V...F.-Q#1.....k....@.c.?.3."T.(..igp2h...CH...>......joI.|n.....LK....C".......[|..D[o+.n..Q9w...>..g.^....C..'~......R....a..)..R1&LXWm..@.nn......kz.?..5_S:...j.....Ho....'.#0.~s>lB.I(.@.&..U...#...7..2....b..'..$N..-.u.;wc..1...3..}3..."..@...............J..d....Z.DId...5.....o.....D.T.H...e.e.~...7b.&.2...Z?..'...A.@j......v]q....O.H1Hu.?SF,<...@.....3.'.Yf.p[.jzi[.U.....W........i....3.v.E(..,x......M..@..i.kA.......a=j...k...h...`>J.U................M..*.6.v.]Vi&.H.B.f.....6......9......[...L.....7...d.T.....[}.M.`.D.77\.5..../.....%4.7.v......j..U...X,.^...U.)6..#7.e...D.g?N..h...Mg..{$........8.h..5.!..k........V....]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671636
                  Entropy (8bit):7.999713847827368
                  Encrypted:true
                  SSDEEP:
                  MD5:0D1083FA750248B61EF25B1FF5E2CBCE
                  SHA1:F66959A3EEF96AA777FD8412459C8B51C9F5A294
                  SHA-256:4FABA021821EE680B9422BB87D498E51B5F9C702966F096ED910F7986148444B
                  SHA-512:2845198F3F6C756C33D4063A15A7B114F9756C5082870ABA960E2E213FE57E9E53769618C63B6D3455F144D3C7D8D901AFAB37FA5B6A545A67C108F4875E6360
                  Malicious:true
                  Preview:%.d......-.[.s'ie.3..a...........a.Ts...Ez.4..M.>...C..Y-*.'P.Dw..2...}.z...gf.hPP......a..-.?....].iiT..|..a..R.......}B..R........}.)2....O.j!."...x8.f.A.m52.....*..3.tF{..6...\"....d.......js.d..#.g.sM]0j......`.....s.S.+.\RA.Lmv....`'..E..,2.....F.......;.-..../...).gk.u4..d..i..C.(.B.....E..2...v#P2.?V...F.-Q#1.....k....@.c.?.3."T.(..igp2h...CH...>......joI.|n.....LK....C".......[|..D[o+.n..Q9w...>..g.^....C..'~......R....a..)..R1&LXWm..@.nn......kz.?..5_S:...j.....Ho....'.#0.~s>lB.I(.@.&..U...#...7..2....b..'..$N..-.u.;wc..1...3..}3..."..@...............J..d....Z.DId...5.....o.....D.T.H...e.e.~...7b.&.2...Z?..'...A.@j......v]q....O.H1Hu.?SF,<...@.....3.'.Yf.p[.jzi[.U.....W........i....3.v.E(..,x......M..@..i.kA.......a=j...k...h...`>J.U................M..*.6.v.]Vi&.H.B.f.....6......9......[...L.....7...d.T.....[}.M.`.D.77\.5..../.....%4.7.v......j..U...X,.^...U.)6..#7.e...D.g?N..h...Mg..{$........8.h..5.!..k........V....]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):741918
                  Entropy (8bit):7.99973610071978
                  Encrypted:true
                  SSDEEP:
                  MD5:7FA43B7ED791A9F6C425A72D04587016
                  SHA1:E51C8982451BCBAF631F827300D24E9AE906E3F2
                  SHA-256:43AE03FF187A1009375DC7F3CD2E46A796940DD274E34E81F049CAC4D2590E9D
                  SHA-512:9460FE2A7E984BF2683D65D34FC5BD3C1CD5F8144D4E4794564467798D0C45A85DF7AFC03A99175FEB696855756FEAE51431E636EA57369C1A05EB9195E23D02
                  Malicious:true
                  Preview:.&..[=... !.D?..HTwX..S;4.k.....1..}.j=.J.=...S.Am....8Q4.qp.3y.3*.6U.i...?..U......-.!.0W.7.z.-..< ..........)qs=...4.gc..+..c...._....".w&..#Bv)eVq.. ...I.;G_NV.....?....H.. g.>..P......E\=..f.d......#.Nf'20...).."Xu!.N.'F.|...z.... .....k..3..M.P.G...n...~.}.U....`.m!..!....h..."y8.UVqv.&c.........Y.......~.S,........\T2.....'...!UB..f....[A.N.d/...3..&$=...........H$GqI..*Y1^.........`..N.z.s.n4..iG.Y.|..~.0/y..M@..@..{...h&.]t%XK"..c.k.;..`.v.AC5...........^..z......3#...._".X..E...qLw.0u[.#..vI.u...x.'Z(.>. .[,.n....yS.h8..E..\.]...+#.&.. JO.K.N.....+..S.n.G.:R........q...X1.XO...W..0.&>.K...A..@..h,...n.VZ...3.W.+..TFeC...2.g.~.k.%..G...|.XC.6..9:._a.R..R. cq.T{...7..4W.....X..{...:#\..X3f_..a.kd&........Y.*'7....d..#\..J....c...,..fg...<X..{..O..2.....*..S..N.....U.v.......I./.[.[..3......g`.....<.W.u..{O..@..yoY0....`9.r.f.c....*..k.Q.9...Xp..^K.x`Ge......<...v.i..#.t..HV..F...O...Q...A...*..7d.P.W.t#.nZ...)..\.8.7..*.z..$.k....>V.M..!.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):741918
                  Entropy (8bit):7.99973610071978
                  Encrypted:true
                  SSDEEP:
                  MD5:7FA43B7ED791A9F6C425A72D04587016
                  SHA1:E51C8982451BCBAF631F827300D24E9AE906E3F2
                  SHA-256:43AE03FF187A1009375DC7F3CD2E46A796940DD274E34E81F049CAC4D2590E9D
                  SHA-512:9460FE2A7E984BF2683D65D34FC5BD3C1CD5F8144D4E4794564467798D0C45A85DF7AFC03A99175FEB696855756FEAE51431E636EA57369C1A05EB9195E23D02
                  Malicious:true
                  Preview:.&..[=... !.D?..HTwX..S;4.k.....1..}.j=.J.=...S.Am....8Q4.qp.3y.3*.6U.i...?..U......-.!.0W.7.z.-..< ..........)qs=...4.gc..+..c...._....".w&..#Bv)eVq.. ...I.;G_NV.....?....H.. g.>..P......E\=..f.d......#.Nf'20...).."Xu!.N.'F.|...z.... .....k..3..M.P.G...n...~.}.U....`.m!..!....h..."y8.UVqv.&c.........Y.......~.S,........\T2.....'...!UB..f....[A.N.d/...3..&$=...........H$GqI..*Y1^.........`..N.z.s.n4..iG.Y.|..~.0/y..M@..@..{...h&.]t%XK"..c.k.;..`.v.AC5...........^..z......3#...._".X..E...qLw.0u[.#..vI.u...x.'Z(.>. .[,.n....yS.h8..E..\.]...+#.&.. JO.K.N.....+..S.n.G.:R........q...X1.XO...W..0.&>.K...A..@..h,...n.VZ...3.W.+..TFeC...2.g.~.k.%..G...|.XC.6..9:._a.R..R. cq.T{...7..4W.....X..{...:#\..X3f_..a.kd&........Y.*'7....d..#\..J....c...,..fg...<X..{..O..2.....*..S..N.....U.v.......I./.[.[..3......g`.....<.W.u..{O..@..yoY0....`9.r.f.c....*..k.Q.9...Xp..^K.x`Ge......<...v.i..#.t..HV..F...O...Q...A...*..7d.P.W.t#.nZ...)..\.8.7..*.z..$.k....>V.M..!.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):741918
                  Entropy (8bit):7.99973610071978
                  Encrypted:true
                  SSDEEP:
                  MD5:7FA43B7ED791A9F6C425A72D04587016
                  SHA1:E51C8982451BCBAF631F827300D24E9AE906E3F2
                  SHA-256:43AE03FF187A1009375DC7F3CD2E46A796940DD274E34E81F049CAC4D2590E9D
                  SHA-512:9460FE2A7E984BF2683D65D34FC5BD3C1CD5F8144D4E4794564467798D0C45A85DF7AFC03A99175FEB696855756FEAE51431E636EA57369C1A05EB9195E23D02
                  Malicious:true
                  Preview:.&..[=... !.D?..HTwX..S;4.k.....1..}.j=.J.=...S.Am....8Q4.qp.3y.3*.6U.i...?..U......-.!.0W.7.z.-..< ..........)qs=...4.gc..+..c...._....".w&..#Bv)eVq.. ...I.;G_NV.....?....H.. g.>..P......E\=..f.d......#.Nf'20...).."Xu!.N.'F.|...z.... .....k..3..M.P.G...n...~.}.U....`.m!..!....h..."y8.UVqv.&c.........Y.......~.S,........\T2.....'...!UB..f....[A.N.d/...3..&$=...........H$GqI..*Y1^.........`..N.z.s.n4..iG.Y.|..~.0/y..M@..@..{...h&.]t%XK"..c.k.;..`.v.AC5...........^..z......3#...._".X..E...qLw.0u[.#..vI.u...x.'Z(.>. .[,.n....yS.h8..E..\.]...+#.&.. JO.K.N.....+..S.n.G.:R........q...X1.XO...W..0.&>.K...A..@..h,...n.VZ...3.W.+..TFeC...2.g.~.k.%..G...|.XC.6..9:._a.R..R. cq.T{...7..4W.....X..{...:#\..X3f_..a.kd&........Y.*'7....d..#\..J....c...,..fg...<X..{..O..2.....*..S..N.....U.v.......I./.[.[..3......g`.....<.W.u..{O..@..yoY0....`9.r.f.c....*..k.Q.9...Xp..^K.x`Ge......<...v.i..#.t..HV..F...O...Q...A...*..7d.P.W.t#.nZ...)..\.8.7..*.z..$.k....>V.M..!.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:PGP Secret Sub-key -
                  Category:dropped
                  Size (bytes):764682
                  Entropy (8bit):7.999769239847902
                  Encrypted:true
                  SSDEEP:
                  MD5:5E468B2BCEEE95627331B8CE01E6FF8D
                  SHA1:19650250C2A5FD1DA0D3CE837FB8A19A5AF54613
                  SHA-256:BFA35F41D7F840A4C97A6816E116B392B3BB45AF08A932B9398147D0BEC4943A
                  SHA-512:D28866243B6B1EF10851816364E43DDFCE2D9F6E7F08D716F3AD6612D34CC09A8D6DDDA6C2D65922C9471A798E490721595DFE9EFDA98A7B94A57F9C72E8041A
                  Malicious:true
                  Preview:....1..kYr..:_V.(b.?M ...S..gI,..U..U...a......}...zv..D2.r8.(....(6.... ^.\...'..D...U[..#.$..h..e.3Q.Qd..:.V....yY....9k[....@%.9.1.MrVz....8'....#.Y.2....529g.n..7....Q.....V.J.p..?=..z...N.].6.4..h.r8.|Bu..^>....f....j....U......AD%>...b!t9.>.....P`.n.8...21....*1..}>m<,.av^&.|.B..|....?...(...7..3.*/..g.},...H...w.I...k....z.....x.....)a...........<_l./..#...9.......Er...'b..v.IA.]@."......Z...=...n...:..'I.)d^XO#...S...j5..K./y....d8dz8..O.L..5..]MD..WI$...@..i........[t..B.,.i..O..W...U..pR.8..!o...&Iw...}.z.|c,71.a.T.A. ...Ph..<...*....=...[.......I..r....7V..[A.9..,S..|....B.Te0...;.M..#...p.V..k....l7e.N...:.l........Jj.2...;[..*...../YV....ad.b.+q&g.[..X..o.....w..n\w.-l.S..A........}._.lXN.......{.9.(........r....7..*......J.2..Y0..*.n.|..^.=.m7..k.oAdG.4..M$[..9MI..9.H.v....s......N...SK.R....`z.SX<.......]*}...y=.....B..i.W.l..FMk.!Q.X....zP..:...@.BO..G.....g.[.F....(..u12+u...L.r....aN...Q..Zn........).......<ku..5+...} /.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:PGP Secret Sub-key -
                  Category:dropped
                  Size (bytes):764682
                  Entropy (8bit):7.999769239847902
                  Encrypted:true
                  SSDEEP:
                  MD5:5E468B2BCEEE95627331B8CE01E6FF8D
                  SHA1:19650250C2A5FD1DA0D3CE837FB8A19A5AF54613
                  SHA-256:BFA35F41D7F840A4C97A6816E116B392B3BB45AF08A932B9398147D0BEC4943A
                  SHA-512:D28866243B6B1EF10851816364E43DDFCE2D9F6E7F08D716F3AD6612D34CC09A8D6DDDA6C2D65922C9471A798E490721595DFE9EFDA98A7B94A57F9C72E8041A
                  Malicious:true
                  Preview:....1..kYr..:_V.(b.?M ...S..gI,..U..U...a......}...zv..D2.r8.(....(6.... ^.\...'..D...U[..#.$..h..e.3Q.Qd..:.V....yY....9k[....@%.9.1.MrVz....8'....#.Y.2....529g.n..7....Q.....V.J.p..?=..z...N.].6.4..h.r8.|Bu..^>....f....j....U......AD%>...b!t9.>.....P`.n.8...21....*1..}>m<,.av^&.|.B..|....?...(...7..3.*/..g.},...H...w.I...k....z.....x.....)a...........<_l./..#...9.......Er...'b..v.IA.]@."......Z...=...n...:..'I.)d^XO#...S...j5..K./y....d8dz8..O.L..5..]MD..WI$...@..i........[t..B.,.i..O..W...U..pR.8..!o...&Iw...}.z.|c,71.a.T.A. ...Ph..<...*....=...[.......I..r....7V..[A.9..,S..|....B.Te0...;.M..#...p.V..k....l7e.N...:.l........Jj.2...;[..*...../YV....ad.b.+q&g.[..X..o.....w..n\w.-l.S..A........}._.lXN.......{.9.(........r....7..*......J.2..Y0..*.n.|..^.=.m7..k.oAdG.4..M$[..9MI..9.H.v....s......N...SK.R....`z.SX<.......]*}...y=.....B..i.W.l..FMk.!Q.X....zP..:...@.BO..G.....g.[.F....(..u12+u...L.r....aN...Q..Zn........).......<ku..5+...} /.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:PGP Secret Sub-key -
                  Category:dropped
                  Size (bytes):764682
                  Entropy (8bit):7.999769239847902
                  Encrypted:true
                  SSDEEP:
                  MD5:5E468B2BCEEE95627331B8CE01E6FF8D
                  SHA1:19650250C2A5FD1DA0D3CE837FB8A19A5AF54613
                  SHA-256:BFA35F41D7F840A4C97A6816E116B392B3BB45AF08A932B9398147D0BEC4943A
                  SHA-512:D28866243B6B1EF10851816364E43DDFCE2D9F6E7F08D716F3AD6612D34CC09A8D6DDDA6C2D65922C9471A798E490721595DFE9EFDA98A7B94A57F9C72E8041A
                  Malicious:true
                  Preview:....1..kYr..:_V.(b.?M ...S..gI,..U..U...a......}...zv..D2.r8.(....(6.... ^.\...'..D...U[..#.$..h..e.3Q.Qd..:.V....yY....9k[....@%.9.1.MrVz....8'....#.Y.2....529g.n..7....Q.....V.J.p..?=..z...N.].6.4..h.r8.|Bu..^>....f....j....U......AD%>...b!t9.>.....P`.n.8...21....*1..}>m<,.av^&.|.B..|....?...(...7..3.*/..g.},...H...w.I...k....z.....x.....)a...........<_l./..#...9.......Er...'b..v.IA.]@."......Z...=...n...:..'I.)d^XO#...S...j5..K./y....d8dz8..O.L..5..]MD..WI$...@..i........[t..B.,.i..O..W...U..pR.8..!o...&Iw...}.z.|c,71.a.T.A. ...Ph..<...*....=...[.......I..r....7V..[A.9..,S..|....B.Te0...;.M..#...p.V..k....l7e.N...:.l........Jj.2...;[..*...../YV....ad.b.+q&g.[..X..o.....w..n\w.-l.S..A........}._.lXN.......{.9.(........r....7..*......J.2..Y0..*.n.|..^.=.m7..k.oAdG.4..M$[..9MI..9.H.v....s......N...SK.R....`z.SX<.......]*}...y=.....B..i.W.l..FMk.!Q.X....zP..:...@.BO..G.....g.[.F....(..u12+u...L.r....aN...Q..Zn........).......<ku..5+...} /.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):981299
                  Entropy (8bit):7.999826484562638
                  Encrypted:true
                  SSDEEP:
                  MD5:23F7156301FC8E1BDDA34E5001F692F5
                  SHA1:241947F945715B0AC59B1FBF37C11A993B74E88D
                  SHA-256:B9E7BAEBCD6E4D978F5AD237B5DBEA3B5354858D5B02FB79BAAFEDB5F7B621D8
                  SHA-512:AC3DFFAAEA81027A9953959382F537E191C3C9F48BC2F76413B740E21E42A2F77D1AB5EA4B2ACFF54B56FA79053C1E6DA0F2CCF4FB3F6B529DA1D08E55B68649
                  Malicious:true
                  Preview:...h.~4..Q.J..|.t60.)U.F...@1..$.)...~........I...........G..$...(~.,...<N.Q..zA...5...L.....#.T"u..]L...jr...+... K....j5.u/.....JHL(.e.h(..f...r2A.91O....Y.S..P[..<_&....ga."...o........x$~..kYo.bs....T.f/.....W...L........V&.*p .....~p,.ze....o.....j.8k.....1.n..4....JI.T....1l..<Nb.;".o^....a.+...R!.....f.i...X.=..q...f.w;t..p..u...a.uA.D.n...L.....l.}!;.X.X.&...>......a...Xs../.".....'..4.P60..W..1X.Pq...=.f..d;.!$h...{ua%..Hav.^......c...(.A.B.q)P..QI\.-....;..;...7.e..36Q.K..G.v9*.i..=.u...Sd.I..;c.....R..5N......._..2.........g..{HVc. .._I.1...Px":..c#...sbS..{.B...%...|......o...y..7....oG...y......W...rqc....V...I..\K.<..o.....=.EsM.h....jk..uc..~Z....o....t.t2...5...y...qY:w'.M........-.{...}%.T#b.?.....}m.....V.9..!5}....d..G..P....f....ON.m.....:.N....(]..+Jy.........._.`.y..:..E.b..!.n.S.......j,a<.P..W......[.."..d..f..?8M .....S..3.w.N.%..Vh9.y..'o.._.LZ...E.p..!V./v.2.{..d..}.b6....Lt.....=q.'...h....X...m..VX:.Zuvt.zK..K..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):981299
                  Entropy (8bit):7.999826484562638
                  Encrypted:true
                  SSDEEP:
                  MD5:23F7156301FC8E1BDDA34E5001F692F5
                  SHA1:241947F945715B0AC59B1FBF37C11A993B74E88D
                  SHA-256:B9E7BAEBCD6E4D978F5AD237B5DBEA3B5354858D5B02FB79BAAFEDB5F7B621D8
                  SHA-512:AC3DFFAAEA81027A9953959382F537E191C3C9F48BC2F76413B740E21E42A2F77D1AB5EA4B2ACFF54B56FA79053C1E6DA0F2CCF4FB3F6B529DA1D08E55B68649
                  Malicious:true
                  Preview:...h.~4..Q.J..|.t60.)U.F...@1..$.)...~........I...........G..$...(~.,...<N.Q..zA...5...L.....#.T"u..]L...jr...+... K....j5.u/.....JHL(.e.h(..f...r2A.91O....Y.S..P[..<_&....ga."...o........x$~..kYo.bs....T.f/.....W...L........V&.*p .....~p,.ze....o.....j.8k.....1.n..4....JI.T....1l..<Nb.;".o^....a.+...R!.....f.i...X.=..q...f.w;t..p..u...a.uA.D.n...L.....l.}!;.X.X.&...>......a...Xs../.".....'..4.P60..W..1X.Pq...=.f..d;.!$h...{ua%..Hav.^......c...(.A.B.q)P..QI\.-....;..;...7.e..36Q.K..G.v9*.i..=.u...Sd.I..;c.....R..5N......._..2.........g..{HVc. .._I.1...Px":..c#...sbS..{.B...%...|......o...y..7....oG...y......W...rqc....V...I..\K.<..o.....=.EsM.h....jk..uc..~Z....o....t.t2...5...y...qY:w'.M........-.{...}%.T#b.?.....}m.....V.9..!5}....d..G..P....f....ON.m.....:.N....(]..+Jy.........._.`.y..:..E.b..!.n.S.......j,a<.P..W......[.."..d..f..?8M .....S..3.w.N.%..Vh9.y..'o.._.LZ...E.p..!V./v.2.{..d..}.b6....Lt.....=q.'...h....X...m..VX:.Zuvt.zK..K..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):981299
                  Entropy (8bit):7.999826484562638
                  Encrypted:true
                  SSDEEP:
                  MD5:23F7156301FC8E1BDDA34E5001F692F5
                  SHA1:241947F945715B0AC59B1FBF37C11A993B74E88D
                  SHA-256:B9E7BAEBCD6E4D978F5AD237B5DBEA3B5354858D5B02FB79BAAFEDB5F7B621D8
                  SHA-512:AC3DFFAAEA81027A9953959382F537E191C3C9F48BC2F76413B740E21E42A2F77D1AB5EA4B2ACFF54B56FA79053C1E6DA0F2CCF4FB3F6B529DA1D08E55B68649
                  Malicious:true
                  Preview:...h.~4..Q.J..|.t60.)U.F...@1..$.)...~........I...........G..$...(~.,...<N.Q..zA...5...L.....#.T"u..]L...jr...+... K....j5.u/.....JHL(.e.h(..f...r2A.91O....Y.S..P[..<_&....ga."...o........x$~..kYo.bs....T.f/.....W...L........V&.*p .....~p,.ze....o.....j.8k.....1.n..4....JI.T....1l..<Nb.;".o^....a.+...R!.....f.i...X.=..q...f.w;t..p..u...a.uA.D.n...L.....l.}!;.X.X.&...>......a...Xs../.".....'..4.P60..W..1X.Pq...=.f..d;.!$h...{ua%..Hav.^......c...(.A.B.q)P..QI\.-....;..;...7.e..36Q.K..G.v9*.i..=.u...Sd.I..;c.....R..5N......._..2.........g..{HVc. .._I.1...Px":..c#...sbS..{.B...%...|......o...y..7....oG...y......W...rqc....V...I..\K.<..o.....=.EsM.h....jk..uc..~Z....o....t.t2...5...y...qY:w'.M........-.{...}%.T#b.?.....}m.....V.9..!5}....d..G..P....f....ON.m.....:.N....(]..+Jy.........._.`.y..:..E.b..!.n.S.......j,a<.P..W......[.."..d..f..?8M .....S..3.w.N.%..Vh9.y..'o.._.LZ...E.p..!V./v.2.{..d..}.b6....Lt.....=q.'...h....X...m..VX:.Zuvt.zK..K..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):472031
                  Entropy (8bit):7.999588473822593
                  Encrypted:true
                  SSDEEP:
                  MD5:94EB757B10E35C38E944490CABF6E493
                  SHA1:F993D636DB24E89358377CCCE752C885E6B52799
                  SHA-256:3474B175F82E62CBA361588340B62E67E85A1810BAA5AA13BCF4FC8B6C0CC9EE
                  SHA-512:D1290B901754E874EDBE5F11A1F6DEB1D9A5DAD43DF1C13BC36BA57E467B6D6AC49247358F1C9C2C8701D4595F07F775E8083E5AC5FA9E47A89173592AA26E01
                  Malicious:true
                  Preview:r.....T-f..?..........V.x'U.......H.#.=k{w.XV.#...c.<at1..a.3.p.;{o.6.0V..U.S...S..t.n...,N.f9A.8#T.:..4...B.>..oDR.G1d....A`.g.r..D..B7}J.8.<:.a.e....Z.9..m+.A.$.9.......Ie..0.K.............i..X..:6.%h.*...{6Z....A..k.PYg...o!.(.r.U.'u.jI0).@...vbt(..S .f..]@_`U%.be,.a.k.....a.Ue...8..a.w#.u...nS.m..Y.It0.lv...../,dp.Q.FvR....Rq..r.91.......m<J<{.h......I...K#........y,x=lm.5.....G. Q#W..'.7. ...i.a.'.p..=?.....K5"../@....zd....S.fR.%e...q...&.Lh....L..|L....AI...8.....(..F.Z.l.......x.lX..........Nw.b.Z.z.in....=.>.f]h.N8.w3.o..^...h.....FC..9A..CP.r.1.\...I...*}....i..}En.w=.M.4x.....f.#.8t..a...z.......d.....2823............hg.B...?.O....+ZK$.uF.B...k.uK....o.Y...:.E^.5..W ......!G.c...G..`.w..h-...\...).p{.(Mg.o..%.l....K..+Z.1... O....%..l.q.a....*..uwZ..1aof.n7^....H...3.Mq.U..m...N..bMMX..........}.Y...9.\.W..:nf....W..p.o.....+.1......ZE..6P.Vtf.0ZIf.4.k$[...4....K.CM.-..-...ui..1O,I.:!....5+.G..`..#..I.6.......-.@..v.L.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):472031
                  Entropy (8bit):7.999588473822593
                  Encrypted:true
                  SSDEEP:
                  MD5:94EB757B10E35C38E944490CABF6E493
                  SHA1:F993D636DB24E89358377CCCE752C885E6B52799
                  SHA-256:3474B175F82E62CBA361588340B62E67E85A1810BAA5AA13BCF4FC8B6C0CC9EE
                  SHA-512:D1290B901754E874EDBE5F11A1F6DEB1D9A5DAD43DF1C13BC36BA57E467B6D6AC49247358F1C9C2C8701D4595F07F775E8083E5AC5FA9E47A89173592AA26E01
                  Malicious:true
                  Preview:r.....T-f..?..........V.x'U.......H.#.=k{w.XV.#...c.<at1..a.3.p.;{o.6.0V..U.S...S..t.n...,N.f9A.8#T.:..4...B.>..oDR.G1d....A`.g.r..D..B7}J.8.<:.a.e....Z.9..m+.A.$.9.......Ie..0.K.............i..X..:6.%h.*...{6Z....A..k.PYg...o!.(.r.U.'u.jI0).@...vbt(..S .f..]@_`U%.be,.a.k.....a.Ue...8..a.w#.u...nS.m..Y.It0.lv...../,dp.Q.FvR....Rq..r.91.......m<J<{.h......I...K#........y,x=lm.5.....G. Q#W..'.7. ...i.a.'.p..=?.....K5"../@....zd....S.fR.%e...q...&.Lh....L..|L....AI...8.....(..F.Z.l.......x.lX..........Nw.b.Z.z.in....=.>.f]h.N8.w3.o..^...h.....FC..9A..CP.r.1.\...I...*}....i..}En.w=.M.4x.....f.#.8t..a...z.......d.....2823............hg.B...?.O....+ZK$.uF.B...k.uK....o.Y...:.E^.5..W ......!G.c...G..`.w..h-...\...).p{.(Mg.o..%.l....K..+Z.1... O....%..l.q.a....*..uwZ..1aof.n7^....H...3.Mq.U..m...N..bMMX..........}.Y...9.\.W..:nf....W..p.o.....+.1......ZE..6P.Vtf.0ZIf.4.k$[...4....K.CM.-..-...ui..1O,I.:!....5+.G..`..#..I.6.......-.@..v.L.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):472031
                  Entropy (8bit):7.999588473822593
                  Encrypted:true
                  SSDEEP:
                  MD5:94EB757B10E35C38E944490CABF6E493
                  SHA1:F993D636DB24E89358377CCCE752C885E6B52799
                  SHA-256:3474B175F82E62CBA361588340B62E67E85A1810BAA5AA13BCF4FC8B6C0CC9EE
                  SHA-512:D1290B901754E874EDBE5F11A1F6DEB1D9A5DAD43DF1C13BC36BA57E467B6D6AC49247358F1C9C2C8701D4595F07F775E8083E5AC5FA9E47A89173592AA26E01
                  Malicious:true
                  Preview:r.....T-f..?..........V.x'U.......H.#.=k{w.XV.#...c.<at1..a.3.p.;{o.6.0V..U.S...S..t.n...,N.f9A.8#T.:..4...B.>..oDR.G1d....A`.g.r..D..B7}J.8.<:.a.e....Z.9..m+.A.$.9.......Ie..0.K.............i..X..:6.%h.*...{6Z....A..k.PYg...o!.(.r.U.'u.jI0).@...vbt(..S .f..]@_`U%.be,.a.k.....a.Ue...8..a.w#.u...nS.m..Y.It0.lv...../,dp.Q.FvR....Rq..r.91.......m<J<{.h......I...K#........y,x=lm.5.....G. Q#W..'.7. ...i.a.'.p..=?.....K5"../@....zd....S.fR.%e...q...&.Lh....L..|L....AI...8.....(..F.Z.l.......x.lX..........Nw.b.Z.z.in....=.>.f]h.N8.w3.o..^...h.....FC..9A..CP.r.1.\...I...*}....i..}En.w=.M.4x.....f.#.8t..a...z.......d.....2823............hg.B...?.O....+ZK$.uF.B...k.uK....o.Y...:.E^.5..W ......!G.c...G..`.w..h-...\...).p{.(Mg.o..%.l....K..+Z.1... O....%..l.q.a....*..uwZ..1aof.n7^....H...3.Mq.U..m...N..bMMX..........}.Y...9.\.W..:nf....W..p.o.....+.1......ZE..6P.Vtf.0ZIf.4.k$[...4....K.CM.-..-...ui..1O,I.:!....5+.G..`..#..I.6.......-.@..v.L.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):475983
                  Entropy (8bit):7.999597601644163
                  Encrypted:true
                  SSDEEP:
                  MD5:03E1D8F4E7A6D889BBD326CE0F711D96
                  SHA1:BFA62CC71DE3066A6003F8A0CAA6183983D8B6D1
                  SHA-256:C0453D99D97139115000BAD4C49EB34517325F4BC006A25A1202E6C36DF9A44C
                  SHA-512:E1CCE00BE47E2AEC0BC7420F3E1638B564A2B277A7D06B0EBF71998D6136A51CB2089C7399342B31B59E5A2CB0C5862892B606E5B46832F922D161EC91ADF42E
                  Malicious:true
                  Preview:S...6..a-...L3r...v.S..........]...zT.NW.......0......b^..9...a?:WM.Cs.Mm."...$nl..W^. Z$p.5..b......Pl.K...I.1..... .x.h.L.[.}C.i..4.|.........{.6.`m.9~..C..].....eeF.%[.Z...+.0xLi..a<.*..'..s.[..N3...2..Y.);B....|...}_.l.Nh.f.A.o.3.s]...k...I..Ch...W....=.$.......zML...Z"...;i.=...6..M....tx....|q..La.^J..P...4.t...`.....x%K.....8.gN.[...j.R.......U...r.s...t.c...P.%.D.h...p..+z\...m.,9W......M.w...I...i..\....Uk...%.C.Rv$..j.Q65.t.W,.m.....4....|...-0.L..q.J.m..,.G_.....P....b1?%......i.HAIi.f ........h..L].M....`...@.(.....g.U.E...m..\L..O@2./....Q..WQ.D..sVQmA........_. .x.e...C..xD......_].....EF..C...Zy5.6..% ............\Hk...Z..w....Q..e[@GJ.l...9Y.Ah6....#.>O.[...k..[..Dt....D..y..|Y...e... .....{...#.{$A... B......G.lR>.D.D.z0..S.+..W.z..t"ON......w{R0..._f|.fMA*.Cm....i@_>..5k...(......}Y.|...0s$.SB.o.t.T..1.\`.q.}.S,...8.K.|V.2...7w. .].bX.:'E...i....R.[:fX!.N...4..F..p........J..-..(tZ.........B.....>.0."..1..hR...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):475983
                  Entropy (8bit):7.999597601644163
                  Encrypted:true
                  SSDEEP:
                  MD5:03E1D8F4E7A6D889BBD326CE0F711D96
                  SHA1:BFA62CC71DE3066A6003F8A0CAA6183983D8B6D1
                  SHA-256:C0453D99D97139115000BAD4C49EB34517325F4BC006A25A1202E6C36DF9A44C
                  SHA-512:E1CCE00BE47E2AEC0BC7420F3E1638B564A2B277A7D06B0EBF71998D6136A51CB2089C7399342B31B59E5A2CB0C5862892B606E5B46832F922D161EC91ADF42E
                  Malicious:true
                  Preview:S...6..a-...L3r...v.S..........]...zT.NW.......0......b^..9...a?:WM.Cs.Mm."...$nl..W^. Z$p.5..b......Pl.K...I.1..... .x.h.L.[.}C.i..4.|.........{.6.`m.9~..C..].....eeF.%[.Z...+.0xLi..a<.*..'..s.[..N3...2..Y.);B....|...}_.l.Nh.f.A.o.3.s]...k...I..Ch...W....=.$.......zML...Z"...;i.=...6..M....tx....|q..La.^J..P...4.t...`.....x%K.....8.gN.[...j.R.......U...r.s...t.c...P.%.D.h...p..+z\...m.,9W......M.w...I...i..\....Uk...%.C.Rv$..j.Q65.t.W,.m.....4....|...-0.L..q.J.m..,.G_.....P....b1?%......i.HAIi.f ........h..L].M....`...@.(.....g.U.E...m..\L..O@2./....Q..WQ.D..sVQmA........_. .x.e...C..xD......_].....EF..C...Zy5.6..% ............\Hk...Z..w....Q..e[@GJ.l...9Y.Ah6....#.>O.[...k..[..Dt....D..y..|Y...e... .....{...#.{$A... B......G.lR>.D.D.z0..S.+..W.z..t"ON......w{R0..._f|.fMA*.Cm....i@_>..5k...(......}Y.|...0s$.SB.o.t.T..1.\`.q.}.S,...8.K.|V.2...7w. .].bX.:'E...i....R.[:fX!.N...4..F..p........J..-..(tZ.........B.....>.0."..1..hR...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):475983
                  Entropy (8bit):7.999597601644163
                  Encrypted:true
                  SSDEEP:
                  MD5:03E1D8F4E7A6D889BBD326CE0F711D96
                  SHA1:BFA62CC71DE3066A6003F8A0CAA6183983D8B6D1
                  SHA-256:C0453D99D97139115000BAD4C49EB34517325F4BC006A25A1202E6C36DF9A44C
                  SHA-512:E1CCE00BE47E2AEC0BC7420F3E1638B564A2B277A7D06B0EBF71998D6136A51CB2089C7399342B31B59E5A2CB0C5862892B606E5B46832F922D161EC91ADF42E
                  Malicious:true
                  Preview:S...6..a-...L3r...v.S..........]...zT.NW.......0......b^..9...a?:WM.Cs.Mm."...$nl..W^. Z$p.5..b......Pl.K...I.1..... .x.h.L.[.}C.i..4.|.........{.6.`m.9~..C..].....eeF.%[.Z...+.0xLi..a<.*..'..s.[..N3...2..Y.);B....|...}_.l.Nh.f.A.o.3.s]...k...I..Ch...W....=.$.......zML...Z"...;i.=...6..M....tx....|q..La.^J..P...4.t...`.....x%K.....8.gN.[...j.R.......U...r.s...t.c...P.%.D.h...p..+z\...m.,9W......M.w...I...i..\....Uk...%.C.Rv$..j.Q65.t.W,.m.....4....|...-0.L..q.J.m..,.G_.....P....b1?%......i.HAIi.f ........h..L].M....`...@.(.....g.U.E...m..\L..O@2./....Q..WQ.D..sVQmA........_. .x.e...C..xD......_].....EF..C...Zy5.6..% ............\Hk...Z..w....Q..e[@GJ.l...9Y.Ah6....#.>O.[...k..[..Dt....D..y..|Y...e... .....{...#.{$A... B......G.lR>.D.D.z0..S.+..W.z..t"ON......w{R0..._f|.fMA*.Cm....i@_>..5k...(......}Y.|...0s$.SB.o.t.T..1.\`.q.}.S,...8.K.|V.2...7w. .].bX.:'E...i....R.[:fX!.N...4..F..p........J..-..(tZ.........B.....>.0."..1..hR...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):436672
                  Entropy (8bit):7.999607665155981
                  Encrypted:true
                  SSDEEP:
                  MD5:C8D25A706E6643FC1E6F962EAAD3A9C3
                  SHA1:7867EA9E581EAFAD5CBB281F9689F2245836D913
                  SHA-256:D847FD26FEF26C732BC94CBBE85F8D6A1E4E2EFFDA75220ACDA0A8809F6C70DD
                  SHA-512:379676912A2E2F7829D0A217B9BBD035DAC74560698244C81A030736E90AD9A061DBD2EE9257201FDD3CAD6BEE2CABE4D5E727C4253468AFBDD7C4EB8E463028
                  Malicious:true
                  Preview:|...H...(m....{.J..}...m...?..}..6i.;...L.Y ..a.3.+.P.>]...\3].p..B.w...88..-.0...(E..".!...f/.wV.."..!..G~....f.@L^./%0...XjJ....%.gs..7....,.W4P.IJA....)....7......F.D.O....b*{..*.e.#.@*O7X.d..a`~Q.......].vR6 .......h..d.K...`.....E.v....u..Nn.Xb.TDj.|<.".......lO.H.l..zD....9....?.}.N[7C..\..5..CM.F.....jK.j..p.,'&)Z..[....!.....,.{o....<..T9[H.X./.M .>.x....h.-..JP.z)..U..y.6r..+in...&..B.f....(..5^..*JG.f*.Od.....].Az"O.....8...n'...A..K....L.nX..I#.=..iD..R...N...=$O>.P..qm.;{B.#{....(":..x).^?....B....C.Gt.I8.6.....,.......N..../u.....E.U...f...{..4.oq.8..."7...n8K...0.:tw`..<@..2qf...K@t.6lj.:.y..M.@..WWc.....,$.}.9...f.L....+...6..g.l:*i=.4.......n.<.e..."..S.nYV..(.+`.p.^.C.)z..I....0.......~.6.g......kuGe..\..ddF.[.....tf.....s.\...Y]..........N$`;...1>o.........e...4..S...2.KkZ...W.....7Z......:.`..G..3!...`....OKy........c..uqB.......{.+.ho5.i. o.....k=)..z...7.k..O(&....j....l8b2.......Zh.6.P.4.....j..z...CJ@....#.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):436672
                  Entropy (8bit):7.999607665155981
                  Encrypted:true
                  SSDEEP:
                  MD5:C8D25A706E6643FC1E6F962EAAD3A9C3
                  SHA1:7867EA9E581EAFAD5CBB281F9689F2245836D913
                  SHA-256:D847FD26FEF26C732BC94CBBE85F8D6A1E4E2EFFDA75220ACDA0A8809F6C70DD
                  SHA-512:379676912A2E2F7829D0A217B9BBD035DAC74560698244C81A030736E90AD9A061DBD2EE9257201FDD3CAD6BEE2CABE4D5E727C4253468AFBDD7C4EB8E463028
                  Malicious:true
                  Preview:|...H...(m....{.J..}...m...?..}..6i.;...L.Y ..a.3.+.P.>]...\3].p..B.w...88..-.0...(E..".!...f/.wV.."..!..G~....f.@L^./%0...XjJ....%.gs..7....,.W4P.IJA....)....7......F.D.O....b*{..*.e.#.@*O7X.d..a`~Q.......].vR6 .......h..d.K...`.....E.v....u..Nn.Xb.TDj.|<.".......lO.H.l..zD....9....?.}.N[7C..\..5..CM.F.....jK.j..p.,'&)Z..[....!.....,.{o....<..T9[H.X./.M .>.x....h.-..JP.z)..U..y.6r..+in...&..B.f....(..5^..*JG.f*.Od.....].Az"O.....8...n'...A..K....L.nX..I#.=..iD..R...N...=$O>.P..qm.;{B.#{....(":..x).^?....B....C.Gt.I8.6.....,.......N..../u.....E.U...f...{..4.oq.8..."7...n8K...0.:tw`..<@..2qf...K@t.6lj.:.y..M.@..WWc.....,$.}.9...f.L....+...6..g.l:*i=.4.......n.<.e..."..S.nYV..(.+`.p.^.C.)z..I....0.......~.6.g......kuGe..\..ddF.[.....tf.....s.\...Y]..........N$`;...1>o.........e...4..S...2.KkZ...W.....7Z......:.`..G..3!...`....OKy........c..uqB.......{.+.ho5.i. o.....k=)..z...7.k..O(&....j....l8b2.......Zh.6.P.4.....j..z...CJ@....#.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):436672
                  Entropy (8bit):7.999607665155981
                  Encrypted:true
                  SSDEEP:
                  MD5:C8D25A706E6643FC1E6F962EAAD3A9C3
                  SHA1:7867EA9E581EAFAD5CBB281F9689F2245836D913
                  SHA-256:D847FD26FEF26C732BC94CBBE85F8D6A1E4E2EFFDA75220ACDA0A8809F6C70DD
                  SHA-512:379676912A2E2F7829D0A217B9BBD035DAC74560698244C81A030736E90AD9A061DBD2EE9257201FDD3CAD6BEE2CABE4D5E727C4253468AFBDD7C4EB8E463028
                  Malicious:true
                  Preview:|...H...(m....{.J..}...m...?..}..6i.;...L.Y ..a.3.+.P.>]...\3].p..B.w...88..-.0...(E..".!...f/.wV.."..!..G~....f.@L^./%0...XjJ....%.gs..7....,.W4P.IJA....)....7......F.D.O....b*{..*.e.#.@*O7X.d..a`~Q.......].vR6 .......h..d.K...`.....E.v....u..Nn.Xb.TDj.|<.".......lO.H.l..zD....9....?.}.N[7C..\..5..CM.F.....jK.j..p.,'&)Z..[....!.....,.{o....<..T9[H.X./.M .>.x....h.-..JP.z)..U..y.6r..+in...&..B.f....(..5^..*JG.f*.Od.....].Az"O.....8...n'...A..K....L.nX..I#.=..iD..R...N...=$O>.P..qm.;{B.#{....(":..x).^?....B....C.Gt.I8.6.....,.......N..../u.....E.U...f...{..4.oq.8..."7...n8K...0.:tw`..<@..2qf...K@t.6lj.:.y..M.@..WWc.....,$.}.9...f.L....+...6..g.l:*i=.4.......n.<.e..."..S.nYV..(.+`.p.^.C.)z..I....0.......~.6.g......kuGe..\..ddF.[.....tf.....s.\...Y]..........N$`;...1>o.........e...4..S...2.KkZ...W.....7Z......:.`..G..3!...`....OKy........c..uqB.......{.+.ho5.i. o.....k=)..z...7.k..O(&....j....l8b2.......Zh.6.P.4.....j..z...CJ@....#.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):470385
                  Entropy (8bit):7.999634987404802
                  Encrypted:true
                  SSDEEP:
                  MD5:F4CE7D3208F51562727D0BCA0808C526
                  SHA1:1E597F927A9CA361091A137DDDC1DCA1A4499A52
                  SHA-256:035CC55625923EDF3436FE6C7A43F7A5C20035C4C3BE311955AC51D3983988BC
                  SHA-512:4E1995305A210DFF5649D1B35C76963C1EBC554AE5069BC1817144AD407D00A53BA6AF96DF82B39A424E45051D8ABF713930174A6D4F1D0BD75AD34EE02794CB
                  Malicious:true
                  Preview:..H.K.*...Y...l..Y.yf7R.1..^.....b......o".i...c..R}..E..!_.&.D.q>....._bv......'..E.@....m...K%....7.M'....<....`..k.1<(.1..%Uq.H4Q.+.c+.9fs.,.yh..k}qZ?.7.Bd.....@7w>-..S...oLC}3..E..{....M.S.R..#.......k;.dku=.\a.MUi.&>."mp.=..Y.J.#R+f..'o ..0(C.}P5<g.{H...j........d0.i.{.........."../..b.G..&....-.g%.}..].=vQL.......t....3?..>.k...%r..<l.......7p.vIW.[akq.D....U...gV..%.....\.fE.iFZ.:y.~...{...m....5`S.80...H..b2.^...h.jQX..H...i..G...2xb...B....`.....7O..Qk.4...Q8..,Y.r.u....]...,._'s.A...*.<g...Y...yo...HJ7....$.a.T.@...0.{@/01.*F.cRj.h.6........\.+....Q.'.......7_..nl........u.....Y....R*@'...........2..p..I_.z......_r..I.*...~g............d..2m....lmlQ.|..K..U.(..h.../.uC.k.......?2&..or.x>r.......wy.)....zB......#r_.. Cp2..`i)9.E.E.s+y..N...e......e..f*.........:.9..M[.{.y......r<...2...@.b.'.1..=.7...o...7ab..$p.2?.zyl..q....\....j_~&aP.N%..kr3*..fv@.;........F...C...%......U....<e....7..E+...eY.y.A]q..Uw..w.V..Ll..Hv...K...x9X....0e.u
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):470385
                  Entropy (8bit):7.999634987404802
                  Encrypted:true
                  SSDEEP:
                  MD5:F4CE7D3208F51562727D0BCA0808C526
                  SHA1:1E597F927A9CA361091A137DDDC1DCA1A4499A52
                  SHA-256:035CC55625923EDF3436FE6C7A43F7A5C20035C4C3BE311955AC51D3983988BC
                  SHA-512:4E1995305A210DFF5649D1B35C76963C1EBC554AE5069BC1817144AD407D00A53BA6AF96DF82B39A424E45051D8ABF713930174A6D4F1D0BD75AD34EE02794CB
                  Malicious:true
                  Preview:..H.K.*...Y...l..Y.yf7R.1..^.....b......o".i...c..R}..E..!_.&.D.q>....._bv......'..E.@....m...K%....7.M'....<....`..k.1<(.1..%Uq.H4Q.+.c+.9fs.,.yh..k}qZ?.7.Bd.....@7w>-..S...oLC}3..E..{....M.S.R..#.......k;.dku=.\a.MUi.&>."mp.=..Y.J.#R+f..'o ..0(C.}P5<g.{H...j........d0.i.{.........."../..b.G..&....-.g%.}..].=vQL.......t....3?..>.k...%r..<l.......7p.vIW.[akq.D....U...gV..%.....\.fE.iFZ.:y.~...{...m....5`S.80...H..b2.^...h.jQX..H...i..G...2xb...B....`.....7O..Qk.4...Q8..,Y.r.u....]...,._'s.A...*.<g...Y...yo...HJ7....$.a.T.@...0.{@/01.*F.cRj.h.6........\.+....Q.'.......7_..nl........u.....Y....R*@'...........2..p..I_.z......_r..I.*...~g............d..2m....lmlQ.|..K..U.(..h.../.uC.k.......?2&..or.x>r.......wy.)....zB......#r_.. Cp2..`i)9.E.E.s+y..N...e......e..f*.........:.9..M[.{.y......r<...2...@.b.'.1..=.7...o...7ab..$p.2?.zyl..q....\....j_~&aP.N%..kr3*..fv@.;........F...C...%......U....<e....7..E+...eY.y.A]q..Uw..w.V..Ll..Hv...K...x9X....0e.u
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):470385
                  Entropy (8bit):7.999634987404802
                  Encrypted:true
                  SSDEEP:
                  MD5:F4CE7D3208F51562727D0BCA0808C526
                  SHA1:1E597F927A9CA361091A137DDDC1DCA1A4499A52
                  SHA-256:035CC55625923EDF3436FE6C7A43F7A5C20035C4C3BE311955AC51D3983988BC
                  SHA-512:4E1995305A210DFF5649D1B35C76963C1EBC554AE5069BC1817144AD407D00A53BA6AF96DF82B39A424E45051D8ABF713930174A6D4F1D0BD75AD34EE02794CB
                  Malicious:true
                  Preview:..H.K.*...Y...l..Y.yf7R.1..^.....b......o".i...c..R}..E..!_.&.D.q>....._bv......'..E.@....m...K%....7.M'....<....`..k.1<(.1..%Uq.H4Q.+.c+.9fs.,.yh..k}qZ?.7.Bd.....@7w>-..S...oLC}3..E..{....M.S.R..#.......k;.dku=.\a.MUi.&>."mp.=..Y.J.#R+f..'o ..0(C.}P5<g.{H...j........d0.i.{.........."../..b.G..&....-.g%.}..].=vQL.......t....3?..>.k...%r..<l.......7p.vIW.[akq.D....U...gV..%.....\.fE.iFZ.:y.~...{...m....5`S.80...H..b2.^...h.jQX..H...i..G...2xb...B....`.....7O..Qk.4...Q8..,Y.r.u....]...,._'s.A...*.<g...Y...yo...HJ7....$.a.T.@...0.{@/01.*F.cRj.h.6........\.+....Q.'.......7_..nl........u.....Y....R*@'...........2..p..I_.z......_r..I.*...~g............d..2m....lmlQ.|..K..U.(..h.../.uC.k.......?2&..or.x>r.......wy.)....zB......#r_.. Cp2..`i)9.E.E.s+y..N...e......e..f*.........:.9..M[.{.y......r<...2...@.b.'.1..=.7...o...7ab..$p.2?.zyl..q....\....j_~&aP.N%..kr3*..fv@.;........F...C...%......U....<e....7..E+...eY.y.A]q..Uw..w.V..Ll..Hv...K...x9X....0e.u
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):836937
                  Entropy (8bit):7.999773957332884
                  Encrypted:true
                  SSDEEP:
                  MD5:E7500D240D9D05C989F402C70091FF18
                  SHA1:FD74465A4E706767C304B6B9ACA980F53B0438B3
                  SHA-256:60EE2A9EA5426DCDF97BD8BA28A4F6E8CBF792AA88E884CD7B6CABBE6BA9E219
                  SHA-512:069CD2DBDDEE003EA4A0A385E3B0CE57CDF8F8FCEA6271386AA611B8A2E7A4AF8205D7B01185976F0B4DC0991B4FB0E1CC586CE6305A0602ABBA25212D9A74CB
                  Malicious:true
                  Preview:%......9.g"......."Y.\.O.$.%'....-..j"...zW2.n.l..9.7.......#...b@4..2.... ..}.....\.P.'....u......A...........t...7$(..3....EGZ].P.%9....R.J.F...0.e...V...{..5....'...z....8.\.+..'...<...{..u.=..9S.o..Adk...(/}$t..Gt..q.*....%......[....t....D..2.?...D..6.e...Xd........E..rw:.#.(.....(..Q.[.._g...I...cw.,5..`...Lr.JZ...F[..Y9.?R..".-._.u.o...j.......X....k{...3.G..O.....P.ky.......r.![.!\<'..#r......#...n}.X.HD.Yd-......g.........MX.q...Q...%.N..)_A.......M...p...Yff...+T~..........-TK...BK...d..I...\V..A......qZ.P..<y..-.*.-..1..D.=T9...l}.tfw.+1.r....#B....FF..U...A..|..O."...H.K$T..\.T..e........!.FP@*.#.)*.......l.*F.._..V.....2.;...51....S..a:f".......y.n".....cw.....Q.(......4u....R.>...n..Q.._.=a..{.....%...z....(...z.7......dY|.tO..?y_z.d.....,....|..^.j[k.....p.E.b]bI...E7k.Y`@....:.U3n..SEF..rbZ..._Vd.I3..F....J.......90..r...D..S......:......X..A,-bdc.3.(D.n._0.[r.....,..F\.k.....)...Q+k.G.....8....Y,.7.gS...C...u....;u|.pvX
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):836937
                  Entropy (8bit):7.999773957332884
                  Encrypted:true
                  SSDEEP:
                  MD5:E7500D240D9D05C989F402C70091FF18
                  SHA1:FD74465A4E706767C304B6B9ACA980F53B0438B3
                  SHA-256:60EE2A9EA5426DCDF97BD8BA28A4F6E8CBF792AA88E884CD7B6CABBE6BA9E219
                  SHA-512:069CD2DBDDEE003EA4A0A385E3B0CE57CDF8F8FCEA6271386AA611B8A2E7A4AF8205D7B01185976F0B4DC0991B4FB0E1CC586CE6305A0602ABBA25212D9A74CB
                  Malicious:true
                  Preview:%......9.g"......."Y.\.O.$.%'....-..j"...zW2.n.l..9.7.......#...b@4..2.... ..}.....\.P.'....u......A...........t...7$(..3....EGZ].P.%9....R.J.F...0.e...V...{..5....'...z....8.\.+..'...<...{..u.=..9S.o..Adk...(/}$t..Gt..q.*....%......[....t....D..2.?...D..6.e...Xd........E..rw:.#.(.....(..Q.[.._g...I...cw.,5..`...Lr.JZ...F[..Y9.?R..".-._.u.o...j.......X....k{...3.G..O.....P.ky.......r.![.!\<'..#r......#...n}.X.HD.Yd-......g.........MX.q...Q...%.N..)_A.......M...p...Yff...+T~..........-TK...BK...d..I...\V..A......qZ.P..<y..-.*.-..1..D.=T9...l}.tfw.+1.r....#B....FF..U...A..|..O."...H.K$T..\.T..e........!.FP@*.#.)*.......l.*F.._..V.....2.;...51....S..a:f".......y.n".....cw.....Q.(......4u....R.>...n..Q.._.=a..{.....%...z....(...z.7......dY|.tO..?y_z.d.....,....|..^.j[k.....p.E.b]bI...E7k.Y`@....:.U3n..SEF..rbZ..._Vd.I3..F....J.......90..r...D..S......:......X..A,-bdc.3.(D.n._0.[r.....,..F\.k.....)...Q+k.G.....8....Y,.7.gS...C...u....;u|.pvX
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):836937
                  Entropy (8bit):7.999773957332884
                  Encrypted:true
                  SSDEEP:
                  MD5:E7500D240D9D05C989F402C70091FF18
                  SHA1:FD74465A4E706767C304B6B9ACA980F53B0438B3
                  SHA-256:60EE2A9EA5426DCDF97BD8BA28A4F6E8CBF792AA88E884CD7B6CABBE6BA9E219
                  SHA-512:069CD2DBDDEE003EA4A0A385E3B0CE57CDF8F8FCEA6271386AA611B8A2E7A4AF8205D7B01185976F0B4DC0991B4FB0E1CC586CE6305A0602ABBA25212D9A74CB
                  Malicious:true
                  Preview:%......9.g"......."Y.\.O.$.%'....-..j"...zW2.n.l..9.7.......#...b@4..2.... ..}.....\.P.'....u......A...........t...7$(..3....EGZ].P.%9....R.J.F...0.e...V...{..5....'...z....8.\.+..'...<...{..u.=..9S.o..Adk...(/}$t..Gt..q.*....%......[....t....D..2.?...D..6.e...Xd........E..rw:.#.(.....(..Q.[.._g...I...cw.,5..`...Lr.JZ...F[..Y9.?R..".-._.u.o...j.......X....k{...3.G..O.....P.ky.......r.![.!\<'..#r......#...n}.X.HD.Yd-......g.........MX.q...Q...%.N..)_A.......M...p...Yff...+T~..........-TK...BK...d..I...\V..A......qZ.P..<y..-.*.-..1..D.=T9...l}.tfw.+1.r....#B....FF..U...A..|..O."...H.K$T..\.T..e........!.FP@*.#.)*.......l.*F.._..V.....2.;...51....S..a:f".......y.n".....cw.....Q.(......4u....R.>...n..Q.._.=a..{.....%...z....(...z.7......dY|.tO..?y_z.d.....,....|..^.j[k.....p.E.b]bI...E7k.Y`@....:.U3n..SEF..rbZ..._Vd.I3..F....J.......90..r...D..S......:......X..A,-bdc.3.(D.n._0.[r.....,..F\.k.....)...Q+k.G.....8....Y,.7.gS...C...u....;u|.pvX
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):377278
                  Entropy (8bit):7.99945442924692
                  Encrypted:true
                  SSDEEP:
                  MD5:F90F1DFF16E97C44AE948716C75CC804
                  SHA1:80520C0E4081ADF53E3F28756105A27F4D137CA0
                  SHA-256:4B19C1EF65D9B295E44721E1425FF5110B5A1C360F9E5079B614729412F1328B
                  SHA-512:861B0EA401899CB5C51006578A3417E9C7BC07C590F5B3E6129B0DC8120A2A70800A6489ADCBCDAF31C4AB5985F13C8306DB598DF97E0E73A3ED24C761109A1F
                  Malicious:true
                  Preview:...v.,.s....1...y...HnO..T..WW1.M.v.~S-@.....f.c.._~Ys:L.. .".....i.x.8LS.M....R.Hbl.QoWHq....gXM.......7.M.;.V.][.G.......$>v...:.Xa..k...q.y.)..sn.. ).6.p.nq.Ke.5>Y'./.FC/:..4.0.S/.Ch...p~.)(..vD...s...Wq".p/C}.....KX.#.].j~...-........t.._.}>.K.J..AF..C.........&%p...L.e....?..tM...,....].aJ...9.....X>...S..p0..P.G}..u..I.MS.T\M....2.$.B.S6.W`5..(8.Vk....o...u=..TT...z..3I..4.&8.J..=y.r..k[rP..i....R.\GV/I...Y.Ip...S..oO(.s..5..v...e...V.v....9..7.{{..9 ...R!s....0.z....XC....g...^......../.>.>......bT#.........iP...^..}i....i...r.mL...c....P..../j^5........-YYz...^.!..N.1...9#].WU....T.*...s...v..D1.*8"B..U@jy..3cv.}.E.et.%..,....Nw...sB,=.....Q#5.J..r!.0v3..@....H)F$..#.....C..z...b.9..........8.z..r2..P..\].'....4(j..z....#.}=.}.*.u......;Z....d...+=.....l..e.ms$"d....4....uj.`$..h...e.Bq.V6.?..L4.<7.j.JI<:...e..//b!._...sh...~D...D....'b.............Z}........H.cg.4..l..W..[.0.....%?....+i\...}z..V^.d@.Z}^.SP.%.U.... mU
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):377278
                  Entropy (8bit):7.99945442924692
                  Encrypted:true
                  SSDEEP:
                  MD5:F90F1DFF16E97C44AE948716C75CC804
                  SHA1:80520C0E4081ADF53E3F28756105A27F4D137CA0
                  SHA-256:4B19C1EF65D9B295E44721E1425FF5110B5A1C360F9E5079B614729412F1328B
                  SHA-512:861B0EA401899CB5C51006578A3417E9C7BC07C590F5B3E6129B0DC8120A2A70800A6489ADCBCDAF31C4AB5985F13C8306DB598DF97E0E73A3ED24C761109A1F
                  Malicious:true
                  Preview:...v.,.s....1...y...HnO..T..WW1.M.v.~S-@.....f.c.._~Ys:L.. .".....i.x.8LS.M....R.Hbl.QoWHq....gXM.......7.M.;.V.][.G.......$>v...:.Xa..k...q.y.)..sn.. ).6.p.nq.Ke.5>Y'./.FC/:..4.0.S/.Ch...p~.)(..vD...s...Wq".p/C}.....KX.#.].j~...-........t.._.}>.K.J..AF..C.........&%p...L.e....?..tM...,....].aJ...9.....X>...S..p0..P.G}..u..I.MS.T\M....2.$.B.S6.W`5..(8.Vk....o...u=..TT...z..3I..4.&8.J..=y.r..k[rP..i....R.\GV/I...Y.Ip...S..oO(.s..5..v...e...V.v....9..7.{{..9 ...R!s....0.z....XC....g...^......../.>.>......bT#.........iP...^..}i....i...r.mL...c....P..../j^5........-YYz...^.!..N.1...9#].WU....T.*...s...v..D1.*8"B..U@jy..3cv.}.E.et.%..,....Nw...sB,=.....Q#5.J..r!.0v3..@....H)F$..#.....C..z...b.9..........8.z..r2..P..\].'....4(j..z....#.}=.}.*.u......;Z....d...+=.....l..e.ms$"d....4....uj.`$..h...e.Bq.V6.?..L4.<7.j.JI<:...e..//b!._...sh...~D...D....'b.............Z}........H.cg.4..l..W..[.0.....%?....+i\...}z..V^.d@.Z}^.SP.%.U.... mU
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):377278
                  Entropy (8bit):7.99945442924692
                  Encrypted:true
                  SSDEEP:
                  MD5:F90F1DFF16E97C44AE948716C75CC804
                  SHA1:80520C0E4081ADF53E3F28756105A27F4D137CA0
                  SHA-256:4B19C1EF65D9B295E44721E1425FF5110B5A1C360F9E5079B614729412F1328B
                  SHA-512:861B0EA401899CB5C51006578A3417E9C7BC07C590F5B3E6129B0DC8120A2A70800A6489ADCBCDAF31C4AB5985F13C8306DB598DF97E0E73A3ED24C761109A1F
                  Malicious:true
                  Preview:...v.,.s....1...y...HnO..T..WW1.M.v.~S-@.....f.c.._~Ys:L.. .".....i.x.8LS.M....R.Hbl.QoWHq....gXM.......7.M.;.V.][.G.......$>v...:.Xa..k...q.y.)..sn.. ).6.p.nq.Ke.5>Y'./.FC/:..4.0.S/.Ch...p~.)(..vD...s...Wq".p/C}.....KX.#.].j~...-........t.._.}>.K.J..AF..C.........&%p...L.e....?..tM...,....].aJ...9.....X>...S..p0..P.G}..u..I.MS.T\M....2.$.B.S6.W`5..(8.Vk....o...u=..TT...z..3I..4.&8.J..=y.r..k[rP..i....R.\GV/I...Y.Ip...S..oO(.s..5..v...e...V.v....9..7.{{..9 ...R!s....0.z....XC....g...^......../.>.>......bT#.........iP...^..}i....i...r.mL...c....P..../j^5........-YYz...^.!..N.1...9#].WU....T.*...s...v..D1.*8"B..U@jy..3cv.}.E.et.%..,....Nw...sB,=.....Q#5.J..r!.0v3..@....H)F$..#.....C..z...b.9..........8.z..r2..P..\].'....4(j..z....#.}=.}.*.u......;Z....d...+=.....l..e.ms$"d....4....uj.`$..h...e.Bq.V6.?..L4.<7.j.JI<:...e..//b!._...sh...~D...D....'b.............Z}........H.cg.4..l..W..[.0.....%?....+i\...}z..V^.d@.Z}^.SP.%.U.... mU
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):380479
                  Entropy (8bit):7.999553489397753
                  Encrypted:true
                  SSDEEP:
                  MD5:CA7915AB244C6FCD85FF5350EE6CC88B
                  SHA1:D2280043DD18A8637823D978AD5C1045E73CC017
                  SHA-256:26ACC794B34B0C7143DC329C5CE344E8413C2EF871E205BB58014C3DDBB58667
                  SHA-512:CC9C0974A04C272A2C97353BA14EFCFE1A0725AF16155524AC2BBAA0D1C958769C0F84D059EA91F034D558BEB3765401DFCBC291DADAA3BDA382E2B0EF104B78
                  Malicious:true
                  Preview:\....U.....$...?..U.U.P...M...b..W.g..Q.Zv`%.._sBW3U..K..&!K.&(B..k......jxvAe.+S...|!v....7......;...act...OP.=...$..g.$v..M{O6..W.@./@:B`...Q....8.E.....-J..&Y..j.p..6...b...T.4D....m...(.t.d.-f.~.P..|..@....b.gm.....3&.),_..2..[....k4dp.....C.m.......Ld.G.L9v..yD....9....G4..y...7...t.L.e.,(:.\......-)-..T...4%..w...S.........U2..{8X.....at.$;]..!...t..X4..\.......#....b=Q.+..Ba...r.....@.p..hD.}F. ..8.(.._R/.WT...Fq(....>./.....,...:t....B?....m..+S..C.s,e.7....#.....q.8....">j.W...\..'0\;.............|z..G.&.#.~...s.k...f|......Z....ICL..r../..-.S.6..a80H..M~.8M.Cv4.gh..O....I..1*..t.c._.q./..H...]o.....{......1.G...K..... YeR.w.8.*..5u9$...SD.1..gIO...0T6..|...a.k1B..S.....I. .=E.]......<u.......g.i...B........f.,N..7..4..S4....)..x.T.^.M...%'..E.#..m..M..Z.8M.i... ..r.F.J.K.. .z..]..GR.C{.......?<1.?:>.Gc.*......`...8....Y..B......9..~....... .l....b.wt.....c....d...$ .-....3`...[...)...ms..3...021.H.1T...a.h{r....:...@...[.W..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):380479
                  Entropy (8bit):7.999553489397753
                  Encrypted:true
                  SSDEEP:
                  MD5:CA7915AB244C6FCD85FF5350EE6CC88B
                  SHA1:D2280043DD18A8637823D978AD5C1045E73CC017
                  SHA-256:26ACC794B34B0C7143DC329C5CE344E8413C2EF871E205BB58014C3DDBB58667
                  SHA-512:CC9C0974A04C272A2C97353BA14EFCFE1A0725AF16155524AC2BBAA0D1C958769C0F84D059EA91F034D558BEB3765401DFCBC291DADAA3BDA382E2B0EF104B78
                  Malicious:true
                  Preview:\....U.....$...?..U.U.P...M...b..W.g..Q.Zv`%.._sBW3U..K..&!K.&(B..k......jxvAe.+S...|!v....7......;...act...OP.=...$..g.$v..M{O6..W.@./@:B`...Q....8.E.....-J..&Y..j.p..6...b...T.4D....m...(.t.d.-f.~.P..|..@....b.gm.....3&.),_..2..[....k4dp.....C.m.......Ld.G.L9v..yD....9....G4..y...7...t.L.e.,(:.\......-)-..T...4%..w...S.........U2..{8X.....at.$;]..!...t..X4..\.......#....b=Q.+..Ba...r.....@.p..hD.}F. ..8.(.._R/.WT...Fq(....>./.....,...:t....B?....m..+S..C.s,e.7....#.....q.8....">j.W...\..'0\;.............|z..G.&.#.~...s.k...f|......Z....ICL..r../..-.S.6..a80H..M~.8M.Cv4.gh..O....I..1*..t.c._.q./..H...]o.....{......1.G...K..... YeR.w.8.*..5u9$...SD.1..gIO...0T6..|...a.k1B..S.....I. .=E.]......<u.......g.i...B........f.,N..7..4..S4....)..x.T.^.M...%'..E.#..m..M..Z.8M.i... ..r.F.J.K.. .z..]..GR.C{.......?<1.?:>.Gc.*......`...8....Y..B......9..~....... .l....b.wt.....c....d...$ .-....3`...[...)...ms..3...021.H.1T...a.h{r....:...@...[.W..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):380479
                  Entropy (8bit):7.999553489397753
                  Encrypted:true
                  SSDEEP:
                  MD5:CA7915AB244C6FCD85FF5350EE6CC88B
                  SHA1:D2280043DD18A8637823D978AD5C1045E73CC017
                  SHA-256:26ACC794B34B0C7143DC329C5CE344E8413C2EF871E205BB58014C3DDBB58667
                  SHA-512:CC9C0974A04C272A2C97353BA14EFCFE1A0725AF16155524AC2BBAA0D1C958769C0F84D059EA91F034D558BEB3765401DFCBC291DADAA3BDA382E2B0EF104B78
                  Malicious:true
                  Preview:\....U.....$...?..U.U.P...M...b..W.g..Q.Zv`%.._sBW3U..K..&!K.&(B..k......jxvAe.+S...|!v....7......;...act...OP.=...$..g.$v..M{O6..W.@./@:B`...Q....8.E.....-J..&Y..j.p..6...b...T.4D....m...(.t.d.-f.~.P..|..@....b.gm.....3&.),_..2..[....k4dp.....C.m.......Ld.G.L9v..yD....9....G4..y...7...t.L.e.,(:.\......-)-..T...4%..w...S.........U2..{8X.....at.$;]..!...t..X4..\.......#....b=Q.+..Ba...r.....@.p..hD.}F. ..8.(.._R/.WT...Fq(....>./.....,...:t....B?....m..+S..C.s,e.7....#.....q.8....">j.W...\..'0\;.............|z..G.&.#.~...s.k...f|......Z....ICL..r../..-.S.6..a80H..M~.8M.Cv4.gh..O....I..1*..t.c._.q./..H...]o.....{......1.G...K..... YeR.w.8.*..5u9$...SD.1..gIO...0T6..|...a.k1B..S.....I. .=E.]......<u.......g.i...B........f.,N..7..4..S4....)..x.T.^.M...%'..E.#..m..M..Z.8M.i... ..r.F.J.K.. .z..]..GR.C{.......?<1.?:>.Gc.*......`...8....Y..B......9..~....... .l....b.wt.....c....d...$ .-....3`...[...)...ms..3...021.H.1T...a.h{r....:...@...[.W..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):460548
                  Entropy (8bit):7.999634306392023
                  Encrypted:true
                  SSDEEP:
                  MD5:639206EB654AB46B0139FACBBFE70781
                  SHA1:EAE8226D04D0105E5014663C0BB2DC093E4B8197
                  SHA-256:A30E9C9800A8DB6FC49D1BA06D53F574721E3FD49544BD48D60FA6DFEC91F27B
                  SHA-512:B56AEAE588FA41121AA695C040474F8FE33E15378E26F1F6D875D1435DC24BAC35F7CB585986B777DEDF83379A052F0AC37FA9A44EA31E2F012DC1B75AAC6AA7
                  Malicious:true
                  Preview:. Fjh........m..........i.....l<..._K.Mk.(.C..9]8.R.G^.^......@.n...a..>E....^..J.{...nW..aRJ+.Y.......uX_.N{.xL+.JQD'."W.BlNa..\.@6YZ...$....y..?...2.~..y.l="...D..K...V.j....%.I(.....4...+y.....i.c...].0L.,M..Az;}...G.........(Dy..O6...8..SL...q[.e.5.jYQ.D\v.y.....[E..dw.la........M.&YD...{.Q...,_>&y.....A.v/..R..`.\V..).-..8.eGH.Sy.h..V...h.e..jA.x..$.Q!..D...KJKu.#...t!..BS.&..e.?.i./\...^J........#...>.......<....b.....O(.|...z.Jo....u..fuNlz;..p.!.1or..|.Y....m..._.HW..Viv....K`..Z..F.b....@.+&,z....<.E.c....k..f.i..}._.gA..9...s.>X...4.!..*o.z?l.x..tb...q....%.s..$...z@v.$.Jlj.*5[...c.....{.#..!..o....Y-..p.&p...........G....w[..[........9wa...8F.L._i."...,.@f..+........j$..h.....'.J.....7...F.......#.+...Y.L.;...P.k9b=....4u......=...E._R.q.k.....a..dP..|Q.V...._.....L}.B.+.#.!...Y..[Q9.o.i4{G.,L....)..D...IM..N0.12.....v,?n.....rZ.M.;.p..........kFz.s...3.ssJW5@...q8H..w.........q.. ...F.2J5V......:.D..Yr.<......,.R.:.B-O.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):460548
                  Entropy (8bit):7.999634306392023
                  Encrypted:true
                  SSDEEP:
                  MD5:639206EB654AB46B0139FACBBFE70781
                  SHA1:EAE8226D04D0105E5014663C0BB2DC093E4B8197
                  SHA-256:A30E9C9800A8DB6FC49D1BA06D53F574721E3FD49544BD48D60FA6DFEC91F27B
                  SHA-512:B56AEAE588FA41121AA695C040474F8FE33E15378E26F1F6D875D1435DC24BAC35F7CB585986B777DEDF83379A052F0AC37FA9A44EA31E2F012DC1B75AAC6AA7
                  Malicious:true
                  Preview:. Fjh........m..........i.....l<..._K.Mk.(.C..9]8.R.G^.^......@.n...a..>E....^..J.{...nW..aRJ+.Y.......uX_.N{.xL+.JQD'."W.BlNa..\.@6YZ...$....y..?...2.~..y.l="...D..K...V.j....%.I(.....4...+y.....i.c...].0L.,M..Az;}...G.........(Dy..O6...8..SL...q[.e.5.jYQ.D\v.y.....[E..dw.la........M.&YD...{.Q...,_>&y.....A.v/..R..`.\V..).-..8.eGH.Sy.h..V...h.e..jA.x..$.Q!..D...KJKu.#...t!..BS.&..e.?.i./\...^J........#...>.......<....b.....O(.|...z.Jo....u..fuNlz;..p.!.1or..|.Y....m..._.HW..Viv....K`..Z..F.b....@.+&,z....<.E.c....k..f.i..}._.gA..9...s.>X...4.!..*o.z?l.x..tb...q....%.s..$...z@v.$.Jlj.*5[...c.....{.#..!..o....Y-..p.&p...........G....w[..[........9wa...8F.L._i."...,.@f..+........j$..h.....'.J.....7...F.......#.+...Y.L.;...P.k9b=....4u......=...E._R.q.k.....a..dP..|Q.V...._.....L}.B.+.#.!...Y..[Q9.o.i4{G.,L....)..D...IM..N0.12.....v,?n.....rZ.M.;.p..........kFz.s...3.ssJW5@...q8H..w.........q.. ...F.2J5V......:.D..Yr.<......,.R.:.B-O.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):460548
                  Entropy (8bit):7.999634306392023
                  Encrypted:true
                  SSDEEP:
                  MD5:639206EB654AB46B0139FACBBFE70781
                  SHA1:EAE8226D04D0105E5014663C0BB2DC093E4B8197
                  SHA-256:A30E9C9800A8DB6FC49D1BA06D53F574721E3FD49544BD48D60FA6DFEC91F27B
                  SHA-512:B56AEAE588FA41121AA695C040474F8FE33E15378E26F1F6D875D1435DC24BAC35F7CB585986B777DEDF83379A052F0AC37FA9A44EA31E2F012DC1B75AAC6AA7
                  Malicious:true
                  Preview:. Fjh........m..........i.....l<..._K.Mk.(.C..9]8.R.G^.^......@.n...a..>E....^..J.{...nW..aRJ+.Y.......uX_.N{.xL+.JQD'."W.BlNa..\.@6YZ...$....y..?...2.~..y.l="...D..K...V.j....%.I(.....4...+y.....i.c...].0L.,M..Az;}...G.........(Dy..O6...8..SL...q[.e.5.jYQ.D\v.y.....[E..dw.la........M.&YD...{.Q...,_>&y.....A.v/..R..`.\V..).-..8.eGH.Sy.h..V...h.e..jA.x..$.Q!..D...KJKu.#...t!..BS.&..e.?.i./\...^J........#...>.......<....b.....O(.|...z.Jo....u..fuNlz;..p.!.1or..|.Y....m..._.HW..Viv....K`..Z..F.b....@.+&,z....<.E.c....k..f.i..}._.gA..9...s.>X...4.!..*o.z?l.x..tb...q....%.s..$...z@v.$.Jlj.*5[...c.....{.#..!..o....Y-..p.&p...........G....w[..[........9wa...8F.L._i."...,.@f..+........j$..h.....'.J.....7...F.......#.+...Y.L.;...P.k9b=....4u......=...E._R.q.k.....a..dP..|Q.V...._.....L}.B.+.#.!...Y..[Q9.o.i4{G.,L....)..D...IM..N0.12.....v,?n.....rZ.M.;.p..........kFz.s...3.ssJW5@...q8H..w.........q.. ...F.2J5V......:.D..Yr.<......,.R.:.B-O.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):459982
                  Entropy (8bit):7.999581264737792
                  Encrypted:true
                  SSDEEP:
                  MD5:4A62945D148703DC4C3485FBA12F6114
                  SHA1:82AB8F97632C1E37B42CA77396C8616BEB72ACBC
                  SHA-256:B03E10FE2D21C6D82B5849DE44170ECE56412EBD3C61F459CAFC38D47DF55962
                  SHA-512:5C35594282EEB0808B4FC6E9C2AC80D0BDAA3BAFB979B68A48BB7FC0B8A3938D2C956E0A589DF89C2081631935B96C2396CA5AEE2C17495DB4EA1CD3E680EA91
                  Malicious:true
                  Preview:].7......j..........|#.?...S......^V..+..(..U..S.).OOV.Vy_..t.;.....~t..v..Z..X...6.2..S.bifH)....Q..........U.F....Z#..).9...w.!...5..q..>s..|Q.{j..r({..........~.....-.V.h...`.n..H.....Vc..M."...e.p)1#.a......u(...Eb.......Tt..}...(Q.]ENE6.#J:..W..B....F_...w...v.....5..H...........RY.MI....`.....=...np._C.e>4...g.E.=.0......S+zA@kb-....}&W."z.!.P6.N...d.S..S9w.+a..'.....i..89.N......B.h....cd4......h..G.g.r.=.u5<...t..Y8|E..=.|I.5.T._.b_.9._....o.K.\..yP\.+.ul....1g...,.....R+~.O..}...8.,U....HbM.....N.E...K%N.L$.&p...A'.....u..&........`"...(...R..3.r..... ]..0.8.=t.j..#..{.Q.w......c.i..n..n..Q.....qvE0.....,./.....7.4w.......`.\.....%..`]........&...}.D]..'+i..._..|..............?...L.U......i1...Q...A.`..*..3..0..J[#EV.Y..".....c/..|qVF=1\f.G.3...!.....'AG..K......,...y$.k.........U..-.E@.G.*z.{...g.#[b$4.....J....|..2.v..P.v...>..'......|.P.}........}....I=U=...E...|7`9.e.#KX...H.q.Y.',=...Wb?...\..........-.}....O.BeH......bG.v.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):459982
                  Entropy (8bit):7.999581264737792
                  Encrypted:true
                  SSDEEP:
                  MD5:4A62945D148703DC4C3485FBA12F6114
                  SHA1:82AB8F97632C1E37B42CA77396C8616BEB72ACBC
                  SHA-256:B03E10FE2D21C6D82B5849DE44170ECE56412EBD3C61F459CAFC38D47DF55962
                  SHA-512:5C35594282EEB0808B4FC6E9C2AC80D0BDAA3BAFB979B68A48BB7FC0B8A3938D2C956E0A589DF89C2081631935B96C2396CA5AEE2C17495DB4EA1CD3E680EA91
                  Malicious:true
                  Preview:].7......j..........|#.?...S......^V..+..(..U..S.).OOV.Vy_..t.;.....~t..v..Z..X...6.2..S.bifH)....Q..........U.F....Z#..).9...w.!...5..q..>s..|Q.{j..r({..........~.....-.V.h...`.n..H.....Vc..M."...e.p)1#.a......u(...Eb.......Tt..}...(Q.]ENE6.#J:..W..B....F_...w...v.....5..H...........RY.MI....`.....=...np._C.e>4...g.E.=.0......S+zA@kb-....}&W."z.!.P6.N...d.S..S9w.+a..'.....i..89.N......B.h....cd4......h..G.g.r.=.u5<...t..Y8|E..=.|I.5.T._.b_.9._....o.K.\..yP\.+.ul....1g...,.....R+~.O..}...8.,U....HbM.....N.E...K%N.L$.&p...A'.....u..&........`"...(...R..3.r..... ]..0.8.=t.j..#..{.Q.w......c.i..n..n..Q.....qvE0.....,./.....7.4w.......`.\.....%..`]........&...}.D]..'+i..._..|..............?...L.U......i1...Q...A.`..*..3..0..J[#EV.Y..".....c/..|qVF=1\f.G.3...!.....'AG..K......,...y$.k.........U..-.E@.G.*z.{...g.#[b$4.....J....|..2.v..P.v...>..'......|.P.}........}....I=U=...E...|7`9.e.#KX...H.q.Y.',=...Wb?...\..........-.}....O.BeH......bG.v.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):459982
                  Entropy (8bit):7.999581264737792
                  Encrypted:true
                  SSDEEP:
                  MD5:4A62945D148703DC4C3485FBA12F6114
                  SHA1:82AB8F97632C1E37B42CA77396C8616BEB72ACBC
                  SHA-256:B03E10FE2D21C6D82B5849DE44170ECE56412EBD3C61F459CAFC38D47DF55962
                  SHA-512:5C35594282EEB0808B4FC6E9C2AC80D0BDAA3BAFB979B68A48BB7FC0B8A3938D2C956E0A589DF89C2081631935B96C2396CA5AEE2C17495DB4EA1CD3E680EA91
                  Malicious:true
                  Preview:].7......j..........|#.?...S......^V..+..(..U..S.).OOV.Vy_..t.;.....~t..v..Z..X...6.2..S.bifH)....Q..........U.F....Z#..).9...w.!...5..q..>s..|Q.{j..r({..........~.....-.V.h...`.n..H.....Vc..M."...e.p)1#.a......u(...Eb.......Tt..}...(Q.]ENE6.#J:..W..B....F_...w...v.....5..H...........RY.MI....`.....=...np._C.e>4...g.E.=.0......S+zA@kb-....}&W."z.!.P6.N...d.S..S9w.+a..'.....i..89.N......B.h....cd4......h..G.g.r.=.u5<...t..Y8|E..=.|I.5.T._.b_.9._....o.K.\..yP\.+.ul....1g...,.....R+~.O..}...8.,U....HbM.....N.E...K%N.L$.&p...A'.....u..&........`"...(...R..3.r..... ]..0.8.=t.j..#..{.Q.w......c.i..n..n..Q.....qvE0.....,./.....7.4w.......`.\.....%..`]........&...}.D]..'+i..._..|..............?...L.U......i1...Q...A.`..*..3..0..J[#EV.Y..".....c/..|qVF=1\f.G.3...!.....'AG..K......,...y$.k.........U..-.E@.G.*z.{...g.#[b$4.....J....|..2.v..P.v...>..'......|.P.}........}....I=U=...E...|7`9.e.#KX...H.q.Y.',=...Wb?...\..........-.}....O.BeH......bG.v.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):417725
                  Entropy (8bit):7.999552933510088
                  Encrypted:true
                  SSDEEP:
                  MD5:31E541407686B8AEC03978CE00273A16
                  SHA1:DF34A0B334A49251841CBA7EA1F5D07BF28F588D
                  SHA-256:AF6340070013154904678F7F982D75C3997CA857B83414ECD23078EB86570554
                  SHA-512:C1A28A487A3E7A1F4539C111413C9008EBD8A0C48B523BDC124F8A67751722DEAA8AC44667A0EB99BCFA7F9C5B1A45DFD3D2DBFB70387FE142464817A21C04D0
                  Malicious:true
                  Preview:.w.'..yf.F...,....@j.Jr.O.]k...`1v.f.[fl......R...d.p......h)....l2j.,."..Q.7.n..X.m.8.UP|}.%`X......h...l.S.+..)..w..D9.....g.ct..X$)....8........v.y..Q_..y...0,=x.H!..f...!..K.2...R....v....).*....N..Z. i..f.N..:h...A..9..".'./..&...M%C0.........Rs..D..9..w..T ....>fDT...c\.......3... v-H..Gt.E...G4...+\........b#.9M5.. c$V...T.f_)..N@V.p*.i.......fS1/..:[..~f."b2........(.s.s.../?H..k.j.'..?.L...w{........S.DH..9.. f;....-.G..u....X N.....Z.2.....f."H.}..h...Ro...L[.WYm.b..f.T.v..$<.|.o^.....@...~...h0..._zf1qR.L...~...,.(.[K...*.h.....8...=B....Jmy...V...ux.....V.8u..T4.Ew...j........oi.i...1o.).7...\.....#.Q>.Pf...a.&_rN....e.*......ISw.D\.V*.1..U.........s..LMK.<]S.<h9.i..q.}.w..x'...B.a3\...x.0.!x}I,.w.s...mC...s..B=......c.].%c..D..........="..U..@p.._....Bm.P.I..k...ARs.....y..(W7....*..... ~.T}...u..I...\.....W....*.z\.Tey.q...M@`{B... .>..tcZ...N....h.......t}y.c..5q.OD...i.g_.=3.:#"..B.p ...)0].......nO`......usvjc4.....Y..._.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):417725
                  Entropy (8bit):7.999552933510088
                  Encrypted:true
                  SSDEEP:
                  MD5:31E541407686B8AEC03978CE00273A16
                  SHA1:DF34A0B334A49251841CBA7EA1F5D07BF28F588D
                  SHA-256:AF6340070013154904678F7F982D75C3997CA857B83414ECD23078EB86570554
                  SHA-512:C1A28A487A3E7A1F4539C111413C9008EBD8A0C48B523BDC124F8A67751722DEAA8AC44667A0EB99BCFA7F9C5B1A45DFD3D2DBFB70387FE142464817A21C04D0
                  Malicious:true
                  Preview:.w.'..yf.F...,....@j.Jr.O.]k...`1v.f.[fl......R...d.p......h)....l2j.,."..Q.7.n..X.m.8.UP|}.%`X......h...l.S.+..)..w..D9.....g.ct..X$)....8........v.y..Q_..y...0,=x.H!..f...!..K.2...R....v....).*....N..Z. i..f.N..:h...A..9..".'./..&...M%C0.........Rs..D..9..w..T ....>fDT...c\.......3... v-H..Gt.E...G4...+\........b#.9M5.. c$V...T.f_)..N@V.p*.i.......fS1/..:[..~f."b2........(.s.s.../?H..k.j.'..?.L...w{........S.DH..9.. f;....-.G..u....X N.....Z.2.....f."H.}..h...Ro...L[.WYm.b..f.T.v..$<.|.o^.....@...~...h0..._zf1qR.L...~...,.(.[K...*.h.....8...=B....Jmy...V...ux.....V.8u..T4.Ew...j........oi.i...1o.).7...\.....#.Q>.Pf...a.&_rN....e.*......ISw.D\.V*.1..U.........s..LMK.<]S.<h9.i..q.}.w..x'...B.a3\...x.0.!x}I,.w.s...mC...s..B=......c.].%c..D..........="..U..@p.._....Bm.P.I..k...ARs.....y..(W7....*..... ~.T}...u..I...\.....W....*.z\.Tey.q...M@`{B... .>..tcZ...N....h.......t}y.c..5q.OD...i.g_.=3.:#"..B.p ...)0].......nO`......usvjc4.....Y..._.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):417725
                  Entropy (8bit):7.999552933510088
                  Encrypted:true
                  SSDEEP:
                  MD5:31E541407686B8AEC03978CE00273A16
                  SHA1:DF34A0B334A49251841CBA7EA1F5D07BF28F588D
                  SHA-256:AF6340070013154904678F7F982D75C3997CA857B83414ECD23078EB86570554
                  SHA-512:C1A28A487A3E7A1F4539C111413C9008EBD8A0C48B523BDC124F8A67751722DEAA8AC44667A0EB99BCFA7F9C5B1A45DFD3D2DBFB70387FE142464817A21C04D0
                  Malicious:true
                  Preview:.w.'..yf.F...,....@j.Jr.O.]k...`1v.f.[fl......R...d.p......h)....l2j.,."..Q.7.n..X.m.8.UP|}.%`X......h...l.S.+..)..w..D9.....g.ct..X$)....8........v.y..Q_..y...0,=x.H!..f...!..K.2...R....v....).*....N..Z. i..f.N..:h...A..9..".'./..&...M%C0.........Rs..D..9..w..T ....>fDT...c\.......3... v-H..Gt.E...G4...+\........b#.9M5.. c$V...T.f_)..N@V.p*.i.......fS1/..:[..~f."b2........(.s.s.../?H..k.j.'..?.L...w{........S.DH..9.. f;....-.G..u....X N.....Z.2.....f."H.}..h...Ro...L[.WYm.b..f.T.v..$<.|.o^.....@...~...h0..._zf1qR.L...~...,.(.[K...*.h.....8...=B....Jmy...V...ux.....V.8u..T4.Ew...j........oi.i...1o.).7...\.....#.Q>.Pf...a.&_rN....e.*......ISw.D\.V*.1..U.........s..LMK.<]S.<h9.i..q.}.w..x'...B.a3\...x.0.!x}I,.w.s...mC...s..B=......c.].%c..D..........="..U..@p.._....Bm.P.I..k...ARs.....y..(W7....*..... ~.T}...u..I...\.....W....*.z\.Tey.q...M@`{B... .>..tcZ...N....h.......t}y.c..5q.OD...i.g_.=3.:#"..B.p ...)0].......nO`......usvjc4.....Y..._.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):679778
                  Entropy (8bit):7.999738000246909
                  Encrypted:true
                  SSDEEP:
                  MD5:FC2D3BA86579AEB2AE2C544894080331
                  SHA1:DCCBD421795D167C870CE1B29B45673BB5A5DDE9
                  SHA-256:F492C5BBF4333C68C63D7C0A6F4214970D05F75786B36903DB1E6D7A97861D0F
                  SHA-512:D15B48D8486956043C1E9DC20EFE7EAF529C9C22348661C72C3B5C84B8B4BE71E34D332722CDEFD9C78AC80B820F5E04B2AD9ABA84ADFC67C86992031AABF5AA
                  Malicious:true
                  Preview:..@wo.....M3.7...l4.;o......Rl..yS.s..`<......bC....c..D.F.:Mf...%LT..i...xVd..........7..k.,.x.GvS.d...m.B.w.....e....k.P..b.p..,..WS`Nv-^wE..7U........(E....{.{T_uC.I.|f...s.c....+..o...1..6..s.....c..1V!.`.t`..F~....{6..{.FgJo.y....E.."......7...f......\./P...@....=|.0;..Z~...(..zY<)p.'u....xec.X..FW..0..a1...+.....fA(...t}...c...yO..,f..l.2z.R..A.....%.F.K.#.jb..F.P...;./..;...c....8....A..........z..I...-..Kg>.gA)..2..B.7J......9..)....A+....U$..>.>...$EKA.$SS....G.Sn.I....."$*6...9.=.......Fw.|.a'J..Y"...{..........G.8huA..&.p.J...%..=.@...Gh.+...M.R...z..u.J...(F.`H..,@.2<.E.j...mOE...8..u...ToA....9..K^..<....Sx...j.]...s........<J..|..G...0~.....N..9]...>........1.|O..F.Q5.NY.J.....Wk....=..5...M..%_.e,.oh...kc.b..X..V./...8Y}..S..n`7.;W.+2R3...<.g.Hb...(...d..4.MI.t....a.`.*).....|....V.../O...V..y.]..Z...Vsh...C..c.gU.W..'......-O[..A.[...{I.g..9..3.T.v.......M....,.=.j......x.4JJ?.Y...%.j.. .............a...EV...A.o..PP
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):679778
                  Entropy (8bit):7.999738000246909
                  Encrypted:true
                  SSDEEP:
                  MD5:FC2D3BA86579AEB2AE2C544894080331
                  SHA1:DCCBD421795D167C870CE1B29B45673BB5A5DDE9
                  SHA-256:F492C5BBF4333C68C63D7C0A6F4214970D05F75786B36903DB1E6D7A97861D0F
                  SHA-512:D15B48D8486956043C1E9DC20EFE7EAF529C9C22348661C72C3B5C84B8B4BE71E34D332722CDEFD9C78AC80B820F5E04B2AD9ABA84ADFC67C86992031AABF5AA
                  Malicious:true
                  Preview:..@wo.....M3.7...l4.;o......Rl..yS.s..`<......bC....c..D.F.:Mf...%LT..i...xVd..........7..k.,.x.GvS.d...m.B.w.....e....k.P..b.p..,..WS`Nv-^wE..7U........(E....{.{T_uC.I.|f...s.c....+..o...1..6..s.....c..1V!.`.t`..F~....{6..{.FgJo.y....E.."......7...f......\./P...@....=|.0;..Z~...(..zY<)p.'u....xec.X..FW..0..a1...+.....fA(...t}...c...yO..,f..l.2z.R..A.....%.F.K.#.jb..F.P...;./..;...c....8....A..........z..I...-..Kg>.gA)..2..B.7J......9..)....A+....U$..>.>...$EKA.$SS....G.Sn.I....."$*6...9.=.......Fw.|.a'J..Y"...{..........G.8huA..&.p.J...%..=.@...Gh.+...M.R...z..u.J...(F.`H..,@.2<.E.j...mOE...8..u...ToA....9..K^..<....Sx...j.]...s........<J..|..G...0~.....N..9]...>........1.|O..F.Q5.NY.J.....Wk....=..5...M..%_.e,.oh...kc.b..X..V./...8Y}..S..n`7.;W.+2R3...<.g.Hb...(...d..4.MI.t....a.`.*).....|....V.../O...V..y.]..Z...Vsh...C..c.gU.W..'......-O[..A.[...{I.g..9..3.T.v.......M....,.=.j......x.4JJ?.Y...%.j.. .............a...EV...A.o..PP
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):679778
                  Entropy (8bit):7.999738000246909
                  Encrypted:true
                  SSDEEP:
                  MD5:FC2D3BA86579AEB2AE2C544894080331
                  SHA1:DCCBD421795D167C870CE1B29B45673BB5A5DDE9
                  SHA-256:F492C5BBF4333C68C63D7C0A6F4214970D05F75786B36903DB1E6D7A97861D0F
                  SHA-512:D15B48D8486956043C1E9DC20EFE7EAF529C9C22348661C72C3B5C84B8B4BE71E34D332722CDEFD9C78AC80B820F5E04B2AD9ABA84ADFC67C86992031AABF5AA
                  Malicious:true
                  Preview:..@wo.....M3.7...l4.;o......Rl..yS.s..`<......bC....c..D.F.:Mf...%LT..i...xVd..........7..k.,.x.GvS.d...m.B.w.....e....k.P..b.p..,..WS`Nv-^wE..7U........(E....{.{T_uC.I.|f...s.c....+..o...1..6..s.....c..1V!.`.t`..F~....{6..{.FgJo.y....E.."......7...f......\./P...@....=|.0;..Z~...(..zY<)p.'u....xec.X..FW..0..a1...+.....fA(...t}...c...yO..,f..l.2z.R..A.....%.F.K.#.jb..F.P...;./..;...c....8....A..........z..I...-..Kg>.gA)..2..B.7J......9..)....A+....U$..>.>...$EKA.$SS....G.Sn.I....."$*6...9.=.......Fw.|.a'J..Y"...{..........G.8huA..&.p.J...%..=.@...Gh.+...M.R...z..u.J...(F.`H..,@.2<.E.j...mOE...8..u...ToA....9..K^..<....Sx...j.]...s........<J..|..G...0~.....N..9]...>........1.|O..F.Q5.NY.J.....Wk....=..5...M..%_.e,.oh...kc.b..X..V./...8Y}..S..n`7.;W.+2R3...<.g.Hb...(...d..4.MI.t....a.`.*).....|....V.../O...V..y.]..Z...Vsh...C..c.gU.W..'......-O[..A.[...{I.g..9..3.T.v.......M....,.=.j......x.4JJ?.Y...%.j.. .............a...EV...A.o..PP
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):424158
                  Entropy (8bit):7.999617809329608
                  Encrypted:true
                  SSDEEP:
                  MD5:7715AC357D4F1D64B5BA0CF2A747677A
                  SHA1:7FF8C981B34AB755EC00E8721AAA083E5B8D5A44
                  SHA-256:FDA090E7AD269BF4ACB001AEBA715208C49676CE1209112F01BA818C0EE462E4
                  SHA-512:F198865F0B2FC8DD35B0FCCDAE18B69356BBA1D31E132DC66480402D1346CCC01B4A68B33F6369C95C4BEA9A6B0BC93E2E4E9C61091E3330DED2A8A5FB6E3A81
                  Malicious:true
                  Preview:6...Nq............G....9.....MO.G#.|#.`.....P.Z...h.+.....Z.g.. .R..`....51.!f.U.j.FY;.y\...Mt...Bb.......U..a....@.M.o..u.......w..?...M@./...9..:.m.k..m...gJ.tM@...l..{.....V..Z.K.....Y4.Z....MR....[.i.".m.............Y7e.B^.......i..9q.51..k.8......w?H.n.Y.p.M#t..p....1....z"..f.;......mC.....]...^.?.M.)..l..`..8R.n.tW.C.[m..B.. ]..P...@..J0....\/..\q...3..n....T8.L.......U~-.L..Kw7r#u.....O..B..I.K..~...&..UHy...R...<f3..E..|1.j...a.v.n.2..$...u.1....Mf......&.Z.3.../3.!...J..O...3..|....3A.+......50.0H.(..{...5...^.?`7Y..Y....b|yMo#...ut.X......b?....u.x..S@....6..^O.5..Q.."R.>.3.0..ha....y.j.0.J....|...d.L/.!..;.c.p.1.s.U..~..{..V|...P.$...w............1S.vB}@.......[H7-|..e..;.....,R..i,.;.2.9.e.p..C..A..e`]....S_.J..8...6.....(;0.......l..X.32I....D....1..:5...@U..t.{&....._[.0.....V\.....3].X..X..z..C...8..v..z.O.....d..{.A..d....8.M... ..y.-.....eC.8..h...f1.2.)..l.Y.....f3...t....6.g.<hjO.,....v.....U|...Z....5.[....nL
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):424158
                  Entropy (8bit):7.999617809329608
                  Encrypted:true
                  SSDEEP:
                  MD5:7715AC357D4F1D64B5BA0CF2A747677A
                  SHA1:7FF8C981B34AB755EC00E8721AAA083E5B8D5A44
                  SHA-256:FDA090E7AD269BF4ACB001AEBA715208C49676CE1209112F01BA818C0EE462E4
                  SHA-512:F198865F0B2FC8DD35B0FCCDAE18B69356BBA1D31E132DC66480402D1346CCC01B4A68B33F6369C95C4BEA9A6B0BC93E2E4E9C61091E3330DED2A8A5FB6E3A81
                  Malicious:true
                  Preview:6...Nq............G....9.....MO.G#.|#.`.....P.Z...h.+.....Z.g.. .R..`....51.!f.U.j.FY;.y\...Mt...Bb.......U..a....@.M.o..u.......w..?...M@./...9..:.m.k..m...gJ.tM@...l..{.....V..Z.K.....Y4.Z....MR....[.i.".m.............Y7e.B^.......i..9q.51..k.8......w?H.n.Y.p.M#t..p....1....z"..f.;......mC.....]...^.?.M.)..l..`..8R.n.tW.C.[m..B.. ]..P...@..J0....\/..\q...3..n....T8.L.......U~-.L..Kw7r#u.....O..B..I.K..~...&..UHy...R...<f3..E..|1.j...a.v.n.2..$...u.1....Mf......&.Z.3.../3.!...J..O...3..|....3A.+......50.0H.(..{...5...^.?`7Y..Y....b|yMo#...ut.X......b?....u.x..S@....6..^O.5..Q.."R.>.3.0..ha....y.j.0.J....|...d.L/.!..;.c.p.1.s.U..~..{..V|...P.$...w............1S.vB}@.......[H7-|..e..;.....,R..i,.;.2.9.e.p..C..A..e`]....S_.J..8...6.....(;0.......l..X.32I....D....1..:5...@U..t.{&....._[.0.....V\.....3].X..X..z..C...8..v..z.O.....d..{.A..d....8.M... ..y.-.....eC.8..h...f1.2.)..l.Y.....f3...t....6.g.<hjO.,....v.....U|...Z....5.[....nL
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):424158
                  Entropy (8bit):7.999617809329608
                  Encrypted:true
                  SSDEEP:
                  MD5:7715AC357D4F1D64B5BA0CF2A747677A
                  SHA1:7FF8C981B34AB755EC00E8721AAA083E5B8D5A44
                  SHA-256:FDA090E7AD269BF4ACB001AEBA715208C49676CE1209112F01BA818C0EE462E4
                  SHA-512:F198865F0B2FC8DD35B0FCCDAE18B69356BBA1D31E132DC66480402D1346CCC01B4A68B33F6369C95C4BEA9A6B0BC93E2E4E9C61091E3330DED2A8A5FB6E3A81
                  Malicious:true
                  Preview:6...Nq............G....9.....MO.G#.|#.`.....P.Z...h.+.....Z.g.. .R..`....51.!f.U.j.FY;.y\...Mt...Bb.......U..a....@.M.o..u.......w..?...M@./...9..:.m.k..m...gJ.tM@...l..{.....V..Z.K.....Y4.Z....MR....[.i.".m.............Y7e.B^.......i..9q.51..k.8......w?H.n.Y.p.M#t..p....1....z"..f.;......mC.....]...^.?.M.)..l..`..8R.n.tW.C.[m..B.. ]..P...@..J0....\/..\q...3..n....T8.L.......U~-.L..Kw7r#u.....O..B..I.K..~...&..UHy...R...<f3..E..|1.j...a.v.n.2..$...u.1....Mf......&.Z.3.../3.!...J..O...3..|....3A.+......50.0H.(..{...5...^.?`7Y..Y....b|yMo#...ut.X......b?....u.x..S@....6..^O.5..Q.."R.>.3.0..ha....y.j.0.J....|...d.L/.!..;.c.p.1.s.U..~..{..V|...P.$...w............1S.vB}@.......[H7-|..e..;.....,R..i,.;.2.9.e.p..C..A..e`]....S_.J..8...6.....(;0.......l..X.32I....D....1..:5...@U..t.{&....._[.0.....V\.....3].X..X..z..C...8..v..z.O.....d..{.A..d....8.M... ..y.-.....eC.8..h...f1.2.)..l.Y.....f3...t....6.g.<hjO.,....v.....U|...Z....5.[....nL
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):480960
                  Entropy (8bit):7.999673209248575
                  Encrypted:true
                  SSDEEP:
                  MD5:A8E2384E781F383EEF9041EA1A10A582
                  SHA1:13BA7EAC86AEF40ECBCF4E403DCBDDC51E3154EB
                  SHA-256:02C5AB7B086CFFBB24F1B3E52731CC699856BE55678806B2285BE8EE9D886F7D
                  SHA-512:DC571936ED9435C4E3A44535B47B42CAE0D47AAA2B45AC37A1C8DD5D7E98FED4ADA49F3DEF9E267A184C6ADD4922DBFDC9C225A00810A6A8C7F9538491797FD9
                  Malicious:true
                  Preview:......<.e...>...s...C3n.-..[..E99....F.t...{e.e.....t.E...g..^..i.R.....X.n....4n..k..]..[.4......1........L'..4r.;L6.|..v.(C.~WF.A..W.v>W.......4m#.\.)...h.%3..9=.Y.6.#....-..*a7...~..e).~i....B.ptH..o.%..].......rA_>St..u...?..]....B_.).......D.N...T..O..V.....(. ..Q...y..s.....ta.;S..i?.4$.p......I.l.U...N..s.=..+~p.RI.I.o.l.@.a..x...Ae..Fv....D4..%...>......w|.$.A..^.6..8...P.......<N....l}Cp.i...'.c4f....n..X..En......]/X".IOi!....|..3...}.^..z......dN.1W..[)Q.j....D.....n.3EJ.=.K.z2U..Q..*r.#@.V..1.|tp?=..q..s.......)!.4o..48*.!].T..Ng...W...w..s........eG.T........`....:t1w.'.X.!.H~X.}.t..{t...@..Z..9."wGTWuf...g.c....~.vzP{....o.>{...u....1...bL..p.......i..K../..3.......i..B.w._$Cu.<h..f...5.....u.~OjCwrp.~sR5..{.x..._.2.n....\=u.<.r...x..s.&.K+}0...P...>....&l..h...xe. .c.!Y.x.~....c.8.......M.yY..zgM.r`.).....15W._.+.....).?.....-P..b.1'...n...8#)h........;..ld...E..h..........b.....7..k..#.Fj..#......D.JP.C.X).}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):480960
                  Entropy (8bit):7.999673209248575
                  Encrypted:true
                  SSDEEP:
                  MD5:A8E2384E781F383EEF9041EA1A10A582
                  SHA1:13BA7EAC86AEF40ECBCF4E403DCBDDC51E3154EB
                  SHA-256:02C5AB7B086CFFBB24F1B3E52731CC699856BE55678806B2285BE8EE9D886F7D
                  SHA-512:DC571936ED9435C4E3A44535B47B42CAE0D47AAA2B45AC37A1C8DD5D7E98FED4ADA49F3DEF9E267A184C6ADD4922DBFDC9C225A00810A6A8C7F9538491797FD9
                  Malicious:true
                  Preview:......<.e...>...s...C3n.-..[..E99....F.t...{e.e.....t.E...g..^..i.R.....X.n....4n..k..]..[.4......1........L'..4r.;L6.|..v.(C.~WF.A..W.v>W.......4m#.\.)...h.%3..9=.Y.6.#....-..*a7...~..e).~i....B.ptH..o.%..].......rA_>St..u...?..]....B_.).......D.N...T..O..V.....(. ..Q...y..s.....ta.;S..i?.4$.p......I.l.U...N..s.=..+~p.RI.I.o.l.@.a..x...Ae..Fv....D4..%...>......w|.$.A..^.6..8...P.......<N....l}Cp.i...'.c4f....n..X..En......]/X".IOi!....|..3...}.^..z......dN.1W..[)Q.j....D.....n.3EJ.=.K.z2U..Q..*r.#@.V..1.|tp?=..q..s.......)!.4o..48*.!].T..Ng...W...w..s........eG.T........`....:t1w.'.X.!.H~X.}.t..{t...@..Z..9."wGTWuf...g.c....~.vzP{....o.>{...u....1...bL..p.......i..K../..3.......i..B.w._$Cu.<h..f...5.....u.~OjCwrp.~sR5..{.x..._.2.n....\=u.<.r...x..s.&.K+}0...P...>....&l..h...xe. .c.!Y.x.~....c.8.......M.yY..zgM.r`.).....15W._.+.....).?.....-P..b.1'...n...8#)h........;..ld...E..h..........b.....7..k..#.Fj..#......D.JP.C.X).}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):480960
                  Entropy (8bit):7.999673209248575
                  Encrypted:true
                  SSDEEP:
                  MD5:A8E2384E781F383EEF9041EA1A10A582
                  SHA1:13BA7EAC86AEF40ECBCF4E403DCBDDC51E3154EB
                  SHA-256:02C5AB7B086CFFBB24F1B3E52731CC699856BE55678806B2285BE8EE9D886F7D
                  SHA-512:DC571936ED9435C4E3A44535B47B42CAE0D47AAA2B45AC37A1C8DD5D7E98FED4ADA49F3DEF9E267A184C6ADD4922DBFDC9C225A00810A6A8C7F9538491797FD9
                  Malicious:true
                  Preview:......<.e...>...s...C3n.-..[..E99....F.t...{e.e.....t.E...g..^..i.R.....X.n....4n..k..]..[.4......1........L'..4r.;L6.|..v.(C.~WF.A..W.v>W.......4m#.\.)...h.%3..9=.Y.6.#....-..*a7...~..e).~i....B.ptH..o.%..].......rA_>St..u...?..]....B_.).......D.N...T..O..V.....(. ..Q...y..s.....ta.;S..i?.4$.p......I.l.U...N..s.=..+~p.RI.I.o.l.@.a..x...Ae..Fv....D4..%...>......w|.$.A..^.6..8...P.......<N....l}Cp.i...'.c4f....n..X..En......]/X".IOi!....|..3...}.^..z......dN.1W..[)Q.j....D.....n.3EJ.=.K.z2U..Q..*r.#@.V..1.|tp?=..q..s.......)!.4o..48*.!].T..Ng...W...w..s........eG.T........`....:t1w.'.X.!.H~X.}.t..{t...@..Z..9."wGTWuf...g.c....~.vzP{....o.>{...u....1...bL..p.......i..K../..3.......i..B.w._$Cu.<h..f...5.....u.~OjCwrp.~sR5..{.x..._.2.n....\=u.<.r...x..s.&.K+}0...P...>....&l..h...xe. .c.!Y.x.~....c.8.......M.yY..zgM.r`.).....15W._.+.....).?.....-P..b.1'...n...8#)h........;..ld...E..h..........b.....7..k..#.Fj..#......D.JP.C.X).}.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):500860
                  Entropy (8bit):7.999673171355819
                  Encrypted:true
                  SSDEEP:
                  MD5:C63771213D1E42C2A8D997B1C429458A
                  SHA1:164A8DC9833D18D74B1106EBDB808FA23453A05F
                  SHA-256:EA8A787F7E65E327999B6AD1991A988B117D6D59F2807A90B032898D693A9EC1
                  SHA-512:EEFD3E4D6BD98B7903E066E1A342CE3893F9D52FB2F2DDADA70BEDDF55E65DE8B81636E8FA9FE232E2A05E0B6A016756A11A9CCC281C6C9109E92307D25C6C4B
                  Malicious:true
                  Preview:.R..T........_M...<Z....F(.elA.k.K.G7.....S.Tc-=.......N%?.d.0.....,T.y=9..71..t.S...r@0."..R.f.......].F{.u<.O.......#...7....,......*.-..jZ.(..G(...........'...nP...e....t.i6..(...:...wy..../;.r.6...P...d......[..}..qy...M .q.....>...H....x...".4_.z...Y#."{].S.....n.Z.;Z.]I.nE..;..C.V.Yq;4.e..!..O....3....i....a#.f..-/.).....wg....[..9K..:."u....T[..S.......Y*z....'.f...l..!.32I.Z3JN.gn.....8l]..'..vI.Z........D......i;.5.3...>...4..UE#.)2y...Y.....b4.-P...6.m..kNA.*AFr..Xi.H......c.`..............k......._`...9*.......XD5.:..ieU*...ED....P............/..,..P..i-..d.......|...9%]..@..P..>.P.b..JJ...$..!.u>.(......*.n.K.V.......B..J"M.. ...h.s./5....-0X.RL...P.x,...c0f%...H......A.,.......q)e.'pV".]-.1..W*(sI..G.d....N.$.%./a=L?v.X.......,...W.km"....5e..._kaw.....RQ..6.F......IB7...j.I.V<..w.!.._........;.+]...!.$.O....[..o...{..$.\.N..y.<g..y..XT<i...'....[k{...q..5.T.o.?,1..H.!...t.....$noC..G...Z.w..f.3....K.p...m.<<e.......h1.\.).
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):500860
                  Entropy (8bit):7.999673171355819
                  Encrypted:true
                  SSDEEP:
                  MD5:C63771213D1E42C2A8D997B1C429458A
                  SHA1:164A8DC9833D18D74B1106EBDB808FA23453A05F
                  SHA-256:EA8A787F7E65E327999B6AD1991A988B117D6D59F2807A90B032898D693A9EC1
                  SHA-512:EEFD3E4D6BD98B7903E066E1A342CE3893F9D52FB2F2DDADA70BEDDF55E65DE8B81636E8FA9FE232E2A05E0B6A016756A11A9CCC281C6C9109E92307D25C6C4B
                  Malicious:true
                  Preview:.R..T........_M...<Z....F(.elA.k.K.G7.....S.Tc-=.......N%?.d.0.....,T.y=9..71..t.S...r@0."..R.f.......].F{.u<.O.......#...7....,......*.-..jZ.(..G(...........'...nP...e....t.i6..(...:...wy..../;.r.6...P...d......[..}..qy...M .q.....>...H....x...".4_.z...Y#."{].S.....n.Z.;Z.]I.nE..;..C.V.Yq;4.e..!..O....3....i....a#.f..-/.).....wg....[..9K..:."u....T[..S.......Y*z....'.f...l..!.32I.Z3JN.gn.....8l]..'..vI.Z........D......i;.5.3...>...4..UE#.)2y...Y.....b4.-P...6.m..kNA.*AFr..Xi.H......c.`..............k......._`...9*.......XD5.:..ieU*...ED....P............/..,..P..i-..d.......|...9%]..@..P..>.P.b..JJ...$..!.u>.(......*.n.K.V.......B..J"M.. ...h.s./5....-0X.RL...P.x,...c0f%...H......A.,.......q)e.'pV".]-.1..W*(sI..G.d....N.$.%./a=L?v.X.......,...W.km"....5e..._kaw.....RQ..6.F......IB7...j.I.V<..w.!.._........;.+]...!.$.O....[..o...{..$.\.N..y.<g..y..XT<i...'....[k{...q..5.T.o.?,1..H.!...t.....$noC..G...Z.w..f.3....K.p...m.<<e.......h1.\.).
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):500860
                  Entropy (8bit):7.999673171355819
                  Encrypted:true
                  SSDEEP:
                  MD5:C63771213D1E42C2A8D997B1C429458A
                  SHA1:164A8DC9833D18D74B1106EBDB808FA23453A05F
                  SHA-256:EA8A787F7E65E327999B6AD1991A988B117D6D59F2807A90B032898D693A9EC1
                  SHA-512:EEFD3E4D6BD98B7903E066E1A342CE3893F9D52FB2F2DDADA70BEDDF55E65DE8B81636E8FA9FE232E2A05E0B6A016756A11A9CCC281C6C9109E92307D25C6C4B
                  Malicious:true
                  Preview:.R..T........_M...<Z....F(.elA.k.K.G7.....S.Tc-=.......N%?.d.0.....,T.y=9..71..t.S...r@0."..R.f.......].F{.u<.O.......#...7....,......*.-..jZ.(..G(...........'...nP...e....t.i6..(...:...wy..../;.r.6...P...d......[..}..qy...M .q.....>...H....x...".4_.z...Y#."{].S.....n.Z.;Z.]I.nE..;..C.V.Yq;4.e..!..O....3....i....a#.f..-/.).....wg....[..9K..:."u....T[..S.......Y*z....'.f...l..!.32I.Z3JN.gn.....8l]..'..vI.Z........D......i;.5.3...>...4..UE#.)2y...Y.....b4.-P...6.m..kNA.*AFr..Xi.H......c.`..............k......._`...9*.......XD5.:..ieU*...ED....P............/..,..P..i-..d.......|...9%]..@..P..>.P.b..JJ...$..!.u>.(......*.n.K.V.......B..J"M.. ...h.s./5....-0X.RL...P.x,...c0f%...H......A.,.......q)e.'pV".]-.1..W*(sI..G.d....N.$.%./a=L?v.X.......,...W.km"....5e..._kaw.....RQ..6.F......IB7...j.I.V<..w.!.._........;.+]...!.$.O....[..o...{..$.\.N..y.<g..y..XT<i...'....[k{...q..5.T.o.?,1..H.!...t.....$noC..G...Z.w..f.3....K.p...m.<<e.......h1.\.).
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):968032
                  Entropy (8bit):7.999836700850901
                  Encrypted:true
                  SSDEEP:
                  MD5:4A7F620E6A0E993E4ADC384BF9011A48
                  SHA1:FF2765ED7B73E8F241C3554467D9F58980E03882
                  SHA-256:C7986161A97D3D9884B97EBB3EDCC635D7BE275FD47F791DFD504A2BA1CEDA8A
                  SHA-512:EC3317216241D3333ED86E751E71062FED35DA67CC313F27D1092C10975F61AE82052FDA891BBA8141C4BE7547F49F937A90A9F456F179E20BC5532EB722FD2F
                  Malicious:true
                  Preview:z..dy.0.....sO.x...............F.....t..#.1...=.......e.]...}..x?!.t.uWXv1B..K\........x.L.<..<KP....S%..Z...X.~9.('..3...#....B=.o/...$.....)...M/./Ub.m(...a#B.U....r..B..A.g...%X........I[....E....8..D.A%Z..4..;.n...J..W.^.>...G...I#.......n-..j.[.@.R..v...zU.i....)..N.].W.%.a$..<>...=...KC....U.^...4".....0......0.,.!b.s..5.3A67q.J.......B..)..$..T.P$.,.?Y....<.!.......z..eZ.N.|..4E.R.].!...h...(.]U{N..G.C.=.|...../_Gg? .....2r.i.....H.*.h............Q.q../*...:.'..8r{...s.`!.(....[...@.....{.*V..J..F.d4.eZ.D....r...4`E..:.z....6..1Z!....hL....<{ouKc..o?.D.]...[.K.\T..4...Bu.......f..gvL...O_y......~.....tI..8%.9n.....9.o.Go.S.e...k)[V99.f.z.oI...V....d .X2.B.5.N4u..$I."...L.;.....S....&......>....h.....Kdx5............GC<.k$J.@{s..x."A.4f.q.@...Dw..=..>9..a'V..........A`...w....7.. n^?hg.\.~|.v..&..+.[..s.GiKs..}...g........T....^..........R..1).........]......R.rY*..hW..M.%.D...@...QXN.w./.*.x....0...4-B'......1.iJR...3...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):968032
                  Entropy (8bit):7.999836700850901
                  Encrypted:true
                  SSDEEP:
                  MD5:4A7F620E6A0E993E4ADC384BF9011A48
                  SHA1:FF2765ED7B73E8F241C3554467D9F58980E03882
                  SHA-256:C7986161A97D3D9884B97EBB3EDCC635D7BE275FD47F791DFD504A2BA1CEDA8A
                  SHA-512:EC3317216241D3333ED86E751E71062FED35DA67CC313F27D1092C10975F61AE82052FDA891BBA8141C4BE7547F49F937A90A9F456F179E20BC5532EB722FD2F
                  Malicious:true
                  Preview:z..dy.0.....sO.x...............F.....t..#.1...=.......e.]...}..x?!.t.uWXv1B..K\........x.L.<..<KP....S%..Z...X.~9.('..3...#....B=.o/...$.....)...M/./Ub.m(...a#B.U....r..B..A.g...%X........I[....E....8..D.A%Z..4..;.n...J..W.^.>...G...I#.......n-..j.[.@.R..v...zU.i....)..N.].W.%.a$..<>...=...KC....U.^...4".....0......0.,.!b.s..5.3A67q.J.......B..)..$..T.P$.,.?Y....<.!.......z..eZ.N.|..4E.R.].!...h...(.]U{N..G.C.=.|...../_Gg? .....2r.i.....H.*.h............Q.q../*...:.'..8r{...s.`!.(....[...@.....{.*V..J..F.d4.eZ.D....r...4`E..:.z....6..1Z!....hL....<{ouKc..o?.D.]...[.K.\T..4...Bu.......f..gvL...O_y......~.....tI..8%.9n.....9.o.Go.S.e...k)[V99.f.z.oI...V....d .X2.B.5.N4u..$I."...L.;.....S....&......>....h.....Kdx5............GC<.k$J.@{s..x."A.4f.q.@...Dw..=..>9..a'V..........A`...w....7.. n^?hg.\.~|.v..&..+.[..s.GiKs..}...g........T....^..........R..1).........]......R.rY*..hW..M.%.D...@...QXN.w./.*.x....0...4-B'......1.iJR...3...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):968032
                  Entropy (8bit):7.999836700850901
                  Encrypted:true
                  SSDEEP:
                  MD5:4A7F620E6A0E993E4ADC384BF9011A48
                  SHA1:FF2765ED7B73E8F241C3554467D9F58980E03882
                  SHA-256:C7986161A97D3D9884B97EBB3EDCC635D7BE275FD47F791DFD504A2BA1CEDA8A
                  SHA-512:EC3317216241D3333ED86E751E71062FED35DA67CC313F27D1092C10975F61AE82052FDA891BBA8141C4BE7547F49F937A90A9F456F179E20BC5532EB722FD2F
                  Malicious:true
                  Preview:z..dy.0.....sO.x...............F.....t..#.1...=.......e.]...}..x?!.t.uWXv1B..K\........x.L.<..<KP....S%..Z...X.~9.('..3...#....B=.o/...$.....)...M/./Ub.m(...a#B.U....r..B..A.g...%X........I[....E....8..D.A%Z..4..;.n...J..W.^.>...G...I#.......n-..j.[.@.R..v...zU.i....)..N.].W.%.a$..<>...=...KC....U.^...4".....0......0.,.!b.s..5.3A67q.J.......B..)..$..T.P$.,.?Y....<.!.......z..eZ.N.|..4E.R.].!...h...(.]U{N..G.C.=.|...../_Gg? .....2r.i.....H.*.h............Q.q../*...:.'..8r{...s.`!.(....[...@.....{.*V..J..F.d4.eZ.D....r...4`E..:.z....6..1Z!....hL....<{ouKc..o?.D.]...[.K.\T..4...Bu.......f..gvL...O_y......~.....tI..8%.9n.....9.o.Go.S.e...k)[V99.f.z.oI...V....d .X2.B.5.N4u..$I."...L.;.....S....&......>....h.....Kdx5............GC<.k$J.@{s..x."A.4f.q.@...Dw..=..>9..a'V..........A`...w....7.. n^?hg.\.~|.v..&..+.[..s.GiKs..}...g........T....^..........R..1).........]......R.rY*..hW..M.%.D...@...QXN.w./.*.x....0...4-B'......1.iJR...3...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):599745
                  Entropy (8bit):7.999711249538813
                  Encrypted:true
                  SSDEEP:
                  MD5:A1FD96B1EB5875ABE589E3A064547233
                  SHA1:25DF3E5A0BE346D1596EBF7C8155E8DD4ED1D4E0
                  SHA-256:C6B233DCB8E590F1404C4AB651FE25ADA57056BDC101650910172233EA7A5C80
                  SHA-512:14785CAC8B6F65BA14EC071522B2B6C7D409BEB8B8FF54EAC65ABD29ED2336B577097760D654489C37DF5B9C1CD53960637C690B1BEF919004B1DF887FF12309
                  Malicious:true
                  Preview:..ei:..#8.%.&...g3N........r.W;..S.J.5@}G.UNU....M..n.....:.Y....x..q_..c1....y.S.;T...Q.7...M....^.C.e.........y.n.5.......|...d`....(....2....q..}...t....=.dv...bW.t........{..sF..a.!S..X3[.|B]@..'....E.N.K.....:..*.>68q...S=.."|.<+.B.X..Y;.K.....^..-I@..>..7..!..8.?On. ..."b.@>/..ym.'..:..Y.[$.j3jP2~d..3O......<.3.Dp.k...eL.d...= ..P#..g..\...'.X.....0. ...T.td..:...S...L^..=Z#..l......U~.it....'o......7...8..I).(3..o..:.Q...........o,..W.Q.Q0.m#^.}E.5.dg....3...G.....^.F.4..Yk.S...+....s8..f.D6..Y..E.:..2+*.~.r..k!;.3.xj.i.|L......=)..:r......;./i......W..d.o]*......s....o..F(u..i....L...kJu.m6d..iN..Kjz0>.x.2.{....g....}.....i.#e....F`..r......._.$Iq.......PK.6...z...)....L...(....bI..4N.....!..p../.d>..h.....C-......O....jX.m..1..R+..@....k.JrV...{*.J|.'L%.`d..%..2}2.w.D{.r...K.x.2.n...g_...icD?.[...)......U|..'OR.a7.."......"r2[.].....-.{^......p..].'.~V.22K.L.4.......csa..V.g .+.......p..Ns..E?..|.........G...%d.<..K.?R..'
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):599745
                  Entropy (8bit):7.999711249538813
                  Encrypted:true
                  SSDEEP:
                  MD5:A1FD96B1EB5875ABE589E3A064547233
                  SHA1:25DF3E5A0BE346D1596EBF7C8155E8DD4ED1D4E0
                  SHA-256:C6B233DCB8E590F1404C4AB651FE25ADA57056BDC101650910172233EA7A5C80
                  SHA-512:14785CAC8B6F65BA14EC071522B2B6C7D409BEB8B8FF54EAC65ABD29ED2336B577097760D654489C37DF5B9C1CD53960637C690B1BEF919004B1DF887FF12309
                  Malicious:true
                  Preview:..ei:..#8.%.&...g3N........r.W;..S.J.5@}G.UNU....M..n.....:.Y....x..q_..c1....y.S.;T...Q.7...M....^.C.e.........y.n.5.......|...d`....(....2....q..}...t....=.dv...bW.t........{..sF..a.!S..X3[.|B]@..'....E.N.K.....:..*.>68q...S=.."|.<+.B.X..Y;.K.....^..-I@..>..7..!..8.?On. ..."b.@>/..ym.'..:..Y.[$.j3jP2~d..3O......<.3.Dp.k...eL.d...= ..P#..g..\...'.X.....0. ...T.td..:...S...L^..=Z#..l......U~.it....'o......7...8..I).(3..o..:.Q...........o,..W.Q.Q0.m#^.}E.5.dg....3...G.....^.F.4..Yk.S...+....s8..f.D6..Y..E.:..2+*.~.r..k!;.3.xj.i.|L......=)..:r......;./i......W..d.o]*......s....o..F(u..i....L...kJu.m6d..iN..Kjz0>.x.2.{....g....}.....i.#e....F`..r......._.$Iq.......PK.6...z...)....L...(....bI..4N.....!..p../.d>..h.....C-......O....jX.m..1..R+..@....k.JrV...{*.J|.'L%.`d..%..2}2.w.D{.r...K.x.2.n...g_...icD?.[...)......U|..'OR.a7.."......"r2[.].....-.{^......p..].'.~V.22K.L.4.......csa..V.g .+.......p..Ns..E?..|.........G...%d.<..K.?R..'
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):599745
                  Entropy (8bit):7.999711249538813
                  Encrypted:true
                  SSDEEP:
                  MD5:A1FD96B1EB5875ABE589E3A064547233
                  SHA1:25DF3E5A0BE346D1596EBF7C8155E8DD4ED1D4E0
                  SHA-256:C6B233DCB8E590F1404C4AB651FE25ADA57056BDC101650910172233EA7A5C80
                  SHA-512:14785CAC8B6F65BA14EC071522B2B6C7D409BEB8B8FF54EAC65ABD29ED2336B577097760D654489C37DF5B9C1CD53960637C690B1BEF919004B1DF887FF12309
                  Malicious:true
                  Preview:..ei:..#8.%.&...g3N........r.W;..S.J.5@}G.UNU....M..n.....:.Y....x..q_..c1....y.S.;T...Q.7...M....^.C.e.........y.n.5.......|...d`....(....2....q..}...t....=.dv...bW.t........{..sF..a.!S..X3[.|B]@..'....E.N.K.....:..*.>68q...S=.."|.<+.B.X..Y;.K.....^..-I@..>..7..!..8.?On. ..."b.@>/..ym.'..:..Y.[$.j3jP2~d..3O......<.3.Dp.k...eL.d...= ..P#..g..\...'.X.....0. ...T.td..:...S...L^..=Z#..l......U~.it....'o......7...8..I).(3..o..:.Q...........o,..W.Q.Q0.m#^.}E.5.dg....3...G.....^.F.4..Yk.S...+....s8..f.D6..Y..E.:..2+*.~.r..k!;.3.xj.i.|L......=)..:r......;./i......W..d.o]*......s....o..F(u..i....L...kJu.m6d..iN..Kjz0>.x.2.{....g....}.....i.#e....F`..r......._.$Iq.......PK.6...z...)....L...(....bI..4N.....!..p../.d>..h.....C-......O....jX.m..1..R+..@....k.JrV...{*.J|.'L%.`d..%..2}2.w.D{.r...K.x.2.n...g_...icD?.[...)......U|..'OR.a7.."......"r2[.].....-.{^......p..].'.~V.22K.L.4.......csa..V.g .+.......p..Ns..E?..|.........G...%d.<..K.?R..'
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1021653
                  Entropy (8bit):7.999811888667037
                  Encrypted:true
                  SSDEEP:
                  MD5:91637B1B8CD8B341E589BEAC942E2A7D
                  SHA1:8D5BA0ADFFB6BFEBC5B70E0FEFC233851D2A692D
                  SHA-256:EF885E88A4308FE716BE6557B2348080435DE94040A9DFA5BCF5E7F7A089E8B3
                  SHA-512:92CB05BABA366C1A0CA303653461F287529838AC60E3849162267568ABB318864F382CBAF020DA83B58F78B5B3EC87755E7C62F91993D4596BBBBD4B0A4A084D
                  Malicious:true
                  Preview:A.?6..).."r...G..oA..|..G.......J....."t./...Q~....K[.0..|N.......&........pG..."5......x.4..............`..`fR..WA.f.k...?7!&..wj.R8........I.3..y...8.w1..es"f..:.J...*..9G..qo..1.aR{..@<C.qG.....:..8[.Z..P*g...PI....N.(8...p..}..|,.}F.#...g:...0.W\..R.S.p.+.8r..Y.5..$,....MI@D.f..\W=...N)...w..Y...U{..k.5.,......u..`=.L.f4.-n......].x..C.2Zu~..F!{........C>.;.D...Vk.,.B....F.'Xx.X.y...-......[;......c.....2............VT2.8.C.3g'...z?.l...u.l.......`....[...+,...R7S\~........U.....wH...P.|......v..2.3b.2g.h.D.......XpOj...Fo..b...f.Vc.\I.Y..xV \...UqQ,..q) ..x4f.. ....`.Sv....JO.R(.>..c...b5"n.3....."@...H..?7.......+..gxPX.Z>..+}m[C...*].%o......ET..L....i...K..Z.=...#........H_d.....x.R....._.4.|...fK..o....q.h@..7.u..k|.VNoG3.C...t<"..z....>.\...`....!..F.|9..(.I....),AK<n{..U.G`-....uJBv}.vN.....%..X..[..p.....l3...?s....P..p0"?....Y.l..^.PN2...btp.z.+S....T..EO...o....o.A.~....r'm9../'.$..a.`..T$.^.k.+s...3..h......./9s...)
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1021653
                  Entropy (8bit):7.999811888667037
                  Encrypted:true
                  SSDEEP:
                  MD5:91637B1B8CD8B341E589BEAC942E2A7D
                  SHA1:8D5BA0ADFFB6BFEBC5B70E0FEFC233851D2A692D
                  SHA-256:EF885E88A4308FE716BE6557B2348080435DE94040A9DFA5BCF5E7F7A089E8B3
                  SHA-512:92CB05BABA366C1A0CA303653461F287529838AC60E3849162267568ABB318864F382CBAF020DA83B58F78B5B3EC87755E7C62F91993D4596BBBBD4B0A4A084D
                  Malicious:true
                  Preview:A.?6..).."r...G..oA..|..G.......J....."t./...Q~....K[.0..|N.......&........pG..."5......x.4..............`..`fR..WA.f.k...?7!&..wj.R8........I.3..y...8.w1..es"f..:.J...*..9G..qo..1.aR{..@<C.qG.....:..8[.Z..P*g...PI....N.(8...p..}..|,.}F.#...g:...0.W\..R.S.p.+.8r..Y.5..$,....MI@D.f..\W=...N)...w..Y...U{..k.5.,......u..`=.L.f4.-n......].x..C.2Zu~..F!{........C>.;.D...Vk.,.B....F.'Xx.X.y...-......[;......c.....2............VT2.8.C.3g'...z?.l...u.l.......`....[...+,...R7S\~........U.....wH...P.|......v..2.3b.2g.h.D.......XpOj...Fo..b...f.Vc.\I.Y..xV \...UqQ,..q) ..x4f.. ....`.Sv....JO.R(.>..c...b5"n.3....."@...H..?7.......+..gxPX.Z>..+}m[C...*].%o......ET..L....i...K..Z.=...#........H_d.....x.R....._.4.|...fK..o....q.h@..7.u..k|.VNoG3.C...t<"..z....>.\...`....!..F.|9..(.I....),AK<n{..U.G`-....uJBv}.vN.....%..X..[..p.....l3...?s....P..p0"?....Y.l..^.PN2...btp.z.+S....T..EO...o....o.A.~....r'm9../'.$..a.`..T$.^.k.+s...3..h......./9s...)
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1021653
                  Entropy (8bit):7.999811888667037
                  Encrypted:true
                  SSDEEP:
                  MD5:91637B1B8CD8B341E589BEAC942E2A7D
                  SHA1:8D5BA0ADFFB6BFEBC5B70E0FEFC233851D2A692D
                  SHA-256:EF885E88A4308FE716BE6557B2348080435DE94040A9DFA5BCF5E7F7A089E8B3
                  SHA-512:92CB05BABA366C1A0CA303653461F287529838AC60E3849162267568ABB318864F382CBAF020DA83B58F78B5B3EC87755E7C62F91993D4596BBBBD4B0A4A084D
                  Malicious:true
                  Preview:A.?6..).."r...G..oA..|..G.......J....."t./...Q~....K[.0..|N.......&........pG..."5......x.4..............`..`fR..WA.f.k...?7!&..wj.R8........I.3..y...8.w1..es"f..:.J...*..9G..qo..1.aR{..@<C.qG.....:..8[.Z..P*g...PI....N.(8...p..}..|,.}F.#...g:...0.W\..R.S.p.+.8r..Y.5..$,....MI@D.f..\W=...N)...w..Y...U{..k.5.,......u..`=.L.f4.-n......].x..C.2Zu~..F!{........C>.;.D...Vk.,.B....F.'Xx.X.y...-......[;......c.....2............VT2.8.C.3g'...z?.l...u.l.......`....[...+,...R7S\~........U.....wH...P.|......v..2.3b.2g.h.D.......XpOj...Fo..b...f.Vc.\I.Y..xV \...UqQ,..q) ..x4f.. ....`.Sv....JO.R(.>..c...b5"n.3....."@...H..?7.......+..gxPX.Z>..+}m[C...*].%o......ET..L....i...K..Z.=...#........H_d.....x.R....._.4.|...fK..o....q.h@..7.u..k|.VNoG3.C...t<"..z....>.\...`....!..F.|9..(.I....),AK<n{..U.G`-....uJBv}.vN.....%..X..[..p.....l3...?s....P..p0"?....Y.l..^.PN2...btp.z.+S....T..EO...o....o.A.~....r'm9../'.$..a.`..T$.^.k.+s...3..h......./9s...)
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):462538
                  Entropy (8bit):7.999631361995454
                  Encrypted:true
                  SSDEEP:
                  MD5:B2FDB00DB2AE88C35226E29B47903E80
                  SHA1:42392E62AD1FEE29F8BDA6686BD835B65DBFE3CB
                  SHA-256:A373AF73150066EB3E3D6FCC73040136ECBBDAB46E8C7A8BD14CB16F2FC04A00
                  SHA-512:7D969E6C439EA5874D22EE13826863CD4130985E6AECCBC25CAF0033C6182BDF3BAD9F4C2C3F051379247C2D1518FAA1194CE2E9F6E3AF171536407C31120C46
                  Malicious:true
                  Preview:=...6.u.W....-z.Z......0.'.....Pl.......`+...?.X..+6...I.v.B.Q..../...D.E......LM..2I'..w...@.O.'...,..5D.!G8...4+..h..h...0.n.@.'x...x&&H8.:...W!7...M.x4-f....F...|...S&.}...j.....3.....x%.C.;....x.(*..f....h....g?.m......\.....JP3..$..$4I[..}...^..Xs.g.*.........Y........Z"..F.-....-|3...s._.O....+....j.X...r.|..?`.l.q3......a. '...?....Y...p..M..E9[....^X.o...o.n....O.j.;M...;-....9...E*.2w....?.......T*...'..*X...`...])..=...i...].....Gz.Y...Se..!P.H3}...e./g.4..3.....#..._....//.U..#. ....2.....5.R...#.$...\.......Z.iX.MtE....v..kf..ni..#.^....x.bp.,..........T.....QE..TyiTYl......Dt9mv.k...y..-3..Ml....0..8..*.j.].......;q.....bV....rd%..g._b.\UT .(s..A..aW...A...{.e.......J...........w.:.......U.UJ...p...F...IL.h&..1....,..n....a.;N.l..H.........~...._}.jsq...|..8.<4S.~...MxCt.?.v..4.R).#.k..3.........<,.D......%!.X.b...,C.@...N|....[..0kg.J..JU.n......k5....w.&PE%...2..#..\.d...@..Hni..w>.waC...}h,..h.. ..:...dka.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):462538
                  Entropy (8bit):7.999631361995454
                  Encrypted:true
                  SSDEEP:
                  MD5:B2FDB00DB2AE88C35226E29B47903E80
                  SHA1:42392E62AD1FEE29F8BDA6686BD835B65DBFE3CB
                  SHA-256:A373AF73150066EB3E3D6FCC73040136ECBBDAB46E8C7A8BD14CB16F2FC04A00
                  SHA-512:7D969E6C439EA5874D22EE13826863CD4130985E6AECCBC25CAF0033C6182BDF3BAD9F4C2C3F051379247C2D1518FAA1194CE2E9F6E3AF171536407C31120C46
                  Malicious:true
                  Preview:=...6.u.W....-z.Z......0.'.....Pl.......`+...?.X..+6...I.v.B.Q..../...D.E......LM..2I'..w...@.O.'...,..5D.!G8...4+..h..h...0.n.@.'x...x&&H8.:...W!7...M.x4-f....F...|...S&.}...j.....3.....x%.C.;....x.(*..f....h....g?.m......\.....JP3..$..$4I[..}...^..Xs.g.*.........Y........Z"..F.-....-|3...s._.O....+....j.X...r.|..?`.l.q3......a. '...?....Y...p..M..E9[....^X.o...o.n....O.j.;M...;-....9...E*.2w....?.......T*...'..*X...`...])..=...i...].....Gz.Y...Se..!P.H3}...e./g.4..3.....#..._....//.U..#. ....2.....5.R...#.$...\.......Z.iX.MtE....v..kf..ni..#.^....x.bp.,..........T.....QE..TyiTYl......Dt9mv.k...y..-3..Ml....0..8..*.j.].......;q.....bV....rd%..g._b.\UT .(s..A..aW...A...{.e.......J...........w.:.......U.UJ...p...F...IL.h&..1....,..n....a.;N.l..H.........~...._}.jsq...|..8.<4S.~...MxCt.?.v..4.R).#.k..3.........<,.D......%!.X.b...,C.@...N|....[..0kg.J..JU.n......k5....w.&PE%...2..#..\.d...@..Hni..w>.waC...}h,..h.. ..:...dka.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):462538
                  Entropy (8bit):7.999631361995454
                  Encrypted:true
                  SSDEEP:
                  MD5:B2FDB00DB2AE88C35226E29B47903E80
                  SHA1:42392E62AD1FEE29F8BDA6686BD835B65DBFE3CB
                  SHA-256:A373AF73150066EB3E3D6FCC73040136ECBBDAB46E8C7A8BD14CB16F2FC04A00
                  SHA-512:7D969E6C439EA5874D22EE13826863CD4130985E6AECCBC25CAF0033C6182BDF3BAD9F4C2C3F051379247C2D1518FAA1194CE2E9F6E3AF171536407C31120C46
                  Malicious:true
                  Preview:=...6.u.W....-z.Z......0.'.....Pl.......`+...?.X..+6...I.v.B.Q..../...D.E......LM..2I'..w...@.O.'...,..5D.!G8...4+..h..h...0.n.@.'x...x&&H8.:...W!7...M.x4-f....F...|...S&.}...j.....3.....x%.C.;....x.(*..f....h....g?.m......\.....JP3..$..$4I[..}...^..Xs.g.*.........Y........Z"..F.-....-|3...s._.O....+....j.X...r.|..?`.l.q3......a. '...?....Y...p..M..E9[....^X.o...o.n....O.j.;M...;-....9...E*.2w....?.......T*...'..*X...`...])..=...i...].....Gz.Y...Se..!P.H3}...e./g.4..3.....#..._....//.U..#. ....2.....5.R...#.$...\.......Z.iX.MtE....v..kf..ni..#.^....x.bp.,..........T.....QE..TyiTYl......Dt9mv.k...y..-3..Ml....0..8..*.j.].......;q.....bV....rd%..g._b.\UT .(s..A..aW...A...{.e.......J...........w.:.......U.UJ...p...F...IL.h&..1....,..n....a.;N.l..H.........~...._}.jsq...|..8.<4S.~...MxCt.?.v..4.R).#.k..3.........<,.D......%!.X.b...,C.@...N|....[..0kg.J..JU.n......k5....w.&PE%...2..#..\.d...@..Hni..w>.waC...}h,..h.. ..:...dka.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):497848
                  Entropy (8bit):7.9996482077671365
                  Encrypted:true
                  SSDEEP:
                  MD5:4E8126651B991EC8CF755A255C752D62
                  SHA1:AF577E0598173E72EC7EF5588FD1C12DFD966C61
                  SHA-256:4C6FC2EE72204344349D6D584BACE2E972626304DAE95F1F231146C766F3485F
                  SHA-512:B7ACC70D35F0D8246339459AFFFCCE17AC08E86E5A1211C1332409740AEE40306D590D46494F0B3E47798DF84EF3FEE8A5DD58D52222764BA8629825306C8A8D
                  Malicious:true
                  Preview:.....6..}..AZ4..G...{.S...pn.....8...b..X.F.}.3..<`Q.....u~.p....N.\u../...*gw..6..1H..f...7o.......f...R@2.R.i...._L_...ML...US.-....K&...N..f..DhT..S...P~.....a/\'..I.X.I.r.s.7olH1z....B-y.O.8. ... K........+...?qDr5x..wn)...1...~...v..Y....6..C".T...H.>.......q.E...7.ZzV.,[6z...5 L..a.......1...."..z...R.(.A..<..a^'D}..3.z7o.......>.'....5HES..aka...M.K.M]...z......YRMn....*..9Jg]un.B.4,.@V.\.W...s..L..P..W{nV..G.H..?....q........U.~...#.<.(....m.'.9.Gi.f.]......;X../w...9..b.+...X..J.'-..h.n&.r..@.....u~2...o.l.".5~F....1E}2.....h..w... ...bn.........;e..........O..~...E...V.or...)...,....Z.n:.t./......6............q.......*...2..........h.....iw.R.Hu...&.B..Kk... ..u..eW..b{..R.S..0[.....Y..x;..o....../..D..=..8.....:....|.v..^.@%.sa....p.B.7...D.&..7K...XT.....F..C.s.y.1..*'...Uy........k..A... .EF..i..np`.r`..0...^l.i3..t1ox....VXT....a.;Q...)......_WL......1.z.~..n..[..S.E..o.AeI..?...RapPi.g..T..Z[a%....e.h...p....^^{|.<..US.\....G.L.4....[
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):497848
                  Entropy (8bit):7.9996482077671365
                  Encrypted:true
                  SSDEEP:
                  MD5:4E8126651B991EC8CF755A255C752D62
                  SHA1:AF577E0598173E72EC7EF5588FD1C12DFD966C61
                  SHA-256:4C6FC2EE72204344349D6D584BACE2E972626304DAE95F1F231146C766F3485F
                  SHA-512:B7ACC70D35F0D8246339459AFFFCCE17AC08E86E5A1211C1332409740AEE40306D590D46494F0B3E47798DF84EF3FEE8A5DD58D52222764BA8629825306C8A8D
                  Malicious:true
                  Preview:.....6..}..AZ4..G...{.S...pn.....8...b..X.F.}.3..<`Q.....u~.p....N.\u../...*gw..6..1H..f...7o.......f...R@2.R.i...._L_...ML...US.-....K&...N..f..DhT..S...P~.....a/\'..I.X.I.r.s.7olH1z....B-y.O.8. ... K........+...?qDr5x..wn)...1...~...v..Y....6..C".T...H.>.......q.E...7.ZzV.,[6z...5 L..a.......1...."..z...R.(.A..<..a^'D}..3.z7o.......>.'....5HES..aka...M.K.M]...z......YRMn....*..9Jg]un.B.4,.@V.\.W...s..L..P..W{nV..G.H..?....q........U.~...#.<.(....m.'.9.Gi.f.]......;X../w...9..b.+...X..J.'-..h.n&.r..@.....u~2...o.l.".5~F....1E}2.....h..w... ...bn.........;e..........O..~...E...V.or...)...,....Z.n:.t./......6............q.......*...2..........h.....iw.R.Hu...&.B..Kk... ..u..eW..b{..R.S..0[.....Y..x;..o....../..D..=..8.....:....|.v..^.@%.sa....p.B.7...D.&..7K...XT.....F..C.s.y.1..*'...Uy........k..A... .EF..i..np`.r`..0...^l.i3..t1ox....VXT....a.;Q...)......_WL......1.z.~..n..[..S.E..o.AeI..?...RapPi.g..T..Z[a%....e.h...p....^^{|.<..US.\....G.L.4....[
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):497848
                  Entropy (8bit):7.9996482077671365
                  Encrypted:true
                  SSDEEP:
                  MD5:4E8126651B991EC8CF755A255C752D62
                  SHA1:AF577E0598173E72EC7EF5588FD1C12DFD966C61
                  SHA-256:4C6FC2EE72204344349D6D584BACE2E972626304DAE95F1F231146C766F3485F
                  SHA-512:B7ACC70D35F0D8246339459AFFFCCE17AC08E86E5A1211C1332409740AEE40306D590D46494F0B3E47798DF84EF3FEE8A5DD58D52222764BA8629825306C8A8D
                  Malicious:true
                  Preview:.....6..}..AZ4..G...{.S...pn.....8...b..X.F.}.3..<`Q.....u~.p....N.\u../...*gw..6..1H..f...7o.......f...R@2.R.i...._L_...ML...US.-....K&...N..f..DhT..S...P~.....a/\'..I.X.I.r.s.7olH1z....B-y.O.8. ... K........+...?qDr5x..wn)...1...~...v..Y....6..C".T...H.>.......q.E...7.ZzV.,[6z...5 L..a.......1...."..z...R.(.A..<..a^'D}..3.z7o.......>.'....5HES..aka...M.K.M]...z......YRMn....*..9Jg]un.B.4,.@V.\.W...s..L..P..W{nV..G.H..?....q........U.~...#.<.(....m.'.9.Gi.f.]......;X../w...9..b.+...X..J.'-..h.n&.r..@.....u~2...o.l.".5~F....1E}2.....h..w... ...bn.........;e..........O..~...E...V.or...)...,....Z.n:.t./......6............q.......*...2..........h.....iw.R.Hu...&.B..Kk... ..u..eW..b{..R.S..0[.....Y..x;..o....../..D..=..8.....:....|.v..^.@%.sa....p.B.7...D.&..7K...XT.....F..C.s.y.1..*'...Uy........k..A... .EF..i..np`.r`..0...^l.i3..t1ox....VXT....a.;Q...)......_WL......1.z.~..n..[..S.E..o.AeI..?...RapPi.g..T..Z[a%....e.h...p....^^{|.<..US.\....G.L.4....[
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):408654
                  Entropy (8bit):7.9995838218704
                  Encrypted:true
                  SSDEEP:
                  MD5:CAC76316762FE9900C9E736DB3C40556
                  SHA1:6CE749AB5AC9556C1F70619DB008A8AD588837ED
                  SHA-256:EAF3953B27BC6E7CFC8AD96B022E77ACFEFAB396D5514FDAC32C4DDBDD287987
                  SHA-512:25654E772AFD688629E5524E813F25E9BF6185C978303304C936326FBC40D23ED38AF2968782B63A4E6D87785063C27286F2F222EABB77BF6C110AA9DA3CA1F3
                  Malicious:true
                  Preview:pWf..@.....R.G..i....3....M../..$?..aKY.L..ED...........q/9..... R...9.G.{.,.?...........%.b.~...dH b..W.o.......t,[-.oi.@3.....*.....c..:D..5.L......|.R....fT@..if..e=..A.R.`...dc./..=C..}Yv..`H....%.{...p2s.......e.EK\..]..Z`...R.v.......0j......Ym..UX....$..@..k7...p.....j..%x....B.Rv..'......{M.....E....U!.V..=...s.&...d.%...!.hMo..0...K..P..Y......`.J..d.C7..O.a..1...st.y}......2.:...%.q......I...5.....B0$d....+.Wa......c..D......I'f}..%....F..z..%F.|..\...1.>.5....<6....|.^.h.4pu4_...Xy.Rl.U.K.w.>....W..L.i...).`...Y...S.d........_.....z....AT.{.."..q..H.6....g....a..b.K.$c:YwmP.ze8..T...R..M.9].*^.?1.....V..[.Q..h..ahixR.o]x:R..D|.X6.p._.H.G.(....[UJ..c2...*.........7..Ja.WE.O..fC..........]"(_.0.f.7.... %"....:...+.n.an.+.|>...@J`.."+..ipB<S...e'Tp.pL Q.f..5@O.b..G..T.z...O..m...8.-.C.w.{YB..X....0.....~+.....&.U........A._...C.ze....H1U.=.....l..-.r.im.{....6...L3Y.W........b...f.V...q>..y.i.?O.....d......6..F..c~./.zA...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):408654
                  Entropy (8bit):7.9995838218704
                  Encrypted:true
                  SSDEEP:
                  MD5:CAC76316762FE9900C9E736DB3C40556
                  SHA1:6CE749AB5AC9556C1F70619DB008A8AD588837ED
                  SHA-256:EAF3953B27BC6E7CFC8AD96B022E77ACFEFAB396D5514FDAC32C4DDBDD287987
                  SHA-512:25654E772AFD688629E5524E813F25E9BF6185C978303304C936326FBC40D23ED38AF2968782B63A4E6D87785063C27286F2F222EABB77BF6C110AA9DA3CA1F3
                  Malicious:true
                  Preview:pWf..@.....R.G..i....3....M../..$?..aKY.L..ED...........q/9..... R...9.G.{.,.?...........%.b.~...dH b..W.o.......t,[-.oi.@3.....*.....c..:D..5.L......|.R....fT@..if..e=..A.R.`...dc./..=C..}Yv..`H....%.{...p2s.......e.EK\..]..Z`...R.v.......0j......Ym..UX....$..@..k7...p.....j..%x....B.Rv..'......{M.....E....U!.V..=...s.&...d.%...!.hMo..0...K..P..Y......`.J..d.C7..O.a..1...st.y}......2.:...%.q......I...5.....B0$d....+.Wa......c..D......I'f}..%....F..z..%F.|..\...1.>.5....<6....|.^.h.4pu4_...Xy.Rl.U.K.w.>....W..L.i...).`...Y...S.d........_.....z....AT.{.."..q..H.6....g....a..b.K.$c:YwmP.ze8..T...R..M.9].*^.?1.....V..[.Q..h..ahixR.o]x:R..D|.X6.p._.H.G.(....[UJ..c2...*.........7..Ja.WE.O..fC..........]"(_.0.f.7.... %"....:...+.n.an.+.|>...@J`.."+..ipB<S...e'Tp.pL Q.f..5@O.b..G..T.z...O..m...8.-.C.w.{YB..X....0.....~+.....&.U........A._...C.ze....H1U.=.....l..-.r.im.{....6...L3Y.W........b...f.V...q>..y.i.?O.....d......6..F..c~./.zA...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):408654
                  Entropy (8bit):7.9995838218704
                  Encrypted:true
                  SSDEEP:
                  MD5:CAC76316762FE9900C9E736DB3C40556
                  SHA1:6CE749AB5AC9556C1F70619DB008A8AD588837ED
                  SHA-256:EAF3953B27BC6E7CFC8AD96B022E77ACFEFAB396D5514FDAC32C4DDBDD287987
                  SHA-512:25654E772AFD688629E5524E813F25E9BF6185C978303304C936326FBC40D23ED38AF2968782B63A4E6D87785063C27286F2F222EABB77BF6C110AA9DA3CA1F3
                  Malicious:true
                  Preview:pWf..@.....R.G..i....3....M../..$?..aKY.L..ED...........q/9..... R...9.G.{.,.?...........%.b.~...dH b..W.o.......t,[-.oi.@3.....*.....c..:D..5.L......|.R....fT@..if..e=..A.R.`...dc./..=C..}Yv..`H....%.{...p2s.......e.EK\..]..Z`...R.v.......0j......Ym..UX....$..@..k7...p.....j..%x....B.Rv..'......{M.....E....U!.V..=...s.&...d.%...!.hMo..0...K..P..Y......`.J..d.C7..O.a..1...st.y}......2.:...%.q......I...5.....B0$d....+.Wa......c..D......I'f}..%....F..z..%F.|..\...1.>.5....<6....|.^.h.4pu4_...Xy.Rl.U.K.w.>....W..L.i...).`...Y...S.d........_.....z....AT.{.."..q..H.6....g....a..b.K.$c:YwmP.ze8..T...R..M.9].*^.?1.....V..[.Q..h..ahixR.o]x:R..D|.X6.p._.H.G.(....[UJ..c2...*.........7..Ja.WE.O..fC..........]"(_.0.f.7.... %"....:...+.n.an.+.|>...@J`.."+..ipB<S...e'Tp.pL Q.f..5@O.b..G..T.z...O..m...8.-.C.w.{YB..X....0.....~+.....&.U........A._...C.ze....H1U.=.....l..-.r.im.{....6...L3Y.W........b...f.V...q>..y.i.?O.....d......6..F..c~./.zA...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):460498
                  Entropy (8bit):7.999570822812181
                  Encrypted:true
                  SSDEEP:
                  MD5:47C8D39A3D6870EDCA964B7CF59AFE29
                  SHA1:FDDA2A4A4F6B70DED0A846B56A1ED83DFA9904A6
                  SHA-256:B57C6175A0B14FC344B1D130E2FBD4794AD2F9E7F44E99539EADC2FF544261C4
                  SHA-512:C98AB2457234CBFFA2123E8FAE29032D015121F13847BC8395B16A110FA8DB8C8EC0BBC1CB832B3AED51831737329C10E0E7625DE8C0020FAE5455A6B266C6ED
                  Malicious:true
                  Preview:...t.?..*. .?....I...:*[.if.K.c-1...Y.Z.O.J..(.#..m..7S....q...9..(&...&P8.d}.....t.`...?.....@.....@W.d....Z..V...i?....x$?3g.h.,.X$.5..#Y.....'..m[V....M..f...9i..!.........A.#-.Z......,.".)...=dB,r.$..P.8..!....'..!.f3..+6.U..f.....{`A..Zz...MvBKZ.T"<.(..G.g..i..$`..S...4.~... <...+.1.z.b....r..N..UZ....r<M...9..x..!.J.@->.1......S.7.N.).......E...$.&<...A.j.....q&+.../........[\c.......U...N.y..*.)...;.....[..F.'..u.6..W.L'.>.y....;rr.t......u..%........6eX3g.L..C.&.9(.......%!.D...Qc?.R'...R]...)..T...y?Ot...[...C..@.@DJ.....1..X............<..........=.B...N...m.`...ds4...;.j...7.......<.9uo>\..3...<vT#W..c.C.....Z....).....\.'E./.s.TH.,...<.....E..xu...W.I.J......f.t..|=......n..i.,.U.6@J.U75...R..sB........s..0.1c8.T.....Pd.5/...^.)...+...S....z..8..^.\.uk.^6..$.v....*l..D)ScQ...mR.).4.....A.b.o..}...U."I.3..n.]T.M.x..[.~=......@^.B..0.b..K..1r.....h..2.W...[.n...Ug.$K..h5...s..\[.Ub...........$J..g......1.P.O....E*..T....r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):460498
                  Entropy (8bit):7.999570822812181
                  Encrypted:true
                  SSDEEP:
                  MD5:47C8D39A3D6870EDCA964B7CF59AFE29
                  SHA1:FDDA2A4A4F6B70DED0A846B56A1ED83DFA9904A6
                  SHA-256:B57C6175A0B14FC344B1D130E2FBD4794AD2F9E7F44E99539EADC2FF544261C4
                  SHA-512:C98AB2457234CBFFA2123E8FAE29032D015121F13847BC8395B16A110FA8DB8C8EC0BBC1CB832B3AED51831737329C10E0E7625DE8C0020FAE5455A6B266C6ED
                  Malicious:true
                  Preview:...t.?..*. .?....I...:*[.if.K.c-1...Y.Z.O.J..(.#..m..7S....q...9..(&...&P8.d}.....t.`...?.....@.....@W.d....Z..V...i?....x$?3g.h.,.X$.5..#Y.....'..m[V....M..f...9i..!.........A.#-.Z......,.".)...=dB,r.$..P.8..!....'..!.f3..+6.U..f.....{`A..Zz...MvBKZ.T"<.(..G.g..i..$`..S...4.~... <...+.1.z.b....r..N..UZ....r<M...9..x..!.J.@->.1......S.7.N.).......E...$.&<...A.j.....q&+.../........[\c.......U...N.y..*.)...;.....[..F.'..u.6..W.L'.>.y....;rr.t......u..%........6eX3g.L..C.&.9(.......%!.D...Qc?.R'...R]...)..T...y?Ot...[...C..@.@DJ.....1..X............<..........=.B...N...m.`...ds4...;.j...7.......<.9uo>\..3...<vT#W..c.C.....Z....).....\.'E./.s.TH.,...<.....E..xu...W.I.J......f.t..|=......n..i.,.U.6@J.U75...R..sB........s..0.1c8.T.....Pd.5/...^.)...+...S....z..8..^.\.uk.^6..$.v....*l..D)ScQ...mR.).4.....A.b.o..}...U."I.3..n.]T.M.x..[.~=......@^.B..0.b..K..1r.....h..2.W...[.n...Ug.$K..h5...s..\[.Ub...........$J..g......1.P.O....E*..T....r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):460498
                  Entropy (8bit):7.999570822812181
                  Encrypted:true
                  SSDEEP:
                  MD5:47C8D39A3D6870EDCA964B7CF59AFE29
                  SHA1:FDDA2A4A4F6B70DED0A846B56A1ED83DFA9904A6
                  SHA-256:B57C6175A0B14FC344B1D130E2FBD4794AD2F9E7F44E99539EADC2FF544261C4
                  SHA-512:C98AB2457234CBFFA2123E8FAE29032D015121F13847BC8395B16A110FA8DB8C8EC0BBC1CB832B3AED51831737329C10E0E7625DE8C0020FAE5455A6B266C6ED
                  Malicious:true
                  Preview:...t.?..*. .?....I...:*[.if.K.c-1...Y.Z.O.J..(.#..m..7S....q...9..(&...&P8.d}.....t.`...?.....@.....@W.d....Z..V...i?....x$?3g.h.,.X$.5..#Y.....'..m[V....M..f...9i..!.........A.#-.Z......,.".)...=dB,r.$..P.8..!....'..!.f3..+6.U..f.....{`A..Zz...MvBKZ.T"<.(..G.g..i..$`..S...4.~... <...+.1.z.b....r..N..UZ....r<M...9..x..!.J.@->.1......S.7.N.).......E...$.&<...A.j.....q&+.../........[\c.......U...N.y..*.)...;.....[..F.'..u.6..W.L'.>.y....;rr.t......u..%........6eX3g.L..C.&.9(.......%!.D...Qc?.R'...R]...)..T...y?Ot...[...C..@.@DJ.....1..X............<..........=.B...N...m.`...ds4...;.j...7.......<.9uo>\..3...<vT#W..c.C.....Z....).....\.'E./.s.TH.,...<.....E..xu...W.I.J......f.t..|=......n..i.,.U.6@J.U75...R..sB........s..0.1c8.T.....Pd.5/...^.)...+...S....z..8..^.\.uk.^6..$.v....*l..D)ScQ...mR.).4.....A.b.o..}...U."I.3..n.]T.M.x..[.~=......@^.B..0.b..K..1r.....h..2.W...[.n...Ug.$K..h5...s..\[.Ub...........$J..g......1.P.O....E*..T....r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):558789
                  Entropy (8bit):7.99964285652248
                  Encrypted:true
                  SSDEEP:
                  MD5:C1411AA71DE1F136B9BA069D354814BD
                  SHA1:ED318BE7361E2C0D73642457C1FA0BF342CB5C8F
                  SHA-256:D338FCB882B6EFAE63A79E46F9A13C20E83CC1E94BEBAF262696CE2D57234953
                  SHA-512:96A3619FA35F4110BFB1FB08EB71086164A78185AA6C9BFD3CF6EB3B197EC3D9E6A9B55F5499B67CF7B8149B3EC641B2BD2EF6082952EBAB6136FFF27A5581EF
                  Malicious:true
                  Preview:8.>.%.gC{..,g...x.a$.ba@(.........=F.....@.`IvN.3..#..F..i..."......B..c....a.'!....P.-.Y...=.j,../...2..8".....F.k{..@..D8.C.T.........O.j..1.7.j.2.Q...W.cG"........p..| ...../..6>.7...e...U...T.iW".....T..6D...Ra.ad.T.t\w.....p.\.Jd..7/.....ym%9.......=Dh..dK.bX/............B7...`ZN..!.J....*=...T...3.tk4..........!..FT\Z.R.N#..:....O,!.5.#Db..N"4..LF..OSX..5...t..Xr.....:.....,..z>.4...F..d..._.A..22...r.K...^*.....P..B/..8z...ai..]..'.=..&...rI/....a......F....J.....l4......5...Af..e&....../G..L..W]xV|..N.bW........[.k..M.!8..zP...<' g.f8....T.....|..1.8...x...).....*Q....4l........As..i.C1[...37..U.....m@.w..}.....R.ZL3/.G.an..u.:.|S..,..*..%)o.. .(i....8Hy..i9.x..:..4../.T@s....11..^.....MC....v&......C%.cO..o.b.l.=}.+p..T .......h|,$......7-..5-8X.4.i.,..$^....f.1Z...._...,.g./...8T.. ....ai.......^(.;{1.YA+...;.T....Dl.y3_R....m..j.:....d.Ir!|..g.].;n...]G.S*...w.3...}...3..7.......kDjR.-..U...r..l1...=Wc9..[.Z...y&7G..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):558789
                  Entropy (8bit):7.99964285652248
                  Encrypted:true
                  SSDEEP:
                  MD5:C1411AA71DE1F136B9BA069D354814BD
                  SHA1:ED318BE7361E2C0D73642457C1FA0BF342CB5C8F
                  SHA-256:D338FCB882B6EFAE63A79E46F9A13C20E83CC1E94BEBAF262696CE2D57234953
                  SHA-512:96A3619FA35F4110BFB1FB08EB71086164A78185AA6C9BFD3CF6EB3B197EC3D9E6A9B55F5499B67CF7B8149B3EC641B2BD2EF6082952EBAB6136FFF27A5581EF
                  Malicious:true
                  Preview:8.>.%.gC{..,g...x.a$.ba@(.........=F.....@.`IvN.3..#..F..i..."......B..c....a.'!....P.-.Y...=.j,../...2..8".....F.k{..@..D8.C.T.........O.j..1.7.j.2.Q...W.cG"........p..| ...../..6>.7...e...U...T.iW".....T..6D...Ra.ad.T.t\w.....p.\.Jd..7/.....ym%9.......=Dh..dK.bX/............B7...`ZN..!.J....*=...T...3.tk4..........!..FT\Z.R.N#..:....O,!.5.#Db..N"4..LF..OSX..5...t..Xr.....:.....,..z>.4...F..d..._.A..22...r.K...^*.....P..B/..8z...ai..]..'.=..&...rI/....a......F....J.....l4......5...Af..e&....../G..L..W]xV|..N.bW........[.k..M.!8..zP...<' g.f8....T.....|..1.8...x...).....*Q....4l........As..i.C1[...37..U.....m@.w..}.....R.ZL3/.G.an..u.:.|S..,..*..%)o.. .(i....8Hy..i9.x..:..4../.T@s....11..^.....MC....v&......C%.cO..o.b.l.=}.+p..T .......h|,$......7-..5-8X.4.i.,..$^....f.1Z...._...,.g./...8T.. ....ai.......^(.;{1.YA+...;.T....Dl.y3_R....m..j.:....d.Ir!|..g.].;n...]G.S*...w.3...}...3..7.......kDjR.-..U...r..l1...=Wc9..[.Z...y&7G..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):558789
                  Entropy (8bit):7.99964285652248
                  Encrypted:true
                  SSDEEP:
                  MD5:C1411AA71DE1F136B9BA069D354814BD
                  SHA1:ED318BE7361E2C0D73642457C1FA0BF342CB5C8F
                  SHA-256:D338FCB882B6EFAE63A79E46F9A13C20E83CC1E94BEBAF262696CE2D57234953
                  SHA-512:96A3619FA35F4110BFB1FB08EB71086164A78185AA6C9BFD3CF6EB3B197EC3D9E6A9B55F5499B67CF7B8149B3EC641B2BD2EF6082952EBAB6136FFF27A5581EF
                  Malicious:true
                  Preview:8.>.%.gC{..,g...x.a$.ba@(.........=F.....@.`IvN.3..#..F..i..."......B..c....a.'!....P.-.Y...=.j,../...2..8".....F.k{..@..D8.C.T.........O.j..1.7.j.2.Q...W.cG"........p..| ...../..6>.7...e...U...T.iW".....T..6D...Ra.ad.T.t\w.....p.\.Jd..7/.....ym%9.......=Dh..dK.bX/............B7...`ZN..!.J....*=...T...3.tk4..........!..FT\Z.R.N#..:....O,!.5.#Db..N"4..LF..OSX..5...t..Xr.....:.....,..z>.4...F..d..._.A..22...r.K...^*.....P..B/..8z...ai..]..'.=..&...rI/....a......F....J.....l4......5...Af..e&....../G..L..W]xV|..N.bW........[.k..M.!8..zP...<' g.f8....T.....|..1.8...x...).....*Q....4l........As..i.C1[...37..U.....m@.w..}.....R.ZL3/.G.an..u.:.|S..,..*..%)o.. .(i....8Hy..i9.x..:..4../.T@s....11..^.....MC....v&......C%.cO..o.b.l.=}.+p..T .......h|,$......7-..5-8X.4.i.,..$^....f.1Z...._...,.g./...8T.. ....ai.......^(.;{1.YA+...;.T....Dl.y3_R....m..j.:....d.Ir!|..g.].;n...]G.S*...w.3...}...3..7.......kDjR.-..U...r..l1...=Wc9..[.Z...y&7G..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1103003
                  Entropy (8bit):7.999823040477682
                  Encrypted:true
                  SSDEEP:
                  MD5:11C2B3F6DF95B0D10D7326E1045F3565
                  SHA1:AAD33C0FAD40799F6736C7129FE7C16A0F802773
                  SHA-256:8E4C30455A9F715C664F502188BA095E304273E1A0F9CB31B49EF81C0241A840
                  SHA-512:965689FFBB9A7FB0AAE5E5D1EE51F350A35ACEF9A6156A74C2594F3974F1DCC2D3FF92F36714637EF96F26C8ED4818788BC7C012C6056FABB8ADFF6E9772753D
                  Malicious:true
                  Preview:.r.,c.N+....9.<....7S;.V...Pm;..}.mB.og....M....]..uW.i...2r.sv)........... ..^^.,{zyk.*.n.G..69....4qu!../.......G%9..~'_5..pQ..H.-..&.4 .Q.E3.\Ok=.k.2RE..$.......~..Uz.....J;.;b...O.e%..H|u(.<...{.k..Hk.#6.E.B7-..P6.Ffo.q.7.Fi9u...>..z..hQp*.z.. O....Q....M.4g...3....\.\...=fC.\~.Uo.....[(*s.|/.zhO.Y.....\.'ew,......:.'.ph.].q..I23...]S..2....q....!..."..........#....tP.Oc.<.j.3..]k..0P.....8&uL...D;=....F|....jN...wZ.&tB#..O&IL8,.4..d...V.Yev..(?........z-..l............p1*..a..I|.......|.....c..ECgP}.yJ.%..Qm.....R..P@..lEbo......7.......E...q6_.]/;..N[.QK/..v.....Y...H.>.D.....Z...}sz..p.{&......(..My.s.p.Q..Z/...]m.....k..M..Q..).S...d..m.Y`xE....].....7e...y...r.)......-UQk..[.-....[.v...}.Md..].;[.Yg.6....d.....s..Z.G.p;........<.i......+.....`l.Z.0.....'..[.]....v.3u.R.$.8}...m......"p8.eq......9.O..C.K..j......57vuG......7..W...m....Sv.{...X$pF.3....{...W..I.oM..A'..zN..*h6z!F...n/..v....4......9.|f.N..+.t..k
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1103003
                  Entropy (8bit):7.999823040477682
                  Encrypted:true
                  SSDEEP:
                  MD5:11C2B3F6DF95B0D10D7326E1045F3565
                  SHA1:AAD33C0FAD40799F6736C7129FE7C16A0F802773
                  SHA-256:8E4C30455A9F715C664F502188BA095E304273E1A0F9CB31B49EF81C0241A840
                  SHA-512:965689FFBB9A7FB0AAE5E5D1EE51F350A35ACEF9A6156A74C2594F3974F1DCC2D3FF92F36714637EF96F26C8ED4818788BC7C012C6056FABB8ADFF6E9772753D
                  Malicious:true
                  Preview:.r.,c.N+....9.<....7S;.V...Pm;..}.mB.og....M....]..uW.i...2r.sv)........... ..^^.,{zyk.*.n.G..69....4qu!../.......G%9..~'_5..pQ..H.-..&.4 .Q.E3.\Ok=.k.2RE..$.......~..Uz.....J;.;b...O.e%..H|u(.<...{.k..Hk.#6.E.B7-..P6.Ffo.q.7.Fi9u...>..z..hQp*.z.. O....Q....M.4g...3....\.\...=fC.\~.Uo.....[(*s.|/.zhO.Y.....\.'ew,......:.'.ph.].q..I23...]S..2....q....!..."..........#....tP.Oc.<.j.3..]k..0P.....8&uL...D;=....F|....jN...wZ.&tB#..O&IL8,.4..d...V.Yev..(?........z-..l............p1*..a..I|.......|.....c..ECgP}.yJ.%..Qm.....R..P@..lEbo......7.......E...q6_.]/;..N[.QK/..v.....Y...H.>.D.....Z...}sz..p.{&......(..My.s.p.Q..Z/...]m.....k..M..Q..).S...d..m.Y`xE....].....7e...y...r.)......-UQk..[.-....[.v...}.Md..].;[.Yg.6....d.....s..Z.G.p;........<.i......+.....`l.Z.0.....'..[.]....v.3u.R.$.8}...m......"p8.eq......9.O..C.K..j......57vuG......7..W...m....Sv.{...X$pF.3....{...W..I.oM..A'..zN..*h6z!F...n/..v....4......9.|f.N..+.t..k
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1103003
                  Entropy (8bit):7.999823040477682
                  Encrypted:true
                  SSDEEP:
                  MD5:11C2B3F6DF95B0D10D7326E1045F3565
                  SHA1:AAD33C0FAD40799F6736C7129FE7C16A0F802773
                  SHA-256:8E4C30455A9F715C664F502188BA095E304273E1A0F9CB31B49EF81C0241A840
                  SHA-512:965689FFBB9A7FB0AAE5E5D1EE51F350A35ACEF9A6156A74C2594F3974F1DCC2D3FF92F36714637EF96F26C8ED4818788BC7C012C6056FABB8ADFF6E9772753D
                  Malicious:true
                  Preview:.r.,c.N+....9.<....7S;.V...Pm;..}.mB.og....M....]..uW.i...2r.sv)........... ..^^.,{zyk.*.n.G..69....4qu!../.......G%9..~'_5..pQ..H.-..&.4 .Q.E3.\Ok=.k.2RE..$.......~..Uz.....J;.;b...O.e%..H|u(.<...{.k..Hk.#6.E.B7-..P6.Ffo.q.7.Fi9u...>..z..hQp*.z.. O....Q....M.4g...3....\.\...=fC.\~.Uo.....[(*s.|/.zhO.Y.....\.'ew,......:.'.ph.].q..I23...]S..2....q....!..."..........#....tP.Oc.<.j.3..]k..0P.....8&uL...D;=....F|....jN...wZ.&tB#..O&IL8,.4..d...V.Yev..(?........z-..l............p1*..a..I|.......|.....c..ECgP}.yJ.%..Qm.....R..P@..lEbo......7.......E...q6_.]/;..N[.QK/..v.....Y...H.>.D.....Z...}sz..p.{&......(..My.s.p.Q..Z/...]m.....k..M..Q..).S...d..m.Y`xE....].....7e...y...r.)......-UQk..[.-....[.v...}.Md..].;[.Yg.6....d.....s..Z.G.p;........<.i......+.....`l.Z.0.....'..[.]....v.3u.R.$.8}...m......"p8.eq......9.O..C.K..j......57vuG......7..W...m....Sv.{...X$pF.3....{...W..I.oM..A'..zN..*h6z!F...n/..v....4......9.|f.N..+.t..k
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):467299
                  Entropy (8bit):7.999577051253888
                  Encrypted:true
                  SSDEEP:
                  MD5:FDB6633DD6B6F7BFA9BC9B14852A2DF4
                  SHA1:773EF76E3097153D72DD7FA5E082811047522B09
                  SHA-256:8B97BE3AAB7E62DE4E31327A3B109F0A140DA26A21A923C2DD170AA3392CE1F1
                  SHA-512:54CA6FB8C3F96DBA2B951DF5355D209ECDA5F7707EB8E4C56D4781FFE3EB1010869987BC96BC8D06F012EF09C32E094E16BA5EB7FD5733DD9ACCD5964EB38FC9
                  Malicious:true
                  Preview:........F.....GW.....B......3=.8..2g.p7(. E.O.iw4c...e.plR..#..q.O...$......M.:.Q.s.~.../..T..G.......^Z.....I5.5.f..FM..B.K.C..R2..........e.Z...P>..-.n.....{....&3.....[s.aC....x.......$.../.R>..2.....\. .=.Z."..k8I.O....Y....Kq|Z.O"...f........5E..>..Zk...M.?<|.G....a....`..Df.....(]f...;.BcS...A.1..glvW|..=...:.J._0'Bqc...)............6...i..ls>H.g...}...........9.$...(.[.+...F..}..i.A.l..&.L....1|....,.Z.....f`:.j?7...d.Z...f....m..d.6....*.\..XP...>8.1`H......W...W.5..LM3..~OJs.Lr.4.-..R..tQ(.q.8._.F..6$...h.\:_C..r...2..".u^]PNF.TY..#6!5.g-\1.O[.:......W...wA.k.......@.:...r....@../.W.7.......%7#..f..Z.(...{.]....R.....F.u....."?......@c..P... ..0.....S..*_w...!..u.L.*&.......5..W...Y.4.+.......fz.Zj...:V. k...MM.c.*x........<d.D.u9....=w.......p..U..S`.s..P^...n.#.zW.(k..3TO.3. ..t.a.$....^...t..[0..x@yD...H...9pi}...c\W.Sq...ZA*....5....I.t.(wg'...o.......:...0?.L..Bg+k.!....N..`.... 40..It.h61.F.u.Q..N;.7.g!.W....ec1...v.x{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):467299
                  Entropy (8bit):7.999577051253888
                  Encrypted:true
                  SSDEEP:
                  MD5:FDB6633DD6B6F7BFA9BC9B14852A2DF4
                  SHA1:773EF76E3097153D72DD7FA5E082811047522B09
                  SHA-256:8B97BE3AAB7E62DE4E31327A3B109F0A140DA26A21A923C2DD170AA3392CE1F1
                  SHA-512:54CA6FB8C3F96DBA2B951DF5355D209ECDA5F7707EB8E4C56D4781FFE3EB1010869987BC96BC8D06F012EF09C32E094E16BA5EB7FD5733DD9ACCD5964EB38FC9
                  Malicious:true
                  Preview:........F.....GW.....B......3=.8..2g.p7(. E.O.iw4c...e.plR..#..q.O...$......M.:.Q.s.~.../..T..G.......^Z.....I5.5.f..FM..B.K.C..R2..........e.Z...P>..-.n.....{....&3.....[s.aC....x.......$.../.R>..2.....\. .=.Z."..k8I.O....Y....Kq|Z.O"...f........5E..>..Zk...M.?<|.G....a....`..Df.....(]f...;.BcS...A.1..glvW|..=...:.J._0'Bqc...)............6...i..ls>H.g...}...........9.$...(.[.+...F..}..i.A.l..&.L....1|....,.Z.....f`:.j?7...d.Z...f....m..d.6....*.\..XP...>8.1`H......W...W.5..LM3..~OJs.Lr.4.-..R..tQ(.q.8._.F..6$...h.\:_C..r...2..".u^]PNF.TY..#6!5.g-\1.O[.:......W...wA.k.......@.:...r....@../.W.7.......%7#..f..Z.(...{.]....R.....F.u....."?......@c..P... ..0.....S..*_w...!..u.L.*&.......5..W...Y.4.+.......fz.Zj...:V. k...MM.c.*x........<d.D.u9....=w.......p..U..S`.s..P^...n.#.zW.(k..3TO.3. ..t.a.$....^...t..[0..x@yD...H...9pi}...c\W.Sq...ZA*....5....I.t.(wg'...o.......:...0?.L..Bg+k.!....N..`.... 40..It.h61.F.u.Q..N;.7.g!.W....ec1...v.x{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):467299
                  Entropy (8bit):7.999577051253888
                  Encrypted:true
                  SSDEEP:
                  MD5:FDB6633DD6B6F7BFA9BC9B14852A2DF4
                  SHA1:773EF76E3097153D72DD7FA5E082811047522B09
                  SHA-256:8B97BE3AAB7E62DE4E31327A3B109F0A140DA26A21A923C2DD170AA3392CE1F1
                  SHA-512:54CA6FB8C3F96DBA2B951DF5355D209ECDA5F7707EB8E4C56D4781FFE3EB1010869987BC96BC8D06F012EF09C32E094E16BA5EB7FD5733DD9ACCD5964EB38FC9
                  Malicious:true
                  Preview:........F.....GW.....B......3=.8..2g.p7(. E.O.iw4c...e.plR..#..q.O...$......M.:.Q.s.~.../..T..G.......^Z.....I5.5.f..FM..B.K.C..R2..........e.Z...P>..-.n.....{....&3.....[s.aC....x.......$.../.R>..2.....\. .=.Z."..k8I.O....Y....Kq|Z.O"...f........5E..>..Zk...M.?<|.G....a....`..Df.....(]f...;.BcS...A.1..glvW|..=...:.J._0'Bqc...)............6...i..ls>H.g...}...........9.$...(.[.+...F..}..i.A.l..&.L....1|....,.Z.....f`:.j?7...d.Z...f....m..d.6....*.\..XP...>8.1`H......W...W.5..LM3..~OJs.Lr.4.-..R..tQ(.q.8._.F..6$...h.\:_C..r...2..".u^]PNF.TY..#6!5.g-\1.O[.:......W...wA.k.......@.:...r....@../.W.7.......%7#..f..Z.(...{.]....R.....F.u....."?......@c..P... ..0.....S..*_w...!..u.L.*&.......5..W...Y.4.+.......fz.Zj...:V. k...MM.c.*x........<d.D.u9....=w.......p..U..S`.s..P^...n.#.zW.(k..3TO.3. ..t.a.$....^...t..[0..x@yD...H...9pi}...c\W.Sq...ZA*....5....I.t.(wg'...o.......:...0?.L..Bg+k.!....N..`.... 40..It.h61.F.u.Q..N;.7.g!.W....ec1...v.x{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):503318
                  Entropy (8bit):7.999643513865518
                  Encrypted:true
                  SSDEEP:
                  MD5:CD77808BD2AB11FA0D12A39428E7DB07
                  SHA1:5B3788727ABD333B4C2319DFFFB290DA208FF55B
                  SHA-256:536B940181F079D8F11E1AEC84E5F3C1B856C7CD2378A412A025F5816028A4BD
                  SHA-512:F95A779044320C334BCE302BAD358A6166A23C1040B811F190A7BD14FFB284087271E2564F3276A674409E9CAF432D08297AC2733227C50A3C630F3171512701
                  Malicious:true
                  Preview:a6..p..h.....d;...XG......+.+.Af.h.J..d....x.N.....I%.%.S(...HE...D..@..._....2k.w.5K]..3.O.U..",.}....Vu.c..~."...WI.....}..].fD..l..P.}.....f......-.4.$G..2g..W....I..3..m.l......E..1...\u..'8.6n.Y,PqX[.PL]....\.'e*,.._..z.V.....@Ed..i7K.....b......:.]...1..FJ T#......~.......zIe-..Q).P.... R..S.w.`.C:..Q.>.9.._.....'>.....P4%.e....mUP..lf..y.....>...U.....%..5..xd....E..).U....OKp$.....o...H..k.....d...>..d.....A.lC]1.....2e.@.7..f.GS../..o.!.1?$..V..Hr.... ..^e......o..4W......pm...|.i.D...#.....X%q..........p.Vstg...S...5..X..js...Q...`..+....."n.h(,..O..V.N...z.2.i.......B.%.F>..nM.U.=4...c1.d..H.}?..u....s..L..ywF......@|.%.._g.)+..."..8...8......`xY...=..1..wB).f....q.M..o7.`....a\.g...~.oU........N...e5..[.F.9..Y.. `...@hOM....#...=...W........._|..I...u,51.Z..S.......}.u.....j..........N.....'..6-4|2....=..y...w...f..09M==..tW.Xs!.w\Y.gm..y...}.7.F.dy.2..0K.=Z...Nxr!:;o..Q...e..$...].-...)D9X...C..O.A.Qy.......F8...$cE.".1.F...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):503318
                  Entropy (8bit):7.999643513865518
                  Encrypted:true
                  SSDEEP:
                  MD5:CD77808BD2AB11FA0D12A39428E7DB07
                  SHA1:5B3788727ABD333B4C2319DFFFB290DA208FF55B
                  SHA-256:536B940181F079D8F11E1AEC84E5F3C1B856C7CD2378A412A025F5816028A4BD
                  SHA-512:F95A779044320C334BCE302BAD358A6166A23C1040B811F190A7BD14FFB284087271E2564F3276A674409E9CAF432D08297AC2733227C50A3C630F3171512701
                  Malicious:true
                  Preview:a6..p..h.....d;...XG......+.+.Af.h.J..d....x.N.....I%.%.S(...HE...D..@..._....2k.w.5K]..3.O.U..",.}....Vu.c..~."...WI.....}..].fD..l..P.}.....f......-.4.$G..2g..W....I..3..m.l......E..1...\u..'8.6n.Y,PqX[.PL]....\.'e*,.._..z.V.....@Ed..i7K.....b......:.]...1..FJ T#......~.......zIe-..Q).P.... R..S.w.`.C:..Q.>.9.._.....'>.....P4%.e....mUP..lf..y.....>...U.....%..5..xd....E..).U....OKp$.....o...H..k.....d...>..d.....A.lC]1.....2e.@.7..f.GS../..o.!.1?$..V..Hr.... ..^e......o..4W......pm...|.i.D...#.....X%q..........p.Vstg...S...5..X..js...Q...`..+....."n.h(,..O..V.N...z.2.i.......B.%.F>..nM.U.=4...c1.d..H.}?..u....s..L..ywF......@|.%.._g.)+..."..8...8......`xY...=..1..wB).f....q.M..o7.`....a\.g...~.oU........N...e5..[.F.9..Y.. `...@hOM....#...=...W........._|..I...u,51.Z..S.......}.u.....j..........N.....'..6-4|2....=..y...w...f..09M==..tW.Xs!.w\Y.gm..y...}.7.F.dy.2..0K.=Z...Nxr!:;o..Q...e..$...].-...)D9X...C..O.A.Qy.......F8...$cE.".1.F...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):503318
                  Entropy (8bit):7.999643513865518
                  Encrypted:true
                  SSDEEP:
                  MD5:CD77808BD2AB11FA0D12A39428E7DB07
                  SHA1:5B3788727ABD333B4C2319DFFFB290DA208FF55B
                  SHA-256:536B940181F079D8F11E1AEC84E5F3C1B856C7CD2378A412A025F5816028A4BD
                  SHA-512:F95A779044320C334BCE302BAD358A6166A23C1040B811F190A7BD14FFB284087271E2564F3276A674409E9CAF432D08297AC2733227C50A3C630F3171512701
                  Malicious:true
                  Preview:a6..p..h.....d;...XG......+.+.Af.h.J..d....x.N.....I%.%.S(...HE...D..@..._....2k.w.5K]..3.O.U..",.}....Vu.c..~."...WI.....}..].fD..l..P.}.....f......-.4.$G..2g..W....I..3..m.l......E..1...\u..'8.6n.Y,PqX[.PL]....\.'e*,.._..z.V.....@Ed..i7K.....b......:.]...1..FJ T#......~.......zIe-..Q).P.... R..S.w.`.C:..Q.>.9.._.....'>.....P4%.e....mUP..lf..y.....>...U.....%..5..xd....E..).U....OKp$.....o...H..k.....d...>..d.....A.lC]1.....2e.@.7..f.GS../..o.!.1?$..V..Hr.... ..^e......o..4W......pm...|.i.D...#.....X%q..........p.Vstg...S...5..X..js...Q...`..+....."n.h(,..O..V.N...z.2.i.......B.%.F>..nM.U.=4...c1.d..H.}?..u....s..L..ywF......@|.%.._g.)+..."..8...8......`xY...=..1..wB).f....q.M..o7.`....a\.g...~.oU........N...e5..[.F.9..Y.. `...@hOM....#...=...W........._|..I...u,51.Z..S.......}.u.....j..........N.....'..6-4|2....=..y...w...f..09M==..tW.Xs!.w\Y.gm..y...}.7.F.dy.2..0K.=Z...Nxr!:;o..Q...e..$...].-...)D9X...C..O.A.Qy.......F8...$cE.".1.F...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):500707
                  Entropy (8bit):7.99959181368382
                  Encrypted:true
                  SSDEEP:
                  MD5:A3DF166D4D873ACD7FB7365DDC01B05F
                  SHA1:3F7486391F552F84BD161C88538CFCF0C10545E9
                  SHA-256:56E12F24AD58C63CB1FF07D641997C4B982472F7820EFE957635D2816F72B09E
                  SHA-512:35BF163D1D0F9C064E5A62F6930528F87C1B5BC40F31B9432028ECCCB18DA3E7806E71E61431FFF0BFAEADF66501D7B03C6DFFD4D3B83A54F6D889551E6F5B29
                  Malicious:true
                  Preview:x....mbh..8..^9Yg...g%..?....B.i.LA.>YWF....[..Uk...%xy..H...i.=..`.fk.\....D..."...OM|...[.3......K...Au..mi.1...6.q......j...C...0.......8P,.Z.[7C.(.~N.<......p..72.-.........!.$#....Q/w..*..e;....-..v...>`..\S..z"..r.u.x..aA.....C.e.;b<.j..t......<...y...i..'.n.H7D....,.-..B.i;.N.....\;.f..O.{.?..ky..4....Z.[:..*.2;.b...j.^..?...G.3.......#.R0.e3p6.........;..f../t..~G.q}.\O..t.6.,4..x.lSQ_K.1!.....>.9:.v.v..K].'...L.P...Q'...i....../Z..u..h....+..8...k.......'Ai!.R...........%.D........8..L?,.....J.....-..!rz.,=..."(.:.[.M9P..P3\G.%....ow......`qW....p..}S"P..y..)..l>:/.;...vf-.6YkS....I.....>..H.!3'3..0...s-...X.>IU..(F_H.{..i.....\..E.B.gG.N....,.....f.QJ6.i.X.[@.%Y..9...Z....3.N......J...t..$.4.@A.7........G...z.....d...Mig.....M..A..6.._.7...6..1.W....O..A...\.H...*.k..VR@I.t.^......4....>.I.3....O2P%G.. Q...8.I1.0f6F....W.p.....Q.IUK1:.LV.5a..].4.1h4.o..!.%I.9...A..$.b.I.=|.H(WM.cmg#+"G..o..4.8)....k9.c;?...._kpI...6f.*...S.C..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):500707
                  Entropy (8bit):7.99959181368382
                  Encrypted:true
                  SSDEEP:
                  MD5:A3DF166D4D873ACD7FB7365DDC01B05F
                  SHA1:3F7486391F552F84BD161C88538CFCF0C10545E9
                  SHA-256:56E12F24AD58C63CB1FF07D641997C4B982472F7820EFE957635D2816F72B09E
                  SHA-512:35BF163D1D0F9C064E5A62F6930528F87C1B5BC40F31B9432028ECCCB18DA3E7806E71E61431FFF0BFAEADF66501D7B03C6DFFD4D3B83A54F6D889551E6F5B29
                  Malicious:true
                  Preview:x....mbh..8..^9Yg...g%..?....B.i.LA.>YWF....[..Uk...%xy..H...i.=..`.fk.\....D..."...OM|...[.3......K...Au..mi.1...6.q......j...C...0.......8P,.Z.[7C.(.~N.<......p..72.-.........!.$#....Q/w..*..e;....-..v...>`..\S..z"..r.u.x..aA.....C.e.;b<.j..t......<...y...i..'.n.H7D....,.-..B.i;.N.....\;.f..O.{.?..ky..4....Z.[:..*.2;.b...j.^..?...G.3.......#.R0.e3p6.........;..f../t..~G.q}.\O..t.6.,4..x.lSQ_K.1!.....>.9:.v.v..K].'...L.P...Q'...i....../Z..u..h....+..8...k.......'Ai!.R...........%.D........8..L?,.....J.....-..!rz.,=..."(.:.[.M9P..P3\G.%....ow......`qW....p..}S"P..y..)..l>:/.;...vf-.6YkS....I.....>..H.!3'3..0...s-...X.>IU..(F_H.{..i.....\..E.B.gG.N....,.....f.QJ6.i.X.[@.%Y..9...Z....3.N......J...t..$.4.@A.7........G...z.....d...Mig.....M..A..6.._.7...6..1.W....O..A...\.H...*.k..VR@I.t.^......4....>.I.3....O2P%G.. Q...8.I1.0f6F....W.p.....Q.IUK1:.LV.5a..].4.1h4.o..!.%I.9...A..$.b.I.=|.H(WM.cmg#+"G..o..4.8)....k9.c;?...._kpI...6f.*...S.C..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):500707
                  Entropy (8bit):7.99959181368382
                  Encrypted:true
                  SSDEEP:
                  MD5:A3DF166D4D873ACD7FB7365DDC01B05F
                  SHA1:3F7486391F552F84BD161C88538CFCF0C10545E9
                  SHA-256:56E12F24AD58C63CB1FF07D641997C4B982472F7820EFE957635D2816F72B09E
                  SHA-512:35BF163D1D0F9C064E5A62F6930528F87C1B5BC40F31B9432028ECCCB18DA3E7806E71E61431FFF0BFAEADF66501D7B03C6DFFD4D3B83A54F6D889551E6F5B29
                  Malicious:true
                  Preview:x....mbh..8..^9Yg...g%..?....B.i.LA.>YWF....[..Uk...%xy..H...i.=..`.fk.\....D..."...OM|...[.3......K...Au..mi.1...6.q......j...C...0.......8P,.Z.[7C.(.~N.<......p..72.-.........!.$#....Q/w..*..e;....-..v...>`..\S..z"..r.u.x..aA.....C.e.;b<.j..t......<...y...i..'.n.H7D....,.-..B.i;.N.....\;.f..O.{.?..ky..4....Z.[:..*.2;.b...j.^..?...G.3.......#.R0.e3p6.........;..f../t..~G.q}.\O..t.6.,4..x.lSQ_K.1!.....>.9:.v.v..K].'...L.P...Q'...i....../Z..u..h....+..8...k.......'Ai!.R...........%.D........8..L?,.....J.....-..!rz.,=..."(.:.[.M9P..P3\G.%....ow......`qW....p..}S"P..y..)..l>:/.;...vf-.6YkS....I.....>..H.!3'3..0...s-...X.>IU..(F_H.{..i.....\..E.B.gG.N....,.....f.QJ6.i.X.[@.%Y..9...Z....3.N......J...t..$.4.@A.7........G...z.....d...Mig.....M..A..6.._.7...6..1.W....O..A...\.H...*.k..VR@I.t.^......4....>.I.3....O2P%G.. Q...8.I1.0f6F....W.p.....Q.IUK1:.LV.5a..].4.1h4.o..!.%I.9...A..$.b.I.=|.H(WM.cmg#+"G..o..4.8)....k9.c;?...._kpI...6f.*...S.C..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1148792
                  Entropy (8bit):7.999819270685327
                  Encrypted:true
                  SSDEEP:
                  MD5:46819D6E8A532C745A64BE3E18FA1D9E
                  SHA1:02FC267AD6783FA751CF7550579B3754BD7E4A6E
                  SHA-256:B5A10C1CA0515B1A0642BDAF06D347C589401CCB4EDD9A04CC5B5376729174EA
                  SHA-512:4C5168E39880EB7FC45D19A98B019EA3958B319B0BD410B0DD8BC5A1179A4E3109CBA316928E3AA6BE76017A3C05C6C284F030A6182717D9EC906A3CE93664A1
                  Malicious:true
                  Preview:.Z.i.E..y...D...U..F.lM.`1X....K...r[...?;.5..Y}...@s g...C.?.\-......$.......t...a...R...N.l.......Ga...U)...4-Z....a.'<.6*^p..a....".@.5-_........o.?......>.V.HK.....pN...l.>.Rn7..Lqk...;p.,..3K.B.....S :.S.I....P.~...y;..2U. ..o...Fb.Y...U....JqK....$.K...........Y...y!.iT._.\0....._-M...j.l...]..Up.....<.4.....*0/Q..]B.0.........wI..D...m.<.pA.d..;N..(7.$.:n..Q_..Y..;h....z.7......o[...m..s..v\7.S..P?..........Ro.c..M.v.JW.`.i:...f.U.....M..|.......=.\...'.].{+<3o{.....-.L5.....$.+.=.p......2.[.N..<./04... ..@.]..]..Z......fx..$....x.m.T~9)j.i...7..@..aF.B.......8..w.C.."...Af...~`..urPX.....x t.D......9..=...$B\y.2eF..(eV...?gZ|.M..X..........+..po!U.B.fbaJ(.........F.L."..,.|..?.............`7....oS...#8..X..?]..s......Y=..Mg...Y,....I.2-#+@.m...cH.....^.-.m...Y}-.6.RK...b.....4.t.X.".(.r{.P..h*.&m..-~.\e..0.buv.a.L.....{.(...a..e./..;....O.:....Y ...N.K.....7..u...f.%f...R....BqNY. ...6...vH/.w...vM.`..h.......JBD.c.u......>}.O.....Z..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1148792
                  Entropy (8bit):7.999819270685327
                  Encrypted:true
                  SSDEEP:
                  MD5:46819D6E8A532C745A64BE3E18FA1D9E
                  SHA1:02FC267AD6783FA751CF7550579B3754BD7E4A6E
                  SHA-256:B5A10C1CA0515B1A0642BDAF06D347C589401CCB4EDD9A04CC5B5376729174EA
                  SHA-512:4C5168E39880EB7FC45D19A98B019EA3958B319B0BD410B0DD8BC5A1179A4E3109CBA316928E3AA6BE76017A3C05C6C284F030A6182717D9EC906A3CE93664A1
                  Malicious:true
                  Preview:.Z.i.E..y...D...U..F.lM.`1X....K...r[...?;.5..Y}...@s g...C.?.\-......$.......t...a...R...N.l.......Ga...U)...4-Z....a.'<.6*^p..a....".@.5-_........o.?......>.V.HK.....pN...l.>.Rn7..Lqk...;p.,..3K.B.....S :.S.I....P.~...y;..2U. ..o...Fb.Y...U....JqK....$.K...........Y...y!.iT._.\0....._-M...j.l...]..Up.....<.4.....*0/Q..]B.0.........wI..D...m.<.pA.d..;N..(7.$.:n..Q_..Y..;h....z.7......o[...m..s..v\7.S..P?..........Ro.c..M.v.JW.`.i:...f.U.....M..|.......=.\...'.].{+<3o{.....-.L5.....$.+.=.p......2.[.N..<./04... ..@.]..]..Z......fx..$....x.m.T~9)j.i...7..@..aF.B.......8..w.C.."...Af...~`..urPX.....x t.D......9..=...$B\y.2eF..(eV...?gZ|.M..X..........+..po!U.B.fbaJ(.........F.L."..,.|..?.............`7....oS...#8..X..?]..s......Y=..Mg...Y,....I.2-#+@.m...cH.....^.-.m...Y}-.6.RK...b.....4.t.X.".(.r{.P..h*.&m..-~.\e..0.buv.a.L.....{.(...a..e./..;....O.:....Y ...N.K.....7..u...f.%f...R....BqNY. ...6...vH/.w...vM.`..h.......JBD.c.u......>}.O.....Z..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1148792
                  Entropy (8bit):7.999819270685327
                  Encrypted:true
                  SSDEEP:
                  MD5:46819D6E8A532C745A64BE3E18FA1D9E
                  SHA1:02FC267AD6783FA751CF7550579B3754BD7E4A6E
                  SHA-256:B5A10C1CA0515B1A0642BDAF06D347C589401CCB4EDD9A04CC5B5376729174EA
                  SHA-512:4C5168E39880EB7FC45D19A98B019EA3958B319B0BD410B0DD8BC5A1179A4E3109CBA316928E3AA6BE76017A3C05C6C284F030A6182717D9EC906A3CE93664A1
                  Malicious:true
                  Preview:.Z.i.E..y...D...U..F.lM.`1X....K...r[...?;.5..Y}...@s g...C.?.\-......$.......t...a...R...N.l.......Ga...U)...4-Z....a.'<.6*^p..a....".@.5-_........o.?......>.V.HK.....pN...l.>.Rn7..Lqk...;p.,..3K.B.....S :.S.I....P.~...y;..2U. ..o...Fb.Y...U....JqK....$.K...........Y...y!.iT._.\0....._-M...j.l...]..Up.....<.4.....*0/Q..]B.0.........wI..D...m.<.pA.d..;N..(7.$.:n..Q_..Y..;h....z.7......o[...m..s..v\7.S..P?..........Ro.c..M.v.JW.`.i:...f.U.....M..|.......=.\...'.].{+<3o{.....-.L5.....$.+.=.p......2.[.N..<./04... ..@.]..]..Z......fx..$....x.m.T~9)j.i...7..@..aF.B.......8..w.C.."...Af...~`..urPX.....x t.D......9..=...$B\y.2eF..(eV...?gZ|.M..X..........+..po!U.B.fbaJ(.........F.L."..,.|..?.............`7....oS...#8..X..?]..s......Y=..Mg...Y,....I.2-#+@.m...cH.....^.-.m...Y}-.6.RK...b.....4.t.X.".(.r{.P..h*.&m..-~.\e..0.buv.a.L.....{.(...a..e./..;....O.:....Y ...N.K.....7..u...f.%f...R....BqNY. ...6...vH/.w...vM.`..h.......JBD.c.u......>}.O.....Z..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):942870
                  Entropy (8bit):7.999807632604298
                  Encrypted:true
                  SSDEEP:
                  MD5:B78C7BBD8BBBD8CB7DA0D9633FD5662B
                  SHA1:3C55E87A7330D7CE97B90E72ECD6704B4DDC6E5B
                  SHA-256:207F61404EC05CA379EAB839154E2088B8F294E1DDC42E4471D872AAFC1B634F
                  SHA-512:0ED747B7C7B5B5717ED35FAFA74A9C858B59309BF7B5644996F13B46C78C352EE1D7E80B6C2064EB327BE34294F3BE85FE150BB871C1D588D6DA3D5A54F86514
                  Malicious:true
                  Preview:..d....F....L....%._|.G.-...........HzU...a.q...*&......&R........V...\.[\u...!...1.....[/...-k...V..........iW[....Id.t D.M..P.Y.-q9.......o.G.=.X.@...QRw.$G.`!rCfb..+.4N....].....j.<+.E-*ic...q.E...=8$..v.1&.UN.[t1..$....I'.....L.v....W.Lm...>!j... 2 W.....<P..3z9..6....[.mOe(|.T.ka.a".<A.<.W..V.t.g..]$i...Y.....Y....w...Q..G..Z..kH.q.`V.x..Q.s.=......H......^q...q~..|g..uFso.m......"...........{..I....w....i.....s~...^E"bow.!..~wJ.|..-.?.:.l.%....C....i.6e.~.....q7.:..:b.........[a.V.=..../..^..(P0r..+...."..ou./...!.J.y#w..Hq.N.>.IZ.....^].|.c...I...j.o.dc..}!.g.o=..gt.4c.C.*8..l*(<p...NS\...rK...D...I...>[*q...E.....j.Z.].6.rN.....x.h..@.^....I.v+.....C....E.|...._..VYBS..?.|.~k=.h.N.;j..=L.Zp.}..fG2zV.....y#Z..d=.o.....-....9..."'.!&.N./..M..T...C..>}..I[Na.G1G..BT{..1.].....*.n+<..^...+0..N...RR.....;..4...[q...:[,...U...M....O.j.....]...x... 4NB...}1...9.-.....W..M.M.c..\.#.......H.....L.(8L.X.Ki..{`.U...=!...3..O)h..\.C5..x
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):942870
                  Entropy (8bit):7.999807632604298
                  Encrypted:true
                  SSDEEP:
                  MD5:B78C7BBD8BBBD8CB7DA0D9633FD5662B
                  SHA1:3C55E87A7330D7CE97B90E72ECD6704B4DDC6E5B
                  SHA-256:207F61404EC05CA379EAB839154E2088B8F294E1DDC42E4471D872AAFC1B634F
                  SHA-512:0ED747B7C7B5B5717ED35FAFA74A9C858B59309BF7B5644996F13B46C78C352EE1D7E80B6C2064EB327BE34294F3BE85FE150BB871C1D588D6DA3D5A54F86514
                  Malicious:true
                  Preview:..d....F....L....%._|.G.-...........HzU...a.q...*&......&R........V...\.[\u...!...1.....[/...-k...V..........iW[....Id.t D.M..P.Y.-q9.......o.G.=.X.@...QRw.$G.`!rCfb..+.4N....].....j.<+.E-*ic...q.E...=8$..v.1&.UN.[t1..$....I'.....L.v....W.Lm...>!j... 2 W.....<P..3z9..6....[.mOe(|.T.ka.a".<A.<.W..V.t.g..]$i...Y.....Y....w...Q..G..Z..kH.q.`V.x..Q.s.=......H......^q...q~..|g..uFso.m......"...........{..I....w....i.....s~...^E"bow.!..~wJ.|..-.?.:.l.%....C....i.6e.~.....q7.:..:b.........[a.V.=..../..^..(P0r..+...."..ou./...!.J.y#w..Hq.N.>.IZ.....^].|.c...I...j.o.dc..}!.g.o=..gt.4c.C.*8..l*(<p...NS\...rK...D...I...>[*q...E.....j.Z.].6.rN.....x.h..@.^....I.v+.....C....E.|...._..VYBS..?.|.~k=.h.N.;j..=L.Zp.}..fG2zV.....y#Z..d=.o.....-....9..."'.!&.N./..M..T...C..>}..I[Na.G1G..BT{..1.].....*.n+<..^...+0..N...RR.....;..4...[q...:[,...U...M....O.j.....]...x... 4NB...}1...9.-.....W..M.M.c..\.#.......H.....L.(8L.X.Ki..{`.U...=!...3..O)h..\.C5..x
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):942870
                  Entropy (8bit):7.999807632604298
                  Encrypted:true
                  SSDEEP:
                  MD5:B78C7BBD8BBBD8CB7DA0D9633FD5662B
                  SHA1:3C55E87A7330D7CE97B90E72ECD6704B4DDC6E5B
                  SHA-256:207F61404EC05CA379EAB839154E2088B8F294E1DDC42E4471D872AAFC1B634F
                  SHA-512:0ED747B7C7B5B5717ED35FAFA74A9C858B59309BF7B5644996F13B46C78C352EE1D7E80B6C2064EB327BE34294F3BE85FE150BB871C1D588D6DA3D5A54F86514
                  Malicious:true
                  Preview:..d....F....L....%._|.G.-...........HzU...a.q...*&......&R........V...\.[\u...!...1.....[/...-k...V..........iW[....Id.t D.M..P.Y.-q9.......o.G.=.X.@...QRw.$G.`!rCfb..+.4N....].....j.<+.E-*ic...q.E...=8$..v.1&.UN.[t1..$....I'.....L.v....W.Lm...>!j... 2 W.....<P..3z9..6....[.mOe(|.T.ka.a".<A.<.W..V.t.g..]$i...Y.....Y....w...Q..G..Z..kH.q.`V.x..Q.s.=......H......^q...q~..|g..uFso.m......"...........{..I....w....i.....s~...^E"bow.!..~wJ.|..-.?.:.l.%....C....i.6e.~.....q7.:..:b.........[a.V.=..../..^..(P0r..+...."..ou./...!.J.y#w..Hq.N.>.IZ.....^].|.c...I...j.o.dc..}!.g.o=..gt.4c.C.*8..l*(<p...NS\...rK...D...I...>[*q...E.....j.Z.].6.rN.....x.h..@.^....I.v+.....C....E.|...._..VYBS..?.|.~k=.h.N.;j..=L.Zp.}..fG2zV.....y#Z..d=.o.....-....9..."'.!&.N./..M..T...C..>}..I[Na.G1G..BT{..1.].....*.n+<..^...+0..N...RR.....;..4...[q...:[,...U...M....O.j.....]...x... 4NB...}1...9.-.....W..M.M.c..\.#.......H.....L.(8L.X.Ki..{`.U...=!...3..O)h..\.C5..x
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):427785
                  Entropy (8bit):7.999563997766469
                  Encrypted:true
                  SSDEEP:
                  MD5:1C07220CC18509777F199E35D4D01817
                  SHA1:A3AAA59A5F1844CD861C72DD620DEC5C5180D50B
                  SHA-256:FAC24394861488FB8169E9F292C14F66CFC1FA30BA67C0CA22D26320F8C45C73
                  SHA-512:F1039018CF421B689E48B40C688E2A5B59B315924C216C66E8F1C7EDE7430BE523E35805FDC2775E8B8988B9CF2FF0B3BF16A7982F19DDA9B50532C7B79D25A5
                  Malicious:true
                  Preview:?..5..........)./l>..}+.8...C.,.E..f.i.2.[.!"b....?..}.&..aEd.y....;.N.p.]..M...C..ialky...6....2.3.n.|..me'.......E0J.mY...}'G....q.......m..Z......j..-l.2.:..c..!:.[.........+.!....g.j...j.... .....[.$M..H..>...H*..+xI.-....ti...2..%k..O.n../j...?.z6k.^.[.N@..v....Q.....Tt......m.....%../....;....M.$D..b.<r.....v..w.`.p.N.t!...:..p'..BK.P.Z.pv<..u.t...........cL."..<UY+..T.M.~...b..N.U..C=.v.....(. .].......c..;.....:....w|.p........RLy.N#E......u..r..O......s.0.iU).. z."...@...*.......7...M.w...S.o#..=.....8.*Q.V..../...gNG%..v)E8.N..#D....f....G... Bk.&..w......../..4.f..Q]....>..>..H....5...NE..-.....+....j...Ea.=hN.ZnUY......@...B}:....oF.....$}..w..P.L..h...?...g.....!..%.M..[kq.........l..k......1i.-m9.........(..~Q..V1.....G)..SW.)..a{0.(..H.G.W40hJx....C.g5 ..[..]...Co6.+kG..".|....h..j.&...+.......Az.?......,.)t*.#.d}?.S.F..t'..Vf.U.b...f|.D.....A....*....:,...R.X...Y<..e.b..1sQ..Ly.D.b...:A..2.n.j....6.e5(66...T...X.^.<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):427785
                  Entropy (8bit):7.999563997766469
                  Encrypted:true
                  SSDEEP:
                  MD5:1C07220CC18509777F199E35D4D01817
                  SHA1:A3AAA59A5F1844CD861C72DD620DEC5C5180D50B
                  SHA-256:FAC24394861488FB8169E9F292C14F66CFC1FA30BA67C0CA22D26320F8C45C73
                  SHA-512:F1039018CF421B689E48B40C688E2A5B59B315924C216C66E8F1C7EDE7430BE523E35805FDC2775E8B8988B9CF2FF0B3BF16A7982F19DDA9B50532C7B79D25A5
                  Malicious:true
                  Preview:?..5..........)./l>..}+.8...C.,.E..f.i.2.[.!"b....?..}.&..aEd.y....;.N.p.]..M...C..ialky...6....2.3.n.|..me'.......E0J.mY...}'G....q.......m..Z......j..-l.2.:..c..!:.[.........+.!....g.j...j.... .....[.$M..H..>...H*..+xI.-....ti...2..%k..O.n../j...?.z6k.^.[.N@..v....Q.....Tt......m.....%../....;....M.$D..b.<r.....v..w.`.p.N.t!...:..p'..BK.P.Z.pv<..u.t...........cL."..<UY+..T.M.~...b..N.U..C=.v.....(. .].......c..;.....:....w|.p........RLy.N#E......u..r..O......s.0.iU).. z."...@...*.......7...M.w...S.o#..=.....8.*Q.V..../...gNG%..v)E8.N..#D....f....G... Bk.&..w......../..4.f..Q]....>..>..H....5...NE..-.....+....j...Ea.=hN.ZnUY......@...B}:....oF.....$}..w..P.L..h...?...g.....!..%.M..[kq.........l..k......1i.-m9.........(..~Q..V1.....G)..SW.)..a{0.(..H.G.W40hJx....C.g5 ..[..]...Co6.+kG..".|....h..j.&...+.......Az.?......,.)t*.#.d}?.S.F..t'..Vf.U.b...f|.D.....A....*....:,...R.X...Y<..e.b..1sQ..Ly.D.b...:A..2.n.j....6.e5(66...T...X.^.<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):427785
                  Entropy (8bit):7.999563997766469
                  Encrypted:true
                  SSDEEP:
                  MD5:1C07220CC18509777F199E35D4D01817
                  SHA1:A3AAA59A5F1844CD861C72DD620DEC5C5180D50B
                  SHA-256:FAC24394861488FB8169E9F292C14F66CFC1FA30BA67C0CA22D26320F8C45C73
                  SHA-512:F1039018CF421B689E48B40C688E2A5B59B315924C216C66E8F1C7EDE7430BE523E35805FDC2775E8B8988B9CF2FF0B3BF16A7982F19DDA9B50532C7B79D25A5
                  Malicious:true
                  Preview:?..5..........)./l>..}+.8...C.,.E..f.i.2.[.!"b....?..}.&..aEd.y....;.N.p.]..M...C..ialky...6....2.3.n.|..me'.......E0J.mY...}'G....q.......m..Z......j..-l.2.:..c..!:.[.........+.!....g.j...j.... .....[.$M..H..>...H*..+xI.-....ti...2..%k..O.n../j...?.z6k.^.[.N@..v....Q.....Tt......m.....%../....;....M.$D..b.<r.....v..w.`.p.N.t!...:..p'..BK.P.Z.pv<..u.t...........cL."..<UY+..T.M.~...b..N.U..C=.v.....(. .].......c..;.....:....w|.p........RLy.N#E......u..r..O......s.0.iU).. z."...@...*.......7...M.w...S.o#..=.....8.*Q.V..../...gNG%..v)E8.N..#D....f....G... Bk.&..w......../..4.f..Q]....>..>..H....5...NE..-.....+....j...Ea.=hN.ZnUY......@...B}:....oF.....$}..w..P.L..h...?...g.....!..%.M..[kq.........l..k......1i.-m9.........(..~Q..V1.....G)..SW.)..a{0.(..H.G.W40hJx....C.g5 ..[..]...Co6.+kG..".|....h..j.&...+.......Az.?......,.)t*.#.d}?.S.F..t'..Vf.U.b...f|.D.....A....*....:,...R.X...Y<..e.b..1sQ..Ly.D.b...:A..2.n.j....6.e5(66...T...X.^.<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):418333
                  Entropy (8bit):7.999531851516022
                  Encrypted:true
                  SSDEEP:
                  MD5:D407D045672E8B05B34876B05B71FE16
                  SHA1:30440B2020DB99A580877BFD71BDBBFAC399D12A
                  SHA-256:AFC8AE97A98E4DB5CC1138DCD1CDC80C2771383A2AA005F9F6C4C2A51DD7996B
                  SHA-512:3B9CD760BE887881D1404028DA65314965F6CD3B11BB0070DD93A1C733586C1489BF399BE955B70BA3A62AA0CD3FAD59FA44DE8C6A71B2FE15E9C851F2EA3FA4
                  Malicious:true
                  Preview:.2..2.\.c....}........m4.r.:.`.>.i.......G.#.F[..a...S.....CSo;.....x.mg3*.!......=.`..xr..%.|.z../8.....\...sA8...).>.A1..f.mq..c.O ._L...-w[...}L.}..8...v.A8.[._C.;4{O.........\.t.....T.E..z.=x.]x..OWq.G.$......o.....*...\........+r.k}.C.W...[n....y-..-..|....=...ao..H....6..B.<...d.P....\x.7.#..EW.D$......o...M+.}..m&..Gu...........s....n}..c`..`..N<.....u...&p.% ....p.m6.x.V..Dt..$...:.. !...N....%H?fF.R..F.(..)jo.s........a.....{.V..Z.-.xQ.l.....)....$...!i....)b..]AN..jk.T......s`.`....E>....z."..^.."{.[..h...]^Y..e.....h..{....$....*./!..`.T'...\.6..*..K..C./'.../.....x...O`hW.e..a.....j..N.....V..BW......9..Ko...0T.bH9....'.L...q...pm,..H.I/.....*5...E7....i....fz....G.2..c....H.p..H..'.o.J.i..h.....f......;.".nO..i]`..y.pX,..O..-|....k....3.:..p.d.B.l.....HV..(..S...-.m.p.....P....!. .?..1.%.N.#..s....b..$:....x>\Q.x.4...%..d..VDC........N..nS....X0..b..v...@...?.p..y.W.Jc=}lx0R..>9..S.......$Qf.Vj*.7vs.F...t......b.B....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):418333
                  Entropy (8bit):7.999531851516022
                  Encrypted:true
                  SSDEEP:
                  MD5:D407D045672E8B05B34876B05B71FE16
                  SHA1:30440B2020DB99A580877BFD71BDBBFAC399D12A
                  SHA-256:AFC8AE97A98E4DB5CC1138DCD1CDC80C2771383A2AA005F9F6C4C2A51DD7996B
                  SHA-512:3B9CD760BE887881D1404028DA65314965F6CD3B11BB0070DD93A1C733586C1489BF399BE955B70BA3A62AA0CD3FAD59FA44DE8C6A71B2FE15E9C851F2EA3FA4
                  Malicious:true
                  Preview:.2..2.\.c....}........m4.r.:.`.>.i.......G.#.F[..a...S.....CSo;.....x.mg3*.!......=.`..xr..%.|.z../8.....\...sA8...).>.A1..f.mq..c.O ._L...-w[...}L.}..8...v.A8.[._C.;4{O.........\.t.....T.E..z.=x.]x..OWq.G.$......o.....*...\........+r.k}.C.W...[n....y-..-..|....=...ao..H....6..B.<...d.P....\x.7.#..EW.D$......o...M+.}..m&..Gu...........s....n}..c`..`..N<.....u...&p.% ....p.m6.x.V..Dt..$...:.. !...N....%H?fF.R..F.(..)jo.s........a.....{.V..Z.-.xQ.l.....)....$...!i....)b..]AN..jk.T......s`.`....E>....z."..^.."{.[..h...]^Y..e.....h..{....$....*./!..`.T'...\.6..*..K..C./'.../.....x...O`hW.e..a.....j..N.....V..BW......9..Ko...0T.bH9....'.L...q...pm,..H.I/.....*5...E7....i....fz....G.2..c....H.p..H..'.o.J.i..h.....f......;.".nO..i]`..y.pX,..O..-|....k....3.:..p.d.B.l.....HV..(..S...-.m.p.....P....!. .?..1.%.N.#..s....b..$:....x>\Q.x.4...%..d..VDC........N..nS....X0..b..v...@...?.p..y.W.Jc=}lx0R..>9..S.......$Qf.Vj*.7vs.F...t......b.B....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):418333
                  Entropy (8bit):7.999531851516022
                  Encrypted:true
                  SSDEEP:
                  MD5:D407D045672E8B05B34876B05B71FE16
                  SHA1:30440B2020DB99A580877BFD71BDBBFAC399D12A
                  SHA-256:AFC8AE97A98E4DB5CC1138DCD1CDC80C2771383A2AA005F9F6C4C2A51DD7996B
                  SHA-512:3B9CD760BE887881D1404028DA65314965F6CD3B11BB0070DD93A1C733586C1489BF399BE955B70BA3A62AA0CD3FAD59FA44DE8C6A71B2FE15E9C851F2EA3FA4
                  Malicious:true
                  Preview:.2..2.\.c....}........m4.r.:.`.>.i.......G.#.F[..a...S.....CSo;.....x.mg3*.!......=.`..xr..%.|.z../8.....\...sA8...).>.A1..f.mq..c.O ._L...-w[...}L.}..8...v.A8.[._C.;4{O.........\.t.....T.E..z.=x.]x..OWq.G.$......o.....*...\........+r.k}.C.W...[n....y-..-..|....=...ao..H....6..B.<...d.P....\x.7.#..EW.D$......o...M+.}..m&..Gu...........s....n}..c`..`..N<.....u...&p.% ....p.m6.x.V..Dt..$...:.. !...N....%H?fF.R..F.(..)jo.s........a.....{.V..Z.-.xQ.l.....)....$...!i....)b..]AN..jk.T......s`.`....E>....z."..^.."{.[..h...]^Y..e.....h..{....$....*./!..`.T'...\.6..*..K..C./'.../.....x...O`hW.e..a.....j..N.....V..BW......9..Ko...0T.bH9....'.L...q...pm,..H.I/.....*5...E7....i....fz....G.2..c....H.p..H..'.o.J.i..h.....f......;.".nO..i]`..y.pX,..O..-|....k....3.:..p.d.B.l.....HV..(..S...-.m.p.....P....!. .?..1.%.N.#..s....b..$:....x>\Q.x.4...%..d..VDC........N..nS....X0..b..v...@...?.p..y.W.Jc=}lx0R..>9..S.......$Qf.Vj*.7vs.F...t......b.B....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):431456
                  Entropy (8bit):7.999594028010377
                  Encrypted:true
                  SSDEEP:
                  MD5:FF0E64AE27CE0C74B446B2EE012F368F
                  SHA1:D09AAE6001A7563666327F83424E4BF514AB2EE4
                  SHA-256:2ED7A40474BF2F37383517936512261AEA66716B4F76CAC5B6EE6DDEF357B418
                  SHA-512:BC88455B74F62B76D5EAA1CFB7D669591B54A3281A0F60A162DA7C467C8C9AF2B01B8FBF1DC85CA8B37280F082A6A2C1ECB60F032DA93D47C19F4D2A86AA5DD6
                  Malicious:true
                  Preview:.V6..D....%g.Q...$F.1T.o|I.;nC....j.e...).S...n..f.%.c.[...fU...Q8m.<.n<....k[. ..s....[T.q.[.....=.4.b..v+?....y.3....2S.S...\_~.u..Dd.U...5...Q....{t...y..+H..Q......$ \,.....<j....E...e....Z.:@C..."d.~......:#X@m...]..VF}..T.g.kD.E9..)........O1..'.....t....Lg*E.6_...P..ew.....M.0!G#.......)+!.k.0r.('77`..'Td..Af....Ny..I...`T....o......mI.!......<@`Mb..{IS.Q.J..t-}...d.k$....+t....i...P....x..]1.&.....s8..g.. ....u..bt~!."..g.....p"...%#:3.....5....BL..m.A[...VB0h.ar3L.....R.0.tf......C7...6.../)_3ip..0.?"zt..'.`..VGm..\.i.p.Xzfg._..p..fp4h.vm..U=....P.T....7H.4.xN...j".*......:l2.Z.y..2.........5qI^-m:a(..R5....j...rG....&.>...+.~.7...h.......M.....).D.z.d.S..>-Va...P...<..^3&.r.*.(KCD..u.<.._)-.x..S....`....%...7....H.Y..D.q...Bw.F(]...._..`..U.%h.n.eF..>g..*.F.s..T....sp..C..o..]..../....V.....7...N........r2..I.0>..K..{I6.W..s.D!...xf.p..u......2..~.F....7.yay..O..W.....E.....s:....09.........j.ze.T.u~.G..M.kB...$...%
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):431456
                  Entropy (8bit):7.999594028010377
                  Encrypted:true
                  SSDEEP:
                  MD5:FF0E64AE27CE0C74B446B2EE012F368F
                  SHA1:D09AAE6001A7563666327F83424E4BF514AB2EE4
                  SHA-256:2ED7A40474BF2F37383517936512261AEA66716B4F76CAC5B6EE6DDEF357B418
                  SHA-512:BC88455B74F62B76D5EAA1CFB7D669591B54A3281A0F60A162DA7C467C8C9AF2B01B8FBF1DC85CA8B37280F082A6A2C1ECB60F032DA93D47C19F4D2A86AA5DD6
                  Malicious:true
                  Preview:.V6..D....%g.Q...$F.1T.o|I.;nC....j.e...).S...n..f.%.c.[...fU...Q8m.<.n<....k[. ..s....[T.q.[.....=.4.b..v+?....y.3....2S.S...\_~.u..Dd.U...5...Q....{t...y..+H..Q......$ \,.....<j....E...e....Z.:@C..."d.~......:#X@m...]..VF}..T.g.kD.E9..)........O1..'.....t....Lg*E.6_...P..ew.....M.0!G#.......)+!.k.0r.('77`..'Td..Af....Ny..I...`T....o......mI.!......<@`Mb..{IS.Q.J..t-}...d.k$....+t....i...P....x..]1.&.....s8..g.. ....u..bt~!."..g.....p"...%#:3.....5....BL..m.A[...VB0h.ar3L.....R.0.tf......C7...6.../)_3ip..0.?"zt..'.`..VGm..\.i.p.Xzfg._..p..fp4h.vm..U=....P.T....7H.4.xN...j".*......:l2.Z.y..2.........5qI^-m:a(..R5....j...rG....&.>...+.~.7...h.......M.....).D.z.d.S..>-Va...P...<..^3&.r.*.(KCD..u.<.._)-.x..S....`....%...7....H.Y..D.q...Bw.F(]...._..`..U.%h.n.eF..>g..*.F.s..T....sp..C..o..]..../....V.....7...N........r2..I.0>..K..{I6.W..s.D!...xf.p..u......2..~.F....7.yay..O..W.....E.....s:....09.........j.ze.T.u~.G..M.kB...$...%
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):431456
                  Entropy (8bit):7.999594028010377
                  Encrypted:true
                  SSDEEP:
                  MD5:FF0E64AE27CE0C74B446B2EE012F368F
                  SHA1:D09AAE6001A7563666327F83424E4BF514AB2EE4
                  SHA-256:2ED7A40474BF2F37383517936512261AEA66716B4F76CAC5B6EE6DDEF357B418
                  SHA-512:BC88455B74F62B76D5EAA1CFB7D669591B54A3281A0F60A162DA7C467C8C9AF2B01B8FBF1DC85CA8B37280F082A6A2C1ECB60F032DA93D47C19F4D2A86AA5DD6
                  Malicious:true
                  Preview:.V6..D....%g.Q...$F.1T.o|I.;nC....j.e...).S...n..f.%.c.[...fU...Q8m.<.n<....k[. ..s....[T.q.[.....=.4.b..v+?....y.3....2S.S...\_~.u..Dd.U...5...Q....{t...y..+H..Q......$ \,.....<j....E...e....Z.:@C..."d.~......:#X@m...]..VF}..T.g.kD.E9..)........O1..'.....t....Lg*E.6_...P..ew.....M.0!G#.......)+!.k.0r.('77`..'Td..Af....Ny..I...`T....o......mI.!......<@`Mb..{IS.Q.J..t-}...d.k$....+t....i...P....x..]1.&.....s8..g.. ....u..bt~!."..g.....p"...%#:3.....5....BL..m.A[...VB0h.ar3L.....R.0.tf......C7...6.../)_3ip..0.?"zt..'.`..VGm..\.i.p.Xzfg._..p..fp4h.vm..U=....P.T....7H.4.xN...j".*......:l2.Z.y..2.........5qI^-m:a(..R5....j...rG....&.>...+.~.7...h.......M.....).D.z.d.S..>-Va...P...<..^3&.r.*.(KCD..u.<.._)-.x..S....`....%...7....H.Y..D.q...Bw.F(]...._..`..U.%h.n.eF..>g..*.F.s..T....sp..C..o..]..../....V.....7...N........r2..I.0>..K..{I6.W..s.D!...xf.p..u......2..~.F....7.yay..O..W.....E.....s:....09.........j.ze.T.u~.G..M.kB...$...%
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):483335
                  Entropy (8bit):7.999586392414984
                  Encrypted:true
                  SSDEEP:
                  MD5:81F502E4E5F1D63A3C1791D41D87C16D
                  SHA1:5DEE5D4348D832134D1AB3D6148F5DA5C964BFF1
                  SHA-256:4CF9C84CC200466539249B1FD241514E04260962A327BA9C799B6240CE64302D
                  SHA-512:EB75FCD1456458D56338935CBC273CEEEF5CC971FC56D9CE0E6BF030798D5D8C68D214763938869CC1303DA1D2A40CF1EDDE5F8EF7CB72F7BFAA80AFDC3CD926
                  Malicious:true
                  Preview:........bT.z.&.8.?...\KG+QX.tE. .(.0l.5......).z7+..A.L...w.....H..x...E..{..[...W.-9.z$Cb.W.\...;m...P..8..B..'B....K...i.2..4..5..<]{.(B.#..`...X}("......G.s...$.r.K&B.d.e.^...,Z ...?s.qj.fWb.x...2.,..o..S).........3&C<.S....g...+.....<&<.X.v.."..v_K../....0.W.f.....2......$.......e...n.9.........V......3[.JV.>.{.u...D..#..S..!....m..6..FU...k...y.........\...6?r....OCu.rP...7.z.A.Z....U...b(.Rc-..,.....w...s..6..N...U..._S......R..N..>...<...P<p'z...OM_.Tv...H_.%n.]/.s.......~/.>Z4`."8w..w.].%5.!k.>>..{.....B.....H.....W#A.2........}7..x.j...S....bb.X[o..5R.i..GP..=.d;4=.F..}.e.J.n.K.Js......u..<...w....x\G-.....hhv.K...p..Z&....D....*..hR.i."H.....k.....u.."v.hy2.Tx..},.{wn..M.~K...<.......Wrr.A.`.-q...Y..{.r1.W.........._R..0(".@....H.t..F3r..[9g.~...V.P..9).L+.....lO.!..B...E.c.#...w...j-+...@.t.}...}..l6..R`..kD.)...c....o..(..=...C.....[..a.OT%..+..&p.'2Q,b..%m........&.Q.`D.Ut.6.fJM...J.9TI........f.3...^z..h.Ri......}.Q....NYX.{Y.zH
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):483335
                  Entropy (8bit):7.999586392414984
                  Encrypted:true
                  SSDEEP:
                  MD5:81F502E4E5F1D63A3C1791D41D87C16D
                  SHA1:5DEE5D4348D832134D1AB3D6148F5DA5C964BFF1
                  SHA-256:4CF9C84CC200466539249B1FD241514E04260962A327BA9C799B6240CE64302D
                  SHA-512:EB75FCD1456458D56338935CBC273CEEEF5CC971FC56D9CE0E6BF030798D5D8C68D214763938869CC1303DA1D2A40CF1EDDE5F8EF7CB72F7BFAA80AFDC3CD926
                  Malicious:true
                  Preview:........bT.z.&.8.?...\KG+QX.tE. .(.0l.5......).z7+..A.L...w.....H..x...E..{..[...W.-9.z$Cb.W.\...;m...P..8..B..'B....K...i.2..4..5..<]{.(B.#..`...X}("......G.s...$.r.K&B.d.e.^...,Z ...?s.qj.fWb.x...2.,..o..S).........3&C<.S....g...+.....<&<.X.v.."..v_K../....0.W.f.....2......$.......e...n.9.........V......3[.JV.>.{.u...D..#..S..!....m..6..FU...k...y.........\...6?r....OCu.rP...7.z.A.Z....U...b(.Rc-..,.....w...s..6..N...U..._S......R..N..>...<...P<p'z...OM_.Tv...H_.%n.]/.s.......~/.>Z4`."8w..w.].%5.!k.>>..{.....B.....H.....W#A.2........}7..x.j...S....bb.X[o..5R.i..GP..=.d;4=.F..}.e.J.n.K.Js......u..<...w....x\G-.....hhv.K...p..Z&....D....*..hR.i."H.....k.....u.."v.hy2.Tx..},.{wn..M.~K...<.......Wrr.A.`.-q...Y..{.r1.W.........._R..0(".@....H.t..F3r..[9g.~...V.P..9).L+.....lO.!..B...E.c.#...w...j-+...@.t.}...}..l6..R`..kD.)...c....o..(..=...C.....[..a.OT%..+..&p.'2Q,b..%m........&.Q.`D.Ut.6.fJM...J.9TI........f.3...^z..h.Ri......}.Q....NYX.{Y.zH
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):483335
                  Entropy (8bit):7.999586392414984
                  Encrypted:true
                  SSDEEP:
                  MD5:81F502E4E5F1D63A3C1791D41D87C16D
                  SHA1:5DEE5D4348D832134D1AB3D6148F5DA5C964BFF1
                  SHA-256:4CF9C84CC200466539249B1FD241514E04260962A327BA9C799B6240CE64302D
                  SHA-512:EB75FCD1456458D56338935CBC273CEEEF5CC971FC56D9CE0E6BF030798D5D8C68D214763938869CC1303DA1D2A40CF1EDDE5F8EF7CB72F7BFAA80AFDC3CD926
                  Malicious:true
                  Preview:........bT.z.&.8.?...\KG+QX.tE. .(.0l.5......).z7+..A.L...w.....H..x...E..{..[...W.-9.z$Cb.W.\...;m...P..8..B..'B....K...i.2..4..5..<]{.(B.#..`...X}("......G.s...$.r.K&B.d.e.^...,Z ...?s.qj.fWb.x...2.,..o..S).........3&C<.S....g...+.....<&<.X.v.."..v_K../....0.W.f.....2......$.......e...n.9.........V......3[.JV.>.{.u...D..#..S..!....m..6..FU...k...y.........\...6?r....OCu.rP...7.z.A.Z....U...b(.Rc-..,.....w...s..6..N...U..._S......R..N..>...<...P<p'z...OM_.Tv...H_.%n.]/.s.......~/.>Z4`."8w..w.].%5.!k.>>..{.....B.....H.....W#A.2........}7..x.j...S....bb.X[o..5R.i..GP..=.d;4=.F..}.e.J.n.K.Js......u..<...w....x\G-.....hhv.K...p..Z&....D....*..hR.i."H.....k.....u.."v.hy2.Tx..},.{wn..M.~K...<.......Wrr.A.`.-q...Y..{.r1.W.........._R..0(".@....H.t..F3r..[9g.~...V.P..9).L+.....lO.!..B...E.c.#...w...j-+...@.t.}...}..l6..R`..kD.)...c....o..(..=...C.....[..a.OT%..+..&p.'2Q,b..%m........&.Q.`D.Ut.6.fJM...J.9TI........f.3...^z..h.Ri......}.Q....NYX.{Y.zH
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):453077
                  Entropy (8bit):7.999557044982967
                  Encrypted:true
                  SSDEEP:
                  MD5:94CFF6C0A9B63186E3F5DE6EBAE2365A
                  SHA1:C96297C7083C8332BE80F9E4AD8F8CE7E4348558
                  SHA-256:BFB22F16D674B9BB6439853925D805211AF609EEEDFD3E924A54EE29B7C1A005
                  SHA-512:8C26251D18D91E4D63980C8641A14DE1A3E5B2F6671C558D4B07FCA36A26F561F4CA19B68D48AED352B2BC6613A3C113132FCF16E6606114D821D905C46AD4B3
                  Malicious:true
                  Preview:...f....iU........VW.4.=......a7.D...[....!.._......ei.Ovd......w.?;.N&.0M....$.T..%E..W..H....:..._...t..Y....5..f>z.+...ow..@R.B..U.^..../....Rj"zm...].G....:Zop:.[6J......c.....y.7p....e =........I..8./9.hI...~s...HH7.....lb.?*;.....H.-$....h...._.u......E....C..i`......bdB...x...L..J${.L...W..k%[..f.f).cRy.5@H.G.`.....\...2.o... ..9.6.....~.. ...e....u.J...}..`#$.....>.....E...@>..Q...M_......@.w.W.).n....J-..z.{.Z.U#..Pgkna3..jG.~..a]...j....,&.U.*...AU.&........gg.. m{Y|.gL..M%].~...!.......b..x...r....J]GgzS1C....J..X..G.:7p...l.7.`...I.X.._.Rx..^.M.w..@..e>.?z..$.........II.*Y(L&S...3H.i.X..|..N.!.>NS..e5?P....z..t......i...?..O....@.....i.=.6..XA...9...........>.zY^G...NC..w...~..O..e.m..u.6.BA...P.....j....|....r..d5..L~.$...g..e=L".p..L.4........3\_..Y.R.W...!....,2..tb.....'.as.a.|..\..ab.....g.....g.r.e....p.f.e...H=#.5.e....7.J..Ct..E...*o.K0.fo.D/-.0..=`...j.d....E..J..y2Z..p..*u[...2......z. ...G......k"..ca....?...}J...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):453077
                  Entropy (8bit):7.999557044982967
                  Encrypted:true
                  SSDEEP:
                  MD5:94CFF6C0A9B63186E3F5DE6EBAE2365A
                  SHA1:C96297C7083C8332BE80F9E4AD8F8CE7E4348558
                  SHA-256:BFB22F16D674B9BB6439853925D805211AF609EEEDFD3E924A54EE29B7C1A005
                  SHA-512:8C26251D18D91E4D63980C8641A14DE1A3E5B2F6671C558D4B07FCA36A26F561F4CA19B68D48AED352B2BC6613A3C113132FCF16E6606114D821D905C46AD4B3
                  Malicious:true
                  Preview:...f....iU........VW.4.=......a7.D...[....!.._......ei.Ovd......w.?;.N&.0M....$.T..%E..W..H....:..._...t..Y....5..f>z.+...ow..@R.B..U.^..../....Rj"zm...].G....:Zop:.[6J......c.....y.7p....e =........I..8./9.hI...~s...HH7.....lb.?*;.....H.-$....h...._.u......E....C..i`......bdB...x...L..J${.L...W..k%[..f.f).cRy.5@H.G.`.....\...2.o... ..9.6.....~.. ...e....u.J...}..`#$.....>.....E...@>..Q...M_......@.w.W.).n....J-..z.{.Z.U#..Pgkna3..jG.~..a]...j....,&.U.*...AU.&........gg.. m{Y|.gL..M%].~...!.......b..x...r....J]GgzS1C....J..X..G.:7p...l.7.`...I.X.._.Rx..^.M.w..@..e>.?z..$.........II.*Y(L&S...3H.i.X..|..N.!.>NS..e5?P....z..t......i...?..O....@.....i.=.6..XA...9...........>.zY^G...NC..w...~..O..e.m..u.6.BA...P.....j....|....r..d5..L~.$...g..e=L".p..L.4........3\_..Y.R.W...!....,2..tb.....'.as.a.|..\..ab.....g.....g.r.e....p.f.e...H=#.5.e....7.J..Ct..E...*o.K0.fo.D/-.0..=`...j.d....E..J..y2Z..p..*u[...2......z. ...G......k"..ca....?...}J...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):453077
                  Entropy (8bit):7.999557044982967
                  Encrypted:true
                  SSDEEP:
                  MD5:94CFF6C0A9B63186E3F5DE6EBAE2365A
                  SHA1:C96297C7083C8332BE80F9E4AD8F8CE7E4348558
                  SHA-256:BFB22F16D674B9BB6439853925D805211AF609EEEDFD3E924A54EE29B7C1A005
                  SHA-512:8C26251D18D91E4D63980C8641A14DE1A3E5B2F6671C558D4B07FCA36A26F561F4CA19B68D48AED352B2BC6613A3C113132FCF16E6606114D821D905C46AD4B3
                  Malicious:true
                  Preview:...f....iU........VW.4.=......a7.D...[....!.._......ei.Ovd......w.?;.N&.0M....$.T..%E..W..H....:..._...t..Y....5..f>z.+...ow..@R.B..U.^..../....Rj"zm...].G....:Zop:.[6J......c.....y.7p....e =........I..8./9.hI...~s...HH7.....lb.?*;.....H.-$....h...._.u......E....C..i`......bdB...x...L..J${.L...W..k%[..f.f).cRy.5@H.G.`.....\...2.o... ..9.6.....~.. ...e....u.J...}..`#$.....>.....E...@>..Q...M_......@.w.W.).n....J-..z.{.Z.U#..Pgkna3..jG.~..a]...j....,&.U.*...AU.&........gg.. m{Y|.gL..M%].~...!.......b..x...r....J]GgzS1C....J..X..G.:7p...l.7.`...I.X.._.Rx..^.M.w..@..e>.?z..$.........II.*Y(L&S...3H.i.X..|..N.!.>NS..e5?P....z..t......i...?..O....@.....i.=.6..XA...9...........>.zY^G...NC..w...~..O..e.m..u.6.BA...P.....j....|....r..d5..L~.$...g..e=L".p..L.4........3\_..Y.R.W...!....,2..tb.....'.as.a.|..\..ab.....g.....g.r.e....p.f.e...H=#.5.e....7.J..Ct..E...*o.K0.fo.D/-.0..=`...j.d....E..J..y2Z..p..*u[...2......z. ...G......k"..ca....?...}J...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):455705
                  Entropy (8bit):7.999591707628024
                  Encrypted:true
                  SSDEEP:
                  MD5:C8BB2CB5EF786A69EA79EC7842F9C631
                  SHA1:84D2B6A69F2ADB458BF217C96DC222508165ACCA
                  SHA-256:7B55ED9638113A580832CBD8ED42D0EB886B47A54A6EB68B83C47E2F8BE3A308
                  SHA-512:BB067B61DDCD2A92FEA71E2CEC9FADC36FB29D0CBE125BB50DDECBE96C6A89F4A63A23E47995FF6E22D080E86A9FF82923073A1A1F2A5EC6BD7C20C41C8DD4C8
                  Malicious:true
                  Preview:...).K......0-u...vU......l.H.\.r..].Bz..i`z.%0Q...).4{/'6|..i.?.5#,.=..M.x.?..n..u..s.[...euSUS...{..5...m..Z+.V.&..yOD.]~..+i..;2I.mk.Yh.4w*r#....4?....}..hv..'..F@....Sx....p..|...]&.j.Q...%.}....%.K.r....6t.O4&...*.y.#V..k0..+{.....D..5u@(1.<.....jF..G..W_a..u.=$O..O..".....2.>g~.F........a6.F.v..]....g3k.f....|dJ.t..^..a#y#....2.-Mq..?.u#y]....F......h.....:.B....NH.~.v /......R..8v.O{t.y..U.........)..YE...~...ss_{...P:.#/..>.......lO..BB\y...S...O.../..> .d(..h...[L ......5x.b..............(.x{#O9...K.3......z.H.....H).|J!hKmw....X.6.s....{a....9.2....T..i..?Se.C..G.`..V1...9?Z.s...iL..!#..'.....w..f..........v..e.....L...qa.-(....SPh..$.w..].Ka[.]B...o.T.'.4.Y..l,.}..4...a.a6..7.?uE.edi\r.....,l...%.:w",.V/0.}7 .....XEj..<..W..]z.).\m.e^}..n!B.H.)'.c..A.{V../z5{~...q...>j...k:>..Kc..4...O..C.Q...p.gjd8G..[...b..m..9..}.#..&...}..tJ..<P...o?..w,y.j.'.=/._.T.m..'........!..EW.....\.!.p.S_D.,.Qu.....:.0.J...u&7xG>f......C..N..f.q+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):455705
                  Entropy (8bit):7.999591707628024
                  Encrypted:true
                  SSDEEP:
                  MD5:C8BB2CB5EF786A69EA79EC7842F9C631
                  SHA1:84D2B6A69F2ADB458BF217C96DC222508165ACCA
                  SHA-256:7B55ED9638113A580832CBD8ED42D0EB886B47A54A6EB68B83C47E2F8BE3A308
                  SHA-512:BB067B61DDCD2A92FEA71E2CEC9FADC36FB29D0CBE125BB50DDECBE96C6A89F4A63A23E47995FF6E22D080E86A9FF82923073A1A1F2A5EC6BD7C20C41C8DD4C8
                  Malicious:true
                  Preview:...).K......0-u...vU......l.H.\.r..].Bz..i`z.%0Q...).4{/'6|..i.?.5#,.=..M.x.?..n..u..s.[...euSUS...{..5...m..Z+.V.&..yOD.]~..+i..;2I.mk.Yh.4w*r#....4?....}..hv..'..F@....Sx....p..|...]&.j.Q...%.}....%.K.r....6t.O4&...*.y.#V..k0..+{.....D..5u@(1.<.....jF..G..W_a..u.=$O..O..".....2.>g~.F........a6.F.v..]....g3k.f....|dJ.t..^..a#y#....2.-Mq..?.u#y]....F......h.....:.B....NH.~.v /......R..8v.O{t.y..U.........)..YE...~...ss_{...P:.#/..>.......lO..BB\y...S...O.../..> .d(..h...[L ......5x.b..............(.x{#O9...K.3......z.H.....H).|J!hKmw....X.6.s....{a....9.2....T..i..?Se.C..G.`..V1...9?Z.s...iL..!#..'.....w..f..........v..e.....L...qa.-(....SPh..$.w..].Ka[.]B...o.T.'.4.Y..l,.}..4...a.a6..7.?uE.edi\r.....,l...%.:w",.V/0.}7 .....XEj..<..W..]z.).\m.e^}..n!B.H.)'.c..A.{V../z5{~...q...>j...k:>..Kc..4...O..C.Q...p.gjd8G..[...b..m..9..}.#..&...}..tJ..<P...o?..w,y.j.'.=/._.T.m..'........!..EW.....\.!.p.S_D.,.Qu.....:.0.J...u&7xG>f......C..N..f.q+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):455705
                  Entropy (8bit):7.999591707628024
                  Encrypted:true
                  SSDEEP:
                  MD5:C8BB2CB5EF786A69EA79EC7842F9C631
                  SHA1:84D2B6A69F2ADB458BF217C96DC222508165ACCA
                  SHA-256:7B55ED9638113A580832CBD8ED42D0EB886B47A54A6EB68B83C47E2F8BE3A308
                  SHA-512:BB067B61DDCD2A92FEA71E2CEC9FADC36FB29D0CBE125BB50DDECBE96C6A89F4A63A23E47995FF6E22D080E86A9FF82923073A1A1F2A5EC6BD7C20C41C8DD4C8
                  Malicious:true
                  Preview:...).K......0-u...vU......l.H.\.r..].Bz..i`z.%0Q...).4{/'6|..i.?.5#,.=..M.x.?..n..u..s.[...euSUS...{..5...m..Z+.V.&..yOD.]~..+i..;2I.mk.Yh.4w*r#....4?....}..hv..'..F@....Sx....p..|...]&.j.Q...%.}....%.K.r....6t.O4&...*.y.#V..k0..+{.....D..5u@(1.<.....jF..G..W_a..u.=$O..O..".....2.>g~.F........a6.F.v..]....g3k.f....|dJ.t..^..a#y#....2.-Mq..?.u#y]....F......h.....:.B....NH.~.v /......R..8v.O{t.y..U.........)..YE...~...ss_{...P:.#/..>.......lO..BB\y...S...O.../..> .d(..h...[L ......5x.b..............(.x{#O9...K.3......z.H.....H).|J!hKmw....X.6.s....{a....9.2....T..i..?Se.C..G.`..V1...9?Z.s...iL..!#..'.....w..f..........v..e.....L...qa.-(....SPh..$.w..].Ka[.]B...o.T.'.4.Y..l,.}..4...a.a6..7.?uE.edi\r.....,l...%.:w",.V/0.}7 .....XEj..<..W..]z.).\m.e^}..n!B.H.)'.c..A.{V../z5{~...q...>j...k:>..Kc..4...O..C.Q...p.gjd8G..[...b..m..9..}.#..&...}..tJ..<P...o?..w,y.j.'.=/._.T.m..'........!..EW.....\.!.p.S_D.,.Qu.....:.0.J...u&7xG>f......C..N..f.q+
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):471406
                  Entropy (8bit):7.999647511511952
                  Encrypted:true
                  SSDEEP:
                  MD5:3F7545A4DF20761373FF1626ED3A1F9E
                  SHA1:22647B7D3B8A0DD185180497361B3F0C46F88146
                  SHA-256:CCF1EE90158077568690D1972AB31B202672B8E00F217B106A28237776EA8DB0
                  SHA-512:65BFEDB064FE303CCD5A26E8E0058C713B497218F22ED9AB28182A68A30C55FF25FF333C22E4EAC42108AD8C82C433C5A884E1C8B7E9376A87E17B623EAD1FE3
                  Malicious:true
                  Preview:.U....&]fV.rJ... g..j..."S..hK_......u.]]...HOqfJ..."...t.........,q....!?..U.6..B}..1r.9>.TA...o{.m)...`.a0b....5.J..m..s.N.M.a.....e..b..h.^..Eg.MN."../.c...E...d..p#.$K|,...iZ.X.*#..7!..nK<N{.:4B..-. .4.[T.......,...~8..8..R;gF.c.T@...u.._...WX...=..'..g.'..fR=........K..$BeVM..z3{...V5.P...S......N;;J..)......~.O.(.;.....D+0.....Y%...:.B.D.p8.._<zd..tn..,..M.u..5..a>.R./.G\.e..=g.x.L..."i._.f.@a.;.6p..2$...1.+....k.z!...sQ.o.T.^....R.i&{.._?s..Dk...J.|k........&$.....).Vn'...0M..J*...Ww]0.P3c.3s..`L..5C..b$.P.t...}1.d..'...C..*JD0b....%.....fo.K:G..5k..N#eZ9...V......81..Z....j..&Z...k...y...t....(..&.Od.%.M.G....NQ....CL9.{.0...E..~.]....?.]ayK.~=n6..0V........^x.O_.6....,.3..K.$to....!C...U.qmC...l..D.".R6...(......~n'.S. ........\].(.b..l. ...8...A../....ZT....^......Z.............:....z.w...V+)zi|...+...~..sB.Ld..!.Ev..cu(.#.E.;.[..I~..>.G.T.. c...-..y............>.....-vA:.h_l...}Nu..s...m.."..!4T`/3...&F....q~iNM.6.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):471406
                  Entropy (8bit):7.999647511511952
                  Encrypted:true
                  SSDEEP:
                  MD5:3F7545A4DF20761373FF1626ED3A1F9E
                  SHA1:22647B7D3B8A0DD185180497361B3F0C46F88146
                  SHA-256:CCF1EE90158077568690D1972AB31B202672B8E00F217B106A28237776EA8DB0
                  SHA-512:65BFEDB064FE303CCD5A26E8E0058C713B497218F22ED9AB28182A68A30C55FF25FF333C22E4EAC42108AD8C82C433C5A884E1C8B7E9376A87E17B623EAD1FE3
                  Malicious:true
                  Preview:.U....&]fV.rJ... g..j..."S..hK_......u.]]...HOqfJ..."...t.........,q....!?..U.6..B}..1r.9>.TA...o{.m)...`.a0b....5.J..m..s.N.M.a.....e..b..h.^..Eg.MN."../.c...E...d..p#.$K|,...iZ.X.*#..7!..nK<N{.:4B..-. .4.[T.......,...~8..8..R;gF.c.T@...u.._...WX...=..'..g.'..fR=........K..$BeVM..z3{...V5.P...S......N;;J..)......~.O.(.;.....D+0.....Y%...:.B.D.p8.._<zd..tn..,..M.u..5..a>.R./.G\.e..=g.x.L..."i._.f.@a.;.6p..2$...1.+....k.z!...sQ.o.T.^....R.i&{.._?s..Dk...J.|k........&$.....).Vn'...0M..J*...Ww]0.P3c.3s..`L..5C..b$.P.t...}1.d..'...C..*JD0b....%.....fo.K:G..5k..N#eZ9...V......81..Z....j..&Z...k...y...t....(..&.Od.%.M.G....NQ....CL9.{.0...E..~.]....?.]ayK.~=n6..0V........^x.O_.6....,.3..K.$to....!C...U.qmC...l..D.".R6...(......~n'.S. ........\].(.b..l. ...8...A../....ZT....^......Z.............:....z.w...V+)zi|...+...~..sB.Ld..!.Ev..cu(.#.E.;.[..I~..>.G.T.. c...-..y............>.....-vA:.h_l...}Nu..s...m.."..!4T`/3...&F....q~iNM.6.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):471406
                  Entropy (8bit):7.999647511511952
                  Encrypted:true
                  SSDEEP:
                  MD5:3F7545A4DF20761373FF1626ED3A1F9E
                  SHA1:22647B7D3B8A0DD185180497361B3F0C46F88146
                  SHA-256:CCF1EE90158077568690D1972AB31B202672B8E00F217B106A28237776EA8DB0
                  SHA-512:65BFEDB064FE303CCD5A26E8E0058C713B497218F22ED9AB28182A68A30C55FF25FF333C22E4EAC42108AD8C82C433C5A884E1C8B7E9376A87E17B623EAD1FE3
                  Malicious:true
                  Preview:.U....&]fV.rJ... g..j..."S..hK_......u.]]...HOqfJ..."...t.........,q....!?..U.6..B}..1r.9>.TA...o{.m)...`.a0b....5.J..m..s.N.M.a.....e..b..h.^..Eg.MN."../.c...E...d..p#.$K|,...iZ.X.*#..7!..nK<N{.:4B..-. .4.[T.......,...~8..8..R;gF.c.T@...u.._...WX...=..'..g.'..fR=........K..$BeVM..z3{...V5.P...S......N;;J..)......~.O.(.;.....D+0.....Y%...:.B.D.p8.._<zd..tn..,..M.u..5..a>.R./.G\.e..=g.x.L..."i._.f.@a.;.6p..2$...1.+....k.z!...sQ.o.T.^....R.i&{.._?s..Dk...J.|k........&$.....).Vn'...0M..J*...Ww]0.P3c.3s..`L..5C..b$.P.t...}1.d..'...C..*JD0b....%.....fo.K:G..5k..N#eZ9...V......81..Z....j..&Z...k...y...t....(..&.Od.%.M.G....NQ....CL9.{.0...E..~.]....?.]ayK.~=n6..0V........^x.O_.6....,.3..K.$to....!C...U.qmC...l..D.".R6...(......~n'.S. ........\].(.b..l. ...8...A../....ZT....^......Z.............:....z.w...V+)zi|...+...~..sB.Ld..!.Ev..cu(.#.E.;.[..I~..>.G.T.. c...-..y............>.....-vA:.h_l...}Nu..s...m.."..!4T`/3...&F....q~iNM.6.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):769752
                  Entropy (8bit):7.999774012232309
                  Encrypted:true
                  SSDEEP:
                  MD5:91912CED472C29C81DBA984CB7F79E63
                  SHA1:1052C3A81F8FCBE8FDEC42C054D8AB40386635A7
                  SHA-256:C6F24CCB3C1A61D183899C24C7C3E8A801F8C152466B04B58A256D5FC4D45160
                  SHA-512:EC2C2B44AD2E79EB3AF468650A09846B4B8C256E26D834979437FDEC5F672F824EEBD0DB8386CE512469577A3E27093B206CAAF02637E25ED9764E17519875EB
                  Malicious:true
                  Preview:..+.&...T..=...7...;..v..T...N.6r.4m.......B},0.oF.S..........G ....h...)^...&S..3.+.[R...)u...k....AN/...<.R.;.-.EFN/Pd...6.m....5;.<......). n.......%4I@.V.J..a.!uWsr.].:..R.I.*I.\....vd h.\@C..k.z..UV....(.V.H ..s.....IHZ.....~..)-.U.Q.I...,.5._.i......+..@$....\.5y.a.....|k\1^dxf..L.=h..7v.Bq..x...3..EP.^...9......'o"x.5....].?.....5....IL...P.c<.......Q.[...DaY.K`+......eW..?.x0.b....R.6-.%].J...y. .d..d...~..?.....7.L.H.I.......!.n.&z...\<v.I~.QS......y....g$.rv.W8k...T$O.......S:.!....y..*..jYha..>5..L..](... +K../.2.c.B.QH.W..D...V}.....#e.'=@t........7;~}....z..^.D.....F...I..6|./.2w....#Hs].L.<.uvN<.f.so..,].(.L $V..,gu.A...,7.E..e.H8...%y.Y.*M...Z.Z..vhf},.a.....ay....-{...r$e.....I<..m..E./p..8.....#.m^......(08w.=.(...S...A.t.D.5.'z.%IY.....g..&.=.q.=P.`..E8....N.... ..J.....J...>..qC.^...,[..O.......(....".`5..-F....M.H....%L.. ...:.......d..0..F..........L>./.0o.?..!c..P.Gmu.Iw"...-.j....aR&d.Zi.3..........2....!z....L
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):769752
                  Entropy (8bit):7.999774012232309
                  Encrypted:true
                  SSDEEP:
                  MD5:91912CED472C29C81DBA984CB7F79E63
                  SHA1:1052C3A81F8FCBE8FDEC42C054D8AB40386635A7
                  SHA-256:C6F24CCB3C1A61D183899C24C7C3E8A801F8C152466B04B58A256D5FC4D45160
                  SHA-512:EC2C2B44AD2E79EB3AF468650A09846B4B8C256E26D834979437FDEC5F672F824EEBD0DB8386CE512469577A3E27093B206CAAF02637E25ED9764E17519875EB
                  Malicious:true
                  Preview:..+.&...T..=...7...;..v..T...N.6r.4m.......B},0.oF.S..........G ....h...)^...&S..3.+.[R...)u...k....AN/...<.R.;.-.EFN/Pd...6.m....5;.<......). n.......%4I@.V.J..a.!uWsr.].:..R.I.*I.\....vd h.\@C..k.z..UV....(.V.H ..s.....IHZ.....~..)-.U.Q.I...,.5._.i......+..@$....\.5y.a.....|k\1^dxf..L.=h..7v.Bq..x...3..EP.^...9......'o"x.5....].?.....5....IL...P.c<.......Q.[...DaY.K`+......eW..?.x0.b....R.6-.%].J...y. .d..d...~..?.....7.L.H.I.......!.n.&z...\<v.I~.QS......y....g$.rv.W8k...T$O.......S:.!....y..*..jYha..>5..L..](... +K../.2.c.B.QH.W..D...V}.....#e.'=@t........7;~}....z..^.D.....F...I..6|./.2w....#Hs].L.<.uvN<.f.so..,].(.L $V..,gu.A...,7.E..e.H8...%y.Y.*M...Z.Z..vhf},.a.....ay....-{...r$e.....I<..m..E./p..8.....#.m^......(08w.=.(...S...A.t.D.5.'z.%IY.....g..&.=.q.=P.`..E8....N.... ..J.....J...>..qC.^...,[..O.......(....".`5..-F....M.H....%L.. ...:.......d..0..F..........L>./.0o.?..!c..P.Gmu.Iw"...-.j....aR&d.Zi.3..........2....!z....L
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):769752
                  Entropy (8bit):7.999774012232309
                  Encrypted:true
                  SSDEEP:
                  MD5:91912CED472C29C81DBA984CB7F79E63
                  SHA1:1052C3A81F8FCBE8FDEC42C054D8AB40386635A7
                  SHA-256:C6F24CCB3C1A61D183899C24C7C3E8A801F8C152466B04B58A256D5FC4D45160
                  SHA-512:EC2C2B44AD2E79EB3AF468650A09846B4B8C256E26D834979437FDEC5F672F824EEBD0DB8386CE512469577A3E27093B206CAAF02637E25ED9764E17519875EB
                  Malicious:true
                  Preview:..+.&...T..=...7...;..v..T...N.6r.4m.......B},0.oF.S..........G ....h...)^...&S..3.+.[R...)u...k....AN/...<.R.;.-.EFN/Pd...6.m....5;.<......). n.......%4I@.V.J..a.!uWsr.].:..R.I.*I.\....vd h.\@C..k.z..UV....(.V.H ..s.....IHZ.....~..)-.U.Q.I...,.5._.i......+..@$....\.5y.a.....|k\1^dxf..L.=h..7v.Bq..x...3..EP.^...9......'o"x.5....].?.....5....IL...P.c<.......Q.[...DaY.K`+......eW..?.x0.b....R.6-.%].J...y. .d..d...~..?.....7.L.H.I.......!.n.&z...\<v.I~.QS......y....g$.rv.W8k...T$O.......S:.!....y..*..jYha..>5..L..](... +K../.2.c.B.QH.W..D...V}.....#e.'=@t........7;~}....z..^.D.....F...I..6|./.2w....#Hs].L.<.uvN<.f.so..,].(.L $V..,gu.A...,7.E..e.H8...%y.Y.*M...Z.Z..vhf},.a.....ay....-{...r$e.....I<..m..E./p..8.....#.m^......(08w.=.(...S...A.t.D.5.'z.%IY.....g..&.=.q.=P.`..E8....N.... ..J.....J...>..qC.^...,[..O.......(....".`5..-F....M.H....%L.. ...:.......d..0..F..........L>./.0o.?..!c..P.Gmu.Iw"...-.j....aR&d.Zi.3..........2....!z....L
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):484043
                  Entropy (8bit):7.999605356816719
                  Encrypted:true
                  SSDEEP:
                  MD5:D3FA5EC7B351A34FA89279046339C1B8
                  SHA1:582EB9D91C743394DA4CDB788C89793F133024D0
                  SHA-256:16D9A5B34704D7E298BE297CF6D6C2449D995DB3E491E706B77F46AD8C5178FF
                  SHA-512:01F345E55BEF57CE8B5A6EBF8D28522627630DC5BA4136D2754C91E8815CE4080E4B83DE7BBA0E7D2A3F0FC48D91EF2B5337164BC10E9F3EDA6398EC0530F7A6
                  Malicious:true
                  Preview:X@..r...`.s3......Q..!.Y.|\....]f.;....r....x...A..W.vE.,H...^..S.22./i.....K~..?5v....Gw.L.e. 2.?.^..(.;m.~_.<....../f.n.2..u.t..........u(.....A....C..i.H@.y....L..C.:...\.Rl....|?>..ew.b..o.%J..E...Gv........h..D..N.M.......t..y....,.j.C..J.d.g..........l.|....-.|/.m?.m0.....2.d.o..p"..$.......%m..0),..V..0Vs.....2.......&!..q........>Pm!.9......U.1A .#...4s{s9d=...q...7....'I..G.<...\EqA{.M.z.S.z.`.).....o....c.T.x.......+....v.@.r...W.@m*...T...4p.w.-..]?<...8.....'...X..../.S..yfj..x.....;R@4.7$....c.\..A.37..T..b....(Fw..bw.w..7..fP.....+.C..FZD.})f....$....D;^.............7v*.....@*.{1...?*..c.Z[....y...l_.F..-.g...c....X:$.*8v`.|...ot.....r.9LB!.L.. ...1]....NBp...j.......O.q5+NvR...Y....,3,0.b9.........n..;..x..tc.kF..D.2..j.,U_ZB.YI...PZ.?*.+`..{..... .z../..............G.<....dN3.1Ik....`..O.8...4.z."...sv.E!.dZ..P.f4..........fyV."1....M.rWsx........*...61.s..........#..j....).S b.r`s.....$.a]c.f....tg..1..R.|.mw...B4)...AV....|M.*..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):484043
                  Entropy (8bit):7.999605356816719
                  Encrypted:true
                  SSDEEP:
                  MD5:D3FA5EC7B351A34FA89279046339C1B8
                  SHA1:582EB9D91C743394DA4CDB788C89793F133024D0
                  SHA-256:16D9A5B34704D7E298BE297CF6D6C2449D995DB3E491E706B77F46AD8C5178FF
                  SHA-512:01F345E55BEF57CE8B5A6EBF8D28522627630DC5BA4136D2754C91E8815CE4080E4B83DE7BBA0E7D2A3F0FC48D91EF2B5337164BC10E9F3EDA6398EC0530F7A6
                  Malicious:true
                  Preview:X@..r...`.s3......Q..!.Y.|\....]f.;....r....x...A..W.vE.,H...^..S.22./i.....K~..?5v....Gw.L.e. 2.?.^..(.;m.~_.<....../f.n.2..u.t..........u(.....A....C..i.H@.y....L..C.:...\.Rl....|?>..ew.b..o.%J..E...Gv........h..D..N.M.......t..y....,.j.C..J.d.g..........l.|....-.|/.m?.m0.....2.d.o..p"..$.......%m..0),..V..0Vs.....2.......&!..q........>Pm!.9......U.1A .#...4s{s9d=...q...7....'I..G.<...\EqA{.M.z.S.z.`.).....o....c.T.x.......+....v.@.r...W.@m*...T...4p.w.-..]?<...8.....'...X..../.S..yfj..x.....;R@4.7$....c.\..A.37..T..b....(Fw..bw.w..7..fP.....+.C..FZD.})f....$....D;^.............7v*.....@*.{1...?*..c.Z[....y...l_.F..-.g...c....X:$.*8v`.|...ot.....r.9LB!.L.. ...1]....NBp...j.......O.q5+NvR...Y....,3,0.b9.........n..;..x..tc.kF..D.2..j.,U_ZB.YI...PZ.?*.+`..{..... .z../..............G.<....dN3.1Ik....`..O.8...4.z."...sv.E!.dZ..P.f4..........fyV."1....M.rWsx........*...61.s..........#..j....).S b.r`s.....$.a]c.f....tg..1..R.|.mw...B4)...AV....|M.*..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):484043
                  Entropy (8bit):7.999605356816719
                  Encrypted:true
                  SSDEEP:
                  MD5:D3FA5EC7B351A34FA89279046339C1B8
                  SHA1:582EB9D91C743394DA4CDB788C89793F133024D0
                  SHA-256:16D9A5B34704D7E298BE297CF6D6C2449D995DB3E491E706B77F46AD8C5178FF
                  SHA-512:01F345E55BEF57CE8B5A6EBF8D28522627630DC5BA4136D2754C91E8815CE4080E4B83DE7BBA0E7D2A3F0FC48D91EF2B5337164BC10E9F3EDA6398EC0530F7A6
                  Malicious:true
                  Preview:X@..r...`.s3......Q..!.Y.|\....]f.;....r....x...A..W.vE.,H...^..S.22./i.....K~..?5v....Gw.L.e. 2.?.^..(.;m.~_.<....../f.n.2..u.t..........u(.....A....C..i.H@.y....L..C.:...\.Rl....|?>..ew.b..o.%J..E...Gv........h..D..N.M.......t..y....,.j.C..J.d.g..........l.|....-.|/.m?.m0.....2.d.o..p"..$.......%m..0),..V..0Vs.....2.......&!..q........>Pm!.9......U.1A .#...4s{s9d=...q...7....'I..G.<...\EqA{.M.z.S.z.`.).....o....c.T.x.......+....v.@.r...W.@m*...T...4p.w.-..]?<...8.....'...X..../.S..yfj..x.....;R@4.7$....c.\..A.37..T..b....(Fw..bw.w..7..fP.....+.C..FZD.})f....$....D;^.............7v*.....@*.{1...?*..c.Z[....y...l_.F..-.g...c....X:$.*8v`.|...ot.....r.9LB!.L.. ...1]....NBp...j.......O.q5+NvR...Y....,3,0.b9.........n..;..x..tc.kF..D.2..j.,U_ZB.YI...PZ.?*.+`..{..... .z../..............G.<....dN3.1Ik....`..O.8...4.z."...sv.E!.dZ..P.f4..........fyV."1....M.rWsx........*...61.s..........#..j....).S b.r`s.....$.a]c.f....tg..1..R.|.mw...B4)...AV....|M.*..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):467245
                  Entropy (8bit):7.99961897738498
                  Encrypted:true
                  SSDEEP:
                  MD5:C6AD29E0DDAACC4F19531D3974B30E7D
                  SHA1:2176DA607C2C259D7CD4866A1B6CAD9E6FDAE37B
                  SHA-256:DB85B8132C8B84E6ECE4B04F1CC4E29D19ACAA11549C1D9CDAA4621498B7704B
                  SHA-512:EE59528F1C1E352B1E0CA347FC91668C25C1404D3310762527731DFAAF986A3EA66F4CAC17371A156F7204D9A59036147C3832A99B148C2C77054232469A9A1E
                  Malicious:true
                  Preview:$:........4..M!...}.....M.8.l..?...^)....[...(...Rx=..!...U~.F.df..X........J...XpDj..a..A...,6I.^E.[*}.X.qjs...-..V.S....z3...N...Y)C.......A..U....`M..HK:M.....W..bd.o....4..L]>....fF...d;n..N..........W....V^.=IiT..9.k....!..t%./.J.....t........P?_2.U...[oPL...gp..........=x..=.m..'......cm2.w../e=...G.5+Pj.....+.O+..ic...me.o1...#a\e.T=e...er.y2.fK.;.......$......?Lr..#..f$b........8.Nn...d..M.\.L$.;........1..t.Q.0...o.._\W5im......)...'.......zq.......X.. .{..F...O..3..._..[]my.$..x..ZW.Q_.~...A.].zkN........L. .9.N...NG_...-D.-..J......%....y...uu..5..|....tE.Q..~..b$......L...m..j....W.._..........@_..d_...8,..E./.(.p`.a..).2-...T.0...r..s|.x`.._.K.,D.Szc.9..d.`LR}.\.m..[.....=......g!y.*.9...u>...@(.../(vH.....YV...)..I......NEh.[.,..|..L.;.[....0....^ .._%D.a~2~...x.K.%+.8CR...}....]...".s....1...G..N..+...+..!.#...J...8AD...X.F...6u.%U...%N...-X........pX.t....^.#=.7..w.....{B..*#:.{.a..;._#N}r.4...o..^....7B..w.. .R.M6D...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):467245
                  Entropy (8bit):7.99961897738498
                  Encrypted:true
                  SSDEEP:
                  MD5:C6AD29E0DDAACC4F19531D3974B30E7D
                  SHA1:2176DA607C2C259D7CD4866A1B6CAD9E6FDAE37B
                  SHA-256:DB85B8132C8B84E6ECE4B04F1CC4E29D19ACAA11549C1D9CDAA4621498B7704B
                  SHA-512:EE59528F1C1E352B1E0CA347FC91668C25C1404D3310762527731DFAAF986A3EA66F4CAC17371A156F7204D9A59036147C3832A99B148C2C77054232469A9A1E
                  Malicious:true
                  Preview:$:........4..M!...}.....M.8.l..?...^)....[...(...Rx=..!...U~.F.df..X........J...XpDj..a..A...,6I.^E.[*}.X.qjs...-..V.S....z3...N...Y)C.......A..U....`M..HK:M.....W..bd.o....4..L]>....fF...d;n..N..........W....V^.=IiT..9.k....!..t%./.J.....t........P?_2.U...[oPL...gp..........=x..=.m..'......cm2.w../e=...G.5+Pj.....+.O+..ic...me.o1...#a\e.T=e...er.y2.fK.;.......$......?Lr..#..f$b........8.Nn...d..M.\.L$.;........1..t.Q.0...o.._\W5im......)...'.......zq.......X.. .{..F...O..3..._..[]my.$..x..ZW.Q_.~...A.].zkN........L. .9.N...NG_...-D.-..J......%....y...uu..5..|....tE.Q..~..b$......L...m..j....W.._..........@_..d_...8,..E./.(.p`.a..).2-...T.0...r..s|.x`.._.K.,D.Szc.9..d.`LR}.\.m..[.....=......g!y.*.9...u>...@(.../(vH.....YV...)..I......NEh.[.,..|..L.;.[....0....^ .._%D.a~2~...x.K.%+.8CR...}....]...".s....1...G..N..+...+..!.#...J...8AD...X.F...6u.%U...%N...-X........pX.t....^.#=.7..w.....{B..*#:.{.a..;._#N}r.4...o..^....7B..w.. .R.M6D...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):467245
                  Entropy (8bit):7.99961897738498
                  Encrypted:true
                  SSDEEP:
                  MD5:C6AD29E0DDAACC4F19531D3974B30E7D
                  SHA1:2176DA607C2C259D7CD4866A1B6CAD9E6FDAE37B
                  SHA-256:DB85B8132C8B84E6ECE4B04F1CC4E29D19ACAA11549C1D9CDAA4621498B7704B
                  SHA-512:EE59528F1C1E352B1E0CA347FC91668C25C1404D3310762527731DFAAF986A3EA66F4CAC17371A156F7204D9A59036147C3832A99B148C2C77054232469A9A1E
                  Malicious:true
                  Preview:$:........4..M!...}.....M.8.l..?...^)....[...(...Rx=..!...U~.F.df..X........J...XpDj..a..A...,6I.^E.[*}.X.qjs...-..V.S....z3...N...Y)C.......A..U....`M..HK:M.....W..bd.o....4..L]>....fF...d;n..N..........W....V^.=IiT..9.k....!..t%./.J.....t........P?_2.U...[oPL...gp..........=x..=.m..'......cm2.w../e=...G.5+Pj.....+.O+..ic...me.o1...#a\e.T=e...er.y2.fK.;.......$......?Lr..#..f$b........8.Nn...d..M.\.L$.;........1..t.Q.0...o.._\W5im......)...'.......zq.......X.. .{..F...O..3..._..[]my.$..x..ZW.Q_.~...A.].zkN........L. .9.N...NG_...-D.-..J......%....y...uu..5..|....tE.Q..~..b$......L...m..j....W.._..........@_..d_...8,..E./.(.p`.a..).2-...T.0...r..s|.x`.._.K.,D.Szc.9..d.`LR}.\.m..[.....=......g!y.*.9...u>...@(.../(vH.....YV...)..I......NEh.[.,..|..L.;.[....0....^ .._%D.a~2~...x.K.%+.8CR...}....]...".s....1...G..N..+...+..!.#...J...8AD...X.F...6u.%U...%N...-X........pX.t....^.#=.7..w.....{B..*#:.{.a..;._#N}r.4...o..^....7B..w.. .R.M6D...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):718482
                  Entropy (8bit):7.999720790196673
                  Encrypted:true
                  SSDEEP:
                  MD5:AF907DD6E27BBFF2563FC9E0591A732F
                  SHA1:8C54735A913E321E12D3B62522C610F2FFAEFD63
                  SHA-256:8B4B3FB967AA7FDFC2029ECC892641398648723CD0438135E6E2FB7A0CE5F9C6
                  SHA-512:D17931B9B8A9B72A864AC11655FEDF3C9DED125405ACBA5D445E70D637B253F7F3AD96D59C1D7D682866C9B123F09A4F950B27CCF60F6C2E6B64D17E3C694010
                  Malicious:true
                  Preview:e....g..NU(.b...f,...........}0P......<.......1...!..vq.."...>._.t..^.G....{o1.....'.e.a....[..^@.....c.d........z..Df*...p.t....u9.~!$GC.A....aY.JpzX.`W..&..u.....t 1.Q..Gf*..7.ct7..5.%.....!!.b.^5.k..>.u..yA<a...z<.lc..Fgnus^a..<g.6../.%8.It...5........*.1....4.T%..&..z..].[S.`...e.......Uz.uT.:...Y....@....>d9...R.....;o.LUQ]..j..H.b.2..CP..^.y..Ys.A....../..v-....%+s@.08m.,7.-..r.-.tI.._.c.....d.....\Q:o.,..{..U|.....:.j-.d....q$..Mc=Q.e.L._S...\....3.......9.]Z0.s..._b4...........h..u.U..T.~4...|.... .p.k.......'dM.....k.O.@6cgV3.z.....N;u....`....P..:.....N.Y...Z.i.+).k47.P.Z.{Y.:Wz.u.]"6..x..b.(."b....6A"Pr.A.~....t1.}Os...h..*.`.ntwL.}..~.x../.n..E......h.;.IP4..O.....,.....k..c...y.#..j......$.v..Z.wb..`t..../.V...&&bt..BB.Or..C.,...sh<....l...b:7}#'@.T.vo.t....!J..v....5.^.0..4.xI.3I.V..c...2....0 5..)...d..>F'_.p..cz_q.J..wV.....>..^..1.O...y%|.l..BZ..5.XF(..}...B.e.p....c#..rz.I.-...o..f..K.+.x5.....k.<.=..........qd.a.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):718482
                  Entropy (8bit):7.999720790196673
                  Encrypted:true
                  SSDEEP:
                  MD5:AF907DD6E27BBFF2563FC9E0591A732F
                  SHA1:8C54735A913E321E12D3B62522C610F2FFAEFD63
                  SHA-256:8B4B3FB967AA7FDFC2029ECC892641398648723CD0438135E6E2FB7A0CE5F9C6
                  SHA-512:D17931B9B8A9B72A864AC11655FEDF3C9DED125405ACBA5D445E70D637B253F7F3AD96D59C1D7D682866C9B123F09A4F950B27CCF60F6C2E6B64D17E3C694010
                  Malicious:true
                  Preview:e....g..NU(.b...f,...........}0P......<.......1...!..vq.."...>._.t..^.G....{o1.....'.e.a....[..^@.....c.d........z..Df*...p.t....u9.~!$GC.A....aY.JpzX.`W..&..u.....t 1.Q..Gf*..7.ct7..5.%.....!!.b.^5.k..>.u..yA<a...z<.lc..Fgnus^a..<g.6../.%8.It...5........*.1....4.T%..&..z..].[S.`...e.......Uz.uT.:...Y....@....>d9...R.....;o.LUQ]..j..H.b.2..CP..^.y..Ys.A....../..v-....%+s@.08m.,7.-..r.-.tI.._.c.....d.....\Q:o.,..{..U|.....:.j-.d....q$..Mc=Q.e.L._S...\....3.......9.]Z0.s..._b4...........h..u.U..T.~4...|.... .p.k.......'dM.....k.O.@6cgV3.z.....N;u....`....P..:.....N.Y...Z.i.+).k47.P.Z.{Y.:Wz.u.]"6..x..b.(."b....6A"Pr.A.~....t1.}Os...h..*.`.ntwL.}..~.x../.n..E......h.;.IP4..O.....,.....k..c...y.#..j......$.v..Z.wb..`t..../.V...&&bt..BB.Or..C.,...sh<....l...b:7}#'@.T.vo.t....!J..v....5.^.0..4.xI.3I.V..c...2....0 5..)...d..>F'_.p..cz_q.J..wV.....>..^..1.O...y%|.l..BZ..5.XF(..}...B.e.p....c#..rz.I.-...o..f..K.+.x5.....k.<.=..........qd.a.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):718482
                  Entropy (8bit):7.999720790196673
                  Encrypted:true
                  SSDEEP:
                  MD5:AF907DD6E27BBFF2563FC9E0591A732F
                  SHA1:8C54735A913E321E12D3B62522C610F2FFAEFD63
                  SHA-256:8B4B3FB967AA7FDFC2029ECC892641398648723CD0438135E6E2FB7A0CE5F9C6
                  SHA-512:D17931B9B8A9B72A864AC11655FEDF3C9DED125405ACBA5D445E70D637B253F7F3AD96D59C1D7D682866C9B123F09A4F950B27CCF60F6C2E6B64D17E3C694010
                  Malicious:true
                  Preview:e....g..NU(.b...f,...........}0P......<.......1...!..vq.."...>._.t..^.G....{o1.....'.e.a....[..^@.....c.d........z..Df*...p.t....u9.~!$GC.A....aY.JpzX.`W..&..u.....t 1.Q..Gf*..7.ct7..5.%.....!!.b.^5.k..>.u..yA<a...z<.lc..Fgnus^a..<g.6../.%8.It...5........*.1....4.T%..&..z..].[S.`...e.......Uz.uT.:...Y....@....>d9...R.....;o.LUQ]..j..H.b.2..CP..^.y..Ys.A....../..v-....%+s@.08m.,7.-..r.-.tI.._.c.....d.....\Q:o.,..{..U|.....:.j-.d....q$..Mc=Q.e.L._S...\....3.......9.]Z0.s..._b4...........h..u.U..T.~4...|.... .p.k.......'dM.....k.O.@6cgV3.z.....N;u....`....P..:.....N.Y...Z.i.+).k47.P.Z.{Y.:Wz.u.]"6..x..b.(."b....6A"Pr.A.~....t1.}Os...h..*.`.ntwL.}..~.x../.n..E......h.;.IP4..O.....,.....k..c...y.#..j......$.v..Z.wb..`t..../.V...&&bt..BB.Or..C.,...sh<....l...b:7}#'@.T.vo.t....!J..v....5.^.0..4.xI.3I.V..c...2....0 5..)...d..>F'_.p..cz_q.J..wV.....>..^..1.O...y%|.l..BZ..5.XF(..}...B.e.p....c#..rz.I.-...o..f..K.+.x5.....k.<.=..........qd.a.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):420764
                  Entropy (8bit):7.999598376443861
                  Encrypted:true
                  SSDEEP:
                  MD5:E0B3CB74EF30F767C56C0D0DADE02BE9
                  SHA1:D79DE87ACA8B216E6C08A9CDD9149465DCECD1F7
                  SHA-256:31E9E7472E2850DCC96DCB93A37059858F45A3F0475841B1F089D8F1E6F5E455
                  SHA-512:196EB26EFA784C8D75E54101DF6F64C21FDCC47DFE39AA2E5759432E7678C97A47CF371F16E2CE1D619F2C09DBFB01962F37C7848DD7842FAFC8ADD2BF8180DD
                  Malicious:true
                  Preview:..;.2....b.&g.I..M.........?J.}...=...!.D(...s_.:..YD.so..PN.=E}.\.W..9._&.n..F.u..j..cU...~...A...).J..g..)......'uO.+......4.?....u.B<>.V.7......Q.....n.9..jJd../..0.....C..R.+o.%.^..?....5..B3...}.^/5.~...h.:.u?N.$..'.v.H... .d'.'..rY.B..~..\.p...XAJ..]...H...$q......{?...Z....@...7..\...~...r[b.h...c.#K.B'.+.DD..g...7.^.e.........!.............tMD$.-E.o...].Y.z.....I..{.$.......t..c...v.....@......f..f6#.K.+5..-..I.c.4s....i...d.<.....1a{...MN.R..Uk(..'.~.F...Sb...L.`..i!.....~...Z.^..a.I.U....#w.T..<..3..N.o.2..2.{...j...?. ..~..L($..ZO.L..A.m.. ..zm..Q....c..V<..<.!.6?....<S...U\....p.........O..c.M.V.E...^H|./.......^.=..q.+....m?......|.L....q...v...x.c.1P=4.c.!.i...#.5+R!.k.....ATaV.....4:.'.^...aI.!....'.!.....R.b&.|.+^J..*..=....*.)..o..a...a.i.yM.l.JZ";.._...U."...#u...E.e:.E..l.4.S6.T!y.....@i.m..).+..}....h`55.]^.b.B.I.s.\z.....OY.Ch.$..$.n..{..X.hQ..z..?N......UE..b.<..V....u....lM.^..w...........1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):420764
                  Entropy (8bit):7.999598376443861
                  Encrypted:true
                  SSDEEP:
                  MD5:E0B3CB74EF30F767C56C0D0DADE02BE9
                  SHA1:D79DE87ACA8B216E6C08A9CDD9149465DCECD1F7
                  SHA-256:31E9E7472E2850DCC96DCB93A37059858F45A3F0475841B1F089D8F1E6F5E455
                  SHA-512:196EB26EFA784C8D75E54101DF6F64C21FDCC47DFE39AA2E5759432E7678C97A47CF371F16E2CE1D619F2C09DBFB01962F37C7848DD7842FAFC8ADD2BF8180DD
                  Malicious:true
                  Preview:..;.2....b.&g.I..M.........?J.}...=...!.D(...s_.:..YD.so..PN.=E}.\.W..9._&.n..F.u..j..cU...~...A...).J..g..)......'uO.+......4.?....u.B<>.V.7......Q.....n.9..jJd../..0.....C..R.+o.%.^..?....5..B3...}.^/5.~...h.:.u?N.$..'.v.H... .d'.'..rY.B..~..\.p...XAJ..]...H...$q......{?...Z....@...7..\...~...r[b.h...c.#K.B'.+.DD..g...7.^.e.........!.............tMD$.-E.o...].Y.z.....I..{.$.......t..c...v.....@......f..f6#.K.+5..-..I.c.4s....i...d.<.....1a{...MN.R..Uk(..'.~.F...Sb...L.`..i!.....~...Z.^..a.I.U....#w.T..<..3..N.o.2..2.{...j...?. ..~..L($..ZO.L..A.m.. ..zm..Q....c..V<..<.!.6?....<S...U\....p.........O..c.M.V.E...^H|./.......^.=..q.+....m?......|.L....q...v...x.c.1P=4.c.!.i...#.5+R!.k.....ATaV.....4:.'.^...aI.!....'.!.....R.b&.|.+^J..*..=....*.)..o..a...a.i.yM.l.JZ";.._...U."...#u...E.e:.E..l.4.S6.T!y.....@i.m..).+..}....h`55.]^.b.B.I.s.\z.....OY.Ch.$..$.n..{..X.hQ..z..?N......UE..b.<..V....u....lM.^..w...........1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):420764
                  Entropy (8bit):7.999598376443861
                  Encrypted:true
                  SSDEEP:
                  MD5:E0B3CB74EF30F767C56C0D0DADE02BE9
                  SHA1:D79DE87ACA8B216E6C08A9CDD9149465DCECD1F7
                  SHA-256:31E9E7472E2850DCC96DCB93A37059858F45A3F0475841B1F089D8F1E6F5E455
                  SHA-512:196EB26EFA784C8D75E54101DF6F64C21FDCC47DFE39AA2E5759432E7678C97A47CF371F16E2CE1D619F2C09DBFB01962F37C7848DD7842FAFC8ADD2BF8180DD
                  Malicious:true
                  Preview:..;.2....b.&g.I..M.........?J.}...=...!.D(...s_.:..YD.so..PN.=E}.\.W..9._&.n..F.u..j..cU...~...A...).J..g..)......'uO.+......4.?....u.B<>.V.7......Q.....n.9..jJd../..0.....C..R.+o.%.^..?....5..B3...}.^/5.~...h.:.u?N.$..'.v.H... .d'.'..rY.B..~..\.p...XAJ..]...H...$q......{?...Z....@...7..\...~...r[b.h...c.#K.B'.+.DD..g...7.^.e.........!.............tMD$.-E.o...].Y.z.....I..{.$.......t..c...v.....@......f..f6#.K.+5..-..I.c.4s....i...d.<.....1a{...MN.R..Uk(..'.~.F...Sb...L.`..i!.....~...Z.^..a.I.U....#w.T..<..3..N.o.2..2.{...j...?. ..~..L($..ZO.L..A.m.. ..zm..Q....c..V<..<.!.6?....<S...U\....p.........O..c.M.V.E...^H|./.......^.=..q.+....m?......|.L....q...v...x.c.1P=4.c.!.i...#.5+R!.k.....ATaV.....4:.'.^...aI.!....'.!.....R.b&.|.+^J..*..=....*.)..o..a...a.i.yM.l.JZ";.._...U."...#u...E.e:.E..l.4.S6.T!y.....@i.m..).+..}....h`55.]^.b.B.I.s.\z.....OY.Ch.$..$.n..{..X.hQ..z..?N......UE..b.<..V....u....lM.^..w...........1.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):442189
                  Entropy (8bit):7.999560868189232
                  Encrypted:true
                  SSDEEP:
                  MD5:B2B7606448548C67D2F91C83CE47CF52
                  SHA1:9C41D167C6E6CD806B83C7C963D6D713FC5FB598
                  SHA-256:7BF6E8C5765AC2E99B26CB09CCA440E62E610B9A22E0010D8EB32AA6BF835CDC
                  SHA-512:D1FE4DD53AFDB55F722A3BB84E6640ADC05C828FF87157719F2AED88BFF8ED8322A8C11A0F2DFF475947E63273AF344BFFA60C6D1FFB02A7DA363BD6338F141B
                  Malicious:true
                  Preview:Y..=N*#..9|..{.B...........p.s...9.#.$.@..0....a....v..}0..&_4..J3Re..t.8!%..0o,..*.w.F.....Rx.....|-.*.B.&2..=...-.%..$..L...@GY.slS..U..Xs.d-.(_N.....!5t..8|...p../.....Ly/%.........;..o.q...<..6.....IK.c!}.H..T..{.E.@.v..G...<C...tu.*2+.Y.&.....%e.)@...6.<j.M.J{?............n88q..VqV.x......W..%.AY|.H.@}.._....*I8..QKa!..v..f..+'!6H..^.b..wj......J O.j.g~6.>."X.....uTSc|...r^. ..<.....&T........`^.M.....B..'1.g...i..@.w.,..ci.-.;l..\z...c-o5jo=.....E j....x.....`b.`)>C.u..*.Q.<..Xyk..9..j,Yk..M..f..B.s.q.T.,...A........A.r........8......*.%I....k........}.,<.|Ra.8...@-.~^.j...g.#.{.#8.N.........n.wG...'k.....V....u}..uz......*.(...?.8...?=O.m.`....x.ve.....<...mP.w.&............=...O.1...D.....,..b(......'...4?...}........p.......D..E......s.,.....V...a...M.M+,...}...1fc.;..^L....)..P}H:.(E.... ......|..Ws.>...5..J03...D<A]@.Z..^...C.Y,i2..?$,.f.I.N...]..u....... .E..W.l.M....3(...;Gh.|E.s.2.yd.......b.`.v.Q.....0.j2f.&......~\..B
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):442189
                  Entropy (8bit):7.999560868189232
                  Encrypted:true
                  SSDEEP:
                  MD5:B2B7606448548C67D2F91C83CE47CF52
                  SHA1:9C41D167C6E6CD806B83C7C963D6D713FC5FB598
                  SHA-256:7BF6E8C5765AC2E99B26CB09CCA440E62E610B9A22E0010D8EB32AA6BF835CDC
                  SHA-512:D1FE4DD53AFDB55F722A3BB84E6640ADC05C828FF87157719F2AED88BFF8ED8322A8C11A0F2DFF475947E63273AF344BFFA60C6D1FFB02A7DA363BD6338F141B
                  Malicious:true
                  Preview:Y..=N*#..9|..{.B...........p.s...9.#.$.@..0....a....v..}0..&_4..J3Re..t.8!%..0o,..*.w.F.....Rx.....|-.*.B.&2..=...-.%..$..L...@GY.slS..U..Xs.d-.(_N.....!5t..8|...p../.....Ly/%.........;..o.q...<..6.....IK.c!}.H..T..{.E.@.v..G...<C...tu.*2+.Y.&.....%e.)@...6.<j.M.J{?............n88q..VqV.x......W..%.AY|.H.@}.._....*I8..QKa!..v..f..+'!6H..^.b..wj......J O.j.g~6.>."X.....uTSc|...r^. ..<.....&T........`^.M.....B..'1.g...i..@.w.,..ci.-.;l..\z...c-o5jo=.....E j....x.....`b.`)>C.u..*.Q.<..Xyk..9..j,Yk..M..f..B.s.q.T.,...A........A.r........8......*.%I....k........}.,<.|Ra.8...@-.~^.j...g.#.{.#8.N.........n.wG...'k.....V....u}..uz......*.(...?.8...?=O.m.`....x.ve.....<...mP.w.&............=...O.1...D.....,..b(......'...4?...}........p.......D..E......s.,.....V...a...M.M+,...}...1fc.;..^L....)..P}H:.(E.... ......|..Ws.>...5..J03...D<A]@.Z..^...C.Y,i2..?$,.f.I.N...]..u....... .E..W.l.M....3(...;Gh.|E.s.2.yd.......b.`.v.Q.....0.j2f.&......~\..B
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):442189
                  Entropy (8bit):7.999560868189232
                  Encrypted:true
                  SSDEEP:
                  MD5:B2B7606448548C67D2F91C83CE47CF52
                  SHA1:9C41D167C6E6CD806B83C7C963D6D713FC5FB598
                  SHA-256:7BF6E8C5765AC2E99B26CB09CCA440E62E610B9A22E0010D8EB32AA6BF835CDC
                  SHA-512:D1FE4DD53AFDB55F722A3BB84E6640ADC05C828FF87157719F2AED88BFF8ED8322A8C11A0F2DFF475947E63273AF344BFFA60C6D1FFB02A7DA363BD6338F141B
                  Malicious:true
                  Preview:Y..=N*#..9|..{.B...........p.s...9.#.$.@..0....a....v..}0..&_4..J3Re..t.8!%..0o,..*.w.F.....Rx.....|-.*.B.&2..=...-.%..$..L...@GY.slS..U..Xs.d-.(_N.....!5t..8|...p../.....Ly/%.........;..o.q...<..6.....IK.c!}.H..T..{.E.@.v..G...<C...tu.*2+.Y.&.....%e.)@...6.<j.M.J{?............n88q..VqV.x......W..%.AY|.H.@}.._....*I8..QKa!..v..f..+'!6H..^.b..wj......J O.j.g~6.>."X.....uTSc|...r^. ..<.....&T........`^.M.....B..'1.g...i..@.w.,..ci.-.;l..\z...c-o5jo=.....E j....x.....`b.`)>C.u..*.Q.<..Xyk..9..j,Yk..M..f..B.s.q.T.,...A........A.r........8......*.%I....k........}.,<.|Ra.8...@-.~^.j...g.#.{.#8.N.........n.wG...'k.....V....u}..uz......*.(...?.8...?=O.m.`....x.ve.....<...mP.w.&............=...O.1...D.....,..b(......'...4?...}........p.......D..E......s.,.....V...a...M.M+,...}...1fc.;..^L....)..P}H:.(E.... ......|..Ws.>...5..J03...D<A]@.Z..^...C.Y,i2..?$,.f.I.N...]..u....... .E..W.l.M....3(...;Gh.|E.s.2.yd.......b.`.v.Q.....0.j2f.&......~\..B
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1140005
                  Entropy (8bit):7.999850963819945
                  Encrypted:true
                  SSDEEP:
                  MD5:9DD58B0E18A259E5F7CD87FC743C3849
                  SHA1:F190DB57A1F4ECADE0CA177CFDCCF530DA559D83
                  SHA-256:2DD4FB6C467A21796EE062B9AE008B2414A929833E8917B3F43292A194BD61F8
                  SHA-512:7029464A5924534242965C1374460FC928A7FB584B99D0C304368C8889A8FF0BBB60DB5EE9772A78F481D9F08E9058BBB73596C72E631E2430A8923F77E84FC9
                  Malicious:true
                  Preview:).......*.V.~..~.#..-x..!c.......?...2d.XjB.$.K.R.....q...j;.X,..U.}H.....2b...._H-d.!%..\..#/...iR...........3&..h*.A.B.+..s.E,^..._...........8"~...!X.p....leR...B..e.g#.\m%i......r...N.J.l6}!&...cN..@.....8:......P.h.5..:.oV.r.A.s.:}7C..Gh.............R...$....N].=.i.|F..h..xl.5....va...~.E.. N1#.p}..>!..M...e8...<P.w0.....1...b.O....."..-..."..y.>.....Q)u...k.H@....z....4...k...>...gk.B..Z....+.vP...#+....6`...X.M=.?*..L..[.&.|jy.@..K...~\.Q...y......3..F~,..Q....v.HZR..^Qf..rf.6.iu....M...5..=....M~`.....+.C..!L.1..........p..y.>..*Z#E.....w .l~.-.!S..5.ma........M.^..@..w.68..[.....|....o.z.c..,S...o.4|.."..T..G.tI,8.@I...{.]..t.7.jDR2.F.nj..9.X....M..R....q.tuJl....%~LS.T..=:.........6.<#......7..e0Z..J4.2]X--NF....2qV...<).^~..Lx..9....{........b..g..?..1*.P..q...@k<>.{.l..X...x..J".J..j..H..w.}h...dYl_x..{N.j8...{.$.^".n..X.....U\.i9.1.4PZ.7...5<6....\'.!Tu.h.>.+...[.G1..F{r#.M....~.e&e.>..d....>!Cw...:..."..U..t/.......&...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1140005
                  Entropy (8bit):7.999850963819945
                  Encrypted:true
                  SSDEEP:
                  MD5:9DD58B0E18A259E5F7CD87FC743C3849
                  SHA1:F190DB57A1F4ECADE0CA177CFDCCF530DA559D83
                  SHA-256:2DD4FB6C467A21796EE062B9AE008B2414A929833E8917B3F43292A194BD61F8
                  SHA-512:7029464A5924534242965C1374460FC928A7FB584B99D0C304368C8889A8FF0BBB60DB5EE9772A78F481D9F08E9058BBB73596C72E631E2430A8923F77E84FC9
                  Malicious:true
                  Preview:).......*.V.~..~.#..-x..!c.......?...2d.XjB.$.K.R.....q...j;.X,..U.}H.....2b...._H-d.!%..\..#/...iR...........3&..h*.A.B.+..s.E,^..._...........8"~...!X.p....leR...B..e.g#.\m%i......r...N.J.l6}!&...cN..@.....8:......P.h.5..:.oV.r.A.s.:}7C..Gh.............R...$....N].=.i.|F..h..xl.5....va...~.E.. N1#.p}..>!..M...e8...<P.w0.....1...b.O....."..-..."..y.>.....Q)u...k.H@....z....4...k...>...gk.B..Z....+.vP...#+....6`...X.M=.?*..L..[.&.|jy.@..K...~\.Q...y......3..F~,..Q....v.HZR..^Qf..rf.6.iu....M...5..=....M~`.....+.C..!L.1..........p..y.>..*Z#E.....w .l~.-.!S..5.ma........M.^..@..w.68..[.....|....o.z.c..,S...o.4|.."..T..G.tI,8.@I...{.]..t.7.jDR2.F.nj..9.X....M..R....q.tuJl....%~LS.T..=:.........6.<#......7..e0Z..J4.2]X--NF....2qV...<).^~..Lx..9....{........b..g..?..1*.P..q...@k<>.{.l..X...x..J".J..j..H..w.}h...dYl_x..{N.j8...{.$.^".n..X.....U\.i9.1.4PZ.7...5<6....\'.!Tu.h.>.+...[.G1..F{r#.M....~.e&e.>..d....>!Cw...:..."..U..t/.......&...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1140005
                  Entropy (8bit):7.999850963819945
                  Encrypted:true
                  SSDEEP:
                  MD5:9DD58B0E18A259E5F7CD87FC743C3849
                  SHA1:F190DB57A1F4ECADE0CA177CFDCCF530DA559D83
                  SHA-256:2DD4FB6C467A21796EE062B9AE008B2414A929833E8917B3F43292A194BD61F8
                  SHA-512:7029464A5924534242965C1374460FC928A7FB584B99D0C304368C8889A8FF0BBB60DB5EE9772A78F481D9F08E9058BBB73596C72E631E2430A8923F77E84FC9
                  Malicious:true
                  Preview:).......*.V.~..~.#..-x..!c.......?...2d.XjB.$.K.R.....q...j;.X,..U.}H.....2b...._H-d.!%..\..#/...iR...........3&..h*.A.B.+..s.E,^..._...........8"~...!X.p....leR...B..e.g#.\m%i......r...N.J.l6}!&...cN..@.....8:......P.h.5..:.oV.r.A.s.:}7C..Gh.............R...$....N].=.i.|F..h..xl.5....va...~.E.. N1#.p}..>!..M...e8...<P.w0.....1...b.O....."..-..."..y.>.....Q)u...k.H@....z....4...k...>...gk.B..Z....+.vP...#+....6`...X.M=.?*..L..[.&.|jy.@..K...~\.Q...y......3..F~,..Q....v.HZR..^Qf..rf.6.iu....M...5..=....M~`.....+.C..!L.1..........p..y.>..*Z#E.....w .l~.-.!S..5.ma........M.^..@..w.68..[.....|....o.z.c..,S...o.4|.."..T..G.tI,8.@I...{.]..t.7.jDR2.F.nj..9.X....M..R....q.tuJl....%~LS.T..=:.........6.<#......7..e0Z..J4.2]X--NF....2qV...<).^~..Lx..9....{........b..g..?..1*.P..q...@k<>.{.l..X...x..J".J..j..H..w.}h...dYl_x..{N.j8...{.$.^".n..X.....U\.i9.1.4PZ.7...5<6....\'.!Tu.h.>.+...[.G1..F{r#.M....~.e&e.>..d....>!Cw...:..."..U..t/.......&...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1053428
                  Entropy (8bit):7.999834837597807
                  Encrypted:true
                  SSDEEP:
                  MD5:5C9CAB243DEF0A232246029B1605747B
                  SHA1:4B9AB3FE86F39819FDE1F79E4504B5F7B4C10E0C
                  SHA-256:6A06E8842B73B22CAD4B318A145A9055DB0B66C5F9D4290E3C5AC885BB67CA6B
                  SHA-512:279C0E41560554CDE63964BF01F551E278C1B16D3BBAFFC15305AAFA330499158342EB594154B4D5626B8D34974B3A721D5902CC97430709BC5D7498888C83C2
                  Malicious:true
                  Preview:...p............B......"......=..h^.....uX..Y.r.E.Q.T......c..z..<kK`F..T.T.....<.C..'k... ...I..;..O..2..y.l.SJ+.@{5..-....F.... .b.9.1.y:.N.D..$:n6....Cy~.B^.o.t......b....j`.=#_~ ..`.*......Y..[.*...K...&.fabd..4(Y..y...f....wDkw.).k....=Me...B.....V.w.......P.....k.'.g...;.1.}.Cs..HNCQ..92j+.3..6G........!O6&...rNP..".Q9._..\.|....:..Y....~..$.]..*.U....yMNZZ......._[.e.....u.]F..P.S..../...j#........C.4...*.z..5.:.n`".1..@.k...3J.K...~ .....w.VB....pn....vb..|......C..Wb.T<.a2.....k.r..D...g|".+.V........w....E...er...3..f.Xs..b..m.&v....D....[..Q..pA.O.. .....IZb.K...,..e..~..`+.<`.'.8..L........Fjm.OQ*..j.d..W..O!.e.{.t."....m+m..c5../4..1;.......e.5.a.aV...V=C.....'....A"*..m.6!..<.j....n^..a.s/.m..!..<.....W.HR.0......+....p.a..@..T...m...".W.n...;...B\.)..4...ef..G...!...z.....%0.NxXq.E...t..N9\....(......."RVH.TFE........p.y......A.C.U.FT.K.<...u.X'&T....*...L;6zki.......o:..6..1..LP.(.|w.o.d.H...W..~bj....'&$....r....GJ.....<v.H
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1053428
                  Entropy (8bit):7.999834837597807
                  Encrypted:true
                  SSDEEP:
                  MD5:5C9CAB243DEF0A232246029B1605747B
                  SHA1:4B9AB3FE86F39819FDE1F79E4504B5F7B4C10E0C
                  SHA-256:6A06E8842B73B22CAD4B318A145A9055DB0B66C5F9D4290E3C5AC885BB67CA6B
                  SHA-512:279C0E41560554CDE63964BF01F551E278C1B16D3BBAFFC15305AAFA330499158342EB594154B4D5626B8D34974B3A721D5902CC97430709BC5D7498888C83C2
                  Malicious:true
                  Preview:...p............B......"......=..h^.....uX..Y.r.E.Q.T......c..z..<kK`F..T.T.....<.C..'k... ...I..;..O..2..y.l.SJ+.@{5..-....F.... .b.9.1.y:.N.D..$:n6....Cy~.B^.o.t......b....j`.=#_~ ..`.*......Y..[.*...K...&.fabd..4(Y..y...f....wDkw.).k....=Me...B.....V.w.......P.....k.'.g...;.1.}.Cs..HNCQ..92j+.3..6G........!O6&...rNP..".Q9._..\.|....:..Y....~..$.]..*.U....yMNZZ......._[.e.....u.]F..P.S..../...j#........C.4...*.z..5.:.n`".1..@.k...3J.K...~ .....w.VB....pn....vb..|......C..Wb.T<.a2.....k.r..D...g|".+.V........w....E...er...3..f.Xs..b..m.&v....D....[..Q..pA.O.. .....IZb.K...,..e..~..`+.<`.'.8..L........Fjm.OQ*..j.d..W..O!.e.{.t."....m+m..c5../4..1;.......e.5.a.aV...V=C.....'....A"*..m.6!..<.j....n^..a.s/.m..!..<.....W.HR.0......+....p.a..@..T...m...".W.n...;...B\.)..4...ef..G...!...z.....%0.NxXq.E...t..N9\....(......."RVH.TFE........p.y......A.C.U.FT.K.<...u.X'&T....*...L;6zki.......o:..6..1..LP.(.|w.o.d.H...W..~bj....'&$....r....GJ.....<v.H
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1053428
                  Entropy (8bit):7.999834837597807
                  Encrypted:true
                  SSDEEP:
                  MD5:5C9CAB243DEF0A232246029B1605747B
                  SHA1:4B9AB3FE86F39819FDE1F79E4504B5F7B4C10E0C
                  SHA-256:6A06E8842B73B22CAD4B318A145A9055DB0B66C5F9D4290E3C5AC885BB67CA6B
                  SHA-512:279C0E41560554CDE63964BF01F551E278C1B16D3BBAFFC15305AAFA330499158342EB594154B4D5626B8D34974B3A721D5902CC97430709BC5D7498888C83C2
                  Malicious:true
                  Preview:...p............B......"......=..h^.....uX..Y.r.E.Q.T......c..z..<kK`F..T.T.....<.C..'k... ...I..;..O..2..y.l.SJ+.@{5..-....F.... .b.9.1.y:.N.D..$:n6....Cy~.B^.o.t......b....j`.=#_~ ..`.*......Y..[.*...K...&.fabd..4(Y..y...f....wDkw.).k....=Me...B.....V.w.......P.....k.'.g...;.1.}.Cs..HNCQ..92j+.3..6G........!O6&...rNP..".Q9._..\.|....:..Y....~..$.]..*.U....yMNZZ......._[.e.....u.]F..P.S..../...j#........C.4...*.z..5.:.n`".1..@.k...3J.K...~ .....w.VB....pn....vb..|......C..Wb.T<.a2.....k.r..D...g|".+.V........w....E...er...3..f.Xs..b..m.&v....D....[..Q..pA.O.. .....IZb.K...,..e..~..`+.<`.'.8..L........Fjm.OQ*..j.d..W..O!.e.{.t."....m+m..c5../4..1;.......e.5.a.aV...V=C.....'....A"*..m.6!..<.j....n^..a.s/.m..!..<.....W.HR.0......+....p.a..@..T...m...".W.n...;...B\.)..4...ef..G...!...z.....%0.NxXq.E...t..N9\....(......."RVH.TFE........p.y......A.C.U.FT.K.<...u.X'&T....*...L;6zki.......o:..6..1..LP.(.|w.o.d.H...W..~bj....'&$....r....GJ.....<v.H
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):889743
                  Entropy (8bit):7.999786945602971
                  Encrypted:true
                  SSDEEP:
                  MD5:C6780E9007B01C5D6D9CEED5D15FEF25
                  SHA1:B44883FEB0736266531248149B94231A88674769
                  SHA-256:4E0F1C5FDE570B566F7ED5DB67215B0577A42E4BC5996E62C2AB058495F24670
                  SHA-512:E6F0339755098C3B3DE4E56837D2ACF57D3192677A71779D1B85A900463CC8C0F6468264A638329B41E73BA87647886CDDE0E99EF948A4E58EFFEC0C7D69FEF7
                  Malicious:true
                  Preview:.......vWa..wp./....*V...-&.......h..<(M@..e...kTz... .2..3..e}..O8..........-{...(.Z.3.#4......r..T...$.....m...F.......73.XE.....E...'....K.:.fBV..5.._...l.=.?..~.w.AK.....,..A.@@d0.$x......%#.=..p...A..XdDp...T"...X.......D..:;....\..d..9....(....z`9og..RU.$.S...z.~"4'..kh.zP'......+`..>.#mzU;_.D..||J...2........JD..z.q....}...P...P..]B=... ...7....`(...V<.+d...jC_.......Q.|V..T....P.AU.|Y.o....f...k.'^,.:..%.c......R.S..V).~(?W.Q;...$.q[D.#..5.$..6..O....i}.1.72#2^.#.O.u.1$O..t.....v....Gwk.....f...'....It...s(..y.HS....79`.......X3...ABH1..b....m....wX....lc..h0.p.-@..g.d|]..~..,.l ...W._.EK{mK...A.9........X......UJ.`..0.M.}}n.D....q......!...<........d.I...}]b..)6.....;.7...<...(Q...L.>2..<.S./.f.+..X.b......R....[..o.2..E..(..L.c{..<..?.......m...p{.....JR.I.TC;...b3..vfO![.T9.@Pu....L.7v.K...s...FH....!..c|...'9.&@.o...1..d!..-...|.'..X...h....c.............Q..4...\.[...K{..p.Q.P....A$.X.@..1&....K/..X...V5.j...^.<.)<M...g..vS
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):889743
                  Entropy (8bit):7.999786945602971
                  Encrypted:true
                  SSDEEP:
                  MD5:C6780E9007B01C5D6D9CEED5D15FEF25
                  SHA1:B44883FEB0736266531248149B94231A88674769
                  SHA-256:4E0F1C5FDE570B566F7ED5DB67215B0577A42E4BC5996E62C2AB058495F24670
                  SHA-512:E6F0339755098C3B3DE4E56837D2ACF57D3192677A71779D1B85A900463CC8C0F6468264A638329B41E73BA87647886CDDE0E99EF948A4E58EFFEC0C7D69FEF7
                  Malicious:true
                  Preview:.......vWa..wp./....*V...-&.......h..<(M@..e...kTz... .2..3..e}..O8..........-{...(.Z.3.#4......r..T...$.....m...F.......73.XE.....E...'....K.:.fBV..5.._...l.=.?..~.w.AK.....,..A.@@d0.$x......%#.=..p...A..XdDp...T"...X.......D..:;....\..d..9....(....z`9og..RU.$.S...z.~"4'..kh.zP'......+`..>.#mzU;_.D..||J...2........JD..z.q....}...P...P..]B=... ...7....`(...V<.+d...jC_.......Q.|V..T....P.AU.|Y.o....f...k.'^,.:..%.c......R.S..V).~(?W.Q;...$.q[D.#..5.$..6..O....i}.1.72#2^.#.O.u.1$O..t.....v....Gwk.....f...'....It...s(..y.HS....79`.......X3...ABH1..b....m....wX....lc..h0.p.-@..g.d|]..~..,.l ...W._.EK{mK...A.9........X......UJ.`..0.M.}}n.D....q......!...<........d.I...}]b..)6.....;.7...<...(Q...L.>2..<.S./.f.+..X.b......R....[..o.2..E..(..L.c{..<..?.......m...p{.....JR.I.TC;...b3..vfO![.T9.@Pu....L.7v.K...s...FH....!..c|...'9.&@.o...1..d!..-...|.'..X...h....c.............Q..4...\.[...K{..p.Q.P....A$.X.@..1&....K/..X...V5.j...^.<.)<M...g..vS
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):889743
                  Entropy (8bit):7.999786945602971
                  Encrypted:true
                  SSDEEP:
                  MD5:C6780E9007B01C5D6D9CEED5D15FEF25
                  SHA1:B44883FEB0736266531248149B94231A88674769
                  SHA-256:4E0F1C5FDE570B566F7ED5DB67215B0577A42E4BC5996E62C2AB058495F24670
                  SHA-512:E6F0339755098C3B3DE4E56837D2ACF57D3192677A71779D1B85A900463CC8C0F6468264A638329B41E73BA87647886CDDE0E99EF948A4E58EFFEC0C7D69FEF7
                  Malicious:true
                  Preview:.......vWa..wp./....*V...-&.......h..<(M@..e...kTz... .2..3..e}..O8..........-{...(.Z.3.#4......r..T...$.....m...F.......73.XE.....E...'....K.:.fBV..5.._...l.=.?..~.w.AK.....,..A.@@d0.$x......%#.=..p...A..XdDp...T"...X.......D..:;....\..d..9....(....z`9og..RU.$.S...z.~"4'..kh.zP'......+`..>.#mzU;_.D..||J...2........JD..z.q....}...P...P..]B=... ...7....`(...V<.+d...jC_.......Q.|V..T....P.AU.|Y.o....f...k.'^,.:..%.c......R.S..V).~(?W.Q;...$.q[D.#..5.$..6..O....i}.1.72#2^.#.O.u.1$O..t.....v....Gwk.....f...'....It...s(..y.HS....79`.......X3...ABH1..b....m....wX....lc..h0.p.-@..g.d|]..~..,.l ...W._.EK{mK...A.9........X......UJ.`..0.M.}}n.D....q......!...<........d.I...}]b..)6.....;.7...<...(Q...L.>2..<.S./.f.+..X.b......R....[..o.2..E..(..L.c{..<..?.......m...p{.....JR.I.TC;...b3..vfO![.T9.@Pu....L.7v.K...s...FH....!..c|...'9.&@.o...1..d!..-...|.'..X...h....c.............Q..4...\.[...K{..p.Q.P....A$.X.@..1&....K/..X...V5.j...^.<.)<M...g..vS
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):451894
                  Entropy (8bit):7.999563050612889
                  Encrypted:true
                  SSDEEP:
                  MD5:49F40256D4C26EDD151D19280EF9B362
                  SHA1:251CDFA6D1FFCE231BD9F2C395700A40B3452F00
                  SHA-256:A2EDB9984323903752C68E302014B50399A4C66E3FFEC2C997B4A922D1072F17
                  SHA-512:62097DFCA38E2D20DB543C6F417F5705D0D272295FEDAB08A33CF360D823B3F270947C81B959652A6B27D59DC1F754502997A5591B20E21C43AFF977B34C50B4
                  Malicious:true
                  Preview:...._[z....Gh.G*....o ..K...Hz.5..4c..F.f.g\|..w.P.......Ump..{.Y.vt...).g]..Y....$.Q=j.h....c.G.....Dg9...E.$.R..._E8.G....X...S..]7K....0.....E.>..t.._j........~.k..%|d.5&NC.U.... ....V.....{k..HP..c..M.St...gj....tl.s..b...[./.t..F~..../p...J5..[ahv..CT.y.S.d...r..90.Oa..E.](.V..%..ss8..@.:kZ....z.{.kg:./_......k....<b...;...$...U.twi.x.Ii.h(M.d9...>...G......3..D...[rH9..::..u......D<Mp.z.*.U.*=i(.7...E...)..tT.LP..T...bn.v$...0!.)*343.2tz.OF..?.J]K..(....etH,..E:.\b.z.Uv? .....(.32X..wc......G.....-.<.O.6wi...vH.[C.F..i..|.n=..-`.6..*.9}.D.6.7.%..d.r.q.`km..U.M.!......'].6.z...z2.V...~.C._....+v9...{.Y..._.).....^Ml.......lC...>..\l...\..0Wx=.^(}@4.w..:ZB.;Zl@..)u(V.N.h.....<.1{..$.'.%0&.!>{..d..i.3$I.y.6..z..J.74....S.....@`.L.F..]8.O+..To..Ic.*..o.3.e5fW..."...)...L..._....Tk..d.dY.....Ke`.0.F.m.5.L'W..9..G..a.t~...:.@f0..[....:xd.}..........F.f..w.....{.SVv]..5V.#..F..{.i...Y.K1>.1Ay*1.#Y..0...g.....Z.X..#.....::.;.La./....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):451894
                  Entropy (8bit):7.999563050612889
                  Encrypted:true
                  SSDEEP:
                  MD5:49F40256D4C26EDD151D19280EF9B362
                  SHA1:251CDFA6D1FFCE231BD9F2C395700A40B3452F00
                  SHA-256:A2EDB9984323903752C68E302014B50399A4C66E3FFEC2C997B4A922D1072F17
                  SHA-512:62097DFCA38E2D20DB543C6F417F5705D0D272295FEDAB08A33CF360D823B3F270947C81B959652A6B27D59DC1F754502997A5591B20E21C43AFF977B34C50B4
                  Malicious:true
                  Preview:...._[z....Gh.G*....o ..K...Hz.5..4c..F.f.g\|..w.P.......Ump..{.Y.vt...).g]..Y....$.Q=j.h....c.G.....Dg9...E.$.R..._E8.G....X...S..]7K....0.....E.>..t.._j........~.k..%|d.5&NC.U.... ....V.....{k..HP..c..M.St...gj....tl.s..b...[./.t..F~..../p...J5..[ahv..CT.y.S.d...r..90.Oa..E.](.V..%..ss8..@.:kZ....z.{.kg:./_......k....<b...;...$...U.twi.x.Ii.h(M.d9...>...G......3..D...[rH9..::..u......D<Mp.z.*.U.*=i(.7...E...)..tT.LP..T...bn.v$...0!.)*343.2tz.OF..?.J]K..(....etH,..E:.\b.z.Uv? .....(.32X..wc......G.....-.<.O.6wi...vH.[C.F..i..|.n=..-`.6..*.9}.D.6.7.%..d.r.q.`km..U.M.!......'].6.z...z2.V...~.C._....+v9...{.Y..._.).....^Ml.......lC...>..\l...\..0Wx=.^(}@4.w..:ZB.;Zl@..)u(V.N.h.....<.1{..$.'.%0&.!>{..d..i.3$I.y.6..z..J.74....S.....@`.L.F..]8.O+..To..Ic.*..o.3.e5fW..."...)...L..._....Tk..d.dY.....Ke`.0.F.m.5.L'W..9..G..a.t~...:.@f0..[....:xd.}..........F.f..w.....{.SVv]..5V.#..F..{.i...Y.K1>.1Ay*1.#Y..0...g.....Z.X..#.....::.;.La./....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):451894
                  Entropy (8bit):7.999563050612889
                  Encrypted:true
                  SSDEEP:
                  MD5:49F40256D4C26EDD151D19280EF9B362
                  SHA1:251CDFA6D1FFCE231BD9F2C395700A40B3452F00
                  SHA-256:A2EDB9984323903752C68E302014B50399A4C66E3FFEC2C997B4A922D1072F17
                  SHA-512:62097DFCA38E2D20DB543C6F417F5705D0D272295FEDAB08A33CF360D823B3F270947C81B959652A6B27D59DC1F754502997A5591B20E21C43AFF977B34C50B4
                  Malicious:true
                  Preview:...._[z....Gh.G*....o ..K...Hz.5..4c..F.f.g\|..w.P.......Ump..{.Y.vt...).g]..Y....$.Q=j.h....c.G.....Dg9...E.$.R..._E8.G....X...S..]7K....0.....E.>..t.._j........~.k..%|d.5&NC.U.... ....V.....{k..HP..c..M.St...gj....tl.s..b...[./.t..F~..../p...J5..[ahv..CT.y.S.d...r..90.Oa..E.](.V..%..ss8..@.:kZ....z.{.kg:./_......k....<b...;...$...U.twi.x.Ii.h(M.d9...>...G......3..D...[rH9..::..u......D<Mp.z.*.U.*=i(.7...E...)..tT.LP..T...bn.v$...0!.)*343.2tz.OF..?.J]K..(....etH,..E:.\b.z.Uv? .....(.32X..wc......G.....-.<.O.6wi...vH.[C.F..i..|.n=..-`.6..*.9}.D.6.7.%..d.r.q.`km..U.M.!......'].6.z...z2.V...~.C._....+v9...{.Y..._.).....^Ml.......lC...>..\l...\..0Wx=.^(}@4.w..:ZB.;Zl@..)u(V.N.h.....<.1{..$.'.%0&.!>{..d..i.3$I.y.6..z..J.74....S.....@`.L.F..]8.O+..To..Ic.*..o.3.e5fW..."...)...L..._....Tk..d.dY.....Ke`.0.F.m.5.L'W..9..G..a.t~...:.@f0..[....:xd.}..........F.f..w.....{.SVv]..5V.#..F..{.i...Y.K1>.1Ay*1.#Y..0...g.....Z.X..#.....::.;.La./....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):769351
                  Entropy (8bit):7.999707099764754
                  Encrypted:true
                  SSDEEP:
                  MD5:952D0E717BE97A7C096D22DAD389B5F2
                  SHA1:7ABE747EA5BCF0523402E70E0B00475C300A5E3D
                  SHA-256:5BE558196EB8BA158343464210A43E965EB98F6D311F09FECCDCFD25EB431917
                  SHA-512:04EE75C68D676C64E8AADA32912AF70B86F6CBD278427E0729E219315F9205361C5A78D4EA708043F156A88DA60582741475EAEB1858452A6C291BD64D18BC1E
                  Malicious:true
                  Preview:X?.Xi.".}.V.J.c.fU..5B.^../*[...6...a.;M...y...elM<....T....w..3.W.u.'..o..[.pP....).b..09.{.....Rm....fn....p..z.*...k.~._..%..E...,..d.Q./._.z.4$R..\...........v.!j%.-..F..:5..)..3.%.^.....\....%P-....=.0.b...y..+..T.s.W..u.$...E..E.2]k...fv.....:.hj..3.5.......[b2......O.[.......^`.......D..Y?..H.mD.....S...8..)0..n.@....8...G'..3._.....X..[>.<..z})..\.%]..0.....!.QOJEZ.a..^....A0T...'.'.)w...n...u..b..?.].$..]..$.U....B.....O.:89).E...........&.,........b...........g..c.....|...8......U.u.1xs...o.?...).....aRsJ._.F7[..*.P..n.e..k>.....7.D.,M.K....D.#P.....rT..f..~WO5..T.9..h.#9.QCE...K.?.ZWK.-.j%..ng.[.k...MS&.;...[.....$.v,....k4....N...6.67.`..(..IB...s...X.i.N..c....BR....z.....R.s.z?F.Xu.w.E..r..[zq.n...1...v....c.Vp.U..'..S.. ..Q(._dyd.L.:9.O..6.v...e.._.h.g...Wi.I....C.RS'.....(S.....D'.G.....R.F.U..[.....2c....>.....o.V..~?.z....'..c.A..h..Qe.e..........@...........4..-.].V....n..t.........u..a........5....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):769351
                  Entropy (8bit):7.999707099764754
                  Encrypted:true
                  SSDEEP:
                  MD5:952D0E717BE97A7C096D22DAD389B5F2
                  SHA1:7ABE747EA5BCF0523402E70E0B00475C300A5E3D
                  SHA-256:5BE558196EB8BA158343464210A43E965EB98F6D311F09FECCDCFD25EB431917
                  SHA-512:04EE75C68D676C64E8AADA32912AF70B86F6CBD278427E0729E219315F9205361C5A78D4EA708043F156A88DA60582741475EAEB1858452A6C291BD64D18BC1E
                  Malicious:true
                  Preview:X?.Xi.".}.V.J.c.fU..5B.^../*[...6...a.;M...y...elM<....T....w..3.W.u.'..o..[.pP....).b..09.{.....Rm....fn....p..z.*...k.~._..%..E...,..d.Q./._.z.4$R..\...........v.!j%.-..F..:5..)..3.%.^.....\....%P-....=.0.b...y..+..T.s.W..u.$...E..E.2]k...fv.....:.hj..3.5.......[b2......O.[.......^`.......D..Y?..H.mD.....S...8..)0..n.@....8...G'..3._.....X..[>.<..z})..\.%]..0.....!.QOJEZ.a..^....A0T...'.'.)w...n...u..b..?.].$..]..$.U....B.....O.:89).E...........&.,........b...........g..c.....|...8......U.u.1xs...o.?...).....aRsJ._.F7[..*.P..n.e..k>.....7.D.,M.K....D.#P.....rT..f..~WO5..T.9..h.#9.QCE...K.?.ZWK.-.j%..ng.[.k...MS&.;...[.....$.v,....k4....N...6.67.`..(..IB...s...X.i.N..c....BR....z.....R.s.z?F.Xu.w.E..r..[zq.n...1...v....c.Vp.U..'..S.. ..Q(._dyd.L.:9.O..6.v...e.._.h.g...Wi.I....C.RS'.....(S.....D'.G.....R.F.U..[.....2c....>.....o.V..~?.z....'..c.A..h..Qe.e..........@...........4..-.].V....n..t.........u..a........5....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):769351
                  Entropy (8bit):7.999707099764754
                  Encrypted:true
                  SSDEEP:
                  MD5:952D0E717BE97A7C096D22DAD389B5F2
                  SHA1:7ABE747EA5BCF0523402E70E0B00475C300A5E3D
                  SHA-256:5BE558196EB8BA158343464210A43E965EB98F6D311F09FECCDCFD25EB431917
                  SHA-512:04EE75C68D676C64E8AADA32912AF70B86F6CBD278427E0729E219315F9205361C5A78D4EA708043F156A88DA60582741475EAEB1858452A6C291BD64D18BC1E
                  Malicious:true
                  Preview:X?.Xi.".}.V.J.c.fU..5B.^../*[...6...a.;M...y...elM<....T....w..3.W.u.'..o..[.pP....).b..09.{.....Rm....fn....p..z.*...k.~._..%..E...,..d.Q./._.z.4$R..\...........v.!j%.-..F..:5..)..3.%.^.....\....%P-....=.0.b...y..+..T.s.W..u.$...E..E.2]k...fv.....:.hj..3.5.......[b2......O.[.......^`.......D..Y?..H.mD.....S...8..)0..n.@....8...G'..3._.....X..[>.<..z})..\.%]..0.....!.QOJEZ.a..^....A0T...'.'.)w...n...u..b..?.].$..]..$.U....B.....O.:89).E...........&.,........b...........g..c.....|...8......U.u.1xs...o.?...).....aRsJ._.F7[..*.P..n.e..k>.....7.D.,M.K....D.#P.....rT..f..~WO5..T.9..h.#9.QCE...K.?.ZWK.-.j%..ng.[.k...MS&.;...[.....$.v,....k4....N...6.67.`..(..IB...s...X.i.N..c....BR....z.....R.s.z?F.Xu.w.E..r..[zq.n...1...v....c.Vp.U..'..S.. ..Q(._dyd.L.:9.O..6.v...e.._.h.g...Wi.I....C.RS'.....(S.....D'.G.....R.F.U..[.....2c....>.....o.V..~?.z....'..c.A..h..Qe.e..........@...........4..-.].V....n..t.........u..a........5....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671205
                  Entropy (8bit):7.999715663324959
                  Encrypted:true
                  SSDEEP:
                  MD5:C60DEE90540D2C68693E116C09DFC745
                  SHA1:F5C86B53FF4D6E563005BC0373810DB692C401C3
                  SHA-256:228B72808317DA7E332589EB3A80EBAE8970333B0BFEB09216FD3FB89980B2B8
                  SHA-512:161568CFA898EBCDABDF302898FA16CA10D9CE867A529C6E33993BDCE353AD85D59874295011E056CAA0A8632A16AAB3123A9BE0B4F86376A365BB4EEBD960C5
                  Malicious:true
                  Preview:.."%S.D.....C.G.>..2.C..p.K.].5.#...=0bc...O...C.J...ml.]..7>>..w0..)..Y...+....\....$-....&BA.E..|Z...a...W#...L.:.......j....g..o/.w..4N.)E.....N...%Bp`j....'F.........L0.A..}=.p...\1[.k3.`o{.#.%M.>."R...q.f...0.H......s"E.D0.p..s=...Ek.N='.....;...5z.w..U..wWQ.U..U.._.\..qG;...y...7\....Lv._.Ts:i..}5.k.5..S.Q.w..].3..9n<D.C....j.....?{}...0tM.#..&".9..*..I..Hq..9#D...L.h.XU.%..b..%u.bV.F.......a1(...M...4%.K....2..kg_a:B[h....":..+(.%(.V...k.Zq..Oc_.p.w"zX.f.r.../........$.m...<.....[7..o..H....9Hs$...nR]..........07...N..<8...<N....i.....c.8S}..].X......@:C...o....SbO...._.P+.n...d.pI.......;.:$ /.Q.."d.}..s.....i1$...#.y.[J.....b0..B..ba.da-e.Dra'.r.<..X..I...H..2K..7...L] ;.a.-.C:-..x).;#H.........p6.i...P.....qY..Qi..L%....W......0.C6.2..i.&..!|.o.v)..k.30j1...Z...&.......\Q.&UFl,q.no......r_....BP.uz...9?...Q.....{.h..}..._T@%.q.40..z$Y9Q...?..V.W.~.;s+.'.Y;H.,..%t..9..........L@.[..Y.?.,#..D.G..Q.I%!mH.4.R...f".n.NR....T..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671205
                  Entropy (8bit):7.999715663324959
                  Encrypted:true
                  SSDEEP:
                  MD5:C60DEE90540D2C68693E116C09DFC745
                  SHA1:F5C86B53FF4D6E563005BC0373810DB692C401C3
                  SHA-256:228B72808317DA7E332589EB3A80EBAE8970333B0BFEB09216FD3FB89980B2B8
                  SHA-512:161568CFA898EBCDABDF302898FA16CA10D9CE867A529C6E33993BDCE353AD85D59874295011E056CAA0A8632A16AAB3123A9BE0B4F86376A365BB4EEBD960C5
                  Malicious:true
                  Preview:.."%S.D.....C.G.>..2.C..p.K.].5.#...=0bc...O...C.J...ml.]..7>>..w0..)..Y...+....\....$-....&BA.E..|Z...a...W#...L.:.......j....g..o/.w..4N.)E.....N...%Bp`j....'F.........L0.A..}=.p...\1[.k3.`o{.#.%M.>."R...q.f...0.H......s"E.D0.p..s=...Ek.N='.....;...5z.w..U..wWQ.U..U.._.\..qG;...y...7\....Lv._.Ts:i..}5.k.5..S.Q.w..].3..9n<D.C....j.....?{}...0tM.#..&".9..*..I..Hq..9#D...L.h.XU.%..b..%u.bV.F.......a1(...M...4%.K....2..kg_a:B[h....":..+(.%(.V...k.Zq..Oc_.p.w"zX.f.r.../........$.m...<.....[7..o..H....9Hs$...nR]..........07...N..<8...<N....i.....c.8S}..].X......@:C...o....SbO...._.P+.n...d.pI.......;.:$ /.Q.."d.}..s.....i1$...#.y.[J.....b0..B..ba.da-e.Dra'.r.<..X..I...H..2K..7...L] ;.a.-.C:-..x).;#H.........p6.i...P.....qY..Qi..L%....W......0.C6.2..i.&..!|.o.v)..k.30j1...Z...&.......\Q.&UFl,q.no......r_....BP.uz...9?...Q.....{.h..}..._T@%.q.40..z$Y9Q...?..V.W.~.;s+.'.Y;H.,..%t..9..........L@.[..Y.?.,#..D.G..Q.I%!mH.4.R...f".n.NR....T..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):671205
                  Entropy (8bit):7.999715663324959
                  Encrypted:true
                  SSDEEP:
                  MD5:C60DEE90540D2C68693E116C09DFC745
                  SHA1:F5C86B53FF4D6E563005BC0373810DB692C401C3
                  SHA-256:228B72808317DA7E332589EB3A80EBAE8970333B0BFEB09216FD3FB89980B2B8
                  SHA-512:161568CFA898EBCDABDF302898FA16CA10D9CE867A529C6E33993BDCE353AD85D59874295011E056CAA0A8632A16AAB3123A9BE0B4F86376A365BB4EEBD960C5
                  Malicious:true
                  Preview:.."%S.D.....C.G.>..2.C..p.K.].5.#...=0bc...O...C.J...ml.]..7>>..w0..)..Y...+....\....$-....&BA.E..|Z...a...W#...L.:.......j....g..o/.w..4N.)E.....N...%Bp`j....'F.........L0.A..}=.p...\1[.k3.`o{.#.%M.>."R...q.f...0.H......s"E.D0.p..s=...Ek.N='.....;...5z.w..U..wWQ.U..U.._.\..qG;...y...7\....Lv._.Ts:i..}5.k.5..S.Q.w..].3..9n<D.C....j.....?{}...0tM.#..&".9..*..I..Hq..9#D...L.h.XU.%..b..%u.bV.F.......a1(...M...4%.K....2..kg_a:B[h....":..+(.%(.V...k.Zq..Oc_.p.w"zX.f.r.../........$.m...<.....[7..o..H....9Hs$...nR]..........07...N..<8...<N....i.....c.8S}..].X......@:C...o....SbO...._.P+.n...d.pI.......;.:$ /.Q.."d.}..s.....i1$...#.y.[J.....b0..B..ba.da-e.Dra'.r.<..X..I...H..2K..7...L] ;.a.-.C:-..x).;#H.........p6.i...P.....qY..Qi..L%....W......0.C6.2..i.&..!|.o.v)..k.30j1...Z...&.......\Q.&UFl,q.no......r_....BP.uz...9?...Q.....{.h..}..._T@%.q.40..z$Y9Q...?..V.W.~.;s+.'.Y;H.,..%t..9..........L@.[..Y.?.,#..D.G..Q.I%!mH.4.R...f".n.NR....T..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):534763
                  Entropy (8bit):7.999657909820659
                  Encrypted:true
                  SSDEEP:
                  MD5:608AE9AA3836639D3F704099528E48A3
                  SHA1:4BE66B0449A2F40228B50D18E79E4AB0A0F8AB92
                  SHA-256:7502B58179298CDB02C3E99FE1B59FF6F0D65696A8BDF14D18DBE305A444B5A0
                  SHA-512:50E5647A129832AB74869D54608D3455E7ED6CEC282DD7E08EFE15F0F3BC580B5A3AA56ECAE594031C7E612A4413A451BDD20BA2D4ED17F9BDE32B7B433A4CA0
                  Malicious:true
                  Preview:..l]...5......3'.o...~cW&....~...`6Z.....3(....na.?B]...V.3[.70.xF.p...=..5B.L.<....{.jQX^.....Ea..Ly....n.h..w.....~.x...2.....e...5...E+..]o..u....3.j.........e.$........}cjo.o.f..I....cI.h.]Q.j.:.2UG.....^iT.jGE../.W.d_%}j.z..+.....w....\..G.*.....N2.#..=.>...q..P[.K.HH..k...w`..:.............h.x}..W..$..F.i.t.V-\...(..=.8.E......Ed..........&.O...f......9..X@2.m..8t.\.....@[.i...P{.o.B...h&.W...N..`.......;.\.B..B..j........;.iF8.$*.{O....W..O.^h.8...H.%..I~....m..A.g.....OR..........b$..F.]!...Y_'.?F./]k...VP..."v.~. .l.8[.RBvt.....P...v..X...K.....~.$*y^..l.q-AIZ..YN.\(\....w..D..-...0........23..bn4.c..t..h...n...|..{o......^...A},.F..*.DGa.Y..)....)_^Y.<........S&(.^.@!.[.m...b..v.h..E......p.......<5j............_..]....y.O.#2i..^G.$...I$...4.!.qbk..O.........[..9z......9...q....O{..@.^r...O1.....j.X.....{..{.yU..lD./0...Z....u......+.......wl..k0t.?|......D......<s7K.O.<.....0jK57.bv........4.(ls..1<."..\g.;.$W....N..#.;`..S.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):534763
                  Entropy (8bit):7.999657909820659
                  Encrypted:true
                  SSDEEP:
                  MD5:608AE9AA3836639D3F704099528E48A3
                  SHA1:4BE66B0449A2F40228B50D18E79E4AB0A0F8AB92
                  SHA-256:7502B58179298CDB02C3E99FE1B59FF6F0D65696A8BDF14D18DBE305A444B5A0
                  SHA-512:50E5647A129832AB74869D54608D3455E7ED6CEC282DD7E08EFE15F0F3BC580B5A3AA56ECAE594031C7E612A4413A451BDD20BA2D4ED17F9BDE32B7B433A4CA0
                  Malicious:true
                  Preview:..l]...5......3'.o...~cW&....~...`6Z.....3(....na.?B]...V.3[.70.xF.p...=..5B.L.<....{.jQX^.....Ea..Ly....n.h..w.....~.x...2.....e...5...E+..]o..u....3.j.........e.$........}cjo.o.f..I....cI.h.]Q.j.:.2UG.....^iT.jGE../.W.d_%}j.z..+.....w....\..G.*.....N2.#..=.>...q..P[.K.HH..k...w`..:.............h.x}..W..$..F.i.t.V-\...(..=.8.E......Ed..........&.O...f......9..X@2.m..8t.\.....@[.i...P{.o.B...h&.W...N..`.......;.\.B..B..j........;.iF8.$*.{O....W..O.^h.8...H.%..I~....m..A.g.....OR..........b$..F.]!...Y_'.?F./]k...VP..."v.~. .l.8[.RBvt.....P...v..X...K.....~.$*y^..l.q-AIZ..YN.\(\....w..D..-...0........23..bn4.c..t..h...n...|..{o......^...A},.F..*.DGa.Y..)....)_^Y.<........S&(.^.@!.[.m...b..v.h..E......p.......<5j............_..]....y.O.#2i..^G.$...I$...4.!.qbk..O.........[..9z......9...q....O{..@.^r...O1.....j.X.....{..{.yU..lD./0...Z....u......+.......wl..k0t.?|......D......<s7K.O.<.....0jK57.bv........4.(ls..1<."..\g.;.$W....N..#.;`..S.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):534763
                  Entropy (8bit):7.999657909820659
                  Encrypted:true
                  SSDEEP:
                  MD5:608AE9AA3836639D3F704099528E48A3
                  SHA1:4BE66B0449A2F40228B50D18E79E4AB0A0F8AB92
                  SHA-256:7502B58179298CDB02C3E99FE1B59FF6F0D65696A8BDF14D18DBE305A444B5A0
                  SHA-512:50E5647A129832AB74869D54608D3455E7ED6CEC282DD7E08EFE15F0F3BC580B5A3AA56ECAE594031C7E612A4413A451BDD20BA2D4ED17F9BDE32B7B433A4CA0
                  Malicious:true
                  Preview:..l]...5......3'.o...~cW&....~...`6Z.....3(....na.?B]...V.3[.70.xF.p...=..5B.L.<....{.jQX^.....Ea..Ly....n.h..w.....~.x...2.....e...5...E+..]o..u....3.j.........e.$........}cjo.o.f..I....cI.h.]Q.j.:.2UG.....^iT.jGE../.W.d_%}j.z..+.....w....\..G.*.....N2.#..=.>...q..P[.K.HH..k...w`..:.............h.x}..W..$..F.i.t.V-\...(..=.8.E......Ed..........&.O...f......9..X@2.m..8t.\.....@[.i...P{.o.B...h&.W...N..`.......;.\.B..B..j........;.iF8.$*.{O....W..O.^h.8...H.%..I~....m..A.g.....OR..........b$..F.]!...Y_'.?F./]k...VP..."v.~. .l.8[.RBvt.....P...v..X...K.....~.$*y^..l.q-AIZ..YN.\(\....w..D..-...0........23..bn4.c..t..h...n...|..{o......^...A},.F..*.DGa.Y..)....)_^Y.<........S&(.^.@!.[.m...b..v.h..E......p.......<5j............_..]....y.O.#2i..^G.$...I$...4.!.qbk..O.........[..9z......9...q....O{..@.^r...O1.....j.X.....{..{.yU..lD./0...Z....u......+.......wl..k0t.?|......D......<s7K.O.<.....0jK57.bv........4.(ls..1<."..\g.;.$W....N..#.;`..S.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):387717
                  Entropy (8bit):7.999497132514266
                  Encrypted:true
                  SSDEEP:
                  MD5:08F0681CDC57B93415A4761DF5924648
                  SHA1:FB11CE30E5482B0E5841BA5BF4CBB0BD9A3A7A83
                  SHA-256:76CF949F16DD94919E2FD7152F6688BA135C2B0A775425A7809D5EFF7C0A8FC5
                  SHA-512:62E3752BD848994F0B8181E1BD8C1DA546AA215076ADB19BA2D5F2E8C662A4F35C8EC65DD0978B846A98B77C1702BDF3E45E4EF4B8695A3F51C3CB24A0140915
                  Malicious:true
                  Preview:lN.L..?......-3.3.....*"..=.A..Qj..R..b.h.GO....j..j......z........T.w,......3(zBK.P..0+...._..@.-...S...F.....y.E0..=...&.t....b}......D.9v8I.t....B..`......f..rnm....P..s....V.....-K. ...RK....0....N..:Rc......mM.T7b...LWc%....Jt_E.........u...+.u .m..O.-.Q..D.}am...6"....Ym..7.D..,..=t...A.y.:....y9.0.;.$..........T.b...k ..R......w.qF.a....C...}-4....'O.b....>....'eI#..aM...5W5g..k.x<.............K.H.i.`...{..._.\..1J.........D.R./..oyt.....P2MN.().)y._...C....#WF...&s..s..>..5.;.\..r.b.W.l.w.a..I......,.F.BP.3.}..n.z.......A.C<.0..yx.;.2...X.m.?...dC;*e........}.D...0.$...(txh...2.0N......96?S0...`p....P...T..\}......J.z..*....Q..V.y[...1X......].s.*.u.?.....G..o?e..<.../....g.v.!9..>`~[....Jms...h..Ii...ye.L.I.#h....>5Qr.i......-.e....m.l...i..QrOa...\..8.....r.`.E.,.+)~..(....\v...&.NG...%a.~}.."........<......;..M,09...2c.c......K...@*-; ....a0?[h.)_..R....N..>Y..2Q....\.6..!....%..~.\....u.d..."p..F..l..U...m_.c. .,.H..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):387717
                  Entropy (8bit):7.999497132514266
                  Encrypted:true
                  SSDEEP:
                  MD5:08F0681CDC57B93415A4761DF5924648
                  SHA1:FB11CE30E5482B0E5841BA5BF4CBB0BD9A3A7A83
                  SHA-256:76CF949F16DD94919E2FD7152F6688BA135C2B0A775425A7809D5EFF7C0A8FC5
                  SHA-512:62E3752BD848994F0B8181E1BD8C1DA546AA215076ADB19BA2D5F2E8C662A4F35C8EC65DD0978B846A98B77C1702BDF3E45E4EF4B8695A3F51C3CB24A0140915
                  Malicious:true
                  Preview:lN.L..?......-3.3.....*"..=.A..Qj..R..b.h.GO....j..j......z........T.w,......3(zBK.P..0+...._..@.-...S...F.....y.E0..=...&.t....b}......D.9v8I.t....B..`......f..rnm....P..s....V.....-K. ...RK....0....N..:Rc......mM.T7b...LWc%....Jt_E.........u...+.u .m..O.-.Q..D.}am...6"....Ym..7.D..,..=t...A.y.:....y9.0.;.$..........T.b...k ..R......w.qF.a....C...}-4....'O.b....>....'eI#..aM...5W5g..k.x<.............K.H.i.`...{..._.\..1J.........D.R./..oyt.....P2MN.().)y._...C....#WF...&s..s..>..5.;.\..r.b.W.l.w.a..I......,.F.BP.3.}..n.z.......A.C<.0..yx.;.2...X.m.?...dC;*e........}.D...0.$...(txh...2.0N......96?S0...`p....P...T..\}......J.z..*....Q..V.y[...1X......].s.*.u.?.....G..o?e..<.../....g.v.!9..>`~[....Jms...h..Ii...ye.L.I.#h....>5Qr.i......-.e....m.l...i..QrOa...\..8.....r.`.E.,.+)~..(....\v...&.NG...%a.~}.."........<......;..M,09...2c.c......K...@*-; ....a0?[h.)_..R....N..>Y..2Q....\.6..!....%..~.\....u.d..."p..F..l..U...m_.c. .,.H..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):387717
                  Entropy (8bit):7.999497132514266
                  Encrypted:true
                  SSDEEP:
                  MD5:08F0681CDC57B93415A4761DF5924648
                  SHA1:FB11CE30E5482B0E5841BA5BF4CBB0BD9A3A7A83
                  SHA-256:76CF949F16DD94919E2FD7152F6688BA135C2B0A775425A7809D5EFF7C0A8FC5
                  SHA-512:62E3752BD848994F0B8181E1BD8C1DA546AA215076ADB19BA2D5F2E8C662A4F35C8EC65DD0978B846A98B77C1702BDF3E45E4EF4B8695A3F51C3CB24A0140915
                  Malicious:true
                  Preview:lN.L..?......-3.3.....*"..=.A..Qj..R..b.h.GO....j..j......z........T.w,......3(zBK.P..0+...._..@.-...S...F.....y.E0..=...&.t....b}......D.9v8I.t....B..`......f..rnm....P..s....V.....-K. ...RK....0....N..:Rc......mM.T7b...LWc%....Jt_E.........u...+.u .m..O.-.Q..D.}am...6"....Ym..7.D..,..=t...A.y.:....y9.0.;.$..........T.b...k ..R......w.qF.a....C...}-4....'O.b....>....'eI#..aM...5W5g..k.x<.............K.H.i.`...{..._.\..1J.........D.R./..oyt.....P2MN.().)y._...C....#WF...&s..s..>..5.;.\..r.b.W.l.w.a..I......,.F.BP.3.}..n.z.......A.C<.0..yx.;.2...X.m.?...dC;*e........}.D...0.$...(txh...2.0N......96?S0...`p....P...T..\}......J.z..*....Q..V.y[...1X......].s.*.u.?.....G..o?e..<.../....g.v.!9..>`~[....Jms...h..Ii...ye.L.I.#h....>5Qr.i......-.e....m.l...i..QrOa...\..8.....r.`.E.,.+)~..(....\v...&.NG...%a.~}.."........<......;..M,09...2c.c......K...@*-; ....a0?[h.)_..R....N..>Y..2Q....\.6..!....%..~.\....u.d..."p..F..l..U...m_.c. .,.H..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):385002
                  Entropy (8bit):7.9994931338954185
                  Encrypted:true
                  SSDEEP:
                  MD5:E0CD7315B22D35F9111A7C24C7507F05
                  SHA1:9874DCBCE411DABFB4833AB2241D8DF910D77FE1
                  SHA-256:1CA6C90FA4B8A96C0CF437417624D0EA3B335ACA563B3DD0604C075AA20DE070
                  SHA-512:4C33C2F1E344C0072CC31258EC2D1FE10B8E7316CF2FA26A74531D16CD88954F6F8A2E0950E1E5A30EA03547DC1CB8D466C089B7B52A3324AE9837B585A77E1D
                  Malicious:true
                  Preview:,...Z4.1..oK..P.]I.5Z...d.*...j../O2..rt. ..z_..0K%...!.G.@J...s...;H.._..S..;...zg.}.....0..;...D...v....d1...xn..].'.{..)..V... ....U..O.fF.j..K...t.K.E.6I........3...v1ts..l.......0^...-..1&N.p...]...H..........d.D[.:.H.......l.p....]b..`SuXi....,..[V#.yJ...+.,-.....~q.pN...i.Fm<R.%.{.S.m.Cj.<(3&...........}........;Q..x....XX^F..h'aA.(>A...D...5.._....h.(.R.X..w.......]h...,...........xk.Xdj.....d....Z2.<.5......)l..:...;..7.l$~..c..{!.X..........s.....-.s..*.E.... u.?.....dT.L.+.0.5n.t.u..y.../z.x...x8...q...w.-Dee...^....X.p.I.I.%.]o..h@i..v.Ki....\....E0...j.....k..?.5U.o_y....-l...H..WV..........O#.tL...S...x.L.46.rg...t......!.._...V....6.Q0..6....U...........]q..S..i.6..r...<9..r.../..vR..K..'...q..w...6a.O.....L...2..g.&..XJ.fI.Ud....1.S.7.u.L..;)..G})[.......Z..,Z...S...w.....0..*..Y-wG.zi.y.op....R%.:i..Z!.~..J;n.|.#.p...>.5.....-..M..'.Y}..C=;....vF`V..8.z.e:.....m4..8.... ...*. n1...'.jJE. .....(..!:,T..I)..M.Yq.zX...Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):385002
                  Entropy (8bit):7.9994931338954185
                  Encrypted:true
                  SSDEEP:
                  MD5:E0CD7315B22D35F9111A7C24C7507F05
                  SHA1:9874DCBCE411DABFB4833AB2241D8DF910D77FE1
                  SHA-256:1CA6C90FA4B8A96C0CF437417624D0EA3B335ACA563B3DD0604C075AA20DE070
                  SHA-512:4C33C2F1E344C0072CC31258EC2D1FE10B8E7316CF2FA26A74531D16CD88954F6F8A2E0950E1E5A30EA03547DC1CB8D466C089B7B52A3324AE9837B585A77E1D
                  Malicious:true
                  Preview:,...Z4.1..oK..P.]I.5Z...d.*...j../O2..rt. ..z_..0K%...!.G.@J...s...;H.._..S..;...zg.}.....0..;...D...v....d1...xn..].'.{..)..V... ....U..O.fF.j..K...t.K.E.6I........3...v1ts..l.......0^...-..1&N.p...]...H..........d.D[.:.H.......l.p....]b..`SuXi....,..[V#.yJ...+.,-.....~q.pN...i.Fm<R.%.{.S.m.Cj.<(3&...........}........;Q..x....XX^F..h'aA.(>A...D...5.._....h.(.R.X..w.......]h...,...........xk.Xdj.....d....Z2.<.5......)l..:...;..7.l$~..c..{!.X..........s.....-.s..*.E.... u.?.....dT.L.+.0.5n.t.u..y.../z.x...x8...q...w.-Dee...^....X.p.I.I.%.]o..h@i..v.Ki....\....E0...j.....k..?.5U.o_y....-l...H..WV..........O#.tL...S...x.L.46.rg...t......!.._...V....6.Q0..6....U...........]q..S..i.6..r...<9..r.../..vR..K..'...q..w...6a.O.....L...2..g.&..XJ.fI.Ud....1.S.7.u.L..;)..G})[.......Z..,Z...S...w.....0..*..Y-wG.zi.y.op....R%.:i..Z!.~..J;n.|.#.p...>.5.....-..M..'.Y}..C=;....vF`V..8.z.e:.....m4..8.... ...*. n1...'.jJE. .....(..!:,T..I)..M.Yq.zX...Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):385002
                  Entropy (8bit):7.9994931338954185
                  Encrypted:true
                  SSDEEP:
                  MD5:E0CD7315B22D35F9111A7C24C7507F05
                  SHA1:9874DCBCE411DABFB4833AB2241D8DF910D77FE1
                  SHA-256:1CA6C90FA4B8A96C0CF437417624D0EA3B335ACA563B3DD0604C075AA20DE070
                  SHA-512:4C33C2F1E344C0072CC31258EC2D1FE10B8E7316CF2FA26A74531D16CD88954F6F8A2E0950E1E5A30EA03547DC1CB8D466C089B7B52A3324AE9837B585A77E1D
                  Malicious:true
                  Preview:,...Z4.1..oK..P.]I.5Z...d.*...j../O2..rt. ..z_..0K%...!.G.@J...s...;H.._..S..;...zg.}.....0..;...D...v....d1...xn..].'.{..)..V... ....U..O.fF.j..K...t.K.E.6I........3...v1ts..l.......0^...-..1&N.p...]...H..........d.D[.:.H.......l.p....]b..`SuXi....,..[V#.yJ...+.,-.....~q.pN...i.Fm<R.%.{.S.m.Cj.<(3&...........}........;Q..x....XX^F..h'aA.(>A...D...5.._....h.(.R.X..w.......]h...,...........xk.Xdj.....d....Z2.<.5......)l..:...;..7.l$~..c..{!.X..........s.....-.s..*.E.... u.?.....dT.L.+.0.5n.t.u..y.../z.x...x8...q...w.-Dee...^....X.p.I.I.%.]o..h@i..v.Ki....\....E0...j.....k..?.5U.o_y....-l...H..WV..........O#.tL...S...x.L.46.rg...t......!.._...V....6.Q0..6....U...........]q..S..i.6..r...<9..r.../..vR..K..'...q..w...6a.O.....L...2..g.&..XJ.fI.Ud....1.S.7.u.L..;)..G})[.......Z..,Z...S...w.....0..*..Y-wG.zi.y.op....R%.:i..Z!.~..J;n.|.#.p...>.5.....-..M..'.Y}..C=;....vF`V..8.z.e:.....m4..8.... ...*. n1...'.jJE. .....(..!:,T..I)..M.Yq.zX...Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):398
                  Entropy (8bit):7.272850424999479
                  Encrypted:false
                  SSDEEP:
                  MD5:476339D6C088D1FA7E85ABACA3257673
                  SHA1:1136E29457A9632F5B3548DDD397C3DCC34AF56B
                  SHA-256:2182E956F06DF4FC0165D3D9B9B3C26955A427E6833E45C87E855DA5581947B5
                  SHA-512:D916D55AE8DC7A379F5C76CD51F8B652F5BC8816540C488FABD224C5C8C8FE25F699036B202190ACC3CCB0B79000A7C262BF33CD4BBAECC497DEA47A031BE410
                  Malicious:false
                  Preview:.O....s.....xV....L.S0..h."eL.1.i....io.G.*.%.`......<A....l.HU<...q...+n...4..(...t.e......z..\PH.e...Ki.q.?.....6.&..k..,....g@@~..w....w..j.5Z.]..<e.....X..\).Y..I.D..}F..K.].%d`.$.W..UL.`...v..r2+.@}..Q..T.b.....*.]......b...H6.&.M....W....D...k.S..|...9...-a.aD...r+C.b.<..xd......wQ.._.W&...........NdT..[....5?.?..'l_..a.<..J^.E......WQe~..=.#..=.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):398
                  Entropy (8bit):7.272850424999479
                  Encrypted:false
                  SSDEEP:
                  MD5:476339D6C088D1FA7E85ABACA3257673
                  SHA1:1136E29457A9632F5B3548DDD397C3DCC34AF56B
                  SHA-256:2182E956F06DF4FC0165D3D9B9B3C26955A427E6833E45C87E855DA5581947B5
                  SHA-512:D916D55AE8DC7A379F5C76CD51F8B652F5BC8816540C488FABD224C5C8C8FE25F699036B202190ACC3CCB0B79000A7C262BF33CD4BBAECC497DEA47A031BE410
                  Malicious:false
                  Preview:.O....s.....xV....L.S0..h."eL.1.i....io.G.*.%.`......<A....l.HU<...q...+n...4..(...t.e......z..\PH.e...Ki.q.?.....6.&..k..,....g@@~..w....w..j.5Z.]..<e.....X..\).Y..I.D..}F..K.].%d`.$.W..UL.`...v..r2+.@}..Q..T.b.....*.]......b...H6.&.M....W....D...k.S..|...9...-a.aD...r+C.b.<..xd......wQ.._.W&...........NdT..[....5?.?..'l_..a.<..J^.E......WQe~..=.#..=.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):398
                  Entropy (8bit):7.272850424999479
                  Encrypted:false
                  SSDEEP:
                  MD5:476339D6C088D1FA7E85ABACA3257673
                  SHA1:1136E29457A9632F5B3548DDD397C3DCC34AF56B
                  SHA-256:2182E956F06DF4FC0165D3D9B9B3C26955A427E6833E45C87E855DA5581947B5
                  SHA-512:D916D55AE8DC7A379F5C76CD51F8B652F5BC8816540C488FABD224C5C8C8FE25F699036B202190ACC3CCB0B79000A7C262BF33CD4BBAECC497DEA47A031BE410
                  Malicious:false
                  Preview:.O....s.....xV....L.S0..h."eL.1.i....io.G.*.%.`......<A....l.HU<...q...+n...4..(...t.e......z..\PH.e...Ki.q.?.....6.&..k..,....g@@~..w....w..j.5Z.]..<e.....X..\).Y..I.D..}F..K.].%d`.$.W..UL.`...v..r2+.@}..Q..T.b.....*.]......b...H6.&.M....W....D...k.S..|...9...-a.aD...r+C.b.<..xd......wQ.._.W&...........NdT..[....5?.?..'l_..a.<..J^.E......WQe~..=.#..=.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8414
                  Entropy (8bit):7.975807435829323
                  Encrypted:false
                  SSDEEP:
                  MD5:13F487CF669032E913FA10EACD6C4047
                  SHA1:198D518B702C117798B9A28E38BAD4755C4FA42A
                  SHA-256:9EBEBB950B5E1B0E0D2FA3E3BA311081A489C92ADC13C59F3F3A1DED70769A01
                  SHA-512:B5041EE2AA2D413EECBE91D5EA12C978C41B054D3FC1B433AC1DAB6428060B76821A6F19B0AF4AB45E752F758724930660F25FA00316BB02F344604EF214D5F7
                  Malicious:false
                  Preview:.O..A.K.u.r..."N...VkR...O.....X-.y%O......w.Li..Or.>i*J...di..N^.S......i..i..N..Se6/.z...A_..l.K^...vv.~t0.,.T...u.j.*."x......@.J..G.!..o......Y.L.....,nGH.....<......Y.O?..A.h\.u.M.IK..\-.[O.d..fA9...8k.U..>..D....t..C1oY%.ke......A.......aI....;I.../../.K(..M....q>.o.1.K.i.........\....5.JSx^l._.F..Cv..p....B.|3z...2.).m.m.gNIy.......e...Pp.b...........]ykYD......!.\.R.B..:FFjyG=..fd..q...PyK..j..Ot.&....>.\i.+..g......I.h...2.....3...I.N.......j..H.{...7....*!.J...#....O.UR...1...v.$1......_....$Zk.;Y..g3..F.y.6..x,.E.!e.....d....`...Gm..."...N..$.;.O|.L.7g.c.s.!.......2]N..C%QP.Np......X.`~8..i..).F./.Z.R..o.p0..L!p4.............*-.0y.u..NN.X...N`*....=(.!f...../[.eAE7.....0..HY{k...+d..?...|Q.M[..L.2N.B....Hf*3.E.o...w|W.{.N..{.......J o'..........w[.>ro...U....0..I.......`..m...._J....2.44&....:%.kW;Fz..;~6...}{.:..B.....4C}%.Fy..F.M..8.o...Kn........V.^...!.W.5...+...(.F.....,#...iI/.-.i..Z..q..+..c...~...T.O.0$..[.P...$J..N
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8414
                  Entropy (8bit):7.975807435829323
                  Encrypted:false
                  SSDEEP:
                  MD5:13F487CF669032E913FA10EACD6C4047
                  SHA1:198D518B702C117798B9A28E38BAD4755C4FA42A
                  SHA-256:9EBEBB950B5E1B0E0D2FA3E3BA311081A489C92ADC13C59F3F3A1DED70769A01
                  SHA-512:B5041EE2AA2D413EECBE91D5EA12C978C41B054D3FC1B433AC1DAB6428060B76821A6F19B0AF4AB45E752F758724930660F25FA00316BB02F344604EF214D5F7
                  Malicious:false
                  Preview:.O..A.K.u.r..."N...VkR...O.....X-.y%O......w.Li..Or.>i*J...di..N^.S......i..i..N..Se6/.z...A_..l.K^...vv.~t0.,.T...u.j.*."x......@.J..G.!..o......Y.L.....,nGH.....<......Y.O?..A.h\.u.M.IK..\-.[O.d..fA9...8k.U..>..D....t..C1oY%.ke......A.......aI....;I.../../.K(..M....q>.o.1.K.i.........\....5.JSx^l._.F..Cv..p....B.|3z...2.).m.m.gNIy.......e...Pp.b...........]ykYD......!.\.R.B..:FFjyG=..fd..q...PyK..j..Ot.&....>.\i.+..g......I.h...2.....3...I.N.......j..H.{...7....*!.J...#....O.UR...1...v.$1......_....$Zk.;Y..g3..F.y.6..x,.E.!e.....d....`...Gm..."...N..$.;.O|.L.7g.c.s.!.......2]N..C%QP.Np......X.`~8..i..).F./.Z.R..o.p0..L!p4.............*-.0y.u..NN.X...N`*....=(.!f...../[.eAE7.....0..HY{k...+d..?...|Q.M[..L.2N.B....Hf*3.E.o...w|W.{.N..{.......J o'..........w[.>ro...U....0..I.......`..m...._J....2.44&....:%.kW;Fz..;~6...}{.:..B.....4C}%.Fy..F.M..8.o...Kn........V.^...!.W.5...+...(.F.....,#...iI/.-.i..Z..q..+..c...~...T.O.0$..[.P...$J..N
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8414
                  Entropy (8bit):7.975807435829323
                  Encrypted:false
                  SSDEEP:
                  MD5:13F487CF669032E913FA10EACD6C4047
                  SHA1:198D518B702C117798B9A28E38BAD4755C4FA42A
                  SHA-256:9EBEBB950B5E1B0E0D2FA3E3BA311081A489C92ADC13C59F3F3A1DED70769A01
                  SHA-512:B5041EE2AA2D413EECBE91D5EA12C978C41B054D3FC1B433AC1DAB6428060B76821A6F19B0AF4AB45E752F758724930660F25FA00316BB02F344604EF214D5F7
                  Malicious:false
                  Preview:.O..A.K.u.r..."N...VkR...O.....X-.y%O......w.Li..Or.>i*J...di..N^.S......i..i..N..Se6/.z...A_..l.K^...vv.~t0.,.T...u.j.*."x......@.J..G.!..o......Y.L.....,nGH.....<......Y.O?..A.h\.u.M.IK..\-.[O.d..fA9...8k.U..>..D....t..C1oY%.ke......A.......aI....;I.../../.K(..M....q>.o.1.K.i.........\....5.JSx^l._.F..Cv..p....B.|3z...2.).m.m.gNIy.......e...Pp.b...........]ykYD......!.\.R.B..:FFjyG=..fd..q...PyK..j..Ot.&....>.\i.+..g......I.h...2.....3...I.N.......j..H.{...7....*!.J...#....O.UR...1...v.$1......_....$Zk.;Y..g3..F.y.6..x,.E.!e.....d....`...Gm..."...N..$.;.O|.L.7g.c.s.!.......2]N..C%QP.Np......X.`~8..i..).F./.Z.R..o.p0..L!p4.............*-.0y.u..NN.X...N`*....=(.!f...../[.eAE7.....0..HY{k...+d..?...|Q.M[..L.2N.B....Hf*3.E.o...w|W.{.N..{.......J o'..........w[.>ro...U....0..I.......`..m...._J....2.44&....:%.kW;Fz..;~6...}{.:..B.....4C}%.Fy..F.M..8.o...Kn........V.^...!.W.5...+...(.F.....,#...iI/.-.i..Z..q..+..c...~...T.O.0$..[.P...$J..N
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28291
                  Entropy (8bit):7.993549537003803
                  Encrypted:true
                  SSDEEP:
                  MD5:654ECC7763528477538E5605638F3192
                  SHA1:93FD1C20578E56AFC5F192B4797E5EE00767EF21
                  SHA-256:40C34C3127A053C72D7FD4BD2F95EBC3A24487635FEF0399DF4D0CF2A4554764
                  SHA-512:B03FB88DDB14C8CA7A75D31D2A84CC8C27A6DA476DC06805EDA76A8DAED5FEF6D1153B9DC9FF8CCA7BEB4BBA7AEB3E82785E2E5F921BF42B7FC36973E482DF12
                  Malicious:true
                  Preview:........*..bn8..+..p.fXe...?./2k...B.r...,....I.Aq24..<.t.%..c..~d..O4..7'w?O..([..6......Q.N`5...[...Gs.6U`..;..R.......5.]6..f...&.eDD.w....)q.!;....16z...Y-a...".q....(...!3.,.V1:...!N...+...i....../vdy.)....a....L<..,zR.A.....x%...[.0.........P.m.!..5.....+H..`X./...C...Yg..r.."=hn8...:.8..1V*.*i..a.5.3.SJ..*....>e]......*PGaKs.?io....|...h..u..\.C.......K..1....M....m....`.o....>..:..T.......g.p..N..b..0...*|X(Ic...@...D......b....4..X.E......S....<....K....peC....v.M....3P(B..xS...)....3...t..S.k..>W.:^...,.zi..............T:..J.$...g....P.Vj..5..#.!.\.&.."u...s.#....Mo.0....(y...pqe_.f.)....-...N.....s.l }..?..H>e.(t.lJ[<.1."E...:.t.....X........./..wt.37fQ.....)..]-K.."$.jD......|.Z.....m....o#...H..........;G..)(..l.2r......k..L......*....33t...Y1...B.UE...q...n%....'.s.:...`...v@.F.2......5....z.....V .....o_..+....5...j....S.)...J.D%a.I.n.2...,)...B.&.2..L.............`..B.aO...u.U3dj(P..;KT...I.Ya.=K.#t.D}.....8..Q.lwb..c.n.P!.2.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28291
                  Entropy (8bit):7.993549537003803
                  Encrypted:true
                  SSDEEP:
                  MD5:654ECC7763528477538E5605638F3192
                  SHA1:93FD1C20578E56AFC5F192B4797E5EE00767EF21
                  SHA-256:40C34C3127A053C72D7FD4BD2F95EBC3A24487635FEF0399DF4D0CF2A4554764
                  SHA-512:B03FB88DDB14C8CA7A75D31D2A84CC8C27A6DA476DC06805EDA76A8DAED5FEF6D1153B9DC9FF8CCA7BEB4BBA7AEB3E82785E2E5F921BF42B7FC36973E482DF12
                  Malicious:true
                  Preview:........*..bn8..+..p.fXe...?./2k...B.r...,....I.Aq24..<.t.%..c..~d..O4..7'w?O..([..6......Q.N`5...[...Gs.6U`..;..R.......5.]6..f...&.eDD.w....)q.!;....16z...Y-a...".q....(...!3.,.V1:...!N...+...i....../vdy.)....a....L<..,zR.A.....x%...[.0.........P.m.!..5.....+H..`X./...C...Yg..r.."=hn8...:.8..1V*.*i..a.5.3.SJ..*....>e]......*PGaKs.?io....|...h..u..\.C.......K..1....M....m....`.o....>..:..T.......g.p..N..b..0...*|X(Ic...@...D......b....4..X.E......S....<....K....peC....v.M....3P(B..xS...)....3...t..S.k..>W.:^...,.zi..............T:..J.$...g....P.Vj..5..#.!.\.&.."u...s.#....Mo.0....(y...pqe_.f.)....-...N.....s.l }..?..H>e.(t.lJ[<.1."E...:.t.....X........./..wt.37fQ.....)..]-K.."$.jD......|.Z.....m....o#...H..........;G..)(..l.2r......k..L......*....33t...Y1...B.UE...q...n%....'.s.:...`...v@.F.2......5....z.....V .....o_..+....5...j....S.)...J.D%a.I.n.2...,)...B.&.2..L.............`..B.aO...u.U3dj(P..;KT...I.Ya.=K.#t.D}.....8..Q.lwb..c.n.P!.2.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28291
                  Entropy (8bit):7.993549537003803
                  Encrypted:true
                  SSDEEP:
                  MD5:654ECC7763528477538E5605638F3192
                  SHA1:93FD1C20578E56AFC5F192B4797E5EE00767EF21
                  SHA-256:40C34C3127A053C72D7FD4BD2F95EBC3A24487635FEF0399DF4D0CF2A4554764
                  SHA-512:B03FB88DDB14C8CA7A75D31D2A84CC8C27A6DA476DC06805EDA76A8DAED5FEF6D1153B9DC9FF8CCA7BEB4BBA7AEB3E82785E2E5F921BF42B7FC36973E482DF12
                  Malicious:true
                  Preview:........*..bn8..+..p.fXe...?./2k...B.r...,....I.Aq24..<.t.%..c..~d..O4..7'w?O..([..6......Q.N`5...[...Gs.6U`..;..R.......5.]6..f...&.eDD.w....)q.!;....16z...Y-a...".q....(...!3.,.V1:...!N...+...i....../vdy.)....a....L<..,zR.A.....x%...[.0.........P.m.!..5.....+H..`X./...C...Yg..r.."=hn8...:.8..1V*.*i..a.5.3.SJ..*....>e]......*PGaKs.?io....|...h..u..\.C.......K..1....M....m....`.o....>..:..T.......g.p..N..b..0...*|X(Ic...@...D......b....4..X.E......S....<....K....peC....v.M....3P(B..xS...)....3...t..S.k..>W.:^...,.zi..............T:..J.$...g....P.Vj..5..#.!.\.&.."u...s.#....Mo.0....(y...pqe_.f.)....-...N.....s.l }..?..H>e.(t.lJ[<.1."E...:.t.....X........./..wt.37fQ.....)..]-K.."$.jD......|.Z.....m....o#...H..........;G..)(..l.2r......k..L......*....33t...Y1...B.UE...q...n%....'.s.:...`...v@.F.2......5....z.....V .....o_..+....5...j....S.)...J.D%a.I.n.2...,)...B.&.2..L.............`..B.aO...u.U3dj(P..;KT...I.Ya.=K.#t.D}.....8..Q.lwb..c.n.P!.2.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24374
                  Entropy (8bit):7.992627138909403
                  Encrypted:true
                  SSDEEP:
                  MD5:F31AFC9569AF1EF55E95D1A5BC07E074
                  SHA1:CE674A2E9EDF097CB993F74979775E9FD5E9BA36
                  SHA-256:54EAFFA64542E68481CD800A4EDFB11213B3F9B91EF1F920B53A6C4BFF93973D
                  SHA-512:A18961D9570E9383EE2E63932672611A1553A08A89D194E83A2E1B9D38A64657CE0053C7C8103A6976D15E06F16B4B2271E357C9650CE04FDF300E7C93FA2DF4
                  Malicious:true
                  Preview:..u..YP..6.G....]....B........B$.^.zm.!t-..`.......Q[X?&..XV'......VQ......m&.<....V=:i)SFK.{4{...|..$..v..).]))..N{..#..r....C....ll..m...Ae..&W#Y.....W....O.PH..!..@X....M..n..0V~..j....jW..Y...H...0..3/.G.....:Q{?.0.:t.)u.j.....";,E.v.'.^.4.Z>^o.Aq..?0.J.N5._)..n._zE!.o..]GEnM.2:...yYf*........m5.......r.x).Q..#.......t..|...h......?.B...vB.../.j>.+.XF..... .H'.ZYy..2'u..U.PZ...>.@|..I|.......JN/eK....]..jK.l..sQ;.....m#..Nv."7....sE...l.ky....)z.r.d.\.-..B.G.m....@...p....t....3j>..tN.5N..z..=c.e..a.X.......3...iC...v.87...N.$.Z.q:Ke..c=MM.)9I'&...W...w..\)..5O..$V..o....@-'Q{....f.7...In...V..f...A..E.O....Kk......c...}/.._...S`d..7g.V.;.S!.w.........*j..o..;.}.S.e.h..Z...G.:.A...........y...'D9.K.....q......T.|.....9OEq.F....zkQe....9~?..8. .....FHJ...GI.]......Z6...gT......./.A.....P}."...X.Q..o...6.,...l0......Q7U.O......!...YV......tw.Y+FD-bJ..K~......&...o.h.Bt.e...Ri...W=..u..lk..=.x7...g...hW....c...m.3...^.......Pu...q.:M
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24374
                  Entropy (8bit):7.992627138909403
                  Encrypted:true
                  SSDEEP:
                  MD5:F31AFC9569AF1EF55E95D1A5BC07E074
                  SHA1:CE674A2E9EDF097CB993F74979775E9FD5E9BA36
                  SHA-256:54EAFFA64542E68481CD800A4EDFB11213B3F9B91EF1F920B53A6C4BFF93973D
                  SHA-512:A18961D9570E9383EE2E63932672611A1553A08A89D194E83A2E1B9D38A64657CE0053C7C8103A6976D15E06F16B4B2271E357C9650CE04FDF300E7C93FA2DF4
                  Malicious:true
                  Preview:..u..YP..6.G....]....B........B$.^.zm.!t-..`.......Q[X?&..XV'......VQ......m&.<....V=:i)SFK.{4{...|..$..v..).]))..N{..#..r....C....ll..m...Ae..&W#Y.....W....O.PH..!..@X....M..n..0V~..j....jW..Y...H...0..3/.G.....:Q{?.0.:t.)u.j.....";,E.v.'.^.4.Z>^o.Aq..?0.J.N5._)..n._zE!.o..]GEnM.2:...yYf*........m5.......r.x).Q..#.......t..|...h......?.B...vB.../.j>.+.XF..... .H'.ZYy..2'u..U.PZ...>.@|..I|.......JN/eK....]..jK.l..sQ;.....m#..Nv."7....sE...l.ky....)z.r.d.\.-..B.G.m....@...p....t....3j>..tN.5N..z..=c.e..a.X.......3...iC...v.87...N.$.Z.q:Ke..c=MM.)9I'&...W...w..\)..5O..$V..o....@-'Q{....f.7...In...V..f...A..E.O....Kk......c...}/.._...S`d..7g.V.;.S!.w.........*j..o..;.}.S.e.h..Z...G.:.A...........y...'D9.K.....q......T.|.....9OEq.F....zkQe....9~?..8. .....FHJ...GI.]......Z6...gT......./.A.....P}."...X.Q..o...6.,...l0......Q7U.O......!...YV......tw.Y+FD-bJ..K~......&...o.h.Bt.e...Ri...W=..u..lk..=.x7...g...hW....c...m.3...^.......Pu...q.:M
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24374
                  Entropy (8bit):7.992627138909403
                  Encrypted:true
                  SSDEEP:
                  MD5:F31AFC9569AF1EF55E95D1A5BC07E074
                  SHA1:CE674A2E9EDF097CB993F74979775E9FD5E9BA36
                  SHA-256:54EAFFA64542E68481CD800A4EDFB11213B3F9B91EF1F920B53A6C4BFF93973D
                  SHA-512:A18961D9570E9383EE2E63932672611A1553A08A89D194E83A2E1B9D38A64657CE0053C7C8103A6976D15E06F16B4B2271E357C9650CE04FDF300E7C93FA2DF4
                  Malicious:true
                  Preview:..u..YP..6.G....]....B........B$.^.zm.!t-..`.......Q[X?&..XV'......VQ......m&.<....V=:i)SFK.{4{...|..$..v..).]))..N{..#..r....C....ll..m...Ae..&W#Y.....W....O.PH..!..@X....M..n..0V~..j....jW..Y...H...0..3/.G.....:Q{?.0.:t.)u.j.....";,E.v.'.^.4.Z>^o.Aq..?0.J.N5._)..n._zE!.o..]GEnM.2:...yYf*........m5.......r.x).Q..#.......t..|...h......?.B...vB.../.j>.+.XF..... .H'.ZYy..2'u..U.PZ...>.@|..I|.......JN/eK....]..jK.l..sQ;.....m#..Nv."7....sE...l.ky....)z.r.d.\.-..B.G.m....@...p....t....3j>..tN.5N..z..=c.e..a.X.......3...iC...v.87...N.$.Z.q:Ke..c=MM.)9I'&...W...w..\)..5O..$V..o....@-'Q{....f.7...In...V..f...A..E.O....Kk......c...}/.._...S`d..7g.V.;.S!.w.........*j..o..;.}.S.e.h..Z...G.:.A...........y...'D9.K.....q......T.|.....9OEq.F....zkQe....9~?..8. .....FHJ...GI.]......Z6...gT......./.A.....P}."...X.Q..o...6.,...l0......Q7U.O......!...YV......tw.Y+FD-bJ..K~......&...o.h.Bt.e...Ri...W=..u..lk..=.x7...g...hW....c...m.3...^.......Pu...q.:M
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28176
                  Entropy (8bit):7.993554817587167
                  Encrypted:true
                  SSDEEP:
                  MD5:BD6A4CD53356411B0B53ACB940BAD3DD
                  SHA1:494CE511155F7527EC279C856DB5BEE3E52A9FE0
                  SHA-256:FBCAFA4E703214D47A9B97492AF49E0042A018D1172A640EBB56C2A30CFB1881
                  SHA-512:2332227B50301CF652451022CAB186D04512E81CE1E0A7D90DD326A379B284950BB63A27E244359F62FAF31CAE6A9B3BF0F05C1B78DDA578334A22B0CD884406
                  Malicious:true
                  Preview:.:&.[....$.c.A8.{3E1S..7)V..<..[..!.'....2..^.CD.1..{n\.....%........V....T.([.h...).O%.`,..s{~.E.si2(.L.G...&..?..].\.. >...l..Y.:is...p<.*...^!&\....m...5A.?.L..C..."x.!=..2W..>.sG.+..;..<......S.;....6S.?....^.y.3.d....v...^.......G.cS.(.E...(.K._.(..Af.W....p..j..........G.6.....B.2...K..Y..5a.%...%.._.c..T.C.iwl.][....4%I....'.^,|^...}..h .ej2gn.zZ`?.*.)Rs.yO?]..> .......>`..j..P[LN....U.]O....`.X......7...6.k.s{.}.a..).d..Z.?.5.....Q.&.=@I5..V..>y...S..9..a?.......d.g'q...~._.M#.....lAM...u !.^.D...U}../t..].*..[.pE.....j.i........%....._.....`.oD..^r.s..Om.."..h..:F.N..ia+..K.gGq...W.-<....z.o8.Zu%Y`a...:..2i..!a....vb.)P.d].*TH...6.G/}....H.p..q.k.D;..|....W...t@......<_.-........U[..Q.R...?>.x...s...<F...[>..Dm.!...3@).._..............9.0g.d.P+j!O..,..h..}.u.E..%.O.m...>.GN...Ls.t.o9Y.#e.8I.....j.I.G.z..=...DAQ.*>Z.'....=^-....?ws... ..K?R..=...y...w[a...~....0.M!.~;..=..5$OR.r..B$....D..lv.#....w...[cc49..r.,=.C.n.@..}Y....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28176
                  Entropy (8bit):7.993554817587167
                  Encrypted:true
                  SSDEEP:
                  MD5:BD6A4CD53356411B0B53ACB940BAD3DD
                  SHA1:494CE511155F7527EC279C856DB5BEE3E52A9FE0
                  SHA-256:FBCAFA4E703214D47A9B97492AF49E0042A018D1172A640EBB56C2A30CFB1881
                  SHA-512:2332227B50301CF652451022CAB186D04512E81CE1E0A7D90DD326A379B284950BB63A27E244359F62FAF31CAE6A9B3BF0F05C1B78DDA578334A22B0CD884406
                  Malicious:true
                  Preview:.:&.[....$.c.A8.{3E1S..7)V..<..[..!.'....2..^.CD.1..{n\.....%........V....T.([.h...).O%.`,..s{~.E.si2(.L.G...&..?..].\.. >...l..Y.:is...p<.*...^!&\....m...5A.?.L..C..."x.!=..2W..>.sG.+..;..<......S.;....6S.?....^.y.3.d....v...^.......G.cS.(.E...(.K._.(..Af.W....p..j..........G.6.....B.2...K..Y..5a.%...%.._.c..T.C.iwl.][....4%I....'.^,|^...}..h .ej2gn.zZ`?.*.)Rs.yO?]..> .......>`..j..P[LN....U.]O....`.X......7...6.k.s{.}.a..).d..Z.?.5.....Q.&.=@I5..V..>y...S..9..a?.......d.g'q...~._.M#.....lAM...u !.^.D...U}../t..].*..[.pE.....j.i........%....._.....`.oD..^r.s..Om.."..h..:F.N..ia+..K.gGq...W.-<....z.o8.Zu%Y`a...:..2i..!a....vb.)P.d].*TH...6.G/}....H.p..q.k.D;..|....W...t@......<_.-........U[..Q.R...?>.x...s...<F...[>..Dm.!...3@).._..............9.0g.d.P+j!O..,..h..}.u.E..%.O.m...>.GN...Ls.t.o9Y.#e.8I.....j.I.G.z..=...DAQ.*>Z.'....=^-....?ws... ..K?R..=...y...w[a...~....0.M!.~;..=..5$OR.r..B$....D..lv.#....w...[cc49..r.,=.C.n.@..}Y....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):28176
                  Entropy (8bit):7.993554817587167
                  Encrypted:true
                  SSDEEP:
                  MD5:BD6A4CD53356411B0B53ACB940BAD3DD
                  SHA1:494CE511155F7527EC279C856DB5BEE3E52A9FE0
                  SHA-256:FBCAFA4E703214D47A9B97492AF49E0042A018D1172A640EBB56C2A30CFB1881
                  SHA-512:2332227B50301CF652451022CAB186D04512E81CE1E0A7D90DD326A379B284950BB63A27E244359F62FAF31CAE6A9B3BF0F05C1B78DDA578334A22B0CD884406
                  Malicious:true
                  Preview:.:&.[....$.c.A8.{3E1S..7)V..<..[..!.'....2..^.CD.1..{n\.....%........V....T.([.h...).O%.`,..s{~.E.si2(.L.G...&..?..].\.. >...l..Y.:is...p<.*...^!&\....m...5A.?.L..C..."x.!=..2W..>.sG.+..;..<......S.;....6S.?....^.y.3.d....v...^.......G.cS.(.E...(.K._.(..Af.W....p..j..........G.6.....B.2...K..Y..5a.%...%.._.c..T.C.iwl.][....4%I....'.^,|^...}..h .ej2gn.zZ`?.*.)Rs.yO?]..> .......>`..j..P[LN....U.]O....`.X......7...6.k.s{.}.a..).d..Z.?.5.....Q.&.=@I5..V..>y...S..9..a?.......d.g'q...~._.M#.....lAM...u !.^.D...U}../t..].*..[.pE.....j.i........%....._.....`.oD..^r.s..Om.."..h..:F.N..ia+..K.gGq...W.-<....z.o8.Zu%Y`a...:..2i..!a....vb.)P.d].*TH...6.G/}....H.p..q.k.D;..|....W...t@......<_.-........U[..Q.R...?>.x...s...<F...[>..Dm.!...3@).._..............9.0g.d.P+j!O..,..h..}.u.E..%.O.m...>.GN...Ls.t.o9Y.#e.8I.....j.I.G.z..=...DAQ.*>Z.'....=^-....?ws... ..K?R..=...y...w[a...~....0.M!.~;..=..5$OR.r..B$....D..lv.#....w...[cc49..r.,=.C.n.@..}Y....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24664
                  Entropy (8bit):7.992421962140185
                  Encrypted:true
                  SSDEEP:
                  MD5:62B915D969BFA57ABF3DFDDF76172690
                  SHA1:9556DC5288DE8DAAF6BFF65906CC7E1A95EA2649
                  SHA-256:206674D30111F0824355C28569B475A17584242685A24E6E49B4DE27ADA1E51F
                  SHA-512:FC1B510850A04F8F05685937973E89CDB48CA9B31DC792BC4C993F1772AE05B77827A52DF0F3C43607B5AA43941668F2DF63EC80AA1A8F5ECF3EE6527344B1CC
                  Malicious:true
                  Preview:.n{y..7...>....?....<T..(O....4/.....WYeH.."S...y.9K..^...q0Y_..3..TI..K."u...A..D.d..e.(.W.@/..S.#8a.Z.3a..#f....M.4.8=.....)nS.{.}.u..e.....Pz....R0-..@.wl...Y...a.L&...9?.......E....x..:..U..TO.....-%..s.txu.[g.x........S....w...L.(.A...N.^S:\.>..3....L.8...t...9.y.`.}.O.......i.F..w.~.X..5.eo^..]...y..w.7.Q...r[zQ.^...Kj~..r.N'.V.S..J.~..o.H.$..Q........)..1..3.o..../..(..[3DCi7u....f>......y..Xg.].o%.g.v*..I6..V.'wrgSYg.M:w.CiB...{.=!d.u.....z...J..@..r..R1.........j.N.]5.......S...1...uc.....PNA}.....S..G..e%;.}..#{.5.K.../.u_.u...P...BF..L )..eI8%.t.g......... .hv.&W...0$.X.P....]... ..A.j..tR.G.gGN..Z..;....j.[.O.G:1(.%...0...]......c>..iIH..|Y..r...........9.>...t.x6(m.&S6.&..u.E.@.4..dE.3..._....7.Y..]...*.0.....3....q..S.K.-.$..T............A.Nn{...\..v.^.5.&z.....X'...^_,..........iL{..t...nV#.....q...|.......t.7.f\.S......V&]....Z..^.[(..G*.~Z4.}.,.N...2xt.J.7.6(l..F.C.ZR.J......v."..ub:.v.v..q|...XP#H.6../..T..z.{..N.Go.N...n.'n....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24664
                  Entropy (8bit):7.992421962140185
                  Encrypted:true
                  SSDEEP:
                  MD5:62B915D969BFA57ABF3DFDDF76172690
                  SHA1:9556DC5288DE8DAAF6BFF65906CC7E1A95EA2649
                  SHA-256:206674D30111F0824355C28569B475A17584242685A24E6E49B4DE27ADA1E51F
                  SHA-512:FC1B510850A04F8F05685937973E89CDB48CA9B31DC792BC4C993F1772AE05B77827A52DF0F3C43607B5AA43941668F2DF63EC80AA1A8F5ECF3EE6527344B1CC
                  Malicious:true
                  Preview:.n{y..7...>....?....<T..(O....4/.....WYeH.."S...y.9K..^...q0Y_..3..TI..K."u...A..D.d..e.(.W.@/..S.#8a.Z.3a..#f....M.4.8=.....)nS.{.}.u..e.....Pz....R0-..@.wl...Y...a.L&...9?.......E....x..:..U..TO.....-%..s.txu.[g.x........S....w...L.(.A...N.^S:\.>..3....L.8...t...9.y.`.}.O.......i.F..w.~.X..5.eo^..]...y..w.7.Q...r[zQ.^...Kj~..r.N'.V.S..J.~..o.H.$..Q........)..1..3.o..../..(..[3DCi7u....f>......y..Xg.].o%.g.v*..I6..V.'wrgSYg.M:w.CiB...{.=!d.u.....z...J..@..r..R1.........j.N.]5.......S...1...uc.....PNA}.....S..G..e%;.}..#{.5.K.../.u_.u...P...BF..L )..eI8%.t.g......... .hv.&W...0$.X.P....]... ..A.j..tR.G.gGN..Z..;....j.[.O.G:1(.%...0...]......c>..iIH..|Y..r...........9.>...t.x6(m.&S6.&..u.E.@.4..dE.3..._....7.Y..]...*.0.....3....q..S.K.-.$..T............A.Nn{...\..v.^.5.&z.....X'...^_,..........iL{..t...nV#.....q...|.......t.7.f\.S......V&]....Z..^.[(..G*.~Z4.}.,.N...2xt.J.7.6(l..F.C.ZR.J......v."..ub:.v.v..q|...XP#H.6../..T..z.{..N.Go.N...n.'n....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24664
                  Entropy (8bit):7.992421962140185
                  Encrypted:true
                  SSDEEP:
                  MD5:62B915D969BFA57ABF3DFDDF76172690
                  SHA1:9556DC5288DE8DAAF6BFF65906CC7E1A95EA2649
                  SHA-256:206674D30111F0824355C28569B475A17584242685A24E6E49B4DE27ADA1E51F
                  SHA-512:FC1B510850A04F8F05685937973E89CDB48CA9B31DC792BC4C993F1772AE05B77827A52DF0F3C43607B5AA43941668F2DF63EC80AA1A8F5ECF3EE6527344B1CC
                  Malicious:true
                  Preview:.n{y..7...>....?....<T..(O....4/.....WYeH.."S...y.9K..^...q0Y_..3..TI..K."u...A..D.d..e.(.W.@/..S.#8a.Z.3a..#f....M.4.8=.....)nS.{.}.u..e.....Pz....R0-..@.wl...Y...a.L&...9?.......E....x..:..U..TO.....-%..s.txu.[g.x........S....w...L.(.A...N.^S:\.>..3....L.8...t...9.y.`.}.O.......i.F..w.~.X..5.eo^..]...y..w.7.Q...r[zQ.^...Kj~..r.N'.V.S..J.~..o.H.$..Q........)..1..3.o..../..(..[3DCi7u....f>......y..Xg.].o%.g.v*..I6..V.'wrgSYg.M:w.CiB...{.=!d.u.....z...J..@..r..R1.........j.N.]5.......S...1...uc.....PNA}.....S..G..e%;.}..#{.5.K.../.u_.u...P...BF..L )..eI8%.t.g......... .hv.&W...0$.X.P....]... ..A.j..tR.G.gGN..Z..;....j.[.O.G:1(.%...0...]......c>..iIH..|Y..r...........9.>...t.x6(m.&S6.&..u.E.@.4..dE.3..._....7.Y..]...*.0.....3....q..S.K.-.$..T............A.Nn{...\..v.^.5.&z.....X'...^_,..........iL{..t...nV#.....q...|.......t.7.f\.S......V&]....Z..^.[(..G*.~Z4.}.,.N...2xt.J.7.6(l..F.C.ZR.J......v."..ub:.v.v..q|...XP#H.6../..T..z.{..N.Go.N...n.'n....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10098
                  Entropy (8bit):7.9798989214179015
                  Encrypted:false
                  SSDEEP:
                  MD5:B2BE570CFB60880217A7BE77C953DA95
                  SHA1:D398A5187CFD741B61E63DF63BF141B5734A8AAB
                  SHA-256:F788BB32B1598B76C2F179AF20330367F124BB53B74ACBA4B6B1ED993A0577D5
                  SHA-512:2F1303A3976398D038D90C5D690A4B6C9919CFB9699DE26C7611AF8056849BE06A84C22B3F49A29BBF8DF29A3D41D01D9ED4A1797A154FD7F8A7692BCE29ADD2
                  Malicious:false
                  Preview:.I..c.R:....3...`q... k.&....X?t..K7.B./..x.?..W..`.\D...d..-.Z..H.o.e.H.n.Y....]5 3.l....?....&..}b.t...No?.B....w.e=...t...L=.H.j..=..Wq.k3....n.4......".....)o.uj....,...O+...._M._P.#'.;.'.....7.4...Y......R?.M#.q......4.<....X.#`.B....%4..D(..v0......f.V.....zI.....e.$.%..T..3..b".W..t)._j...I*...\z....a...t./"w.<..p2.!b.e7...f......KQ6,.Y..-c..H.}..~....Vg...$...T.I...K|ff_pM........8?R.F...7T..7.od...Kwm_I.HD.k.g...g..5.`.j..l....}.Ay...*Z+.......v.R...g....<..Ys...?..i...........;.5&`s....F......&4..&...A..]...d..D....Q..c.p.U^I.....-..T.p......P..._t.....8...D.`{.<. .M.C.:r...H| .V..<.r..Qn....".e....]T...s..v..h.(.....ia..*T...`..l,...hc..T..;......q1&........zW.P..!..U<.8.....n...C.@...)....uf....:...-.1..X......N.V......Z3....5..j....U..i.@.gi$2.'.,.I.}E,K.?..q..zj..8.0...Kb9..Q"..aZ>aP]d..`w)..mx..aRG,....~D.:.3.d..Tb1&/....`.....=.4.}...$..s......O...N.z....3e...w.lH!..O>....R...C%....(j.=NcI<].,.F..}...knL...."..o....j.$+N.=.ugM.x]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10098
                  Entropy (8bit):7.9798989214179015
                  Encrypted:false
                  SSDEEP:
                  MD5:B2BE570CFB60880217A7BE77C953DA95
                  SHA1:D398A5187CFD741B61E63DF63BF141B5734A8AAB
                  SHA-256:F788BB32B1598B76C2F179AF20330367F124BB53B74ACBA4B6B1ED993A0577D5
                  SHA-512:2F1303A3976398D038D90C5D690A4B6C9919CFB9699DE26C7611AF8056849BE06A84C22B3F49A29BBF8DF29A3D41D01D9ED4A1797A154FD7F8A7692BCE29ADD2
                  Malicious:false
                  Preview:.I..c.R:....3...`q... k.&....X?t..K7.B./..x.?..W..`.\D...d..-.Z..H.o.e.H.n.Y....]5 3.l....?....&..}b.t...No?.B....w.e=...t...L=.H.j..=..Wq.k3....n.4......".....)o.uj....,...O+...._M._P.#'.;.'.....7.4...Y......R?.M#.q......4.<....X.#`.B....%4..D(..v0......f.V.....zI.....e.$.%..T..3..b".W..t)._j...I*...\z....a...t./"w.<..p2.!b.e7...f......KQ6,.Y..-c..H.}..~....Vg...$...T.I...K|ff_pM........8?R.F...7T..7.od...Kwm_I.HD.k.g...g..5.`.j..l....}.Ay...*Z+.......v.R...g....<..Ys...?..i...........;.5&`s....F......&4..&...A..]...d..D....Q..c.p.U^I.....-..T.p......P..._t.....8...D.`{.<. .M.C.:r...H| .V..<.r..Qn....".e....]T...s..v..h.(.....ia..*T...`..l,...hc..T..;......q1&........zW.P..!..U<.8.....n...C.@...)....uf....:...-.1..X......N.V......Z3....5..j....U..i.@.gi$2.'.,.I.}E,K.?..q..zj..8.0...Kb9..Q"..aZ>aP]d..`w)..mx..aRG,....~D.:.3.d..Tb1&/....`.....=.4.}...$..s......O...N.z....3e...w.lH!..O>....R...C%....(j.=NcI<].,.F..}...knL...."..o....j.$+N.=.ugM.x]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10098
                  Entropy (8bit):7.9798989214179015
                  Encrypted:false
                  SSDEEP:
                  MD5:B2BE570CFB60880217A7BE77C953DA95
                  SHA1:D398A5187CFD741B61E63DF63BF141B5734A8AAB
                  SHA-256:F788BB32B1598B76C2F179AF20330367F124BB53B74ACBA4B6B1ED993A0577D5
                  SHA-512:2F1303A3976398D038D90C5D690A4B6C9919CFB9699DE26C7611AF8056849BE06A84C22B3F49A29BBF8DF29A3D41D01D9ED4A1797A154FD7F8A7692BCE29ADD2
                  Malicious:false
                  Preview:.I..c.R:....3...`q... k.&....X?t..K7.B./..x.?..W..`.\D...d..-.Z..H.o.e.H.n.Y....]5 3.l....?....&..}b.t...No?.B....w.e=...t...L=.H.j..=..Wq.k3....n.4......".....)o.uj....,...O+...._M._P.#'.;.'.....7.4...Y......R?.M#.q......4.<....X.#`.B....%4..D(..v0......f.V.....zI.....e.$.%..T..3..b".W..t)._j...I*...\z....a...t./"w.<..p2.!b.e7...f......KQ6,.Y..-c..H.}..~....Vg...$...T.I...K|ff_pM........8?R.F...7T..7.od...Kwm_I.HD.k.g...g..5.`.j..l....}.Ay...*Z+.......v.R...g....<..Ys...?..i...........;.5&`s....F......&4..&...A..]...d..D....Q..c.p.U^I.....-..T.p......P..._t.....8...D.`{.<. .M.C.:r...H| .V..<.r..Qn....".e....]T...s..v..h.(.....ia..*T...`..l,...hc..T..;......q1&........zW.P..!..U<.8.....n...C.@...)....uf....:...-.1..X......N.V......Z3....5..j....U..i.@.gi$2.'.,.I.}E,K.?..q..zj..8.0...Kb9..Q"..aZ>aP]d..`w)..mx..aRG,....~D.:.3.d..Tb1&/....`.....=.4.}...$..s......O...N.z....3e...w.lH!..O>....R...C%....(j.=NcI<].,.F..}...knL...."..o....j.$+N.=.ugM.x]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):9019
                  Entropy (8bit):7.978576388571011
                  Encrypted:false
                  SSDEEP:
                  MD5:F55FD2FAA3BEF901C0B28E177227260D
                  SHA1:A39CDF4F3874560C84CDC3D5A0B2AFF6D6C54265
                  SHA-256:495CC56464B53D66E614CB47EDD5AB3FC158B1F4C77BACDEF0FDA542EDBAD3FB
                  SHA-512:35EA705E26E743396C8A96D6870FD31D833D14C37DEB3346CAF572A97AD94E8F7721071384CCEB0F463C2B9053B9829615E489E9FC80302CDA2C1638AAB60207
                  Malicious:false
                  Preview:...z).......U.."l..D..........e`F..[.z>)...fDT...].\4A...!:&I...ho.G...|n...d."RA..d-.#...Uso.}.,.M>O.......F..J,3(&8W.#.WT..d....._.@..h'.%.lS.Nt^T..V...*.P..D.B..&.....kx%...J....%..6.X..(}..O..M$..m..b.O.e....f.?...0.v.. P.<G#.9.V....0..!{...`w..bS9........Du.S..[....ja.P..Wuz@.?.(E:.2...P)U...Sd.......t.]_K.. M.@}2.YQ"u._..E$.`Qb.z...J.........r`..a..N.c.MrE..~3.`/...}O..\..y'0......|.`F....a..B..c.:h.N4(...I.S...>7g.f?.U......j......W.6@.a.[.m3..B/....k..B.(..6.:fuk....;X.c...3..............@...m...n...Y|.......z..E).QD.W]....uR.gc.6.%..............w.J.9..\sS..hS.O.7....|9tj..b:...8..9LR...f...".m..h..@....2...&.zAv...E?..^..B2.3...r.....T..3s.......A....:.;....@...GRd...8..h..?...5TID.g......-.N.....EGN....??....$R........=..a&.G(}r..>HM...`..$.dY..Lli'.V?#..yi.9...BU..Y.O+...Z....~qH....##..V..G.{.X.....S......u..)d..~.......C.Jt.{e9f{>-1._T..F.C6b......Cq.....n...x9.7...b........zL'[.....N..,T;........R..!..Z.{#e.;Q.PZ.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):9019
                  Entropy (8bit):7.978576388571011
                  Encrypted:false
                  SSDEEP:
                  MD5:F55FD2FAA3BEF901C0B28E177227260D
                  SHA1:A39CDF4F3874560C84CDC3D5A0B2AFF6D6C54265
                  SHA-256:495CC56464B53D66E614CB47EDD5AB3FC158B1F4C77BACDEF0FDA542EDBAD3FB
                  SHA-512:35EA705E26E743396C8A96D6870FD31D833D14C37DEB3346CAF572A97AD94E8F7721071384CCEB0F463C2B9053B9829615E489E9FC80302CDA2C1638AAB60207
                  Malicious:false
                  Preview:...z).......U.."l..D..........e`F..[.z>)...fDT...].\4A...!:&I...ho.G...|n...d."RA..d-.#...Uso.}.,.M>O.......F..J,3(&8W.#.WT..d....._.@..h'.%.lS.Nt^T..V...*.P..D.B..&.....kx%...J....%..6.X..(}..O..M$..m..b.O.e....f.?...0.v.. P.<G#.9.V....0..!{...`w..bS9........Du.S..[....ja.P..Wuz@.?.(E:.2...P)U...Sd.......t.]_K.. M.@}2.YQ"u._..E$.`Qb.z...J.........r`..a..N.c.MrE..~3.`/...}O..\..y'0......|.`F....a..B..c.:h.N4(...I.S...>7g.f?.U......j......W.6@.a.[.m3..B/....k..B.(..6.:fuk....;X.c...3..............@...m...n...Y|.......z..E).QD.W]....uR.gc.6.%..............w.J.9..\sS..hS.O.7....|9tj..b:...8..9LR...f...".m..h..@....2...&.zAv...E?..^..B2.3...r.....T..3s.......A....:.;....@...GRd...8..h..?...5TID.g......-.N.....EGN....??....$R........=..a&.G(}r..>HM...`..$.dY..Lli'.V?#..yi.9...BU..Y.O+...Z....~qH....##..V..G.{.X.....S......u..)d..~.......C.Jt.{e9f{>-1._T..F.C6b......Cq.....n...x9.7...b........zL'[.....N..,T;........R..!..Z.{#e.;Q.PZ.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):9019
                  Entropy (8bit):7.978576388571011
                  Encrypted:false
                  SSDEEP:
                  MD5:F55FD2FAA3BEF901C0B28E177227260D
                  SHA1:A39CDF4F3874560C84CDC3D5A0B2AFF6D6C54265
                  SHA-256:495CC56464B53D66E614CB47EDD5AB3FC158B1F4C77BACDEF0FDA542EDBAD3FB
                  SHA-512:35EA705E26E743396C8A96D6870FD31D833D14C37DEB3346CAF572A97AD94E8F7721071384CCEB0F463C2B9053B9829615E489E9FC80302CDA2C1638AAB60207
                  Malicious:false
                  Preview:...z).......U.."l..D..........e`F..[.z>)...fDT...].\4A...!:&I...ho.G...|n...d."RA..d-.#...Uso.}.,.M>O.......F..J,3(&8W.#.WT..d....._.@..h'.%.lS.Nt^T..V...*.P..D.B..&.....kx%...J....%..6.X..(}..O..M$..m..b.O.e....f.?...0.v.. P.<G#.9.V....0..!{...`w..bS9........Du.S..[....ja.P..Wuz@.?.(E:.2...P)U...Sd.......t.]_K.. M.@}2.YQ"u._..E$.`Qb.z...J.........r`..a..N.c.MrE..~3.`/...}O..\..y'0......|.`F....a..B..c.:h.N4(...I.S...>7g.f?.U......j......W.6@.a.[.m3..B/....k..B.(..6.:fuk....;X.c...3..............@...m...n...Y|.......z..E).QD.W]....uR.gc.6.%..............w.J.9..\sS..hS.O.7....|9tj..b:...8..9LR...f...".m..h..@....2...&.zAv...E?..^..B2.3...r.....T..3s.......A....:.;....@...GRd...8..h..?...5TID.g......-.N.....EGN....??....$R........=..a&.G(}r..>HM...`..$.dY..Lli'.V?#..yi.9...BU..Y.O+...Z....~qH....##..V..G.{.X.....S......u..)d..~.......C.Jt.{e9f{>-1._T..F.C6b......Cq.....n...x9.7...b........zL'[.....N..,T;........R..!..Z.{#e.;Q.PZ.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9901
                  Entropy (8bit):7.979982161917679
                  Encrypted:false
                  SSDEEP:
                  MD5:99E3BA3A1D417E5200A3E43FFA24AB10
                  SHA1:784E0872276E896F3A5D223E1A27692139AF460F
                  SHA-256:54F0D046C9BD5F70CADAE530482993391FA94B161C5D79323F38488231BFF342
                  SHA-512:979F19989B773610AEADDB99595F08EB3EDCE709E6D62D7B9FF18D988EFC4D3B6F2BFCE62E5E77F88BDCCA81E7AA525E9A8CA963CECC05CD935BCF88264F0B74
                  Malicious:false
                  Preview:;&...-q.e.%.%...fx...j1..x...3.......[..^.|..Y...`....,.#.k?.I...7''.5D..9.......|.P.@.U....Mp.(Ab..b'[.!cb,.......N.|J90.9GkfO....[}.`...uGi#..A..3]P..CLm$........X...2....1.#i...pB.6h.U..b...Y LRE!...........V..>uNNi...&.%..d..'H.....]...n.....%.Q).~.0.H...".>[..........F.S...]..3x..q..b+...4r4q..s-c/.W...f......P.....h.w|....`.....Y.v.I.w.Wk.@~e.....>..+.Q.ue..-....&...b;=;Q......<..8%..6..`q......:....PF&.O:..h...n..pd.uT.*....{......9Y.-sqfR.........-...&o...-..m(?'....*Z...^1....Cfw,.A..56....$b@u........!.\.....3k....M..6..)..$...............4m.5...B..7O.RP]....q]Q.....!Q?..|....s.^]D. .Zf..Q.;{Z.J..k$...<.,.....x....'....#...&...xJl[.d'l..w........J.sB..M.~......n......>;....jb..9a8....gg.6%.D}.!%.n.E...j.....E)..0.H......X....+{........G.\...n`m..c;.}..i..zR.}$}.}o_=..n.I)...:.../....zZ.~...).g'..J..N..I...Q....Er-..^.6c...|.._...:n.iAw.T.......l.:..l).I.:1h.6..4.k.wJr.f!"e8.....R...#.f....V..(UIqO0.....3...+A|p.)...w....j
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9901
                  Entropy (8bit):7.979982161917679
                  Encrypted:false
                  SSDEEP:
                  MD5:99E3BA3A1D417E5200A3E43FFA24AB10
                  SHA1:784E0872276E896F3A5D223E1A27692139AF460F
                  SHA-256:54F0D046C9BD5F70CADAE530482993391FA94B161C5D79323F38488231BFF342
                  SHA-512:979F19989B773610AEADDB99595F08EB3EDCE709E6D62D7B9FF18D988EFC4D3B6F2BFCE62E5E77F88BDCCA81E7AA525E9A8CA963CECC05CD935BCF88264F0B74
                  Malicious:false
                  Preview:;&...-q.e.%.%...fx...j1..x...3.......[..^.|..Y...`....,.#.k?.I...7''.5D..9.......|.P.@.U....Mp.(Ab..b'[.!cb,.......N.|J90.9GkfO....[}.`...uGi#..A..3]P..CLm$........X...2....1.#i...pB.6h.U..b...Y LRE!...........V..>uNNi...&.%..d..'H.....]...n.....%.Q).~.0.H...".>[..........F.S...]..3x..q..b+...4r4q..s-c/.W...f......P.....h.w|....`.....Y.v.I.w.Wk.@~e.....>..+.Q.ue..-....&...b;=;Q......<..8%..6..`q......:....PF&.O:..h...n..pd.uT.*....{......9Y.-sqfR.........-...&o...-..m(?'....*Z...^1....Cfw,.A..56....$b@u........!.\.....3k....M..6..)..$...............4m.5...B..7O.RP]....q]Q.....!Q?..|....s.^]D. .Zf..Q.;{Z.J..k$...<.,.....x....'....#...&...xJl[.d'l..w........J.sB..M.~......n......>;....jb..9a8....gg.6%.D}.!%.n.E...j.....E)..0.H......X....+{........G.\...n`m..c;.}..i..zR.}$}.}o_=..n.I)...:.../....zZ.~...).g'..J..N..I...Q....Er-..^.6c...|.._...:n.iAw.T.......l.:..l).I.:1h.6..4.k.wJr.f!"e8.....R...#.f....V..(UIqO0.....3...+A|p.)...w....j
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9901
                  Entropy (8bit):7.979982161917679
                  Encrypted:false
                  SSDEEP:
                  MD5:99E3BA3A1D417E5200A3E43FFA24AB10
                  SHA1:784E0872276E896F3A5D223E1A27692139AF460F
                  SHA-256:54F0D046C9BD5F70CADAE530482993391FA94B161C5D79323F38488231BFF342
                  SHA-512:979F19989B773610AEADDB99595F08EB3EDCE709E6D62D7B9FF18D988EFC4D3B6F2BFCE62E5E77F88BDCCA81E7AA525E9A8CA963CECC05CD935BCF88264F0B74
                  Malicious:false
                  Preview:;&...-q.e.%.%...fx...j1..x...3.......[..^.|..Y...`....,.#.k?.I...7''.5D..9.......|.P.@.U....Mp.(Ab..b'[.!cb,.......N.|J90.9GkfO....[}.`...uGi#..A..3]P..CLm$........X...2....1.#i...pB.6h.U..b...Y LRE!...........V..>uNNi...&.%..d..'H.....]...n.....%.Q).~.0.H...".>[..........F.S...]..3x..q..b+...4r4q..s-c/.W...f......P.....h.w|....`.....Y.v.I.w.Wk.@~e.....>..+.Q.ue..-....&...b;=;Q......<..8%..6..`q......:....PF&.O:..h...n..pd.uT.*....{......9Y.-sqfR.........-...&o...-..m(?'....*Z...^1....Cfw,.A..56....$b@u........!.\.....3k....M..6..)..$...............4m.5...B..7O.RP]....q]Q.....!Q?..|....s.^]D. .Zf..Q.;{Z.J..k$...<.,.....x....'....#...&...xJl[.d'l..w........J.sB..M.~......n......>;....jb..9a8....gg.6%.D}.!%.n.E...j.....E)..0.H......X....+{........G.\...n`m..c;.}..i..zR.}$}.}o_=..n.I)...:.../....zZ.~...).g'..J..N..I...Q....Er-..^.6c...|.._...:n.iAw.T.......l.:..l).I.:1h.6..4.k.wJr.f!"e8.....R...#.f....V..(UIqO0.....3...+A|p.)...w....j
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9119
                  Entropy (8bit):7.978348383547147
                  Encrypted:false
                  SSDEEP:
                  MD5:777024C8E04D25CD70C4990719061E1B
                  SHA1:C9DCB8046B07286D252FC6A4312F93F7DA53E5B7
                  SHA-256:72C4E380DB956CA92E439F7D7CABD2428A28186F354EBC16BC8ECF5805428B9E
                  SHA-512:8168704B38A1D84D58412DB07A31517F68EA17426A1503D19186CF0EC425E83FB539FBE4194C84F7F4FF64ABD464203E933A6B89E9A389CD60C6998D59D96583
                  Malicious:false
                  Preview:...X!xE..e........g..L.Q.ms.n.....X.l.Hz.+.Ba.&..$V../X.6........,..=......D.sqM....&b%..DF.>.h.bz.p.Q.Q..E..&.t..x..+`hU.....uI...=..CR.gB+hL.a-.He6$.._DV...T0.*d.kF..>2.. ..f......u.....M...E....EVh.XU...YA...).-......q......j.b...-H...@..$.......c.I....u............>;.....y.mi..o (4.&.?..oD..q..N.".....5.....y.CrI.R:.w.j>..t.YAi,....n.....@[.6M.T....x.3....._.w.....>j .?b.7.9Q..l+?..#.S...7.X.B..j.)..y..F...^..1.....:!^.=...X....8..F.f.R.`..R...cT.Q.qW.l.....e.8>d.i..~.WA.....m@.H....9...z..Rb.......j.(.u.1%.d...t..0.W...O..D.0Y.....uQ..{.....Z.*.6."."4~k........y..l......)..T.5HvC....|......tM+.../..L.H.]...}...1..9..R&G.+vC.j....f4H...-.<.%.%..(.mC....d....]...?W........Y:hH..T...687.KH.t.Q....|&....dS..;}rU`.s,=`...?.tPo.ha^w7.Q.....f......:"....ek./c.EQ.&...\d.(.c{.,.9..|}[......QUO..Y......#..P....+.j...4.g....c!....$j_..'.......F........VK....O[z%yD.r...u.7mA .X.Xi...?.\.X.[...,.......J...M .....o0...!_.t....{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9119
                  Entropy (8bit):7.978348383547147
                  Encrypted:false
                  SSDEEP:
                  MD5:777024C8E04D25CD70C4990719061E1B
                  SHA1:C9DCB8046B07286D252FC6A4312F93F7DA53E5B7
                  SHA-256:72C4E380DB956CA92E439F7D7CABD2428A28186F354EBC16BC8ECF5805428B9E
                  SHA-512:8168704B38A1D84D58412DB07A31517F68EA17426A1503D19186CF0EC425E83FB539FBE4194C84F7F4FF64ABD464203E933A6B89E9A389CD60C6998D59D96583
                  Malicious:false
                  Preview:...X!xE..e........g..L.Q.ms.n.....X.l.Hz.+.Ba.&..$V../X.6........,..=......D.sqM....&b%..DF.>.h.bz.p.Q.Q..E..&.t..x..+`hU.....uI...=..CR.gB+hL.a-.He6$.._DV...T0.*d.kF..>2.. ..f......u.....M...E....EVh.XU...YA...).-......q......j.b...-H...@..$.......c.I....u............>;.....y.mi..o (4.&.?..oD..q..N.".....5.....y.CrI.R:.w.j>..t.YAi,....n.....@[.6M.T....x.3....._.w.....>j .?b.7.9Q..l+?..#.S...7.X.B..j.)..y..F...^..1.....:!^.=...X....8..F.f.R.`..R...cT.Q.qW.l.....e.8>d.i..~.WA.....m@.H....9...z..Rb.......j.(.u.1%.d...t..0.W...O..D.0Y.....uQ..{.....Z.*.6."."4~k........y..l......)..T.5HvC....|......tM+.../..L.H.]...}...1..9..R&G.+vC.j....f4H...-.<.%.%..(.mC....d....]...?W........Y:hH..T...687.KH.t.Q....|&....dS..;}rU`.s,=`...?.tPo.ha^w7.Q.....f......:"....ek./c.EQ.&...\d.(.c{.,.9..|}[......QUO..Y......#..P....+.j...4.g....c!....$j_..'.......F........VK....O[z%yD.r...u.7mA .X.Xi...?.\.X.[...,.......J...M .....o0...!_.t....{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):9119
                  Entropy (8bit):7.978348383547147
                  Encrypted:false
                  SSDEEP:
                  MD5:777024C8E04D25CD70C4990719061E1B
                  SHA1:C9DCB8046B07286D252FC6A4312F93F7DA53E5B7
                  SHA-256:72C4E380DB956CA92E439F7D7CABD2428A28186F354EBC16BC8ECF5805428B9E
                  SHA-512:8168704B38A1D84D58412DB07A31517F68EA17426A1503D19186CF0EC425E83FB539FBE4194C84F7F4FF64ABD464203E933A6B89E9A389CD60C6998D59D96583
                  Malicious:false
                  Preview:...X!xE..e........g..L.Q.ms.n.....X.l.Hz.+.Ba.&..$V../X.6........,..=......D.sqM....&b%..DF.>.h.bz.p.Q.Q..E..&.t..x..+`hU.....uI...=..CR.gB+hL.a-.He6$.._DV...T0.*d.kF..>2.. ..f......u.....M...E....EVh.XU...YA...).-......q......j.b...-H...@..$.......c.I....u............>;.....y.mi..o (4.&.?..oD..q..N.".....5.....y.CrI.R:.w.j>..t.YAi,....n.....@[.6M.T....x.3....._.w.....>j .?b.7.9Q..l+?..#.S...7.X.B..j.)..y..F...^..1.....:!^.=...X....8..F.f.R.`..R...cT.Q.qW.l.....e.8>d.i..~.WA.....m@.H....9...z..Rb.......j.(.u.1%.d...t..0.W...O..D.0Y.....uQ..{.....Z.*.6."."4~k........y..l......)..T.5HvC....|......tM+.../..L.H.]...}...1..9..R&G.+vC.j....f4H...-.<.%.%..(.mC....d....]...?W........Y:hH..T...687.KH.t.Q....|&....dS..;}rU`.s,=`...?.tPo.ha^w7.Q.....f......:"....ek./c.EQ.&...\d.(.c{.,.9..|}[......QUO..Y......#..P....+.j...4.g....c!....$j_..'.......F........VK....O[z%yD.r...u.7mA .X.Xi...?.\.X.[...,.......J...M .....o0...!_.t....{.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):633
                  Entropy (8bit):7.610004957430911
                  Encrypted:false
                  SSDEEP:
                  MD5:B9BDF666D99A775A08E7807475FD2B56
                  SHA1:A45BE7258C5BF45F3B58E5B598A5E6FEBB9725F2
                  SHA-256:20E5BE4E6D73A7AF8E0CDE0AD6DBC1F8C552AD6440321222F210316628FFE42E
                  SHA-512:4276FD1275D111EB9AD5E8D717FB297F0F9B6361E6659CAEFAF6CEF9ED9FF6941EA3FDD9389003DCAF9690560797CE1E258D726E68E73738F0EFDC3C64F478EB
                  Malicious:false
                  Preview:D..>.5G.J..MrI...@....M.5...;.|..Sy........Fc.f.%V.l....i<R..tke..'%?.U........cb.A.(...)....4.4{<....?.Uf.&F5&{.h.Pb...m..).+..K......`6'..@...L.a&.b.........J.q@(.ef=.... ...H8..\.. ..q.V...d....=}^.5...x..x.8Z.l....~?..[q.....A.|.=@@.F.D.u.D..*.....7...)..v.J..!.v..4..7.....&.k...}.....T..E.../Q...X...4..cI*..........$P.Xq....._"V[.......>(.>[=.!4Bt....{K.w.l:|......p...r...uJ..y.m~..s.YHmMQ4....`!..".....B1...../...Y...N.>.....$LjP..b.6.l.B.F.|..W.i..7....>..]xgtg.q..9...Sg$.I..}..P.Zn..z.O.."C.g.LC.2........e.Ov.../...{(~H..\ZR^..TH.>..B9..W.. 6..@[6.0[!.`.=.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):633
                  Entropy (8bit):7.610004957430911
                  Encrypted:false
                  SSDEEP:
                  MD5:B9BDF666D99A775A08E7807475FD2B56
                  SHA1:A45BE7258C5BF45F3B58E5B598A5E6FEBB9725F2
                  SHA-256:20E5BE4E6D73A7AF8E0CDE0AD6DBC1F8C552AD6440321222F210316628FFE42E
                  SHA-512:4276FD1275D111EB9AD5E8D717FB297F0F9B6361E6659CAEFAF6CEF9ED9FF6941EA3FDD9389003DCAF9690560797CE1E258D726E68E73738F0EFDC3C64F478EB
                  Malicious:false
                  Preview:D..>.5G.J..MrI...@....M.5...;.|..Sy........Fc.f.%V.l....i<R..tke..'%?.U........cb.A.(...)....4.4{<....?.Uf.&F5&{.h.Pb...m..).+..K......`6'..@...L.a&.b.........J.q@(.ef=.... ...H8..\.. ..q.V...d....=}^.5...x..x.8Z.l....~?..[q.....A.|.=@@.F.D.u.D..*.....7...)..v.J..!.v..4..7.....&.k...}.....T..E.../Q...X...4..cI*..........$P.Xq....._"V[.......>(.>[=.!4Bt....{K.w.l:|......p...r...uJ..y.m~..s.YHmMQ4....`!..".....B1...../...Y...N.>.....$LjP..b.6.l.B.F.|..W.i..7....>..]xgtg.q..9...Sg$.I..}..P.Zn..z.O.."C.g.LC.2........e.Ov.../...{(~H..\ZR^..TH.>..B9..W.. 6..@[6.0[!.`.=.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):633
                  Entropy (8bit):7.610004957430911
                  Encrypted:false
                  SSDEEP:
                  MD5:B9BDF666D99A775A08E7807475FD2B56
                  SHA1:A45BE7258C5BF45F3B58E5B598A5E6FEBB9725F2
                  SHA-256:20E5BE4E6D73A7AF8E0CDE0AD6DBC1F8C552AD6440321222F210316628FFE42E
                  SHA-512:4276FD1275D111EB9AD5E8D717FB297F0F9B6361E6659CAEFAF6CEF9ED9FF6941EA3FDD9389003DCAF9690560797CE1E258D726E68E73738F0EFDC3C64F478EB
                  Malicious:false
                  Preview:D..>.5G.J..MrI...@....M.5...;.|..Sy........Fc.f.%V.l....i<R..tke..'%?.U........cb.A.(...)....4.4{<....?.Uf.&F5&{.h.Pb...m..).+..K......`6'..@...L.a&.b.........J.q@(.ef=.... ...H8..\.. ..q.V...d....=}^.5...x..x.8Z.l....~?..[q.....A.|.=@@.F.D.u.D..*.....7...)..v.J..!.v..4..7.....&.k...}.....T..E.../Q...X...4..cI*..........$P.Xq....._"V[.......>(.>[=.!4Bt....{K.w.l:|......p...r...uJ..y.m~..s.YHmMQ4....`!..".....B1...../...Y...N.>.....$LjP..b.6.l.B.F.|..W.i..7....>..]xgtg.q..9...Sg$.I..}..P.Zn..z.O.."C.g.LC.2........e.Ov.../...{(~H..\ZR^..TH.>..B9..W.. 6..@[6.0[!.`.=.............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.860656015751546
                  Encrypted:false
                  SSDEEP:
                  MD5:CDFA7899F1C9114A0FD3601DDFB1D0F9
                  SHA1:2B801EC368658E5B8A31DA66F5E5225ABBC2B774
                  SHA-256:75132743EB64C3665CED9B3283D9A99C98D90233B75BF37A35ED37378BAF4BC6
                  SHA-512:91AC404E5FCDFDA5022D3E216C32072CC8B4467490E15E9A48AB6A1081BB8AEF473A3B937761A2868028ECDB9B7AD06254368FCB75C72BE826713315D3838DCA
                  Malicious:false
                  Preview:G...=Yy'.?..... ...M.+c.f}#...%......v.......F..........>I^t....UN.....`q.V(.A..m.{.~.V.l!.0..b....d..f.,5....'.Bi..?w.*/o..Z.........n....LqT..l.1...........nl.....:p.L.|a9.NE..iL.`...o|.....z...)...;..|.K..).....z...++'7..K...F.6|...$D..S.0.'..T6].S#5.K....."W.~.Jp.b.m..M...I...H...0..{.XH.....G.\...E..2..9.z,0.5....qPH.#.T..g.I...L.R@.TAi.....`....hL...A(.V.-u...p...Q....H..D.W.L.....EI.....@d...`..8T..>nU$.y...&pm.7.j.B.$..#......di..F.......'..U.y.z...L.).|...x*r......I_+.7..=Wa..}oy.p......C.L?.......?vp%9(q...C1..z..t........5z;........#7k..R.v.Uh.1.V.2m.A.....<w..}G.RT.....w.4.7.'...x.....V...v...I..3_6....{..IM...?..X4...)..W60..;1...[....mQ/...{.9n.[.W9.....3(...B5.U.d.......7....".^..16"........u!...{..7.....=E..MT...Q3k.C.0..T......3h.ea#d..92./..U.6...cW.%....H@..}B.._ ......W..Nyx.3....97.j...e... .@Ux..p>.X)V".`'H......x.}.T..I..I+....G.cD!.].U...$.Ng.........K...u0x.n)....9.*Z|..rM....'....&...=.o.3...qo6C...J.X..3..q.#a...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.860656015751546
                  Encrypted:false
                  SSDEEP:
                  MD5:CDFA7899F1C9114A0FD3601DDFB1D0F9
                  SHA1:2B801EC368658E5B8A31DA66F5E5225ABBC2B774
                  SHA-256:75132743EB64C3665CED9B3283D9A99C98D90233B75BF37A35ED37378BAF4BC6
                  SHA-512:91AC404E5FCDFDA5022D3E216C32072CC8B4467490E15E9A48AB6A1081BB8AEF473A3B937761A2868028ECDB9B7AD06254368FCB75C72BE826713315D3838DCA
                  Malicious:false
                  Preview:G...=Yy'.?..... ...M.+c.f}#...%......v.......F..........>I^t....UN.....`q.V(.A..m.{.~.V.l!.0..b....d..f.,5....'.Bi..?w.*/o..Z.........n....LqT..l.1...........nl.....:p.L.|a9.NE..iL.`...o|.....z...)...;..|.K..).....z...++'7..K...F.6|...$D..S.0.'..T6].S#5.K....."W.~.Jp.b.m..M...I...H...0..{.XH.....G.\...E..2..9.z,0.5....qPH.#.T..g.I...L.R@.TAi.....`....hL...A(.V.-u...p...Q....H..D.W.L.....EI.....@d...`..8T..>nU$.y...&pm.7.j.B.$..#......di..F.......'..U.y.z...L.).|...x*r......I_+.7..=Wa..}oy.p......C.L?.......?vp%9(q...C1..z..t........5z;........#7k..R.v.Uh.1.V.2m.A.....<w..}G.RT.....w.4.7.'...x.....V...v...I..3_6....{..IM...?..X4...)..W60..;1...[....mQ/...{.9n.[.W9.....3(...B5.U.d.......7....".^..16"........u!...{..7.....=E..MT...Q3k.C.0..T......3h.ea#d..92./..U.6...cW.%....H@..}B.._ ......W..Nyx.3....97.j...e... .@Ux..p>.X)V".`'H......x.}.T..I..I+....G.cD!.].U...$.Ng.........K...u0x.n)....9.*Z|..rM....'....&...=.o.3...qo6C...J.X..3..q.#a...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.860656015751546
                  Encrypted:false
                  SSDEEP:
                  MD5:CDFA7899F1C9114A0FD3601DDFB1D0F9
                  SHA1:2B801EC368658E5B8A31DA66F5E5225ABBC2B774
                  SHA-256:75132743EB64C3665CED9B3283D9A99C98D90233B75BF37A35ED37378BAF4BC6
                  SHA-512:91AC404E5FCDFDA5022D3E216C32072CC8B4467490E15E9A48AB6A1081BB8AEF473A3B937761A2868028ECDB9B7AD06254368FCB75C72BE826713315D3838DCA
                  Malicious:false
                  Preview:G...=Yy'.?..... ...M.+c.f}#...%......v.......F..........>I^t....UN.....`q.V(.A..m.{.~.V.l!.0..b....d..f.,5....'.Bi..?w.*/o..Z.........n....LqT..l.1...........nl.....:p.L.|a9.NE..iL.`...o|.....z...)...;..|.K..).....z...++'7..K...F.6|...$D..S.0.'..T6].S#5.K....."W.~.Jp.b.m..M...I...H...0..{.XH.....G.\...E..2..9.z,0.5....qPH.#.T..g.I...L.R@.TAi.....`....hL...A(.V.-u...p...Q....H..D.W.L.....EI.....@d...`..8T..>nU$.y...&pm.7.j.B.$..#......di..F.......'..U.y.z...L.).|...x*r......I_+.7..=Wa..}oy.p......C.L?.......?vp%9(q...C1..z..t........5z;........#7k..R.v.Uh.1.V.2m.A.....<w..}G.RT.....w.4.7.'...x.....V...v...I..3_6....{..IM...?..X4...)..W60..;1...[....mQ/...{.9n.[.W9.....3(...B5.U.d.......7....".^..16"........u!...{..7.....=E..MT...Q3k.C.0..T......3h.ea#d..92./..U.6...cW.%....H@..}B.._ ......W..Nyx.3....97.j...e... .@Ux..p>.X)V".`'H......x.}.T..I..I+....G.cD!.].U...$.Ng.........K...u0x.n)....9.*Z|..rM....'....&...=.o.3...qo6C...J.X..3..q.#a...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1098
                  Entropy (8bit):7.760097129466019
                  Encrypted:false
                  SSDEEP:
                  MD5:D9C456FD1130DDCF47ACC75518D2F043
                  SHA1:9BC04958F3439AD5B21B2F9D0E0CAB61F6A038A9
                  SHA-256:0BCF58DA0B70A6754762EACCB664655B08E9E04517754F0DDCD4163883B2DCB1
                  SHA-512:5A0D80E5E73F0518F75FEFDAC175A3E220B19E495E660E1CC1E26118D771E209FEA8B5058B52F9E37E152D8303D923518354DE76B70CB8F26C7C4BA3E06A93E9
                  Malicious:false
                  Preview:f.&.{(..l....3.@]...C..4...v.=..3-AW.&v...yUx....y.o@.KA.f...I5..{...1}.C.kf I....>.....f.....eI...!.d.."R.....2...E.F'...|..i...m..)x...=Ax..2.....=......86.P.p&.6C....+.n....W((Pm&k......Z.Q@...F.;..y.6.8........\.AAW.D..EU4..#-}.g.l.4.n.j....Y.B.....b...u........i..LfZ.B....c.B..OS.\d..U._..$.}.....s....f;u.T..wA....c.J..Xc.."...>d{..hM..].....0[`&...|...%L...x.i..I..y....T....`...6A.HsA.{...E.3..|....so/.1..oz..M.IA..;Y.'... .K...!..}../.......1..yw.T.B..f..ft`(.@B.fi.......@.04.......8.-...'.r..-$?A{......5.V.;...b.2TB.i...#.d..SM..r..c..h.y.3A...#).$].~......i..<..t...z..M.v..Me....Q...Cc......J!......)Q.. .a.l......,.a.TI.?.$m\u5.v.Q.......{..F!...4[...._d\@`n.c,..^..x......P...D.....Gy.=..h5..........-+k.s.>4..Z...c..]-c.q....'...u........qx>.......b.....6.O....M..y+...v..?.....&..>....)@......e.r.i.0...I.^/....q.D.p..].....j.....F.....Z....QX..#....@...i8...o.. ...G3.!....UGAi.&F..@=. Z7.G...?.....`.J..U0..;......v!..Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1098
                  Entropy (8bit):7.760097129466019
                  Encrypted:false
                  SSDEEP:
                  MD5:D9C456FD1130DDCF47ACC75518D2F043
                  SHA1:9BC04958F3439AD5B21B2F9D0E0CAB61F6A038A9
                  SHA-256:0BCF58DA0B70A6754762EACCB664655B08E9E04517754F0DDCD4163883B2DCB1
                  SHA-512:5A0D80E5E73F0518F75FEFDAC175A3E220B19E495E660E1CC1E26118D771E209FEA8B5058B52F9E37E152D8303D923518354DE76B70CB8F26C7C4BA3E06A93E9
                  Malicious:false
                  Preview:f.&.{(..l....3.@]...C..4...v.=..3-AW.&v...yUx....y.o@.KA.f...I5..{...1}.C.kf I....>.....f.....eI...!.d.."R.....2...E.F'...|..i...m..)x...=Ax..2.....=......86.P.p&.6C....+.n....W((Pm&k......Z.Q@...F.;..y.6.8........\.AAW.D..EU4..#-}.g.l.4.n.j....Y.B.....b...u........i..LfZ.B....c.B..OS.\d..U._..$.}.....s....f;u.T..wA....c.J..Xc.."...>d{..hM..].....0[`&...|...%L...x.i..I..y....T....`...6A.HsA.{...E.3..|....so/.1..oz..M.IA..;Y.'... .K...!..}../.......1..yw.T.B..f..ft`(.@B.fi.......@.04.......8.-...'.r..-$?A{......5.V.;...b.2TB.i...#.d..SM..r..c..h.y.3A...#).$].~......i..<..t...z..M.v..Me....Q...Cc......J!......)Q.. .a.l......,.a.TI.?.$m\u5.v.Q.......{..F!...4[...._d\@`n.c,..^..x......P...D.....Gy.=..h5..........-+k.s.>4..Z...c..]-c.q....'...u........qx>.......b.....6.O....M..y+...v..?.....&..>....)@......e.r.i.0...I.^/....q.D.p..].....j.....F.....Z....QX..#....@...i8...o.. ...G3.!....UGAi.&F..@=. Z7.G...?.....`.J..U0..;......v!..Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1098
                  Entropy (8bit):7.760097129466019
                  Encrypted:false
                  SSDEEP:
                  MD5:D9C456FD1130DDCF47ACC75518D2F043
                  SHA1:9BC04958F3439AD5B21B2F9D0E0CAB61F6A038A9
                  SHA-256:0BCF58DA0B70A6754762EACCB664655B08E9E04517754F0DDCD4163883B2DCB1
                  SHA-512:5A0D80E5E73F0518F75FEFDAC175A3E220B19E495E660E1CC1E26118D771E209FEA8B5058B52F9E37E152D8303D923518354DE76B70CB8F26C7C4BA3E06A93E9
                  Malicious:false
                  Preview:f.&.{(..l....3.@]...C..4...v.=..3-AW.&v...yUx....y.o@.KA.f...I5..{...1}.C.kf I....>.....f.....eI...!.d.."R.....2...E.F'...|..i...m..)x...=Ax..2.....=......86.P.p&.6C....+.n....W((Pm&k......Z.Q@...F.;..y.6.8........\.AAW.D..EU4..#-}.g.l.4.n.j....Y.B.....b...u........i..LfZ.B....c.B..OS.\d..U._..$.}.....s....f;u.T..wA....c.J..Xc.."...>d{..hM..].....0[`&...|...%L...x.i..I..y....T....`...6A.HsA.{...E.3..|....so/.1..oz..M.IA..;Y.'... .K...!..}../.......1..yw.T.B..f..ft`(.@B.fi.......@.04.......8.-...'.r..-$?A{......5.V.;...b.2TB.i...#.d..SM..r..c..h.y.3A...#).$].~......i..<..t...z..M.v..Me....Q...Cc......J!......)Q.. .a.l......,.a.TI.?.$m\u5.v.Q.......{..F!...4[...._d\@`n.c,..^..x......P...D.....Gy.=..h5..........-+k.s.>4..Z...c..]-c.q....'...u........qx>.......b.....6.O....M..y+...v..?.....&..>....)@......e.r.i.0...I.^/....q.D.p..].....j.....F.....Z....QX..#....@...i8...o.. ...G3.!....UGAi.&F..@=. Z7.G...?.....`.J..U0..;......v!..Z
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.843408452828493
                  Encrypted:false
                  SSDEEP:
                  MD5:4D41D7EB9C6D8E78675E16801C70EBF1
                  SHA1:397B73114EC21942F99BDC3AA4350B477BBB6418
                  SHA-256:B00AFA5F97D0F12CD5FF42E32495A863513ED4784DFD53F62B088EBEF9A491EB
                  SHA-512:17EDEDB41F858CB6BFCA0DAEFB323F1129A3BF7C66A7AB0692C3B023BC3FC99F1AE1CBFE4E02442F69F33CD094F2314F41567786BADA2DD9DD1BF0066F10CBFC
                  Malicious:false
                  Preview:..^2^E..7.o...)...<.I..%..jog......r#.l.n..z.g.....2.q...y.>aw..ax..).v."..^.=......Ed-$sA.......@....Q.(.....2....Y..+.S.X......`+.5.j...u......k{..2.b._...-..$..~,........M.)urso..t...#.t6..T....j.!."..G.=..Q....C....nb..!.....].U..P.U7:]....Ed,'.!.......6.(..?......v........Rw...}...*.^C.tW.....|k.R.@6.........k3...[.4...@.C.{@..<_..Xl....V.O....%x.*.,... ..7.q.w.....q.t.d.TIk.....-.n...?..s.......^cm.=.kM.D.>hES'..".....cD3^.....13....g.K.......M.p./2|....p......(e7Z.g.g-...-...:kg..*\#.4...8...1.>.b.....;.`s.o(p.....'...\.!=\F..Fli..9.G.C.......EZ[7..>.w.4\.F.7..B.Wg...-.qT.[......L.Q.dk....K...Q..;...[...VJ..b..C..5... .."..j$..[......L..!.. ...yc...:..(...|.P.8W.Z..CB..SC.....c~w.U..!.1..C.e..r.{.L$M..P..G..v.R......<.......)..5k.,~q6.`..a6dG,O..\.......r.#...t.A.E5..P...|D...!..J.?.....Wm.h.....7i...J&....H@.....b.,..SG..9...T..C.O........7.3:...T....\...R.vA....G<....81..3...LH_...c...tb..kO.Uc;w..Ix....,.G.o.u!......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.843408452828493
                  Encrypted:false
                  SSDEEP:
                  MD5:4D41D7EB9C6D8E78675E16801C70EBF1
                  SHA1:397B73114EC21942F99BDC3AA4350B477BBB6418
                  SHA-256:B00AFA5F97D0F12CD5FF42E32495A863513ED4784DFD53F62B088EBEF9A491EB
                  SHA-512:17EDEDB41F858CB6BFCA0DAEFB323F1129A3BF7C66A7AB0692C3B023BC3FC99F1AE1CBFE4E02442F69F33CD094F2314F41567786BADA2DD9DD1BF0066F10CBFC
                  Malicious:false
                  Preview:..^2^E..7.o...)...<.I..%..jog......r#.l.n..z.g.....2.q...y.>aw..ax..).v."..^.=......Ed-$sA.......@....Q.(.....2....Y..+.S.X......`+.5.j...u......k{..2.b._...-..$..~,........M.)urso..t...#.t6..T....j.!."..G.=..Q....C....nb..!.....].U..P.U7:]....Ed,'.!.......6.(..?......v........Rw...}...*.^C.tW.....|k.R.@6.........k3...[.4...@.C.{@..<_..Xl....V.O....%x.*.,... ..7.q.w.....q.t.d.TIk.....-.n...?..s.......^cm.=.kM.D.>hES'..".....cD3^.....13....g.K.......M.p./2|....p......(e7Z.g.g-...-...:kg..*\#.4...8...1.>.b.....;.`s.o(p.....'...\.!=\F..Fli..9.G.C.......EZ[7..>.w.4\.F.7..B.Wg...-.qT.[......L.Q.dk....K...Q..;...[...VJ..b..C..5... .."..j$..[......L..!.. ...yc...:..(...|.P.8W.Z..CB..SC.....c~w.U..!.1..C.e..r.{.L$M..P..G..v.R......<.......)..5k.,~q6.`..a6dG,O..\.......r.#...t.A.E5..P...|D...!..J.?.....Wm.h.....7i...J&....H@.....b.,..SG..9...T..C.O........7.3:...T....\...R.vA....G<....81..3...LH_...c...tb..kO.Uc;w..Ix....,.G.o.u!......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.843408452828493
                  Encrypted:false
                  SSDEEP:
                  MD5:4D41D7EB9C6D8E78675E16801C70EBF1
                  SHA1:397B73114EC21942F99BDC3AA4350B477BBB6418
                  SHA-256:B00AFA5F97D0F12CD5FF42E32495A863513ED4784DFD53F62B088EBEF9A491EB
                  SHA-512:17EDEDB41F858CB6BFCA0DAEFB323F1129A3BF7C66A7AB0692C3B023BC3FC99F1AE1CBFE4E02442F69F33CD094F2314F41567786BADA2DD9DD1BF0066F10CBFC
                  Malicious:false
                  Preview:..^2^E..7.o...)...<.I..%..jog......r#.l.n..z.g.....2.q...y.>aw..ax..).v."..^.=......Ed-$sA.......@....Q.(.....2....Y..+.S.X......`+.5.j...u......k{..2.b._...-..$..~,........M.)urso..t...#.t6..T....j.!."..G.=..Q....C....nb..!.....].U..P.U7:]....Ed,'.!.......6.(..?......v........Rw...}...*.^C.tW.....|k.R.@6.........k3...[.4...@.C.{@..<_..Xl....V.O....%x.*.,... ..7.q.w.....q.t.d.TIk.....-.n...?..s.......^cm.=.kM.D.>hES'..".....cD3^.....13....g.K.......M.p./2|....p......(e7Z.g.g-...-...:kg..*\#.4...8...1.>.b.....;.`s.o(p.....'...\.!=\F..Fli..9.G.C.......EZ[7..>.w.4\.F.7..B.Wg...-.qT.[......L.Q.dk....K...Q..;...[...VJ..b..C..5... .."..j$..[......L..!.. ...yc...:..(...|.P.8W.Z..CB..SC.....c~w.U..!.1..C.e..r.{.L$M..P..G..v.R......<.......)..5k.,~q6.`..a6dG,O..\.......r.#...t.A.E5..P...|D...!..J.?.....Wm.h.....7i...J&....H@.....b.,..SG..9...T..C.O........7.3:...T....\...R.vA....G<....81..3...LH_...c...tb..kO.Uc;w..Ix....,.G.o.u!......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.881419852033789
                  Encrypted:false
                  SSDEEP:
                  MD5:89915B014ECD5675AF36CAB9329D3279
                  SHA1:06D9CA883077343307BD368E27936B40F4291993
                  SHA-256:A0681391180C956702BC3F94AC7E1ABD91D15DB3ECB043A95948D6E8191F42CA
                  SHA-512:7B9473D3ACFE95588D35EE731A83C6A1CBC6A906A9B48ECB4D6A9BFAFF1273898B392239C1BB15DD21F2A1A01423A639C4DDBAA725FB2F6F5FEC5E0AFDF8C2A0
                  Malicious:false
                  Preview:....7s.S3.8l..zX..}.}........r.TD*.p...Q..|.F....E.|..........2..dx.}.>.mT..b.....P*M.F.T.;B......b`.......V......X`<D1A...m...^..]..kF........a'M..........F..A..q....@.b.._. .O"...m.....j..J.*bnr..I...O_S...Y.2...8c.$...., W.)5.|......Y.)x.".\6f$.t.s.C.d...5AK...$6..Q.GU..'.-1...`N.HC,..R.E.l.6..va..8......9...k..6..yL..X.....!..do{|...1...p.i.].(..|S.WP..G:..~...b.....f.k5.ON8}...j.O..dK..U.G..p...H...(.#.......3F....#...|.3......c....f.E...B-t.y..-.9 ....3...mYd...V.h....p*.B-..........-..'..<..._..<..z.....IN..l.l...<..{U...Oo..6.x. ..,.=..f..~#..[. ......t.."...$..o...5sm.n}.Hd=D....d.......0.....+B...<...l .D|.6.J...@#;.v^.V5.C..Iu...lW.I.../....).....q..,...Qf.....(.........3Oz^.eX.j..?q...Q..5NP.C5$..l&n...T.Aq....H.Mf..9...})...N[.{..&,...[k.+...I..oT.."...pkDI.....p6.sa~l.).R.._.<.....f;$..tg.g..;O(:....j..n~H..W~....(rUEi.8...@.....iF).f23...yH>\.Z..%....S0W..Q.x1hG5G..[`.1c.!.T....'....k..&....O.,..]e..s..[bQ.{.&?..X.7.T\.+.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.881419852033789
                  Encrypted:false
                  SSDEEP:
                  MD5:89915B014ECD5675AF36CAB9329D3279
                  SHA1:06D9CA883077343307BD368E27936B40F4291993
                  SHA-256:A0681391180C956702BC3F94AC7E1ABD91D15DB3ECB043A95948D6E8191F42CA
                  SHA-512:7B9473D3ACFE95588D35EE731A83C6A1CBC6A906A9B48ECB4D6A9BFAFF1273898B392239C1BB15DD21F2A1A01423A639C4DDBAA725FB2F6F5FEC5E0AFDF8C2A0
                  Malicious:false
                  Preview:....7s.S3.8l..zX..}.}........r.TD*.p...Q..|.F....E.|..........2..dx.}.>.mT..b.....P*M.F.T.;B......b`.......V......X`<D1A...m...^..]..kF........a'M..........F..A..q....@.b.._. .O"...m.....j..J.*bnr..I...O_S...Y.2...8c.$...., W.)5.|......Y.)x.".\6f$.t.s.C.d...5AK...$6..Q.GU..'.-1...`N.HC,..R.E.l.6..va..8......9...k..6..yL..X.....!..do{|...1...p.i.].(..|S.WP..G:..~...b.....f.k5.ON8}...j.O..dK..U.G..p...H...(.#.......3F....#...|.3......c....f.E...B-t.y..-.9 ....3...mYd...V.h....p*.B-..........-..'..<..._..<..z.....IN..l.l...<..{U...Oo..6.x. ..,.=..f..~#..[. ......t.."...$..o...5sm.n}.Hd=D....d.......0.....+B...<...l .D|.6.J...@#;.v^.V5.C..Iu...lW.I.../....).....q..,...Qf.....(.........3Oz^.eX.j..?q...Q..5NP.C5$..l&n...T.Aq....H.Mf..9...})...N[.{..&,...[k.+...I..oT.."...pkDI.....p6.sa~l.).R.._.<.....f;$..tg.g..;O(:....j..n~H..W~....(rUEi.8...@.....iF).f23...yH>\.Z..%....S0W..Q.x1hG5G..[`.1c.!.T....'....k..&....O.,..]e..s..[bQ.{.&?..X.7.T\.+.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1587
                  Entropy (8bit):7.881419852033789
                  Encrypted:false
                  SSDEEP:
                  MD5:89915B014ECD5675AF36CAB9329D3279
                  SHA1:06D9CA883077343307BD368E27936B40F4291993
                  SHA-256:A0681391180C956702BC3F94AC7E1ABD91D15DB3ECB043A95948D6E8191F42CA
                  SHA-512:7B9473D3ACFE95588D35EE731A83C6A1CBC6A906A9B48ECB4D6A9BFAFF1273898B392239C1BB15DD21F2A1A01423A639C4DDBAA725FB2F6F5FEC5E0AFDF8C2A0
                  Malicious:false
                  Preview:....7s.S3.8l..zX..}.}........r.TD*.p...Q..|.F....E.|..........2..dx.}.>.mT..b.....P*M.F.T.;B......b`.......V......X`<D1A...m...^..]..kF........a'M..........F..A..q....@.b.._. .O"...m.....j..J.*bnr..I...O_S...Y.2...8c.$...., W.)5.|......Y.)x.".\6f$.t.s.C.d...5AK...$6..Q.GU..'.-1...`N.HC,..R.E.l.6..va..8......9...k..6..yL..X.....!..do{|...1...p.i.].(..|S.WP..G:..~...b.....f.k5.ON8}...j.O..dK..U.G..p...H...(.#.......3F....#...|.3......c....f.E...B-t.y..-.9 ....3...mYd...V.h....p*.B-..........-..'..<..._..<..z.....IN..l.l...<..{U...Oo..6.x. ..,.=..f..~#..[. ......t.."...$..o...5sm.n}.Hd=D....d.......0.....+B...<...l .D|.6.J...@#;.v^.V5.C..Iu...lW.I.../....).....q..,...Qf.....(.........3Oz^.eX.j..?q...Q..5NP.C5$..l&n...T.Aq....H.Mf..9...})...N[.{..&,...[k.+...I..oT.."...pkDI.....p6.sa~l.).R.._.<.....f;$..tg.g..;O(:....j..n~H..W~....(rUEi.8...@.....iF).f23...yH>\.Z..%....S0W..Q.x1hG5G..[`.1c.!.T....'....k..&....O.,..]e..s..[bQ.{.&?..X.7.T\.+.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:Dyalog APL version 44.108
                  Category:dropped
                  Size (bytes):696581
                  Entropy (8bit):7.999722351365021
                  Encrypted:true
                  SSDEEP:
                  MD5:4C0380E1008FB3681BC1FC51B949F4A6
                  SHA1:55D4A341A0A6F03A9E77B8950FD541421964F38B
                  SHA-256:8877A6B07DAF2A8A0AA4051B4B008263B61DB640F440060C70C056E1B59BD3E4
                  SHA-512:0F6CE2C9AEF3554D554D15A5B2ADF217AB6CBDDA4278C30B813C27F00E164E089247DF4BE941C2AF2AF796000184390D475AB0104B5C4EA6257B108B952DCBE2
                  Malicious:true
                  Preview:..,l..o....../C....V...wG."....>.FS\Z.<...M.:.rL.[.(...U..j.z.d|.1<..k.S.B].7N.(/....2H.9.U..V.T..".e0.[H`7F[.(......C?-./\..".. ...1.hg7.tY6..CyEX.n.2t.a.).....1...OV.....m.1.f.E.O..5......1*/.+|.B...;.B..}.N.j.. ..#..dE.W9.8.dJh..... .D.r...[v [.R..A].t..4!?..j.W.D.(.Nf..9".9o.O4.....e.O.(....>1......Z..|...*.._.....M...q.E`.....Q.?..n.2-T...).3./!..=...Og].QM...x..o)......,~..n~.Y....ZF. h.VK+.?......!.D.[....#........+q.y.f..n.|hmw...A@.<VI."$.$...M;..D......q'.@.:.......SR>....0....?.[Zp&.;.U.s......[.Q......5..gGMV../...N2..........U.._S..z.n...n...0S.......XOf...j.[.bHF....K.l.p.....\\.].!....o.....` zyR2....7..1'....0.X....8.`e.A9.../M....o...:....@D*..^?......e.4..X.....+I...-..j...+.YQ...>.......ec.N8xG..`.N.!...=4sfV-....g..kw.HWS.*u.o.M..K.dCm"x`....h.....^.w.Z....p3.].0u...6.m.=....Z......).7}..$.WJ.}.i.<.q."..mX+.&.%p.z.[..G AB&.q..>..I....Z.&...U..A)...0.K..t........ .G..5.B..\.s.dDW..r.P.n6E..'-..c`.v.E.....>@.w.hTt
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:Dyalog APL version 44.108
                  Category:dropped
                  Size (bytes):696581
                  Entropy (8bit):7.999722351365021
                  Encrypted:true
                  SSDEEP:
                  MD5:4C0380E1008FB3681BC1FC51B949F4A6
                  SHA1:55D4A341A0A6F03A9E77B8950FD541421964F38B
                  SHA-256:8877A6B07DAF2A8A0AA4051B4B008263B61DB640F440060C70C056E1B59BD3E4
                  SHA-512:0F6CE2C9AEF3554D554D15A5B2ADF217AB6CBDDA4278C30B813C27F00E164E089247DF4BE941C2AF2AF796000184390D475AB0104B5C4EA6257B108B952DCBE2
                  Malicious:true
                  Preview:..,l..o....../C....V...wG."....>.FS\Z.<...M.:.rL.[.(...U..j.z.d|.1<..k.S.B].7N.(/....2H.9.U..V.T..".e0.[H`7F[.(......C?-./\..".. ...1.hg7.tY6..CyEX.n.2t.a.).....1...OV.....m.1.f.E.O..5......1*/.+|.B...;.B..}.N.j.. ..#..dE.W9.8.dJh..... .D.r...[v [.R..A].t..4!?..j.W.D.(.Nf..9".9o.O4.....e.O.(....>1......Z..|...*.._.....M...q.E`.....Q.?..n.2-T...).3./!..=...Og].QM...x..o)......,~..n~.Y....ZF. h.VK+.?......!.D.[....#........+q.y.f..n.|hmw...A@.<VI."$.$...M;..D......q'.@.:.......SR>....0....?.[Zp&.;.U.s......[.Q......5..gGMV../...N2..........U.._S..z.n...n...0S.......XOf...j.[.bHF....K.l.p.....\\.].!....o.....` zyR2....7..1'....0.X....8.`e.A9.../M....o...:....@D*..^?......e.4..X.....+I...-..j...+.YQ...>.......ec.N8xG..`.N.!...=4sfV-....g..kw.HWS.*u.o.M..K.dCm"x`....h.....^.w.Z....p3.].0u...6.m.=....Z......).7}..$.WJ.}.i.<.q."..mX+.&.%p.z.[..G AB&.q..>..I....Z.&...U..A)...0.K..t........ .G..5.B..\.s.dDW..r.P.n6E..'-..c`.v.E.....>@.w.hTt
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:Dyalog APL version 44.108
                  Category:dropped
                  Size (bytes):696581
                  Entropy (8bit):7.999722351365021
                  Encrypted:true
                  SSDEEP:
                  MD5:4C0380E1008FB3681BC1FC51B949F4A6
                  SHA1:55D4A341A0A6F03A9E77B8950FD541421964F38B
                  SHA-256:8877A6B07DAF2A8A0AA4051B4B008263B61DB640F440060C70C056E1B59BD3E4
                  SHA-512:0F6CE2C9AEF3554D554D15A5B2ADF217AB6CBDDA4278C30B813C27F00E164E089247DF4BE941C2AF2AF796000184390D475AB0104B5C4EA6257B108B952DCBE2
                  Malicious:true
                  Preview:..,l..o....../C....V...wG."....>.FS\Z.<...M.:.rL.[.(...U..j.z.d|.1<..k.S.B].7N.(/....2H.9.U..V.T..".e0.[H`7F[.(......C?-./\..".. ...1.hg7.tY6..CyEX.n.2t.a.).....1...OV.....m.1.f.E.O..5......1*/.+|.B...;.B..}.N.j.. ..#..dE.W9.8.dJh..... .D.r...[v [.R..A].t..4!?..j.W.D.(.Nf..9".9o.O4.....e.O.(....>1......Z..|...*.._.....M...q.E`.....Q.?..n.2-T...).3./!..=...Og].QM...x..o)......,~..n~.Y....ZF. h.VK+.?......!.D.[....#........+q.y.f..n.|hmw...A@.<VI."$.$...M;..D......q'.@.:.......SR>....0....?.[Zp&.;.U.s......[.Q......5..gGMV../...N2..........U.._S..z.n...n...0S.......XOf...j.[.bHF....K.l.p.....\\.].!....o.....` zyR2....7..1'....0.X....8.`e.A9.../M....o...:....@D*..^?......e.4..X.....+I...-..j...+.YQ...>.......ec.N8xG..`.N.!...=4sfV-....g..kw.HWS.*u.o.M..K.dCm"x`....h.....^.w.Z....p3.].0u...6.m.=....Z......).7}..$.WJ.}.i.<.q."..mX+.&.%p.z.[..G AB&.q..>..I....Z.&...U..A)...0.K..t........ .G..5.B..\.s.dDW..r.P.n6E..'-..c`.v.E.....>@.w.hTt
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1117804
                  Entropy (8bit):7.999837158780516
                  Encrypted:true
                  SSDEEP:
                  MD5:9B192FA330140AD4DEC361840FCDC8F4
                  SHA1:A9C1A96DA97D44AEE10ECC3E814498774E8F6351
                  SHA-256:28E2CA7697CA5046BC2E431512C06FDFCA319453E4928B01513C82D7ED465367
                  SHA-512:025223A66F7F9557FA8BC70F42A6902BFE4D80B15247771160C2797B51F471C5C2C833EFE9050327AC6E6D777AEF43B761721C320E7BDB54C9AAB0D8712E8005
                  Malicious:true
                  Preview:}6.....~....R....t..Q..8f.1.7.f[...cqd1Fa...r../.u]F....,......z.k.S.#...("U\....P7...y.m.,P_..&.Q.+.....'..d..UX.....v....../..X.F...4t..L._...%.).{)..../.jUk..S..........D...?+6?Y.Z...s.o.3.....q8......)...I..W.X........N.=g,6...K@R... /.AJ...<....P=...Y...._...[.;E.w..9..5d.@......A..*A1..j.5.d...[D:m)..J..J.f[..m.^Fw.Hn.+.......{x.vp>Q..G;...!...C!..H.....T.\...wl...D.........!......=a`.(;.w._. ..Q.R.....7...i.....H.-.."...Z.{9'...s?.`.G...T!z j.O..5........x....]m3.P...0.C..U.%....../.W?.H..m.7........"..;h..G ..%.v<^f.S......4P.R/..^...:|.U.3..\.e.i.;6...S.9.(.;.h.p.dv..oG...}.....ES.7N...)JGN.....]..pp....f....C...I@.7p.f..G.P....|...}.]..(.qU..f..;...Z.}=i.S..k..+].{....^.....T..7..^..-..Z).Q....Uz..92..d.5T..il.O..X..d....2...X(..Z0.."......Z^....@.....2.O.RwD.m@...o....[p/..4.C5...K...ea...S$.J....b..4~u.Q..&F.OWRQrH..P.>.[B.w.G..o...........65.p.>.xA#...~./}..|..s.w.aE0u;.n.?....Y...7..".X....E(%.9...{j...D\>.....R.t...._
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1117804
                  Entropy (8bit):7.999837158780516
                  Encrypted:true
                  SSDEEP:
                  MD5:9B192FA330140AD4DEC361840FCDC8F4
                  SHA1:A9C1A96DA97D44AEE10ECC3E814498774E8F6351
                  SHA-256:28E2CA7697CA5046BC2E431512C06FDFCA319453E4928B01513C82D7ED465367
                  SHA-512:025223A66F7F9557FA8BC70F42A6902BFE4D80B15247771160C2797B51F471C5C2C833EFE9050327AC6E6D777AEF43B761721C320E7BDB54C9AAB0D8712E8005
                  Malicious:true
                  Preview:}6.....~....R....t..Q..8f.1.7.f[...cqd1Fa...r../.u]F....,......z.k.S.#...("U\....P7...y.m.,P_..&.Q.+.....'..d..UX.....v....../..X.F...4t..L._...%.).{)..../.jUk..S..........D...?+6?Y.Z...s.o.3.....q8......)...I..W.X........N.=g,6...K@R... /.AJ...<....P=...Y...._...[.;E.w..9..5d.@......A..*A1..j.5.d...[D:m)..J..J.f[..m.^Fw.Hn.+.......{x.vp>Q..G;...!...C!..H.....T.\...wl...D.........!......=a`.(;.w._. ..Q.R.....7...i.....H.-.."...Z.{9'...s?.`.G...T!z j.O..5........x....]m3.P...0.C..U.%....../.W?.H..m.7........"..;h..G ..%.v<^f.S......4P.R/..^...:|.U.3..\.e.i.;6...S.9.(.;.h.p.dv..oG...}.....ES.7N...)JGN.....]..pp....f....C...I@.7p.f..G.P....|...}.]..(.qU..f..;...Z.}=i.S..k..+].{....^.....T..7..^..-..Z).Q....Uz..92..d.5T..il.O..X..d....2...X(..Z0.."......Z^....@.....2.O.RwD.m@...o....[p/..4.C5...K...ea...S$.J....b..4~u.Q..&F.OWRQrH..P.>.[B.w.G..o...........65.p.>.xA#...~./}..|..s.w.aE0u;.n.?....Y...7..".X....E(%.9...{j...D\>.....R.t...._
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1117804
                  Entropy (8bit):7.999837158780516
                  Encrypted:true
                  SSDEEP:
                  MD5:9B192FA330140AD4DEC361840FCDC8F4
                  SHA1:A9C1A96DA97D44AEE10ECC3E814498774E8F6351
                  SHA-256:28E2CA7697CA5046BC2E431512C06FDFCA319453E4928B01513C82D7ED465367
                  SHA-512:025223A66F7F9557FA8BC70F42A6902BFE4D80B15247771160C2797B51F471C5C2C833EFE9050327AC6E6D777AEF43B761721C320E7BDB54C9AAB0D8712E8005
                  Malicious:true
                  Preview:}6.....~....R....t..Q..8f.1.7.f[...cqd1Fa...r../.u]F....,......z.k.S.#...("U\....P7...y.m.,P_..&.Q.+.....'..d..UX.....v....../..X.F...4t..L._...%.).{)..../.jUk..S..........D...?+6?Y.Z...s.o.3.....q8......)...I..W.X........N.=g,6...K@R... /.AJ...<....P=...Y...._...[.;E.w..9..5d.@......A..*A1..j.5.d...[D:m)..J..J.f[..m.^Fw.Hn.+.......{x.vp>Q..G;...!...C!..H.....T.\...wl...D.........!......=a`.(;.w._. ..Q.R.....7...i.....H.-.."...Z.{9'...s?.`.G...T!z j.O..5........x....]m3.P...0.C..U.%....../.W?.H..m.7........"..;h..G ..%.v<^f.S......4P.R/..^...:|.U.3..\.e.i.;6...S.9.(.;.h.p.dv..oG...}.....ES.7N...)JGN.....]..pp....f....C...I@.7p.f..G.P....|...}.]..(.qU..f..;...Z.}=i.S..k..+].{....^.....T..7..^..-..Z).Q....Uz..92..d.5T..il.O..X..d....2...X(..Z0.."......Z^....@.....2.O.RwD.m@...o....[p/..4.C5...K...ea...S$.J....b..4~u.Q..&F.OWRQrH..P.>.[B.w.G..o...........65.p.>.xA#...~./}..|..s.w.aE0u;.n.?....Y...7..".X....E(%.9...{j...D\>.....R.t...._
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):451
                  Entropy (8bit):7.378645271629178
                  Encrypted:false
                  SSDEEP:
                  MD5:07C47235CFD052F8D19011CADAD11CEC
                  SHA1:D598346CF20F03B6AE860E2FF0838A755BC7DFCD
                  SHA-256:C61573D592AE4CE115DF2C6912ACF39B4F25E25E3B3707BAFD133C8BD178AAD1
                  SHA-512:99E5587FC1EC92425216FDFE19F215328A36EE34F82C9772640C9FAF6A602237E8B7B92B7ECC0201C65F41A64346F94D21C9034A54E4EBD6B8C39A2E055EEB97
                  Malicious:false
                  Preview:{..s.5t....".mAxN..^...#.%...1._...6*...U.......d..#.....BS.O )...@z.b..~.....zy..../.M.{......`.r$T....G..-....Y.A.|#....jOL.L.6..X.F.m....1.j"........9....A...h.`...<'.y..p....+........<.Q.|..1.+ F2*r.R4N|..sYE..fdw.i.Y(.{.SF.c~a.......0.#....[B..)?"..c.{.0..&j..J..o...JP~.x.T..2..................yb..R[...w.D.%.9a.-C^.6.E........%....9.#.........}..;.TB.-.NY...%;f2.....=.vs:..S..V3f....C0...Wn.../........#...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):451
                  Entropy (8bit):7.378645271629178
                  Encrypted:false
                  SSDEEP:
                  MD5:07C47235CFD052F8D19011CADAD11CEC
                  SHA1:D598346CF20F03B6AE860E2FF0838A755BC7DFCD
                  SHA-256:C61573D592AE4CE115DF2C6912ACF39B4F25E25E3B3707BAFD133C8BD178AAD1
                  SHA-512:99E5587FC1EC92425216FDFE19F215328A36EE34F82C9772640C9FAF6A602237E8B7B92B7ECC0201C65F41A64346F94D21C9034A54E4EBD6B8C39A2E055EEB97
                  Malicious:false
                  Preview:{..s.5t....".mAxN..^...#.%...1._...6*...U.......d..#.....BS.O )...@z.b..~.....zy..../.M.{......`.r$T....G..-....Y.A.|#....jOL.L.6..X.F.m....1.j"........9....A...h.`...<'.y..p....+........<.Q.|..1.+ F2*r.R4N|..sYE..fdw.i.Y(.{.SF.c~a.......0.#....[B..)?"..c.{.0..&j..J..o...JP~.x.T..2..................yb..R[...w.D.%.9a.-C^.6.E........%....9.#.........}..;.TB.-.NY...%;f2.....=.vs:..S..V3f....C0...Wn.../........#...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):451
                  Entropy (8bit):7.378645271629178
                  Encrypted:false
                  SSDEEP:
                  MD5:07C47235CFD052F8D19011CADAD11CEC
                  SHA1:D598346CF20F03B6AE860E2FF0838A755BC7DFCD
                  SHA-256:C61573D592AE4CE115DF2C6912ACF39B4F25E25E3B3707BAFD133C8BD178AAD1
                  SHA-512:99E5587FC1EC92425216FDFE19F215328A36EE34F82C9772640C9FAF6A602237E8B7B92B7ECC0201C65F41A64346F94D21C9034A54E4EBD6B8C39A2E055EEB97
                  Malicious:false
                  Preview:{..s.5t....".mAxN..^...#.%...1._...6*...U.......d..#.....BS.O )...@z.b..~.....zy..../.M.{......`.r$T....G..-....Y.A.|#....jOL.L.6..X.F.m....1.j"........9....A...h.`...<'.y..p....+........<.Q.|..1.+ F2*r.R4N|..sYE..fdw.i.Y(.{.SF.c~a.......0.#....[B..)?"..c.{.0..&j..J..o...JP~.x.T..2..................yb..R[...w.D.%.9a.-C^.6.E........%....9.#.........}..;.TB.-.NY...%;f2.....=.vs:..S..V3f....C0...Wn.../........#...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10717808
                  Entropy (8bit):6.467820237483993
                  Encrypted:false
                  SSDEEP:
                  MD5:D2C229E9028BC100828BB7FC1D326585
                  SHA1:4109E1577FFE840934B64717F6939C66B08D3B4F
                  SHA-256:10CB86D8F22124E5494E045BDB7407EB3546B0079BA09B0523B46D2C3B5BFE58
                  SHA-512:B91D7324064C50DFC9827E4FE7EB0945067A4D19F03A59697ADC53A936513D25AB94038BDBEC4A0EC3D3EAD76B0E98A771747430D3078134FB658D1C6BA548C4
                  Malicious:false
                  Preview:42p....s...[6.G...DD........ev7|..D._:..V..<../TBR.+..g.P..3....r_f.......Bd....S\"4?....NnE....v ...u......r.......^.M...5R..Yk.5Jq".....>....~"..;..O.g.,.mCk..X..y..%.......u~<.)O........g.s.z+...uP<n.........OR..^...../....1........4..Q....C...8...t_..'.y.0p~..Z9/l.+.. 3.....O.~.........0c....qK......P..PA.c...cn.cR.&.(@.aP.O...tT.u....b3..P._:v*....h...'..#..W..l;.....a.._K92...2.:s.Cc ..Z+9.J..".Y .N..-...Ub..H8}..;?.f..ie.......P.S'....#.F........5.!..@.v_..G]....w..Mn._...pk..c..u......3.........H|...4.8}u..S._......7..{_.~..oSV..1;.!.m.X..".1FZ.-..v...X.f../PQ..~*_P......!a$.uri.,J.`..=.jrocG...n..?.....x4..V..`05.....R..I...).........]J`.,..^.,....m.L..2{.v.........(..b.#s1a...]h.Eb........-<.b..9.&...e.>...^m...X..@5..G...y.&.Th....(..0[....._h.f..J]q...!H.r.......!....lr."...Gk6.q-...e$CxE..q8I.B...'".?.S\...~Z..)..`...9.e.j-.9>r-.;..S..Y.,.'h.....`.\.N.e........Y.S.F.)..]!!..4...!!|-@...................LM..^m..L0._MU..u...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):10717808
                  Entropy (8bit):6.467820237483993
                  Encrypted:false
                  SSDEEP:
                  MD5:D2C229E9028BC100828BB7FC1D326585
                  SHA1:4109E1577FFE840934B64717F6939C66B08D3B4F
                  SHA-256:10CB86D8F22124E5494E045BDB7407EB3546B0079BA09B0523B46D2C3B5BFE58
                  SHA-512:B91D7324064C50DFC9827E4FE7EB0945067A4D19F03A59697ADC53A936513D25AB94038BDBEC4A0EC3D3EAD76B0E98A771747430D3078134FB658D1C6BA548C4
                  Malicious:false
                  Preview:42p....s...[6.G...DD........ev7|..D._:..V..<../TBR.+..g.P..3....r_f.......Bd....S\"4?....NnE....v ...u......r.......^.M...5R..Yk.5Jq".....>....~"..;..O.g.,.mCk..X..y..%.......u~<.)O........g.s.z+...uP<n.........OR..^...../....1........4..Q....C...8...t_..'.y.0p~..Z9/l.+.. 3.....O.~.........0c....qK......P..PA.c...cn.cR.&.(@.aP.O...tT.u....b3..P._:v*....h...'..#..W..l;.....a.._K92...2.:s.Cc ..Z+9.J..".Y .N..-...Ub..H8}..;?.f..ie.......P.S'....#.F........5.!..@.v_..G]....w..Mn._...pk..c..u......3.........H|...4.8}u..S._......7..{_.~..oSV..1;.!.m.X..".1FZ.-..v...X.f../PQ..~*_P......!a$.uri.,J.`..=.jrocG...n..?.....x4..V..`05.....R..I...).........]J`.,..^.,....m.L..2{.v.........(..b.#s1a...]h.Eb........-<.b..9.&...e.>...^m...X..@5..G...y.&.Th....(..0[....._h.f..J]q...!H.r.......!....lr."...Gk6.q-...e$CxE..q8I.B...'".?.S\...~Z..)..`...9.e.j-.9>r-.;..S..Y.,.'h.....`.\.N.e........Y.S.F.)..]!!..4...!!|-@...................LM..^m..L0._MU..u...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4392560
                  Entropy (8bit):7.999962355717949
                  Encrypted:true
                  SSDEEP:
                  MD5:5CF275A20100B87E4AA607D956C4175B
                  SHA1:5E52148F80C43AAF8412C2BF482B5DF74D6BFB14
                  SHA-256:8F7676D93659DD43A83A2E7266C3C5FB1BB86B23E74F0BC9DDEF848B7F43C8FA
                  SHA-512:FC962BBB3F92BB22F2C81977A301A5D99A225D6F2B964F92D234C62AD79E9B3AE92EBA237FE744F208CE1DBA86658FCC9431FC5193FAF096988186A527B6AE1D
                  Malicious:true
                  Preview:....,..f..]k.[..I......,j.[ky.{.Nc...I...C.....sl.h.............n...o..HK..q...d&m^..k?/.\...t:..N.....=........-..z..'n.i.:...:l....j.{..kzL1......+eH..d....,.!.y...K.c..%..M.k.`9...._taJbs.K.A.|....C.&s.].9.L*...-GS....^)D.k...c..!....5..C55`....V..@&!...2...m......N9..m.`7.a......gN...Z.8......u.V.m.F..s.J...?..A...H..r...p...YB..r.......AV..RY<.k.Z[....g..w...6({.%(.....B.+$.Tk\$.I....W...._.+.4_....LU..Pe.@.V.;<.....;....@..6..h......9}.Ys9....()...d....@.>2.....D.....8.4.+^a.Zne..VPt..v..:.5.TC..<........5Q.#.f}|..1..npd$...vgO.%eK}...`.(e...N....._.....<...wA...9.2]..5&..j....n......}.5.#..[]:.{...`.bt.....-.......>...@......h..@z..k...iVg<.....(.-4.../7....Bi....G....k.f(F..Eq.Pw,....g.......`....2....x+.+.G...a=\.u.E..."?'..!.`M-..c....U.#..q.. .u.Y.Q.&E..87..J%c]..2lB.\..k%0...Wq.$Zu........Y... ..F.](}...;.......C.2b.W..l.L.e.9Q.cq.D.....e..%i...)..p.B4a..!.di....@.X..g......^......m.;..[....T..7.r..L..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4392560
                  Entropy (8bit):7.999962355717949
                  Encrypted:true
                  SSDEEP:
                  MD5:5CF275A20100B87E4AA607D956C4175B
                  SHA1:5E52148F80C43AAF8412C2BF482B5DF74D6BFB14
                  SHA-256:8F7676D93659DD43A83A2E7266C3C5FB1BB86B23E74F0BC9DDEF848B7F43C8FA
                  SHA-512:FC962BBB3F92BB22F2C81977A301A5D99A225D6F2B964F92D234C62AD79E9B3AE92EBA237FE744F208CE1DBA86658FCC9431FC5193FAF096988186A527B6AE1D
                  Malicious:true
                  Preview:....,..f..]k.[..I......,j.[ky.{.Nc...I...C.....sl.h.............n...o..HK..q...d&m^..k?/.\...t:..N.....=........-..z..'n.i.:...:l....j.{..kzL1......+eH..d....,.!.y...K.c..%..M.k.`9...._taJbs.K.A.|....C.&s.].9.L*...-GS....^)D.k...c..!....5..C55`....V..@&!...2...m......N9..m.`7.a......gN...Z.8......u.V.m.F..s.J...?..A...H..r...p...YB..r.......AV..RY<.k.Z[....g..w...6({.%(.....B.+$.Tk\$.I....W...._.+.4_....LU..Pe.@.V.;<.....;....@..6..h......9}.Ys9....()...d....@.>2.....D.....8.4.+^a.Zne..VPt..v..:.5.TC..<........5Q.#.f}|..1..npd$...vgO.%eK}...`.(e...N....._.....<...wA...9.2]..5&..j....n......}.5.#..[]:.{...`.bt.....-.......>...@......h..@z..k...iVg<.....(.-4.../7....Bi....G....k.f(F..Eq.Pw,....g.......`....2....x+.+.G...a=\.u.E..."?'..!.`M-..c....U.#..q.. .u.Y.Q.&E..87..J%c]..2lB.\..k%0...Wq.$Zu........Y... ..F.](}...;.......C.2b.W..l.L.e.9Q.cq.D.....e..%i...)..p.B4a..!.di....@.X..g......^......m.;..[....T..7.r..L..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4392560
                  Entropy (8bit):7.999962355717949
                  Encrypted:true
                  SSDEEP:
                  MD5:5CF275A20100B87E4AA607D956C4175B
                  SHA1:5E52148F80C43AAF8412C2BF482B5DF74D6BFB14
                  SHA-256:8F7676D93659DD43A83A2E7266C3C5FB1BB86B23E74F0BC9DDEF848B7F43C8FA
                  SHA-512:FC962BBB3F92BB22F2C81977A301A5D99A225D6F2B964F92D234C62AD79E9B3AE92EBA237FE744F208CE1DBA86658FCC9431FC5193FAF096988186A527B6AE1D
                  Malicious:true
                  Preview:....,..f..]k.[..I......,j.[ky.{.Nc...I...C.....sl.h.............n...o..HK..q...d&m^..k?/.\...t:..N.....=........-..z..'n.i.:...:l....j.{..kzL1......+eH..d....,.!.y...K.c..%..M.k.`9...._taJbs.K.A.|....C.&s.].9.L*...-GS....^)D.k...c..!....5..C55`....V..@&!...2...m......N9..m.`7.a......gN...Z.8......u.V.m.F..s.J...?..A...H..r...p...YB..r.......AV..RY<.k.Z[....g..w...6({.%(.....B.+$.Tk\$.I....W...._.+.4_....LU..Pe.@.V.;<.....;....@..6..h......9}.Ys9....()...d....@.>2.....D.....8.4.+^a.Zne..VPt..v..:.5.TC..<........5Q.#.f}|..1..npd$...vgO.%eK}...`.(e...N....._.....<...wA...9.2]..5&..j....n......}.5.#..[]:.{...`.bt.....-.......>...@......h..@z..k...iVg<.....(.-4.../7....Bi....G....k.f(F..Eq.Pw,....g.......`....2....x+.+.G...a=\.u.E..."?'..!.`M-..c....U.#..q.. .u.Y.Q.&E..87..J%c]..2lB.\..k%0...Wq.$Zu........Y... ..F.](}...;.......C.2b.W..l.L.e.9Q.cq.D.....e..%i...)..p.B4a..!.di....@.X..g......^......m.;..[....T..7.r..L..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):8393062
                  Entropy (8bit):7.99745825913726
                  Encrypted:true
                  SSDEEP:
                  MD5:1F664F33460D61F868BCAEC370F3EBCA
                  SHA1:D4727B3F681D14035927B6D1F1844788E0DB515D
                  SHA-256:C924417491FE3DB3CAD6D529BFBB463BC9199D590BF065B8BDABB7DEF694614A
                  SHA-512:D13DBC068C74A33A06EAA1E3D781C07BAF862B40B094017FA3CD27C5A3A783DECF68AE10C4BF15B0F3A9163F7364289F2F0305D3941A955F0249F91949DFEC61
                  Malicious:true
                  Preview:.x.wS.pS@....pp(.........:p..m.l...A`...]!.....1.Uj._...e7........A,..A......=>m81.YJ..cy4k...-4.}......G...i....E@"..[Y./..)X.?...&.....x..,.s.....f@.%."1.|....r.....F..?...N...+.WM.......N.......M~9..Hx<S3.ES/K..)m..q.Z.q0aj..L1..MG@..n....@.E.>..L....=.Z?..WUM..8.K.`R.Z{..d..3.@q.e.|..2a.".K..>|.F....E&..~....(.i4..@.....nE%)*...i~f...7%.......9...8V_............!.w...H.m%c.#ab.....l!... ....'d...w.........wi..a{+...y..L...7.&...."d.eK...0..u....Z...L........)G....G...3.J)y.9r.HJ....=.-..cC....7.....>T.%.u...U.;..;..k...+....%...._r`....d.&.h..k....!.....@]K .E..#.t..P..{....e.R.b....~....T,.'.Bn..1.(?4...P....*I..z..krQ.....(....Fd....j.:#.D8..d..\ ....AM..........;.....S.j.....PAE{.9.FBp..5@.Gl....P....p....>.<.....(."y...."....k...A.S..R.0.Y..@Rk%..UH...}..6$w......+.:..g..".h!.WVV..b.N.......R......--?n..m4A[.....L..-...G;.>...>^.c..bV@..$x...bB..l.uI..wC.......e...~.7lq..,.q....cL1.2...x...I.8..q.?.hLU.....q..g...N...+NR..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):8393062
                  Entropy (8bit):7.99745825913726
                  Encrypted:true
                  SSDEEP:
                  MD5:1F664F33460D61F868BCAEC370F3EBCA
                  SHA1:D4727B3F681D14035927B6D1F1844788E0DB515D
                  SHA-256:C924417491FE3DB3CAD6D529BFBB463BC9199D590BF065B8BDABB7DEF694614A
                  SHA-512:D13DBC068C74A33A06EAA1E3D781C07BAF862B40B094017FA3CD27C5A3A783DECF68AE10C4BF15B0F3A9163F7364289F2F0305D3941A955F0249F91949DFEC61
                  Malicious:true
                  Preview:.x.wS.pS@....pp(.........:p..m.l...A`...]!.....1.Uj._...e7........A,..A......=>m81.YJ..cy4k...-4.}......G...i....E@"..[Y./..)X.?...&.....x..,.s.....f@.%."1.|....r.....F..?...N...+.WM.......N.......M~9..Hx<S3.ES/K..)m..q.Z.q0aj..L1..MG@..n....@.E.>..L....=.Z?..WUM..8.K.`R.Z{..d..3.@q.e.|..2a.".K..>|.F....E&..~....(.i4..@.....nE%)*...i~f...7%.......9...8V_............!.w...H.m%c.#ab.....l!... ....'d...w.........wi..a{+...y..L...7.&...."d.eK...0..u....Z...L........)G....G...3.J)y.9r.HJ....=.-..cC....7.....>T.%.u...U.;..;..k...+....%...._r`....d.&.h..k....!.....@]K .E..#.t..P..{....e.R.b....~....T,.'.Bn..1.(?4...P....*I..z..krQ.....(....Fd....j.:#.D8..d..\ ....AM..........;.....S.j.....PAE{.9.FBp..5@.Gl....P....p....>.<.....(."y...."....k...A.S..R.0.Y..@Rk%..UH...}..6$w......+.:..g..".h!.WVV..b.N.......R......--?n..m4A[.....L..-...G;.>...>^.c..bV@..$x...bB..l.uI..wC.......e...~.7lq..,.q....cL1.2...x...I.8..q.?.hLU.....q..g...N...+NR..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):618775
                  Entropy (8bit):7.999696921738371
                  Encrypted:true
                  SSDEEP:
                  MD5:7E0F239CAEC4B454E787CAFD5D4EF4C6
                  SHA1:282FE57AF35DEDC8B7D8EEC7281ECEF733CB77FD
                  SHA-256:F62B4601F23FAA609D368E18C6F04F6131EBB761EDCB499E8B7A3F97D769CB4C
                  SHA-512:7FCFAA12EF51B0A78A8D249BF1881677BC6A0874D572D838D13D2B657EB41F3040018058C793A178853F610D7C5AEC319DEFB1B135E80A9999A74017D8E3ECAE
                  Malicious:true
                  Preview:@.....|#.$..<..YwuEm1..cM:t.A.I(2...#$O]{..2Z.^.u....u.^..O..l|.zu.+.J.Ey.....Fy.3.....+1..}...=..|G........4.. ,.Y.w..Q....q ...l...I.!3i.f..ob.....pu..vk.j..1...^.W.6.S.phG....%8x.b.r .!......#...|..0.'.h.s...$c...^.!Uf..j.x,.....H.R...........t....=.,0%... 9.${.^....7.3^6v.a3C..[7I...=..........c..=.N...1..........].@S.X..p.B./`E.gH...n..Q}`.F.$s..%.e......@......w.M..$.....3..*G.B.......q..V. rd....^.^x.#..O`".......H.1>...hk.M..k..l.'...........'.B...Y.$!........r~..RL.=#....4..84....U...N..F..K....G6.V...QA.. ....*..i .F5..6..%0.I-aM="$:c6v..............A.|...F.......H...7..V.>..~].^D.gm...?Q.Hj.....A..?x.g.h.+6f[.Kl<..]d!....x..;.$.gx...+.z.e.i.{.Z...`.La.R|B.x.c{X*..........$$..;.T3.....".3Od....Z........j..Di5.V@...a.?n.7.......`..:z?5.....X.2....Y8...lm.+^..u.%.[.B.E+....!........j."nhII.F..s.@E4K..zM...NT...N.2qd........a.A.....=:3u..B.......p.2^s.b.i..k.ke..J..)"#....z...b.....:.1.+h..$\.)jj.oR..F.....n........j3;.c)(8..r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):618775
                  Entropy (8bit):7.999696921738371
                  Encrypted:true
                  SSDEEP:
                  MD5:7E0F239CAEC4B454E787CAFD5D4EF4C6
                  SHA1:282FE57AF35DEDC8B7D8EEC7281ECEF733CB77FD
                  SHA-256:F62B4601F23FAA609D368E18C6F04F6131EBB761EDCB499E8B7A3F97D769CB4C
                  SHA-512:7FCFAA12EF51B0A78A8D249BF1881677BC6A0874D572D838D13D2B657EB41F3040018058C793A178853F610D7C5AEC319DEFB1B135E80A9999A74017D8E3ECAE
                  Malicious:true
                  Preview:@.....|#.$..<..YwuEm1..cM:t.A.I(2...#$O]{..2Z.^.u....u.^..O..l|.zu.+.J.Ey.....Fy.3.....+1..}...=..|G........4.. ,.Y.w..Q....q ...l...I.!3i.f..ob.....pu..vk.j..1...^.W.6.S.phG....%8x.b.r .!......#...|..0.'.h.s...$c...^.!Uf..j.x,.....H.R...........t....=.,0%... 9.${.^....7.3^6v.a3C..[7I...=..........c..=.N...1..........].@S.X..p.B./`E.gH...n..Q}`.F.$s..%.e......@......w.M..$.....3..*G.B.......q..V. rd....^.^x.#..O`".......H.1>...hk.M..k..l.'...........'.B...Y.$!........r~..RL.=#....4..84....U...N..F..K....G6.V...QA.. ....*..i .F5..6..%0.I-aM="$:c6v..............A.|...F.......H...7..V.>..~].^D.gm...?Q.Hj.....A..?x.g.h.+6f[.Kl<..]d!....x..;.$.gx...+.z.e.i.{.Z...`.La.R|B.x.c{X*..........$$..;.T3.....".3Od....Z........j..Di5.V@...a.?n.7.......`..:z?5.....X.2....Y8...lm.+^..u.%.[.B.E+....!........j."nhII.F..s.@E4K..zM...NT...N.2qd........a.A.....=:3u..B.......p.2^s.b.i..k.ke..J..)"#....z...b.....:.1.+h..$\.)jj.oR..F.....n........j3;.c)(8..r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):618775
                  Entropy (8bit):7.999696921738371
                  Encrypted:true
                  SSDEEP:
                  MD5:7E0F239CAEC4B454E787CAFD5D4EF4C6
                  SHA1:282FE57AF35DEDC8B7D8EEC7281ECEF733CB77FD
                  SHA-256:F62B4601F23FAA609D368E18C6F04F6131EBB761EDCB499E8B7A3F97D769CB4C
                  SHA-512:7FCFAA12EF51B0A78A8D249BF1881677BC6A0874D572D838D13D2B657EB41F3040018058C793A178853F610D7C5AEC319DEFB1B135E80A9999A74017D8E3ECAE
                  Malicious:true
                  Preview:@.....|#.$..<..YwuEm1..cM:t.A.I(2...#$O]{..2Z.^.u....u.^..O..l|.zu.+.J.Ey.....Fy.3.....+1..}...=..|G........4.. ,.Y.w..Q....q ...l...I.!3i.f..ob.....pu..vk.j..1...^.W.6.S.phG....%8x.b.r .!......#...|..0.'.h.s...$c...^.!Uf..j.x,.....H.R...........t....=.,0%... 9.${.^....7.3^6v.a3C..[7I...=..........c..=.N...1..........].@S.X..p.B./`E.gH...n..Q}`.F.$s..%.e......@......w.M..$.....3..*G.B.......q..V. rd....^.^x.#..O`".......H.1>...hk.M..k..l.'...........'.B...Y.$!........r~..RL.=#....4..84....U...N..F..K....G6.V...QA.. ....*..i .F5..6..%0.I-aM="$:c6v..............A.|...F.......H...7..V.>..~].^D.gm...?Q.Hj.....A..?x.g.h.+6f[.Kl<..]d!....x..;.$.gx...+.z.e.i.{.Z...`.La.R|B.x.c{X*..........$$..;.T3.....".3Od....Z........j..Di5.V@...a.?n.7.......`..:z?5.....X.2....Y8...lm.+^..u.%.[.B.E+....!........j."nhII.F..s.@E4K..zM...NT...N.2qd........a.A.....=:3u..B.......p.2^s.b.i..k.ke..J..)"#....z...b.....:.1.+h..$\.)jj.oR..F.....n........j3;.c)(8..r
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):266
                  Entropy (8bit):6.7660575582668
                  Encrypted:false
                  SSDEEP:
                  MD5:A15146FB4B7A5C0E1820E16355F09546
                  SHA1:2B05CDD674A2DE8A3DB08A4899C39F6647D2FB9B
                  SHA-256:C445D5D701A95F0A7322E5D09B57BB0A607BC7B55D14DB898DCD770189BE58DE
                  SHA-512:2C417FC89B91011C9DD0304184255D6F8EF3B1E4C2868BD53B446F5B41C1634E07745C08AE333B90D9806E956E9C6A646B0962F6C93F835ABE9FBDC692984E63
                  Malicious:false
                  Preview:.\E.P....M0 .G....."....".*.q...~.I,..E......n...7..ip..1....#t.6.J.f:...NZ8Yjj4.=H*k..:]e.j,.U.7.K..`...[f.5.I@X}a$.k.7..S....1.s.a.|.g.Y.0k.8.a...3.{.....*...f.^j.........F..0(3...vQ..M.C....i...;.>w.h.e..hE.1.....;~2..........j...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):266
                  Entropy (8bit):6.7660575582668
                  Encrypted:false
                  SSDEEP:
                  MD5:A15146FB4B7A5C0E1820E16355F09546
                  SHA1:2B05CDD674A2DE8A3DB08A4899C39F6647D2FB9B
                  SHA-256:C445D5D701A95F0A7322E5D09B57BB0A607BC7B55D14DB898DCD770189BE58DE
                  SHA-512:2C417FC89B91011C9DD0304184255D6F8EF3B1E4C2868BD53B446F5B41C1634E07745C08AE333B90D9806E956E9C6A646B0962F6C93F835ABE9FBDC692984E63
                  Malicious:false
                  Preview:.\E.P....M0 .G....."....".*.q...~.I,..E......n...7..ip..1....#t.6.J.f:...NZ8Yjj4.=H*k..:]e.j,.U.7.K..`...[f.5.I@X}a$.k.7..S....1.s.a.|.g.Y.0k.8.a...3.{.....*...f.^j.........F..0(3...vQ..M.C....i...;.>w.h.e..hE.1.....;~2..........j...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):266
                  Entropy (8bit):6.7660575582668
                  Encrypted:false
                  SSDEEP:
                  MD5:A15146FB4B7A5C0E1820E16355F09546
                  SHA1:2B05CDD674A2DE8A3DB08A4899C39F6647D2FB9B
                  SHA-256:C445D5D701A95F0A7322E5D09B57BB0A607BC7B55D14DB898DCD770189BE58DE
                  SHA-512:2C417FC89B91011C9DD0304184255D6F8EF3B1E4C2868BD53B446F5B41C1634E07745C08AE333B90D9806E956E9C6A646B0962F6C93F835ABE9FBDC692984E63
                  Malicious:false
                  Preview:.\E.P....M0 .G....."....".*.q...~.I,..E......n...7..ip..1....#t.6.J.f:...NZ8Yjj4.=H*k..:]e.j,.U.7.K..`...[f.5.I@X}a$.k.7..S....1.s.a.|.g.Y.0k.8.a...3.{.....*...f.^j.........F..0(3...vQ..M.C....i...;.>w.h.e..hE.1.....;~2..........j...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):573
                  Entropy (8bit):7.525918734604442
                  Encrypted:false
                  SSDEEP:
                  MD5:C603A8813149473CD77D5E7DCA10F225
                  SHA1:F7CC160E6DBCE0DA351551D93F62239606BA53BD
                  SHA-256:E4223FBE2A0403F6FCAC013519336DDB60A4F1D035549D13303E6913C091409A
                  SHA-512:0981D909AC9C8C533B25E2BC587020E06FC0797E88A8D63353EB3682539A001D299ACC8FEEF5973D1A9083FC2ADAF25FD0646AB6E99041701155B976CCBE671A
                  Malicious:false
                  Preview:...?...t?.1yY5.-1....J;.....v.G.L.+.pU...dQM=........._.AG..Y..k..@.|s.[.....{8[j.....3h..{...8.(....(.GO....v.. 8 L..bg@5..D3 .d#q0.4&...V.5.z....R.....'.....td. ..q..c.sG......v.kP.$~.M.$y...1....Y..:..s..:._.f.. .B>..L.N....8.....*\.V..[.U.4.|......fz_.j..2vT4...R.a.uA..b7.LL.3Ag..K6O.~........]...}.,..DC.z!.K..s....i8.+Rj_.L.!yx.} I7..C....cJ.Q7+o..}...-.....8.${..u...^].33.tG6jn...h..5.:..p;..v....\.a.At.7ScF.#....`lZ...<e}....Uf...2!.-.%........jr.d...............1E...\iZ....X.<.B.p....)&(.p.e..`..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):573
                  Entropy (8bit):7.525918734604442
                  Encrypted:false
                  SSDEEP:
                  MD5:C603A8813149473CD77D5E7DCA10F225
                  SHA1:F7CC160E6DBCE0DA351551D93F62239606BA53BD
                  SHA-256:E4223FBE2A0403F6FCAC013519336DDB60A4F1D035549D13303E6913C091409A
                  SHA-512:0981D909AC9C8C533B25E2BC587020E06FC0797E88A8D63353EB3682539A001D299ACC8FEEF5973D1A9083FC2ADAF25FD0646AB6E99041701155B976CCBE671A
                  Malicious:false
                  Preview:...?...t?.1yY5.-1....J;.....v.G.L.+.pU...dQM=........._.AG..Y..k..@.|s.[.....{8[j.....3h..{...8.(....(.GO....v.. 8 L..bg@5..D3 .d#q0.4&...V.5.z....R.....'.....td. ..q..c.sG......v.kP.$~.M.$y...1....Y..:..s..:._.f.. .B>..L.N....8.....*\.V..[.U.4.|......fz_.j..2vT4...R.a.uA..b7.LL.3Ag..K6O.~........]...}.,..DC.z!.K..s....i8.+Rj_.L.!yx.} I7..C....cJ.Q7+o..}...-.....8.${..u...^].33.tG6jn...h..5.:..p;..v....\.a.At.7ScF.#....`lZ...<e}....Uf...2!.-.%........jr.d...............1E...\iZ....X.<.B.p....)&(.p.e..`..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):573
                  Entropy (8bit):7.525918734604442
                  Encrypted:false
                  SSDEEP:
                  MD5:C603A8813149473CD77D5E7DCA10F225
                  SHA1:F7CC160E6DBCE0DA351551D93F62239606BA53BD
                  SHA-256:E4223FBE2A0403F6FCAC013519336DDB60A4F1D035549D13303E6913C091409A
                  SHA-512:0981D909AC9C8C533B25E2BC587020E06FC0797E88A8D63353EB3682539A001D299ACC8FEEF5973D1A9083FC2ADAF25FD0646AB6E99041701155B976CCBE671A
                  Malicious:false
                  Preview:...?...t?.1yY5.-1....J;.....v.G.L.+.pU...dQM=........._.AG..Y..k..@.|s.[.....{8[j.....3h..{...8.(....(.GO....v.. 8 L..bg@5..D3 .d#q0.4&...V.5.z....R.....'.....td. ..q..c.sG......v.kP.$~.M.$y...1....Y..:..s..:._.f.. .B>..L.N....8.....*\.V..[.U.4.|......fz_.j..2vT4...R.a.uA..b7.LL.3Ag..K6O.~........]...}.,..DC.z!.K..s....i8.+Rj_.L.!yx.} I7..C....cJ.Q7+o..}...-.....8.${..u...^].33.tG6jn...h..5.:..p;..v....\.a.At.7ScF.#....`lZ...<e}....Uf...2!.-.%........jr.d...............1E...\iZ....X.<.B.p....)&(.p.e..`..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):547146
                  Entropy (8bit):7.999615451008865
                  Encrypted:true
                  SSDEEP:
                  MD5:11749A0ED3D959E18CCFAB7BED5FFB53
                  SHA1:2F15C9DDD313231FEC4640118B544D05E29355AC
                  SHA-256:14C59E7FBA00CCD51D9F2750E1E7AB7FDEBB2637DE39F12A619BDE82370BC23C
                  SHA-512:02C7A2C9247ECDB012D1375A880F873AE9160DB144510B59417605C592B96579D8EBBA171FD968F0AB2F55FF4712900C5ED2C8AA8BCF4D6BCA2C18E04D320B2E
                  Malicious:true
                  Preview:..{..n...I...C...H@..0"h.w.r...0Vo..>=.........zX`....+.#K.<X.Q.9j.....G.9i....+O.2...._...T..z.......4..Q....:d.,%.5~..W..&...g....|oL"..*.F..;P\4w...}...._I..`..N. /F.t......+.}.?qo..S......O.j(..wz.s..w...A7...b~}.A....y.Z.I}."RX.B.........=......5.P....'.....%.sb..DA....&.j;.$.7....(..h...C...c..-K*..L.R..J&....-r.......a>....h../u[..k....Kk.1.._S2x.[5...Mm..c..\.../.....}s:+....Y6.6.....9..a........ .Pn..P.Sp.,N+.dG..9.G...?0@..{...0.P..h.e.....+Z...?.!H.+:.....Cx.L.K\.2....bnep...IN.v..Z....}>...? ..=<.....,|K:.H..)O..]y@..+...S..y...JoM.......y..N.Z7....u...2?\BOr....Ys....-..}k...GLtz.Ol(..^...W[.Q..w-.. .v.oQr.J]a.gp.%..XL..;.r.`...%,....O4.K....<......t...e.s..~.oK.K.{x...Y/.../.j.A!../dva.`.Kx...X..8...v_..Zu.u.F[M.=.o"...;..P.aH.|...8a..>..Vr....I.8....G_i...;.B....8.M.d......T..]b+B!..,9..GD.....Q.L.).9...\.....U..*.."9Z.~.!..#:l#..zt.M.|.o....K.0..... ..q...1..6$eDc#;....Wy....c..'n...q....[.f...0....._......u3..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):547146
                  Entropy (8bit):7.999615451008865
                  Encrypted:true
                  SSDEEP:
                  MD5:11749A0ED3D959E18CCFAB7BED5FFB53
                  SHA1:2F15C9DDD313231FEC4640118B544D05E29355AC
                  SHA-256:14C59E7FBA00CCD51D9F2750E1E7AB7FDEBB2637DE39F12A619BDE82370BC23C
                  SHA-512:02C7A2C9247ECDB012D1375A880F873AE9160DB144510B59417605C592B96579D8EBBA171FD968F0AB2F55FF4712900C5ED2C8AA8BCF4D6BCA2C18E04D320B2E
                  Malicious:true
                  Preview:..{..n...I...C...H@..0"h.w.r...0Vo..>=.........zX`....+.#K.<X.Q.9j.....G.9i....+O.2...._...T..z.......4..Q....:d.,%.5~..W..&...g....|oL"..*.F..;P\4w...}...._I..`..N. /F.t......+.}.?qo..S......O.j(..wz.s..w...A7...b~}.A....y.Z.I}."RX.B.........=......5.P....'.....%.sb..DA....&.j;.$.7....(..h...C...c..-K*..L.R..J&....-r.......a>....h../u[..k....Kk.1.._S2x.[5...Mm..c..\.../.....}s:+....Y6.6.....9..a........ .Pn..P.Sp.,N+.dG..9.G...?0@..{...0.P..h.e.....+Z...?.!H.+:.....Cx.L.K\.2....bnep...IN.v..Z....}>...? ..=<.....,|K:.H..)O..]y@..+...S..y...JoM.......y..N.Z7....u...2?\BOr....Ys....-..}k...GLtz.Ol(..^...W[.Q..w-.. .v.oQr.J]a.gp.%..XL..;.r.`...%,....O4.K....<......t...e.s..~.oK.K.{x...Y/.../.j.A!../dva.`.Kx...X..8...v_..Zu.u.F[M.=.o"...;..P.aH.|...8a..>..Vr....I.8....G_i...;.B....8.M.d......T..]b+B!..,9..GD.....Q.L.).9...\.....U..*.."9Z.~.!..#:l#..zt.M.|.o....K.0..... ..q...1..6$eDc#;....Wy....c..'n...q....[.f...0....._......u3..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):547146
                  Entropy (8bit):7.999615451008865
                  Encrypted:true
                  SSDEEP:
                  MD5:11749A0ED3D959E18CCFAB7BED5FFB53
                  SHA1:2F15C9DDD313231FEC4640118B544D05E29355AC
                  SHA-256:14C59E7FBA00CCD51D9F2750E1E7AB7FDEBB2637DE39F12A619BDE82370BC23C
                  SHA-512:02C7A2C9247ECDB012D1375A880F873AE9160DB144510B59417605C592B96579D8EBBA171FD968F0AB2F55FF4712900C5ED2C8AA8BCF4D6BCA2C18E04D320B2E
                  Malicious:true
                  Preview:..{..n...I...C...H@..0"h.w.r...0Vo..>=.........zX`....+.#K.<X.Q.9j.....G.9i....+O.2...._...T..z.......4..Q....:d.,%.5~..W..&...g....|oL"..*.F..;P\4w...}...._I..`..N. /F.t......+.}.?qo..S......O.j(..wz.s..w...A7...b~}.A....y.Z.I}."RX.B.........=......5.P....'.....%.sb..DA....&.j;.$.7....(..h...C...c..-K*..L.R..J&....-r.......a>....h../u[..k....Kk.1.._S2x.[5...Mm..c..\.../.....}s:+....Y6.6.....9..a........ .Pn..P.Sp.,N+.dG..9.G...?0@..{...0.P..h.e.....+Z...?.!H.+:.....Cx.L.K\.2....bnep...IN.v..Z....}>...? ..=<.....,|K:.H..)O..]y@..+...S..y...JoM.......y..N.Z7....u...2?\BOr....Ys....-..}k...GLtz.Ol(..^...W[.Q..w-.. .v.oQr.J]a.gp.%..XL..;.r.`...%,....O4.K....<......t...e.s..~.oK.K.{x...Y/.../.j.A!../dva.`.Kx...X..8...v_..Zu.u.F[M.=.o"...;..P.aH.|...8a..>..Vr....I.8....G_i...;.B....8.M.d......T..]b+B!..,9..GD.....Q.L.).9...\.....U..*.."9Z.~.!..#:l#..zt.M.|.o....K.0..... ..q...1..6$eDc#;....Wy....c..'n...q....[.f...0....._......u3..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):74366
                  Entropy (8bit):7.997396330375104
                  Encrypted:true
                  SSDEEP:
                  MD5:66BD9383D12362DCE00A01C5866B0CBE
                  SHA1:707520ED233792C1227B525CAE70EBE70E849D57
                  SHA-256:B4E040D0B222EBBDDC120A00AC698CEB3AC7A22B4AB752F425B87F550E98A629
                  SHA-512:697E1BCCE940DF8D40323109E963692F9DF39999118CC3C105520F8C930024F47BD6054E76C842EF3C3B2652C779D513A6DE7D702783C94A279530398FF0954F
                  Malicious:true
                  Preview:.....<4|...G.....sWL>D.....}1vi..>.2?...}..6.G.2...g.!e...o.Z.3.?} Z.0I.-..n.].C...%G..4...{N...*......ct..........Yi7CS...*....=Os.)..\,...ht.....3..[E.K.,b......I7.q.ve.c9x;|... .T..Cih?........].D..I....b..cS.M.9N..L.7.....oT.z.vl[..a.+.CH....N5...../....pQ.tU..<...h|]......j!.K5..` ......I..f.3@..H..l..X5.......5K.....D.hB.]zE.F...F.EO........ or..9F:_.'......Sn5.+|>...t.j,..).._...%.8..\.N...<....o....l( Y...Y..O.n.@.o.O)O.W......q.Q.!u...R.G......X.w.9$....n.B?.L.7P).KQ.{YM..c+..4.X6$.O.{wb&..P..m<..C......Lp.....2.z:..99P...v......=.i.;t....;..k..'. ....Y.^..p..i.F.../.....[A..<o...J..F.pZ.q..Y.....)...Q.{X.....Bjq..).r."u.nu......@%.?n.e.hvvI.`..x.[....v&b..q...m.Y....#8.7.......n..+...?.{.f.b..r8....Me.$..lS.=^...f........,.....k.fD.e..#.....W4....KEW..$G;....o.M)..D........{,..K.e.Y..#.C.....<&.O3.....D.@..}.}.O.....e.......y!D.E.t:.......f.....7.....";x..n.-Q..../>Z.{6(l......iU....3I.[...r>(.J...MqTK..n...ct.T.5g.j. ...Q-.o..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):74366
                  Entropy (8bit):7.997396330375104
                  Encrypted:true
                  SSDEEP:
                  MD5:66BD9383D12362DCE00A01C5866B0CBE
                  SHA1:707520ED233792C1227B525CAE70EBE70E849D57
                  SHA-256:B4E040D0B222EBBDDC120A00AC698CEB3AC7A22B4AB752F425B87F550E98A629
                  SHA-512:697E1BCCE940DF8D40323109E963692F9DF39999118CC3C105520F8C930024F47BD6054E76C842EF3C3B2652C779D513A6DE7D702783C94A279530398FF0954F
                  Malicious:true
                  Preview:.....<4|...G.....sWL>D.....}1vi..>.2?...}..6.G.2...g.!e...o.Z.3.?} Z.0I.-..n.].C...%G..4...{N...*......ct..........Yi7CS...*....=Os.)..\,...ht.....3..[E.K.,b......I7.q.ve.c9x;|... .T..Cih?........].D..I....b..cS.M.9N..L.7.....oT.z.vl[..a.+.CH....N5...../....pQ.tU..<...h|]......j!.K5..` ......I..f.3@..H..l..X5.......5K.....D.hB.]zE.F...F.EO........ or..9F:_.'......Sn5.+|>...t.j,..).._...%.8..\.N...<....o....l( Y...Y..O.n.@.o.O)O.W......q.Q.!u...R.G......X.w.9$....n.B?.L.7P).KQ.{YM..c+..4.X6$.O.{wb&..P..m<..C......Lp.....2.z:..99P...v......=.i.;t....;..k..'. ....Y.^..p..i.F.../.....[A..<o...J..F.pZ.q..Y.....)...Q.{X.....Bjq..).r."u.nu......@%.?n.e.hvvI.`..x.[....v&b..q...m.Y....#8.7.......n..+...?.{.f.b..r8....Me.$..lS.=^...f........,.....k.fD.e..#.....W4....KEW..$G;....o.M)..D........{,..K.e.Y..#.C.....<&.O3.....D.@..}.}.O.....e.......y!D.E.t:.......f.....7.....";x..n.-Q..../>Z.{6(l......iU....3I.[...r>(.J...MqTK..n...ct.T.5g.j. ...Q-.o..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):74366
                  Entropy (8bit):7.997396330375104
                  Encrypted:true
                  SSDEEP:
                  MD5:66BD9383D12362DCE00A01C5866B0CBE
                  SHA1:707520ED233792C1227B525CAE70EBE70E849D57
                  SHA-256:B4E040D0B222EBBDDC120A00AC698CEB3AC7A22B4AB752F425B87F550E98A629
                  SHA-512:697E1BCCE940DF8D40323109E963692F9DF39999118CC3C105520F8C930024F47BD6054E76C842EF3C3B2652C779D513A6DE7D702783C94A279530398FF0954F
                  Malicious:true
                  Preview:.....<4|...G.....sWL>D.....}1vi..>.2?...}..6.G.2...g.!e...o.Z.3.?} Z.0I.-..n.].C...%G..4...{N...*......ct..........Yi7CS...*....=Os.)..\,...ht.....3..[E.K.,b......I7.q.ve.c9x;|... .T..Cih?........].D..I....b..cS.M.9N..L.7.....oT.z.vl[..a.+.CH....N5...../....pQ.tU..<...h|]......j!.K5..` ......I..f.3@..H..l..X5.......5K.....D.hB.]zE.F...F.EO........ or..9F:_.'......Sn5.+|>...t.j,..).._...%.8..\.N...<....o....l( Y...Y..O.n.@.o.O)O.W......q.Q.!u...R.G......X.w.9$....n.B?.L.7P).KQ.{YM..c+..4.X6$.O.{wb&..P..m<..C......Lp.....2.z:..99P...v......=.i.;t....;..k..'. ....Y.^..p..i.F.../.....[A..<o...J..F.pZ.q..Y.....)...Q.{X.....Bjq..).r."u.nu......@%.?n.e.hvvI.`..x.[....v&b..q...m.Y....#8.7.......n..+...?.{.f.b..r8....Me.$..lS.=^...f........,.....k.fD.e..#.....W4....KEW..$G;....o.M)..D........{,..K.e.Y..#.C.....<&.O3.....D.@..}.}.O.....e.......y!D.E.t:.......f.....7.....";x..n.-Q..../>Z.{6(l......iU....3I.[...r>(.J...MqTK..n...ct.T.5g.j. ...Q-.o..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1059
                  Entropy (8bit):7.780916022166799
                  Encrypted:false
                  SSDEEP:
                  MD5:3D9ABDD322F58552E9ADA4F64134D52E
                  SHA1:6C6C0D7D0A70E195209662D66B2133C5CDC6D23F
                  SHA-256:D9B11ED14C0C342F7F193A3D0B3C69FE18CFB6A39C573084E126477D6FD9374C
                  SHA-512:7FCAD85F1DBD2322CE1E129341DA075471FA3FA5DDFA40835E7119C2D7D4DD72520434A1DB3DB97081569D0940300EA9FBA9FC10CD1102C51F72BBDE798D0761
                  Malicious:false
                  Preview:.2l.%d.a.6,@Wg....=i.;....?.h...2x....$.MOn...Z.HF+.R.=.......3......$.....gq.~1*.Np-.T{^D.W......wm..e......Y:i.C......M.....l......4.\...kZ.vm..].0i'.h.i.$i.t....'G...g../.%...D.F...m..k.C.a.p...c$.G@L.Z.<r..).........P......V.6.h[;.ig.]..lW.)BPr..g..UaOV..W.....y..+Q.b.w*...;..}..I.e..I..$.+y:;*e.[.|P.h...TwA.v~#........5.o^}..Se)<..u....;<...{..Q.0.6..."P.=.(........Wa9.l.WX.....pS.....&].._"...b.......5".*..D$..X..X...P..xR`..meh../_9....^...#.......5A..e;V..[4...\8..Uu.8.. jq...q..k...;.K..U.b).=u$R.......r.%Y..j.....]....(.w..T.$..?....;.....G.Z3..C..."x..j@s.......e.R..\.2..........i..I..{J....n..0.+F.>}.jX........C..SZP9.1.3.%..!...80f1Fm..2"ZH.'.12."4...&........8\.',...@..r.m...&e.-.o(..,.....;1jp./.6..Goi!.|..."...pV.82.0..e._..Z...qGn...Y;../^.....0..S.oh.xf..r.(..f....w.'xP.w...o.z.....C.J.s.0<.......b....2..P...*..x....X.1..#.z../.fpH...K.....c&..P...Q4!....5.W......H........D....}z........f5..rP.."_.F5....j...+..I.4..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1059
                  Entropy (8bit):7.780916022166799
                  Encrypted:false
                  SSDEEP:
                  MD5:3D9ABDD322F58552E9ADA4F64134D52E
                  SHA1:6C6C0D7D0A70E195209662D66B2133C5CDC6D23F
                  SHA-256:D9B11ED14C0C342F7F193A3D0B3C69FE18CFB6A39C573084E126477D6FD9374C
                  SHA-512:7FCAD85F1DBD2322CE1E129341DA075471FA3FA5DDFA40835E7119C2D7D4DD72520434A1DB3DB97081569D0940300EA9FBA9FC10CD1102C51F72BBDE798D0761
                  Malicious:false
                  Preview:.2l.%d.a.6,@Wg....=i.;....?.h...2x....$.MOn...Z.HF+.R.=.......3......$.....gq.~1*.Np-.T{^D.W......wm..e......Y:i.C......M.....l......4.\...kZ.vm..].0i'.h.i.$i.t....'G...g../.%...D.F...m..k.C.a.p...c$.G@L.Z.<r..).........P......V.6.h[;.ig.]..lW.)BPr..g..UaOV..W.....y..+Q.b.w*...;..}..I.e..I..$.+y:;*e.[.|P.h...TwA.v~#........5.o^}..Se)<..u....;<...{..Q.0.6..."P.=.(........Wa9.l.WX.....pS.....&].._"...b.......5".*..D$..X..X...P..xR`..meh../_9....^...#.......5A..e;V..[4...\8..Uu.8.. jq...q..k...;.K..U.b).=u$R.......r.%Y..j.....]....(.w..T.$..?....;.....G.Z3..C..."x..j@s.......e.R..\.2..........i..I..{J....n..0.+F.>}.jX........C..SZP9.1.3.%..!...80f1Fm..2"ZH.'.12."4...&........8\.',...@..r.m...&e.-.o(..,.....;1jp./.6..Goi!.|..."...pV.82.0..e._..Z...qGn...Y;../^.....0..S.oh.xf..r.(..f....w.'xP.w...o.z.....C.J.s.0<.......b....2..P...*..x....X.1..#.z../.fpH...K.....c&..P...Q4!....5.W......H........D....}z........f5..rP.."_.F5....j...+..I.4..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1059
                  Entropy (8bit):7.780916022166799
                  Encrypted:false
                  SSDEEP:
                  MD5:3D9ABDD322F58552E9ADA4F64134D52E
                  SHA1:6C6C0D7D0A70E195209662D66B2133C5CDC6D23F
                  SHA-256:D9B11ED14C0C342F7F193A3D0B3C69FE18CFB6A39C573084E126477D6FD9374C
                  SHA-512:7FCAD85F1DBD2322CE1E129341DA075471FA3FA5DDFA40835E7119C2D7D4DD72520434A1DB3DB97081569D0940300EA9FBA9FC10CD1102C51F72BBDE798D0761
                  Malicious:false
                  Preview:.2l.%d.a.6,@Wg....=i.;....?.h...2x....$.MOn...Z.HF+.R.=.......3......$.....gq.~1*.Np-.T{^D.W......wm..e......Y:i.C......M.....l......4.\...kZ.vm..].0i'.h.i.$i.t....'G...g../.%...D.F...m..k.C.a.p...c$.G@L.Z.<r..).........P......V.6.h[;.ig.]..lW.)BPr..g..UaOV..W.....y..+Q.b.w*...;..}..I.e..I..$.+y:;*e.[.|P.h...TwA.v~#........5.o^}..Se)<..u....;<...{..Q.0.6..."P.=.(........Wa9.l.WX.....pS.....&].._"...b.......5".*..D$..X..X...P..xR`..meh../_9....^...#.......5A..e;V..[4...\8..Uu.8.. jq...q..k...;.K..U.b).=u$R.......r.%Y..j.....]....(.w..T.$..?....;.....G.Z3..C..."x..j@s.......e.R..\.2..........i..I..{J....n..0.+F.>}.jX........C..SZP9.1.3.%..!...80f1Fm..2"ZH.'.12."4...&........8\.',...@..r.m...&e.-.o(..,.....;1jp./.6..Goi!.|..."...pV.82.0..e._..Z...qGn...Y;../^.....0..S.oh.xf..r.(..f....w.'xP.w...o.z.....C.J.s.0<.......b....2..P...*..x....X.1..#.z../.fpH...K.....c&..P...Q4!....5.W......H........D....}z........f5..rP.."_.F5....j...+..I.4..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15824
                  Entropy (8bit):7.987357451838791
                  Encrypted:false
                  SSDEEP:
                  MD5:5FC53F118F9FBAD399D598E85BA2AFBB
                  SHA1:2561029729C89C46499982B0830E8C0856471B0C
                  SHA-256:5557EAD8990136BD5987535E580DB1767932C42EAA930507AF04F828E032213A
                  SHA-512:DF36C917A30774740BD009509685C2CB1D13D5BF4B07985468832C11AFC9556BA8DE1C0804A32303330263F95EC48EAF1FDBC154EE3B0814E42A2579F99B4D02
                  Malicious:false
                  Preview:#.q?.c....0 .....W..6.....=9}*.z.ZK.J-..#.....SI.g...cZy*.6...4.u*..?~...0.VH.n...-.Y./$.S.YZX.......)@(.W..N ......C....V..9)..v './...M*T8.d.P......W. .x...G....Tk...R...j.......0i*.Q.'\B...s.~q..2.....H.......h.....H.\1.5..u....J........>..U.d.....Y..&[H.K...3..W.38\.U..,H.!|*.7....o....F9..|~.....8.....+;..n6M.~......u........O....*..;.-.r.V;. .$.B..U.hU.i....(Le....E..5.p..SWib.B=q.kw_<..j.~.........b.}?............;.P'..R...(.....nI.t...r...._....Z??....W..0".c.~...^-..z..(..5.a5&..F.{..1X..-..c......_...\...h..q....Q.(....R.1.5...Lq......R...f.ksT.:..UK..5eJ......1`..@_^nk.K.:..v.....&y.._~E........|..V<......P...P8>..M9d..../Pz...~.uSO#.]...M?.Pz.T!k .LWY.S.WY1..3.....)..O......!.....AC..g.}..:%]...&*...R.o....4.....c.S.....NR{.yO..(.\.F..R6..........pwPk..e..$.........^oHp.<u&.KP....L..xHb.[5..3H....>%.u.*.. ....,B.9.sl.v..f~.u.b.w......O.P.....!?...jL..@..*.{.......};.T.....0.g.,5o].e.q..T^I......p..Ii. ......Q...4.(.....i..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15824
                  Entropy (8bit):7.987357451838791
                  Encrypted:false
                  SSDEEP:
                  MD5:5FC53F118F9FBAD399D598E85BA2AFBB
                  SHA1:2561029729C89C46499982B0830E8C0856471B0C
                  SHA-256:5557EAD8990136BD5987535E580DB1767932C42EAA930507AF04F828E032213A
                  SHA-512:DF36C917A30774740BD009509685C2CB1D13D5BF4B07985468832C11AFC9556BA8DE1C0804A32303330263F95EC48EAF1FDBC154EE3B0814E42A2579F99B4D02
                  Malicious:false
                  Preview:#.q?.c....0 .....W..6.....=9}*.z.ZK.J-..#.....SI.g...cZy*.6...4.u*..?~...0.VH.n...-.Y./$.S.YZX.......)@(.W..N ......C....V..9)..v './...M*T8.d.P......W. .x...G....Tk...R...j.......0i*.Q.'\B...s.~q..2.....H.......h.....H.\1.5..u....J........>..U.d.....Y..&[H.K...3..W.38\.U..,H.!|*.7....o....F9..|~.....8.....+;..n6M.~......u........O....*..;.-.r.V;. .$.B..U.hU.i....(Le....E..5.p..SWib.B=q.kw_<..j.~.........b.}?............;.P'..R...(.....nI.t...r...._....Z??....W..0".c.~...^-..z..(..5.a5&..F.{..1X..-..c......_...\...h..q....Q.(....R.1.5...Lq......R...f.ksT.:..UK..5eJ......1`..@_^nk.K.:..v.....&y.._~E........|..V<......P...P8>..M9d..../Pz...~.uSO#.]...M?.Pz.T!k .LWY.S.WY1..3.....)..O......!.....AC..g.}..:%]...&*...R.o....4.....c.S.....NR{.yO..(.\.F..R6..........pwPk..e..$.........^oHp.<u&.KP....L..xHb.[5..3H....>%.u.*.. ....,B.9.sl.v..f~.u.b.w......O.P.....!?...jL..@..*.{.......};.T.....0.g.,5o].e.q..T^I......p..Ii. ......Q...4.(.....i..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):15824
                  Entropy (8bit):7.987357451838791
                  Encrypted:false
                  SSDEEP:
                  MD5:5FC53F118F9FBAD399D598E85BA2AFBB
                  SHA1:2561029729C89C46499982B0830E8C0856471B0C
                  SHA-256:5557EAD8990136BD5987535E580DB1767932C42EAA930507AF04F828E032213A
                  SHA-512:DF36C917A30774740BD009509685C2CB1D13D5BF4B07985468832C11AFC9556BA8DE1C0804A32303330263F95EC48EAF1FDBC154EE3B0814E42A2579F99B4D02
                  Malicious:false
                  Preview:#.q?.c....0 .....W..6.....=9}*.z.ZK.J-..#.....SI.g...cZy*.6...4.u*..?~...0.VH.n...-.Y./$.S.YZX.......)@(.W..N ......C....V..9)..v './...M*T8.d.P......W. .x...G....Tk...R...j.......0i*.Q.'\B...s.~q..2.....H.......h.....H.\1.5..u....J........>..U.d.....Y..&[H.K...3..W.38\.U..,H.!|*.7....o....F9..|~.....8.....+;..n6M.~......u........O....*..;.-.r.V;. .$.B..U.hU.i....(Le....E..5.p..SWib.B=q.kw_<..j.~.........b.}?............;.P'..R...(.....nI.t...r...._....Z??....W..0".c.~...^-..z..(..5.a5&..F.{..1X..-..c......_...\...h..q....Q.(....R.1.5...Lq......R...f.ksT.:..UK..5eJ......1`..@_^nk.K.:..v.....&y.._~E........|..V<......P...P8>..M9d..../Pz...~.uSO#.]...M?.Pz.T!k .LWY.S.WY1..3.....)..O......!.....AC..g.}..:%]...&*...R.o....4.....c.S.....NR{.yO..(.\.F..R6..........pwPk..e..$.........^oHp.<u&.KP....L..xHb.[5..3H....>%.u.*.. ....,B.9.sl.v..f~.u.b.w......O.P.....!?...jL..@..*.{.......};.T.....0.g.,5o].e.q..T^I......p..Ii. ......Q...4.(.....i..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5912
                  Entropy (8bit):7.969248728981797
                  Encrypted:false
                  SSDEEP:
                  MD5:9C962DF5E487A0E20CBEF5190677DC30
                  SHA1:352CBB520E03C96D839BFB1110011F34B531EED2
                  SHA-256:B4DFA6A6DA6BB15793901DBBCDE721FF986E582052CDEDC9D32A5ED01AF3AE05
                  SHA-512:38ED8DD024FEAF5DD191E857160E96FDD6DD998D91FA4E91CEEF9915C72FF56598F0AB4BC3DF090CDC03E39D815906DA6E929BFD70BE345DD1B5B6A4264F726F
                  Malicious:false
                  Preview:)...u......fF..`..4....^m...B4`.).:5d@?.-..H....`.|.........\....yjD<..`M..56~.[...%.....U..)H..~.0.j.=2.\.................E..Y:..[.\3.x9..R?..yx....K...O1....i4..."9)....).#...^..H[T}.....s..z..Q]..;C.<...w.........T....q.......ae>.L.@~|..... .-.x.s.Tw..B....r%..0..&...+...<<v..G~...*..{c..rE.v.6.. .N.\..u1.5...c*./.W2....<......v.NaU...O.gmLl.U...S./....}....a.d.iEL>...&...pJMy7..{..o..w...e1?..._..r....,......+ ...b..U.W.&cH.X....g.'Lc...+s.~i.Qs.......A......Z..0.j.o.X..'^GEDF../.)8.+.....V..Ke...]20.#...-.k{/.6.r..>#u..i...I.U.D@...S2JG..V.....`'....e../|.w.RI......`.a.(....).7..0BmP.6......^.@H..u..........mi...........-........a.M1y..H.PM....)>$....*.`.B..vdc......J%..-.Er..u..I.~=...K.]L..:. ;.O../....R....e...P...]..S~.h?.t@..6'2x.,....3..f.DB...=xC.R.nJ.....o&Qs..p..".b...6]..*j.Z].<..b:..K...tF.F...`.X.)Y....-<DR(.j.....gl...F.-...=.Ykf........xK.k..m.1y..jlK....5....l.b....;.Y..9..6..... ..L..........t...._u.......E...Q..f..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5912
                  Entropy (8bit):7.969248728981797
                  Encrypted:false
                  SSDEEP:
                  MD5:9C962DF5E487A0E20CBEF5190677DC30
                  SHA1:352CBB520E03C96D839BFB1110011F34B531EED2
                  SHA-256:B4DFA6A6DA6BB15793901DBBCDE721FF986E582052CDEDC9D32A5ED01AF3AE05
                  SHA-512:38ED8DD024FEAF5DD191E857160E96FDD6DD998D91FA4E91CEEF9915C72FF56598F0AB4BC3DF090CDC03E39D815906DA6E929BFD70BE345DD1B5B6A4264F726F
                  Malicious:false
                  Preview:)...u......fF..`..4....^m...B4`.).:5d@?.-..H....`.|.........\....yjD<..`M..56~.[...%.....U..)H..~.0.j.=2.\.................E..Y:..[.\3.x9..R?..yx....K...O1....i4..."9)....).#...^..H[T}.....s..z..Q]..;C.<...w.........T....q.......ae>.L.@~|..... .-.x.s.Tw..B....r%..0..&...+...<<v..G~...*..{c..rE.v.6.. .N.\..u1.5...c*./.W2....<......v.NaU...O.gmLl.U...S./....}....a.d.iEL>...&...pJMy7..{..o..w...e1?..._..r....,......+ ...b..U.W.&cH.X....g.'Lc...+s.~i.Qs.......A......Z..0.j.o.X..'^GEDF../.)8.+.....V..Ke...]20.#...-.k{/.6.r..>#u..i...I.U.D@...S2JG..V.....`'....e../|.w.RI......`.a.(....).7..0BmP.6......^.@H..u..........mi...........-........a.M1y..H.PM....)>$....*.`.B..vdc......J%..-.Er..u..I.~=...K.]L..:. ;.O../....R....e...P...]..S~.h?.t@..6'2x.,....3..f.DB...=xC.R.nJ.....o&Qs..p..".b...6]..*j.Z].<..b:..K...tF.F...`.X.)Y....-<DR(.j.....gl...F.-...=.Ykf........xK.k..m.1y..jlK....5....l.b....;.Y..9..6..... ..L..........t...._u.......E...Q..f..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):5912
                  Entropy (8bit):7.969248728981797
                  Encrypted:false
                  SSDEEP:
                  MD5:9C962DF5E487A0E20CBEF5190677DC30
                  SHA1:352CBB520E03C96D839BFB1110011F34B531EED2
                  SHA-256:B4DFA6A6DA6BB15793901DBBCDE721FF986E582052CDEDC9D32A5ED01AF3AE05
                  SHA-512:38ED8DD024FEAF5DD191E857160E96FDD6DD998D91FA4E91CEEF9915C72FF56598F0AB4BC3DF090CDC03E39D815906DA6E929BFD70BE345DD1B5B6A4264F726F
                  Malicious:false
                  Preview:)...u......fF..`..4....^m...B4`.).:5d@?.-..H....`.|.........\....yjD<..`M..56~.[...%.....U..)H..~.0.j.=2.\.................E..Y:..[.\3.x9..R?..yx....K...O1....i4..."9)....).#...^..H[T}.....s..z..Q]..;C.<...w.........T....q.......ae>.L.@~|..... .-.x.s.Tw..B....r%..0..&...+...<<v..G~...*..{c..rE.v.6.. .N.\..u1.5...c*./.W2....<......v.NaU...O.gmLl.U...S./....}....a.d.iEL>...&...pJMy7..{..o..w...e1?..._..r....,......+ ...b..U.W.&cH.X....g.'Lc...+s.~i.Qs.......A......Z..0.j.o.X..'^GEDF../.)8.+.....V..Ke...]20.#...-.k{/.6.r..>#u..i...I.U.D@...S2JG..V.....`'....e../|.w.RI......`.a.(....).7..0BmP.6......^.@H..u..........mi...........-........a.M1y..H.PM....)>$....*.`.B..vdc......J%..-.Er..u..I.~=...K.]L..:. ;.O../....R....e...P...]..S~.h?.t@..6'2x.,....3..f.DB...=xC.R.nJ.....o&Qs..p..".b...6]..*j.Z].<..b:..K...tF.F...`.X.)Y....-<DR(.j.....gl...F.-...=.Ykf........xK.k..m.1y..jlK....5....l.b....;.Y..9..6..... ..L..........t...._u.......E...Q..f..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):23197
                  Entropy (8bit):7.992295287527494
                  Encrypted:true
                  SSDEEP:
                  MD5:3DCAD309F6EA28F96F9F8F0BC5737231
                  SHA1:FDFCB8E03B32DBFD97D45D2E948193B223FA6BE5
                  SHA-256:71F82F01D5B4573865013D91BD138FCF568AAEA02D9ADE72A0DD06ACE8B47AAB
                  SHA-512:6C479429C2A8660806DF796295C4C61D18EF30C5947D0D02329086CA45B2174B37D7A62FFE9916E0D4AA57701AF3A1EBE63D31B08F7245B7177E867E9E9F2350
                  Malicious:true
                  Preview:................t.#T....?..........#]..J...6.u..kg$.....p...+.....c.......RA?..&...r..n.r.....Jw.C...H..T.{.D.#.J-$ 4SF...U...zU?.....1k.w.U.....BWO.....F].i.7@Qv..W.K...D...j..A$...B.....%........Gu....\.w..I...8..........k..Y.1!|x..xF.$...<[..2.sXQ.{...b......y....?J;r.t&.Ry....s........C.._..a .e.g.K...7...|GZ..jM.t......w..,W.df.W...T...]NQv.X..{..k..U.2.._HL..D...!.k.`0.J..Z.uq...).k\..,...).7..iR.{...Ct.......g....8&.....:.O=...=.u...x.3.....w..3m.e*..*9.Qv.).j...(._.;.:.=&p*O896&......zT..u.S3.=wM......U.Q.9Y../.B...'.b...F..a...o...eD).:....G!0..uB.$.I.OW.Yh....*.r......Na...F].Q.7.%.F..L.*..a.,FbF.uD+.............Jv".Z!..z....r.k....'..4QM..G..7......ht".[.&....Xz..Tx........_.+i0....;.Q..;_....ru..zx....^.hZ .......0...\..$}..4...bvn..q.*L.......L..".......*.....g..U..D.G... B..RB.]..y..]...3.]J...;.`.jY.e...g...R?x.0...*..$.x...Oo..4..y...)9I .nF..!......(}p.Z....=..aH.B..P.R..?}&.......d....5GS....U.'...=..Tj...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):23197
                  Entropy (8bit):7.992295287527494
                  Encrypted:true
                  SSDEEP:
                  MD5:3DCAD309F6EA28F96F9F8F0BC5737231
                  SHA1:FDFCB8E03B32DBFD97D45D2E948193B223FA6BE5
                  SHA-256:71F82F01D5B4573865013D91BD138FCF568AAEA02D9ADE72A0DD06ACE8B47AAB
                  SHA-512:6C479429C2A8660806DF796295C4C61D18EF30C5947D0D02329086CA45B2174B37D7A62FFE9916E0D4AA57701AF3A1EBE63D31B08F7245B7177E867E9E9F2350
                  Malicious:true
                  Preview:................t.#T....?..........#]..J...6.u..kg$.....p...+.....c.......RA?..&...r..n.r.....Jw.C...H..T.{.D.#.J-$ 4SF...U...zU?.....1k.w.U.....BWO.....F].i.7@Qv..W.K...D...j..A$...B.....%........Gu....\.w..I...8..........k..Y.1!|x..xF.$...<[..2.sXQ.{...b......y....?J;r.t&.Ry....s........C.._..a .e.g.K...7...|GZ..jM.t......w..,W.df.W...T...]NQv.X..{..k..U.2.._HL..D...!.k.`0.J..Z.uq...).k\..,...).7..iR.{...Ct.......g....8&.....:.O=...=.u...x.3.....w..3m.e*..*9.Qv.).j...(._.;.:.=&p*O896&......zT..u.S3.=wM......U.Q.9Y../.B...'.b...F..a...o...eD).:....G!0..uB.$.I.OW.Yh....*.r......Na...F].Q.7.%.F..L.*..a.,FbF.uD+.............Jv".Z!..z....r.k....'..4QM..G..7......ht".[.&....Xz..Tx........_.+i0....;.Q..;_....ru..zx....^.hZ .......0...\..$}..4...bvn..q.*L.......L..".......*.....g..U..D.G... B..RB.]..y..]...3.]J...;.`.jY.e...g...R?x.0...*..$.x...Oo..4..y...)9I .nF..!......(}p.Z....=..aH.B..P.R..?}&.......d....5GS....U.'...=..Tj...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Secret Key
                  Category:dropped
                  Size (bytes):23197
                  Entropy (8bit):7.992295287527494
                  Encrypted:true
                  SSDEEP:
                  MD5:3DCAD309F6EA28F96F9F8F0BC5737231
                  SHA1:FDFCB8E03B32DBFD97D45D2E948193B223FA6BE5
                  SHA-256:71F82F01D5B4573865013D91BD138FCF568AAEA02D9ADE72A0DD06ACE8B47AAB
                  SHA-512:6C479429C2A8660806DF796295C4C61D18EF30C5947D0D02329086CA45B2174B37D7A62FFE9916E0D4AA57701AF3A1EBE63D31B08F7245B7177E867E9E9F2350
                  Malicious:true
                  Preview:................t.#T....?..........#]..J...6.u..kg$.....p...+.....c.......RA?..&...r..n.r.....Jw.C...H..T.{.D.#.J-$ 4SF...U...zU?.....1k.w.U.....BWO.....F].i.7@Qv..W.K...D...j..A$...B.....%........Gu....\.w..I...8..........k..Y.1!|x..xF.$...<[..2.sXQ.{...b......y....?J;r.t&.Ry....s........C.._..a .e.g.K...7...|GZ..jM.t......w..,W.df.W...T...]NQv.X..{..k..U.2.._HL..D...!.k.`0.J..Z.uq...).k\..,...).7..iR.{...Ct.......g....8&.....:.O=...=.u...x.3.....w..3m.e*..*9.Qv.).j...(._.;.:.=&p*O896&......zT..u.S3.=wM......U.Q.9Y../.B...'.b...F..a...o...eD).:....G!0..uB.$.I.OW.Yh....*.r......Na...F].Q.7.%.F..L.*..a.,FbF.uD+.............Jv".Z!..z....r.k....'..4QM..G..7......ht".[.&....Xz..Tx........_.+i0....;.Q..;_....ru..zx....^.hZ .......0...\..$}..4...bvn..q.*L.......L..".......*.....g..U..D.G... B..RB.]..y..]...3.]J...;.`.jY.e...g...R?x.0...*..$.x...Oo..4..y...)9I .nF..!......(}p.Z....=..aH.B..P.R..?}&.......d....5GS....U.'...=..Tj...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8923
                  Entropy (8bit):7.978260498823914
                  Encrypted:false
                  SSDEEP:
                  MD5:E4BA8E3C6D2E5D34CB4EA8BB737E18AA
                  SHA1:72B3A3DC35DA186D3D234C106960CA33389492B9
                  SHA-256:61E33D5BF809B8ECF2499AEE473571DB70B29F727B55CBF80B1795B03C97D3E9
                  SHA-512:14CF38C87C37CCC27E97BF595AFB7463E9F9744C6C4E52FB1AFC667A79F844692F4F5AA5ED1F848365744E1408F2AC507058A135FB2234C2FF746FF5F000E1C4
                  Malicious:false
                  Preview:..0.6.J+.E.u...L-....l#@....?n.......R].P.].^..h+..N.=[/.[.....R.N({..Y.@ .......$\..?.0Y........g.Y.".{9y?k/./6!+.{.l.._..;F.......FJ..Y..12....n..K.9......r..f.7.m..Q...dC.....|...O%...h....}.8....?.%.%.....2%.a...."r47*..O.HP..j.+..{..$.g.,.I.5(....5T<..q.C..,....|.......D...W.......s..L$...QY.O.g.....9.)......Qs.~.q...u....8.......r,... $6.n6.~aS......9..hCE.)Dp..t8.h.M.g.p..h...|.vQ....<w..>._....Z.Gv..O..U....D.y....J...?J....J.%.Q....G.. ..6....m..d.).....:;...._y~....1..N9v..p.A..Gy................0.. S.......9..@7.....P...zQ..{Z..TnwA.}...R.)0!."};`.Vg.5.7......v..H.F.W.i~Y%0.O....9...V>^.@..M.'.;w.!.5z&...o...8.D.........|h..*.4.qV.c.3~9....R.B.k.sP0@.KHiX.d.$....;.t..O.8..}:B..*..b..FU..g.]....j....Kd...^K.f..u.B.ry~..lY..5.....I.......}..o|.6..*.##...r!..?..'......k..b...&4e.?....Z.atP...FqRL...-.W...._..X..2.j.Z..G...../...h?.vJ.yA0;M...0.S...%........e..~v.R.O.[...B(...-.).]5.t..w.N.....+../$.*....)6..3..vX)......jg].
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8923
                  Entropy (8bit):7.978260498823914
                  Encrypted:false
                  SSDEEP:
                  MD5:E4BA8E3C6D2E5D34CB4EA8BB737E18AA
                  SHA1:72B3A3DC35DA186D3D234C106960CA33389492B9
                  SHA-256:61E33D5BF809B8ECF2499AEE473571DB70B29F727B55CBF80B1795B03C97D3E9
                  SHA-512:14CF38C87C37CCC27E97BF595AFB7463E9F9744C6C4E52FB1AFC667A79F844692F4F5AA5ED1F848365744E1408F2AC507058A135FB2234C2FF746FF5F000E1C4
                  Malicious:false
                  Preview:..0.6.J+.E.u...L-....l#@....?n.......R].P.].^..h+..N.=[/.[.....R.N({..Y.@ .......$\..?.0Y........g.Y.".{9y?k/./6!+.{.l.._..;F.......FJ..Y..12....n..K.9......r..f.7.m..Q...dC.....|...O%...h....}.8....?.%.%.....2%.a...."r47*..O.HP..j.+..{..$.g.,.I.5(....5T<..q.C..,....|.......D...W.......s..L$...QY.O.g.....9.)......Qs.~.q...u....8.......r,... $6.n6.~aS......9..hCE.)Dp..t8.h.M.g.p..h...|.vQ....<w..>._....Z.Gv..O..U....D.y....J...?J....J.%.Q....G.. ..6....m..d.).....:;...._y~....1..N9v..p.A..Gy................0.. S.......9..@7.....P...zQ..{Z..TnwA.}...R.)0!."};`.Vg.5.7......v..H.F.W.i~Y%0.O....9...V>^.@..M.'.;w.!.5z&...o...8.D.........|h..*.4.qV.c.3~9....R.B.k.sP0@.KHiX.d.$....;.t..O.8..}:B..*..b..FU..g.]....j....Kd...^K.f..u.B.ry~..lY..5.....I.......}..o|.6..*.##...r!..?..'......k..b...&4e.?....Z.atP...FqRL...-.W...._..X..2.j.Z..G...../...h?.vJ.yA0;M...0.S...%........e..~v.R.O.[...B(...-.).]5.t..w.N.....+../$.*....)6..3..vX)......jg].
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):8923
                  Entropy (8bit):7.978260498823914
                  Encrypted:false
                  SSDEEP:
                  MD5:E4BA8E3C6D2E5D34CB4EA8BB737E18AA
                  SHA1:72B3A3DC35DA186D3D234C106960CA33389492B9
                  SHA-256:61E33D5BF809B8ECF2499AEE473571DB70B29F727B55CBF80B1795B03C97D3E9
                  SHA-512:14CF38C87C37CCC27E97BF595AFB7463E9F9744C6C4E52FB1AFC667A79F844692F4F5AA5ED1F848365744E1408F2AC507058A135FB2234C2FF746FF5F000E1C4
                  Malicious:false
                  Preview:..0.6.J+.E.u...L-....l#@....?n.......R].P.].^..h+..N.=[/.[.....R.N({..Y.@ .......$\..?.0Y........g.Y.".{9y?k/./6!+.{.l.._..;F.......FJ..Y..12....n..K.9......r..f.7.m..Q...dC.....|...O%...h....}.8....?.%.%.....2%.a...."r47*..O.HP..j.+..{..$.g.,.I.5(....5T<..q.C..,....|.......D...W.......s..L$...QY.O.g.....9.)......Qs.~.q...u....8.......r,... $6.n6.~aS......9..hCE.)Dp..t8.h.M.g.p..h...|.vQ....<w..>._....Z.Gv..O..U....D.y....J...?J....J.%.Q....G.. ..6....m..d.).....:;...._y~....1..N9v..p.A..Gy................0.. S.......9..@7.....P...zQ..{Z..TnwA.}...R.)0!."};`.Vg.5.7......v..H.F.W.i~Y%0.O....9...V>^.@..M.'.;w.!.5z&...o...8.D.........|h..*.4.qV.c.3~9....R.B.k.sP0@.KHiX.d.$....;.t..O.8..}:B..*..b..FU..g.]....j....Kd...^K.f..u.B.ry~..lY..5.....I.......}..o|.6..*.##...r!..?..'......k..b...&4e.?....Z.atP...FqRL...-.W...._..X..2.j.Z..G...../...h?.vJ.yA0;M...0.S...%........e..~v.R.O.[...B(...-.).]5.t..w.N.....+../$.*....)6..3..vX)......jg].
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):947
                  Entropy (8bit):7.715218135204767
                  Encrypted:false
                  SSDEEP:
                  MD5:5D873AD209FCDFD2DC074A033C77DC42
                  SHA1:7ADEDD2803F4D8657923A27344D08EB34988D77D
                  SHA-256:3E955BFD0CD586681841435627ACE5E46FD1C78FCE6C4D8D85721F42DF27C2AB
                  SHA-512:4B23817FF23779EBD22C31E7C670BEF8BEA59C2C641362A025EFE739207A57A9A80635AEED588CE16B0287A44B060156080A3B1E7D7586CCBE3B3A9B34EE53B4
                  Malicious:false
                  Preview:..8.8.^.B8._..X.<......<...E..y..Am.NM.p;/Y.&..........-...WE..DGB.6.CmH..muM..~!.w.>.....'`..j....4......)..B.z|fR.|....&..'..g./A.R.q4.....;.,@_.d......!c.Mv.2.9n~.E...^.D.`5.5... (..j.ox.g ...w.Q...J...[u......|T4sI....P.46*.F...F.*9.^.]...mZ.B..~..T\?.t..)2..^..7TUQ...Z$.-.&...{-"..).G......R}..h.5j9..0.@Y........-.z..6!^#..._.+MEH.m..v.?JO]$...1..h.%.Q."...........I...P.w#..)d~.9..H...N..............`={.cB<.......DH8..B...8,H.m8.T.M.=....j@e.~3O..w..._.AU+w7}..w-.k..F!}...z..b$a{:L..(.2LG.B.u..W....e1.".Tv.R.'+<.k.&.Hv...*>.E+./....PG...N..j1#.m..A...7\..Y..Y}..,j...ka:...\....C..(.c...=..N.n.$..P.Oy6....\..7A..c_yI..EQ...d..~....5.t..e.y..5..qX}.;..jF..`..:...N..ItL\+.p...o...n.5.i.'....34....".E.....E.,$Q.zfy....q.x.......0.m.|[.....*W..:...[..N..H..a#.Iz:DH.`.~.....z4...f>.... c?j.UCJ.&,z'.........#X...5.>.Tbj.b.:@....m.V_..P5.....V.gD.1D.....j.=..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):947
                  Entropy (8bit):7.715218135204767
                  Encrypted:false
                  SSDEEP:
                  MD5:5D873AD209FCDFD2DC074A033C77DC42
                  SHA1:7ADEDD2803F4D8657923A27344D08EB34988D77D
                  SHA-256:3E955BFD0CD586681841435627ACE5E46FD1C78FCE6C4D8D85721F42DF27C2AB
                  SHA-512:4B23817FF23779EBD22C31E7C670BEF8BEA59C2C641362A025EFE739207A57A9A80635AEED588CE16B0287A44B060156080A3B1E7D7586CCBE3B3A9B34EE53B4
                  Malicious:false
                  Preview:..8.8.^.B8._..X.<......<...E..y..Am.NM.p;/Y.&..........-...WE..DGB.6.CmH..muM..~!.w.>.....'`..j....4......)..B.z|fR.|....&..'..g./A.R.q4.....;.,@_.d......!c.Mv.2.9n~.E...^.D.`5.5... (..j.ox.g ...w.Q...J...[u......|T4sI....P.46*.F...F.*9.^.]...mZ.B..~..T\?.t..)2..^..7TUQ...Z$.-.&...{-"..).G......R}..h.5j9..0.@Y........-.z..6!^#..._.+MEH.m..v.?JO]$...1..h.%.Q."...........I...P.w#..)d~.9..H...N..............`={.cB<.......DH8..B...8,H.m8.T.M.=....j@e.~3O..w..._.AU+w7}..w-.k..F!}...z..b$a{:L..(.2LG.B.u..W....e1.".Tv.R.'+<.k.&.Hv...*>.E+./....PG...N..j1#.m..A...7\..Y..Y}..,j...ka:...\....C..(.c...=..N.n.$..P.Oy6....\..7A..c_yI..EQ...d..~....5.t..e.y..5..qX}.;..jF..`..:...N..ItL\+.p...o...n.5.i.'....34....".E.....E.,$Q.zfy....q.x.......0.m.|[.....*W..:...[..N..H..a#.Iz:DH.`.~.....z4...f>.... c?j.UCJ.&,z'.........#X...5.>.Tbj.b.:@....m.V_..P5.....V.gD.1D.....j.=..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):947
                  Entropy (8bit):7.715218135204767
                  Encrypted:false
                  SSDEEP:
                  MD5:5D873AD209FCDFD2DC074A033C77DC42
                  SHA1:7ADEDD2803F4D8657923A27344D08EB34988D77D
                  SHA-256:3E955BFD0CD586681841435627ACE5E46FD1C78FCE6C4D8D85721F42DF27C2AB
                  SHA-512:4B23817FF23779EBD22C31E7C670BEF8BEA59C2C641362A025EFE739207A57A9A80635AEED588CE16B0287A44B060156080A3B1E7D7586CCBE3B3A9B34EE53B4
                  Malicious:false
                  Preview:..8.8.^.B8._..X.<......<...E..y..Am.NM.p;/Y.&..........-...WE..DGB.6.CmH..muM..~!.w.>.....'`..j....4......)..B.z|fR.|....&..'..g./A.R.q4.....;.,@_.d......!c.Mv.2.9n~.E...^.D.`5.5... (..j.ox.g ...w.Q...J...[u......|T4sI....P.46*.F...F.*9.^.]...mZ.B..~..T\?.t..)2..^..7TUQ...Z$.-.&...{-"..).G......R}..h.5j9..0.@Y........-.z..6!^#..._.+MEH.m..v.?JO]$...1..h.%.Q."...........I...P.w#..)d~.9..H...N..............`={.cB<.......DH8..B...8,H.m8.T.M.=....j@e.~3O..w..._.AU+w7}..w-.k..F!}...z..b$a{:L..(.2LG.B.u..W....e1.".Tv.R.'+<.k.&.Hv...*>.E+./....PG...N..j1#.m..A...7\..Y..Y}..,j...ka:...\....C..(.c...=..N.n.$..P.Oy6....\..7A..c_yI..EQ...d..~....5.t..e.y..5..qX}.;..jF..`..:...N..ItL\+.p...o...n.5.i.'....34....".E.....E.,$Q.zfy....q.x.......0.m.|[.....*W..:...[..N..H..a#.Iz:DH.`.~.....z4...f>.... c?j.UCJ.&,z'.........#X...5.>.Tbj.b.:@....m.V_..P5.....V.gD.1D.....j.=..........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):139062
                  Entropy (8bit):7.9986332946817145
                  Encrypted:true
                  SSDEEP:
                  MD5:3863D8197FEABE1A502245AC090C790D
                  SHA1:0D4368C16174108D409DB929210B0B478C05D9A6
                  SHA-256:2724A5305488E5FF4DDAFC0EAA27992E65586BC6052B79AEE484ABCDE98697A8
                  SHA-512:330BD18CA9EBA3F5FEA8C6BA48A2D8FE9FA1857466738328D755820EF745BF5122C983F6B28789FB6AF583AD89350BCA07E9F8E3E1A420B803492A86FAA5E4CC
                  Malicious:true
                  Preview:...+..Ej....S..,......).......a.+..0{V^.9\B..*..IZe..........=..%..C.F...to...".+$.S..19.\2n...|m..Y#...Y9..y...:.1R)..cH/..m.5.6j.@....eK.>....u...i......O ...W.....f..2..v...(.....C.........X.uVe....0..F.Lb....m....]6`5.Kr....j.A7..^j.H.`...VE.Z..(.q\...i\..M..Y..4aG....+..@1q...2C#..O@..3.V.e./..m.Ktj`....6...6.E<MP.%U..<y..Y....f.*0C.OI.y......43.:nd....Z.m.B........X.w.$.......y....[..[...,N;.....aTfW....;.K.Z..br.6...KTG}..U.......u....._......."...n..:;b/......8..7...eI.v..2|....t....B){.~.........NL..s.d.?i.j.j..........o&.....jk..l..I.I<..".2LX..U.q.}A..........b..d{J....i.....Pm<.:..x.\-t<s..^.np)......X:.K^"."$..f..8....~B...( .....i..1.........9.,..<..k....v.U..l9..f}.D...O..c3...c./.....Q.....jBL..B....\....g.d..t....3......8o..@Z....W..b&.._...z..p.........;...?.O....-..R3..W...b.-......:._.. .0.......Kb...^fu.$..V.QT..R.0...?e... .r....>e..|..t...em...aZ.+..$Z....^......,.L.XC...9Q..<.l.9R!]r ...j...Z..].....t6X..`.5[.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):139062
                  Entropy (8bit):7.9986332946817145
                  Encrypted:true
                  SSDEEP:
                  MD5:3863D8197FEABE1A502245AC090C790D
                  SHA1:0D4368C16174108D409DB929210B0B478C05D9A6
                  SHA-256:2724A5305488E5FF4DDAFC0EAA27992E65586BC6052B79AEE484ABCDE98697A8
                  SHA-512:330BD18CA9EBA3F5FEA8C6BA48A2D8FE9FA1857466738328D755820EF745BF5122C983F6B28789FB6AF583AD89350BCA07E9F8E3E1A420B803492A86FAA5E4CC
                  Malicious:true
                  Preview:...+..Ej....S..,......).......a.+..0{V^.9\B..*..IZe..........=..%..C.F...to...".+$.S..19.\2n...|m..Y#...Y9..y...:.1R)..cH/..m.5.6j.@....eK.>....u...i......O ...W.....f..2..v...(.....C.........X.uVe....0..F.Lb....m....]6`5.Kr....j.A7..^j.H.`...VE.Z..(.q\...i\..M..Y..4aG....+..@1q...2C#..O@..3.V.e./..m.Ktj`....6...6.E<MP.%U..<y..Y....f.*0C.OI.y......43.:nd....Z.m.B........X.w.$.......y....[..[...,N;.....aTfW....;.K.Z..br.6...KTG}..U.......u....._......."...n..:;b/......8..7...eI.v..2|....t....B){.~.........NL..s.d.?i.j.j..........o&.....jk..l..I.I<..".2LX..U.q.}A..........b..d{J....i.....Pm<.:..x.\-t<s..^.np)......X:.K^"."$..f..8....~B...( .....i..1.........9.,..<..k....v.U..l9..f}.D...O..c3...c./.....Q.....jBL..B....\....g.d..t....3......8o..@Z....W..b&.._...z..p.........;...?.O....-..R3..W...b.-......:._.. .0.......Kb...^fu.$..V.QT..R.0...?e... .r....>e..|..t...em...aZ.+..$Z....^......,.L.XC...9Q..<.l.9R!]r ...j...Z..].....t6X..`.5[.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):139062
                  Entropy (8bit):7.9986332946817145
                  Encrypted:true
                  SSDEEP:
                  MD5:3863D8197FEABE1A502245AC090C790D
                  SHA1:0D4368C16174108D409DB929210B0B478C05D9A6
                  SHA-256:2724A5305488E5FF4DDAFC0EAA27992E65586BC6052B79AEE484ABCDE98697A8
                  SHA-512:330BD18CA9EBA3F5FEA8C6BA48A2D8FE9FA1857466738328D755820EF745BF5122C983F6B28789FB6AF583AD89350BCA07E9F8E3E1A420B803492A86FAA5E4CC
                  Malicious:true
                  Preview:...+..Ej....S..,......).......a.+..0{V^.9\B..*..IZe..........=..%..C.F...to...".+$.S..19.\2n...|m..Y#...Y9..y...:.1R)..cH/..m.5.6j.@....eK.>....u...i......O ...W.....f..2..v...(.....C.........X.uVe....0..F.Lb....m....]6`5.Kr....j.A7..^j.H.`...VE.Z..(.q\...i\..M..Y..4aG....+..@1q...2C#..O@..3.V.e./..m.Ktj`....6...6.E<MP.%U..<y..Y....f.*0C.OI.y......43.:nd....Z.m.B........X.w.$.......y....[..[...,N;.....aTfW....;.K.Z..br.6...KTG}..U.......u....._......."...n..:;b/......8..7...eI.v..2|....t....B){.~.........NL..s.d.?i.j.j..........o&.....jk..l..I.I<..".2LX..U.q.}A..........b..d{J....i.....Pm<.:..x.\-t<s..^.np)......X:.K^"."$..f..8....~B...( .....i..1.........9.,..<..k....v.U..l9..f}.D...O..c3...c./.....Q.....jBL..B....\....g.d..t....3......8o..@Z....W..b&.._...z..p.........;...?.O....-..R3..W...b.-......:._.. .0.......Kb...^fu.$..V.QT..R.0...?e... .r....>e..|..t...em...aZ.+..$Z....^......,.L.XC...9Q..<.l.9R!]r ...j...Z..].....t6X..`.5[.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):62407
                  Entropy (8bit):7.997276698017676
                  Encrypted:true
                  SSDEEP:
                  MD5:CAC47EB39E5A021C8B181D549264D95D
                  SHA1:732CF1EED63E58F77B9E899B20420C89E7F27F16
                  SHA-256:0AC7DC6DB2BA00C6727A7408CB93C368605D71C76B6EED305511EC1E6A8E2BA7
                  SHA-512:44C8A49F18BABA1BD6705C6836543D5567010F18C4CD840DF8AD827D3D2D074542A802E7E274A38D29175018AC367B73C71B30DED9D07E47D96209D5CEB17BD5
                  Malicious:true
                  Preview:.g.0.b...~..t..v.....).D.wE.......l.S..v...j.rM\U.uK.....|m..,.xx.o........YL...?.^..25|..p..5.`_.Ycg&....}~....H.y..s..v..]...Z!._...ID:.} ..9..<...4.....{..K`......=?.+./P`..!F...jWk....^T.!P..9...m/A..MU..W.KG.....5.<...O.....:.v.b...H..)..Qo.._.s...{.....OdN....DpY.. ..b.p..im....k __.F#..EH.I).Ty.v.xM.....$2.....hH..}[]v.-.?...S..k.......W.BQ%....l.}g.M.g.8.<.g..C3..@Fb.....$Q.E..h.;...o.UX/......P<......D.....fY....@..P...3.DJ...f"O....fB.....V'...6....-......j|.:&.....r`.....X..+{G\2.Zv'V.....j"[.HSb...^; A.$.....w..0.NN....Ul..I<..=@.e.<k#...[...~.$... ...A..S...5..5..^b)^J..Oo.J..P...N...x..t.H_j..y....b...q.x.BE...-...t.Ii.W.v.\k....X]..c.c..5....B.z.a.......'.......c.....v..>.w.Z..l.[.d.k.]..q.y..^.n.EG.q\...l.w.....J$.9.}.....Yq+.......l_R41.3.../.+.*.i...DD.......:...]k.....u...rl4..y.^.\zy..n....g.B..7.8..A.c.......@.}4d...-.......bw......7#.........Z..3..%L...%R......Q..~C._.G. ......4../+./P.j.....}..^..d.4.l2..w#gD..2
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):62407
                  Entropy (8bit):7.997276698017676
                  Encrypted:true
                  SSDEEP:
                  MD5:CAC47EB39E5A021C8B181D549264D95D
                  SHA1:732CF1EED63E58F77B9E899B20420C89E7F27F16
                  SHA-256:0AC7DC6DB2BA00C6727A7408CB93C368605D71C76B6EED305511EC1E6A8E2BA7
                  SHA-512:44C8A49F18BABA1BD6705C6836543D5567010F18C4CD840DF8AD827D3D2D074542A802E7E274A38D29175018AC367B73C71B30DED9D07E47D96209D5CEB17BD5
                  Malicious:true
                  Preview:.g.0.b...~..t..v.....).D.wE.......l.S..v...j.rM\U.uK.....|m..,.xx.o........YL...?.^..25|..p..5.`_.Ycg&....}~....H.y..s..v..]...Z!._...ID:.} ..9..<...4.....{..K`......=?.+./P`..!F...jWk....^T.!P..9...m/A..MU..W.KG.....5.<...O.....:.v.b...H..)..Qo.._.s...{.....OdN....DpY.. ..b.p..im....k __.F#..EH.I).Ty.v.xM.....$2.....hH..}[]v.-.?...S..k.......W.BQ%....l.}g.M.g.8.<.g..C3..@Fb.....$Q.E..h.;...o.UX/......P<......D.....fY....@..P...3.DJ...f"O....fB.....V'...6....-......j|.:&.....r`.....X..+{G\2.Zv'V.....j"[.HSb...^; A.$.....w..0.NN....Ul..I<..=@.e.<k#...[...~.$... ...A..S...5..5..^b)^J..Oo.J..P...N...x..t.H_j..y....b...q.x.BE...-...t.Ii.W.v.\k....X]..c.c..5....B.z.a.......'.......c.....v..>.w.Z..l.[.d.k.]..q.y..^.n.EG.q\...l.w.....J$.9.}.....Yq+.......l_R41.3.../.+.*.i...DD.......:...]k.....u...rl4..y.^.\zy..n....g.B..7.8..A.c.......@.}4d...-.......bw......7#.........Z..3..%L...%R......Q..~C._.G. ......4../+./P.j.....}..^..d.4.l2..w#gD..2
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):62407
                  Entropy (8bit):7.997276698017676
                  Encrypted:true
                  SSDEEP:
                  MD5:CAC47EB39E5A021C8B181D549264D95D
                  SHA1:732CF1EED63E58F77B9E899B20420C89E7F27F16
                  SHA-256:0AC7DC6DB2BA00C6727A7408CB93C368605D71C76B6EED305511EC1E6A8E2BA7
                  SHA-512:44C8A49F18BABA1BD6705C6836543D5567010F18C4CD840DF8AD827D3D2D074542A802E7E274A38D29175018AC367B73C71B30DED9D07E47D96209D5CEB17BD5
                  Malicious:true
                  Preview:.g.0.b...~..t..v.....).D.wE.......l.S..v...j.rM\U.uK.....|m..,.xx.o........YL...?.^..25|..p..5.`_.Ycg&....}~....H.y..s..v..]...Z!._...ID:.} ..9..<...4.....{..K`......=?.+./P`..!F...jWk....^T.!P..9...m/A..MU..W.KG.....5.<...O.....:.v.b...H..)..Qo.._.s...{.....OdN....DpY.. ..b.p..im....k __.F#..EH.I).Ty.v.xM.....$2.....hH..}[]v.-.?...S..k.......W.BQ%....l.}g.M.g.8.<.g..C3..@Fb.....$Q.E..h.;...o.UX/......P<......D.....fY....@..P...3.DJ...f"O....fB.....V'...6....-......j|.:&.....r`.....X..+{G\2.Zv'V.....j"[.HSb...^; A.$.....w..0.NN....Ul..I<..=@.e.<k#...[...~.$... ...A..S...5..5..^b)^J..Oo.J..P...N...x..t.H_j..y....b...q.x.BE...-...t.Ii.W.v.\k....X]..c.c..5....B.z.a.......'.......c.....v..>.w.Z..l.[.d.k.]..q.y..^.n.EG.q\...l.w.....J$.9.}.....Yq+.......l_R41.3.../.+.*.i...DD.......:...]k.....u...rl4..y.^.\zy..n....g.B..7.8..A.c.......@.}4d...-.......bw......7#.........Z..3..%L...%R......Q..~C._.G. ......4../+./P.j.....}..^..d.4.l2..w#gD..2
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:COM executable for DOS
                  Category:dropped
                  Size (bytes):172429
                  Entropy (8bit):7.998800435823792
                  Encrypted:true
                  SSDEEP:
                  MD5:48762F1E11F0AE885E10B9DF4C2E4AB4
                  SHA1:0E44A22E095831C1E045ECD313B87CB10B510D61
                  SHA-256:26245809F31B666CB369B19077750FE2FD8C2E43B55E11F76E5D02FFF89F500E
                  SHA-512:D688B28EFC06EFDC71781A0AB63EBCCC0809F90E1A2CA6B1DE546889751838DBCA0BCABE874D32F103BF0C5B344F49AE156D6F862E64455D30141009C63D5A81
                  Malicious:true
                  Preview:...?......`N8........pP..6.|.u".Clu4..}.....1..'..^..XXG6......R.U.......T......m.[.&n.....p...4@..)Y..9...`.=.,..$4..Z..-.s.+.R.b......d.;J..<W.?:...j.P..J...Sd..[..Q..e........4.h...c.n...>@A........yzn.?7...B.=...x75hDXT.c..|.. ......3g.&....9.qb.sb?..p.H/.aY..C{O....2...or..=.K...rW.........2.7t+k.J...r.....=.z.$..?......c......&..N..p....eE...D.Dn.k=[S.+.h.4i..I..-.@!^.D..G(./YZN..C.8.2........h]...Zy'..q MG.HX./T'.|... E.....H.c...9..O_~`77x.W..V....L.....NY[F([.mv[l...&)..%.......=\......k].t.".=..|(..C..&..N..Yc..-$.**p...~..q3._G..Rz.5`d...(.]xB..Qc.O....c.l......@[...R..K..Z.w.].[5/}.=..C..%/..y"..W1..{l.....'....T.M3.=.......-.n....V..5..f...RO.C....T+q....)D.i,F.y.%...Q..._.t..Y>..H....._d.]"`...c.8/.k,ur..~.P...:u.S.R.qp..kN.=#..........V..Au.;.....:/.o.K62=..@..L2G....Du....~..p2.....r*.. R.d.f."T.?u.. ...iy)...;.C..xY.DM......N...m.......&..a.CKhZz.O..6h..~...)..T.oY.@..>...V....).........FL.!.....wja..V!h~)m......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:COM executable for DOS
                  Category:dropped
                  Size (bytes):172429
                  Entropy (8bit):7.998800435823792
                  Encrypted:true
                  SSDEEP:
                  MD5:48762F1E11F0AE885E10B9DF4C2E4AB4
                  SHA1:0E44A22E095831C1E045ECD313B87CB10B510D61
                  SHA-256:26245809F31B666CB369B19077750FE2FD8C2E43B55E11F76E5D02FFF89F500E
                  SHA-512:D688B28EFC06EFDC71781A0AB63EBCCC0809F90E1A2CA6B1DE546889751838DBCA0BCABE874D32F103BF0C5B344F49AE156D6F862E64455D30141009C63D5A81
                  Malicious:true
                  Preview:...?......`N8........pP..6.|.u".Clu4..}.....1..'..^..XXG6......R.U.......T......m.[.&n.....p...4@..)Y..9...`.=.,..$4..Z..-.s.+.R.b......d.;J..<W.?:...j.P..J...Sd..[..Q..e........4.h...c.n...>@A........yzn.?7...B.=...x75hDXT.c..|.. ......3g.&....9.qb.sb?..p.H/.aY..C{O....2...or..=.K...rW.........2.7t+k.J...r.....=.z.$..?......c......&..N..p....eE...D.Dn.k=[S.+.h.4i..I..-.@!^.D..G(./YZN..C.8.2........h]...Zy'..q MG.HX./T'.|... E.....H.c...9..O_~`77x.W..V....L.....NY[F([.mv[l...&)..%.......=\......k].t.".=..|(..C..&..N..Yc..-$.**p...~..q3._G..Rz.5`d...(.]xB..Qc.O....c.l......@[...R..K..Z.w.].[5/}.=..C..%/..y"..W1..{l.....'....T.M3.=.......-.n....V..5..f...RO.C....T+q....)D.i,F.y.%...Q..._.t..Y>..H....._d.]"`...c.8/.k,ur..~.P...:u.S.R.qp..kN.=#..........V..Au.;.....:/.o.K62=..@..L2G....Du....~..p2.....r*.. R.d.f."T.?u.. ...iy)...;.C..xY.DM......N...m.......&..a.CKhZz.O..6h..~...)..T.oY.@..>...V....).........FL.!.....wja..V!h~)m......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:COM executable for DOS
                  Category:dropped
                  Size (bytes):172429
                  Entropy (8bit):7.998800435823792
                  Encrypted:true
                  SSDEEP:
                  MD5:48762F1E11F0AE885E10B9DF4C2E4AB4
                  SHA1:0E44A22E095831C1E045ECD313B87CB10B510D61
                  SHA-256:26245809F31B666CB369B19077750FE2FD8C2E43B55E11F76E5D02FFF89F500E
                  SHA-512:D688B28EFC06EFDC71781A0AB63EBCCC0809F90E1A2CA6B1DE546889751838DBCA0BCABE874D32F103BF0C5B344F49AE156D6F862E64455D30141009C63D5A81
                  Malicious:true
                  Preview:...?......`N8........pP..6.|.u".Clu4..}.....1..'..^..XXG6......R.U.......T......m.[.&n.....p...4@..)Y..9...`.=.,..$4..Z..-.s.+.R.b......d.;J..<W.?:...j.P..J...Sd..[..Q..e........4.h...c.n...>@A........yzn.?7...B.=...x75hDXT.c..|.. ......3g.&....9.qb.sb?..p.H/.aY..C{O....2...or..=.K...rW.........2.7t+k.J...r.....=.z.$..?......c......&..N..p....eE...D.Dn.k=[S.+.h.4i..I..-.@!^.D..G(./YZN..C.8.2........h]...Zy'..q MG.HX./T'.|... E.....H.c...9..O_~`77x.W..V....L.....NY[F([.mv[l...&)..%.......=\......k].t.".=..|(..C..&..N..Yc..-$.**p...~..q3._G..Rz.5`d...(.]xB..Qc.O....c.l......@[...R..K..Z.w.].[5/}.=..C..%/..y"..W1..{l.....'....T.M3.=.......-.n....V..5..f...RO.C....T+q....)D.i,F.y.%...Q..._.t..Y>..H....._d.]"`...c.8/.k,ur..~.P...:u.S.R.qp..kN.=#..........V..Au.;.....:/.o.K62=..@..L2G....Du....~..p2.....r*.. R.d.f."T.?u.. ...iy)...;.C..xY.DM......N...m.......&..a.CKhZz.O..6h..~...)..T.oY.@..>...V....).........FL.!.....wja..V!h~)m......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):31001
                  Entropy (8bit):7.993787644834624
                  Encrypted:true
                  SSDEEP:
                  MD5:8044845F559FF45B4DDC3E73F9FE4F6E
                  SHA1:5703453B1FD00E73E960C169F54FCF89D521F847
                  SHA-256:A575A683F402CBAA971DDD632E0F9F8CF4587839CDD490CA0CC559B78E3C2CE6
                  SHA-512:ECDF9082F953283DDD61E235667B294E15628350733D1C065ADC5FE696C760885950293F71D46286F01805E017820B5391286C6A38D9AF3E8586BB1361220D29
                  Malicious:true
                  Preview:..m.E.R...y...A....$......j_y..[s..I..n..Z.]...&1...=dn.\l.W..+c.}.....hV.y..O;..../..Y...q.......q.....H.<..!...._.oA,ok....m.z.G%..]........3..Qi>X'..!km.t...]I8.....g..r*..5S...q]j~..0..Tv.I%.......<..V.R...T....:.......V.|...em.....s.z...0.)0...1..p......-..b.....[G..!BTH]......W.\.T4.....u]...W....T!.....\..$.z..Z.s...C8.6...P...\{V+.-.@...W.o).hG.=.W<.b{.Bo.k.....P/#f`./B...U..}&...t_..G....mn...v4f;>.. .T.......?....L.......I......[....g`.y.|..C.....{Z<..mx6.........}+.(...\,....A#...K.O.L..&:.......l1U........fFi.W.o.\..Z.......^5.E~.....`.e.0.....w.K....n@.....`po.L0.F.$..R.i.)....xt..FFnc]..%=.."_.......Z.....bp...k.z6V....I.7.g..,!o.D....p#..6....&6...`..J.M..0,..W....h=......!P...](2...J.@...S*..~.u.3.......[..1..?.s.57..]57*!Tdd...9`#...7.[!FL.....T.h....(.RVN...Pqt.......[..?....m..R...V..X'..CjG~.E..2>.,^yO....n .....-.)..D....V3uW7....*F..=6...oH.k...H%<B.m%oGT..Q...=..9"..%Q.....\....].q...n+.M......:....Hv.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):31001
                  Entropy (8bit):7.993787644834624
                  Encrypted:true
                  SSDEEP:
                  MD5:8044845F559FF45B4DDC3E73F9FE4F6E
                  SHA1:5703453B1FD00E73E960C169F54FCF89D521F847
                  SHA-256:A575A683F402CBAA971DDD632E0F9F8CF4587839CDD490CA0CC559B78E3C2CE6
                  SHA-512:ECDF9082F953283DDD61E235667B294E15628350733D1C065ADC5FE696C760885950293F71D46286F01805E017820B5391286C6A38D9AF3E8586BB1361220D29
                  Malicious:true
                  Preview:..m.E.R...y...A....$......j_y..[s..I..n..Z.]...&1...=dn.\l.W..+c.}.....hV.y..O;..../..Y...q.......q.....H.<..!...._.oA,ok....m.z.G%..]........3..Qi>X'..!km.t...]I8.....g..r*..5S...q]j~..0..Tv.I%.......<..V.R...T....:.......V.|...em.....s.z...0.)0...1..p......-..b.....[G..!BTH]......W.\.T4.....u]...W....T!.....\..$.z..Z.s...C8.6...P...\{V+.-.@...W.o).hG.=.W<.b{.Bo.k.....P/#f`./B...U..}&...t_..G....mn...v4f;>.. .T.......?....L.......I......[....g`.y.|..C.....{Z<..mx6.........}+.(...\,....A#...K.O.L..&:.......l1U........fFi.W.o.\..Z.......^5.E~.....`.e.0.....w.K....n@.....`po.L0.F.$..R.i.)....xt..FFnc]..%=.."_.......Z.....bp...k.z6V....I.7.g..,!o.D....p#..6....&6...`..J.M..0,..W....h=......!P...](2...J.@...S*..~.u.3.......[..1..?.s.57..]57*!Tdd...9`#...7.[!FL.....T.h....(.RVN...Pqt.......[..?....m..R...V..X'..CjG~.E..2>.,^yO....n .....-.)..D....V3uW7....*F..=6...oH.k...H%<B.m%oGT..Q...=..9"..%Q.....\....].q...n+.M......:....Hv.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):31001
                  Entropy (8bit):7.993787644834624
                  Encrypted:true
                  SSDEEP:
                  MD5:8044845F559FF45B4DDC3E73F9FE4F6E
                  SHA1:5703453B1FD00E73E960C169F54FCF89D521F847
                  SHA-256:A575A683F402CBAA971DDD632E0F9F8CF4587839CDD490CA0CC559B78E3C2CE6
                  SHA-512:ECDF9082F953283DDD61E235667B294E15628350733D1C065ADC5FE696C760885950293F71D46286F01805E017820B5391286C6A38D9AF3E8586BB1361220D29
                  Malicious:true
                  Preview:..m.E.R...y...A....$......j_y..[s..I..n..Z.]...&1...=dn.\l.W..+c.}.....hV.y..O;..../..Y...q.......q.....H.<..!...._.oA,ok....m.z.G%..]........3..Qi>X'..!km.t...]I8.....g..r*..5S...q]j~..0..Tv.I%.......<..V.R...T....:.......V.|...em.....s.z...0.)0...1..p......-..b.....[G..!BTH]......W.\.T4.....u]...W....T!.....\..$.z..Z.s...C8.6...P...\{V+.-.@...W.o).hG.=.W<.b{.Bo.k.....P/#f`./B...U..}&...t_..G....mn...v4f;>.. .T.......?....L.......I......[....g`.y.|..C.....{Z<..mx6.........}+.(...\,....A#...K.O.L..&:.......l1U........fFi.W.o.\..Z.......^5.E~.....`.e.0.....w.K....n@.....`po.L0.F.$..R.i.)....xt..FFnc]..%=.."_.......Z.....bp...k.z6V....I.7.g..,!o.D....p#..6....&6...`..J.M..0,..W....h=......!P...](2...J.@...S*..~.u.3.......[..1..?.s.57..]57*!Tdd...9`#...7.[!FL.....T.h....(.RVN...Pqt.......[..?....m..R...V..X'..CjG~.E..2>.,^yO....n .....-.)..D....V3uW7....*F..=6...oH.k...H%<B.m%oGT..Q...=..9"..%Q.....\....].q...n+.M......:....Hv.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):424100
                  Entropy (8bit):7.999586395401116
                  Encrypted:true
                  SSDEEP:
                  MD5:C8E19BFEFAB496F2164A1D0F545307A8
                  SHA1:23EBDB39892CCC15F251A5607E2D32B559A196D8
                  SHA-256:5080B14BDFEE264F84A8330175A61ADF5B30AD7ADBA5441E3D92661B8B6F13B2
                  SHA-512:F434125EBA7F5D914D6DF166EDCC94F5D0A7FC516653049E2A9CF4CC992D1B4E03FA54C4E2F093DCFCF3E80261B7B2222220822CA785DDDF37C6D425762043BF
                  Malicious:true
                  Preview:u..o.w...?Wg...../&Q......}FF..$....R=j$L..G1.`.f..2'..R"p{.U..X.I......5...b:.M......V4Q.5.J$..%...s..z?.U..2..&..1,..NA...........R.5...&U.B..0.R...../&.h0`..`...t..a.y.P...M.IGe...s..bn..e...}..*a..S#S............59.%..Z.Ve.....z...*7.. ..fF.\}....Sc.pG..8.VA.o..S.}n..N.`....x....&%......x$.Oi...H.X.H..J.....y.I..v....~Wm.......\..s..t.T..W..I5..sK.}c.d...P....@.xq1.^<.n.&1G0=.W..P...Q.v...3.....W4=.D.#.....I)..[.....z......^.[.U..-7....0n&h......RM.L...-..*+L.......q..#C....Y.....q.(.!P..iL.s..$.s$.k.S.Pgu3...i.%;'r.-.U`...!-kn...... ./\..L.JQ0....5sBS..'.......n..).F.....U..C\..\......J...g..W`.av.T......M....x.....Ox.8|:(..z...H.....po.l.`....d.J....oW...u...X*..7....9l...n..%&M......j.#.e1.*....q.....(....2..!..5V@,..W ..~..2:c.N....$....jo..T.......Xc..].H.p@LeT...a%.F)...WY../.|.>y./:..%.?....`...............0..+B....G....".t.@.}..Ob),.[..).....7..MnTR*W7..6...|(......]..=$.Z?g..5>\.0.@....\r.E...d........Z...U.9.....:
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):424100
                  Entropy (8bit):7.999586395401116
                  Encrypted:true
                  SSDEEP:
                  MD5:C8E19BFEFAB496F2164A1D0F545307A8
                  SHA1:23EBDB39892CCC15F251A5607E2D32B559A196D8
                  SHA-256:5080B14BDFEE264F84A8330175A61ADF5B30AD7ADBA5441E3D92661B8B6F13B2
                  SHA-512:F434125EBA7F5D914D6DF166EDCC94F5D0A7FC516653049E2A9CF4CC992D1B4E03FA54C4E2F093DCFCF3E80261B7B2222220822CA785DDDF37C6D425762043BF
                  Malicious:true
                  Preview:u..o.w...?Wg...../&Q......}FF..$....R=j$L..G1.`.f..2'..R"p{.U..X.I......5...b:.M......V4Q.5.J$..%...s..z?.U..2..&..1,..NA...........R.5...&U.B..0.R...../&.h0`..`...t..a.y.P...M.IGe...s..bn..e...}..*a..S#S............59.%..Z.Ve.....z...*7.. ..fF.\}....Sc.pG..8.VA.o..S.}n..N.`....x....&%......x$.Oi...H.X.H..J.....y.I..v....~Wm.......\..s..t.T..W..I5..sK.}c.d...P....@.xq1.^<.n.&1G0=.W..P...Q.v...3.....W4=.D.#.....I)..[.....z......^.[.U..-7....0n&h......RM.L...-..*+L.......q..#C....Y.....q.(.!P..iL.s..$.s$.k.S.Pgu3...i.%;'r.-.U`...!-kn...... ./\..L.JQ0....5sBS..'.......n..).F.....U..C\..\......J...g..W`.av.T......M....x.....Ox.8|:(..z...H.....po.l.`....d.J....oW...u...X*..7....9l...n..%&M......j.#.e1.*....q.....(....2..!..5V@,..W ..~..2:c.N....$....jo..T.......Xc..].H.p@LeT...a%.F)...WY../.|.>y./:..%.?....`...............0..+B....G....".t.@.}..Ob),.[..).....7..MnTR*W7..6...|(......]..=$.Z?g..5>\.0.@....\r.E...d........Z...U.9.....:
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):424100
                  Entropy (8bit):7.999586395401116
                  Encrypted:true
                  SSDEEP:
                  MD5:C8E19BFEFAB496F2164A1D0F545307A8
                  SHA1:23EBDB39892CCC15F251A5607E2D32B559A196D8
                  SHA-256:5080B14BDFEE264F84A8330175A61ADF5B30AD7ADBA5441E3D92661B8B6F13B2
                  SHA-512:F434125EBA7F5D914D6DF166EDCC94F5D0A7FC516653049E2A9CF4CC992D1B4E03FA54C4E2F093DCFCF3E80261B7B2222220822CA785DDDF37C6D425762043BF
                  Malicious:true
                  Preview:u..o.w...?Wg...../&Q......}FF..$....R=j$L..G1.`.f..2'..R"p{.U..X.I......5...b:.M......V4Q.5.J$..%...s..z?.U..2..&..1,..NA...........R.5...&U.B..0.R...../&.h0`..`...t..a.y.P...M.IGe...s..bn..e...}..*a..S#S............59.%..Z.Ve.....z...*7.. ..fF.\}....Sc.pG..8.VA.o..S.}n..N.`....x....&%......x$.Oi...H.X.H..J.....y.I..v....~Wm.......\..s..t.T..W..I5..sK.}c.d...P....@.xq1.^<.n.&1G0=.W..P...Q.v...3.....W4=.D.#.....I)..[.....z......^.[.U..-7....0n&h......RM.L...-..*+L.......q..#C....Y.....q.(.!P..iL.s..$.s$.k.S.Pgu3...i.%;'r.-.U`...!-kn...... ./\..L.JQ0....5sBS..'.......n..).F.....U..C\..\......J...g..W`.av.T......M....x.....Ox.8|:(..z...H.....po.l.`....d.J....oW...u...X*..7....9l...n..%&M......j.#.e1.*....q.....(....2..!..5V@,..W ..~..2:c.N....$....jo..T.......Xc..].H.p@LeT...a%.F)...WY../.|.>y./:..%.?....`...............0..+B....G....".t.@.}..Ob),.[..).....7..MnTR*W7..6...|(......]..=$.Z?g..5>\.0.@....\r.E...d........Z...U.9.....:
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):42505084
                  Entropy (8bit):6.050583741322705
                  Encrypted:false
                  SSDEEP:
                  MD5:581FC64BF47AC9CE7D56960D6EA493AF
                  SHA1:F86AA426BAAAAC5C0FB4489A2D5C1C721901325A
                  SHA-256:3C5382632731523AA25051CC2D56F3EABAA08970378FC9BC2BA7CA28DD84E899
                  SHA-512:23DB49E9CE0124DEFDAA3F84905A75EBAE6734604FC0F198AFCCA731D0F96B829B739D64CB593268612F34CF7971569AC402EC5502118475BCB567130B8388D1
                  Malicious:false
                  Preview:n,9...2<.1Rc4.7..z3.L.>..Z..,E...G.........z.h.W...2<.p..,...2.-......d...H~.p.....p....L...|=...4..4..)....4..8.!.[.m.k./m.........Qn.......-.....x}........L...w.......?....p.m...uUA..!].l.L.s.t?!..*5.h.......G..+4,q.\.9...K.Z..2..n%.*./,.L.....D+.-7.z7P3B...%..4..#...;.q..&G.^.HG\.....i.&.GJ|1t..9.._?.t..]@s.7.......DW..).cVN...).$..p...N.c.9.?f.^..u...2@Y.$~.5u.....`._Q."....G..g...oS.H:.......T.5n.O.X'X..m.......M..+,...=-....sS..v..........9....<.*..f.IX...?....{....O'.nc.P..:..w...C..j..".O.al...S.....,...s......O....7.|.O>$.m...u...b0.xd{.....v....Ic.a.2.>..y"......1..s. .D......m...4....P.!..M6..J@...."....3."<.tE.^...}.%'6...*.9...C.V.n.9)...H.l.8...l..........]\......UC..-Q&.'..i.n..f..5^..g..`{.......?..H....u<.#.,l..>M."...g'gM..93.x....:]...@.G...t.:...[R.T....f..n:...S..3T..l...v.x..:.S...........8?4....>dV.a....^9.6c.e.s5H.;'J4....-.{e......y.........zrw.C.~...6V....x.$...U.Hp'`eDL+.{....G.M.v~+Sm.?..RHe.g^K....... u...........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):42505084
                  Entropy (8bit):6.050583741322705
                  Encrypted:false
                  SSDEEP:
                  MD5:581FC64BF47AC9CE7D56960D6EA493AF
                  SHA1:F86AA426BAAAAC5C0FB4489A2D5C1C721901325A
                  SHA-256:3C5382632731523AA25051CC2D56F3EABAA08970378FC9BC2BA7CA28DD84E899
                  SHA-512:23DB49E9CE0124DEFDAA3F84905A75EBAE6734604FC0F198AFCCA731D0F96B829B739D64CB593268612F34CF7971569AC402EC5502118475BCB567130B8388D1
                  Malicious:false
                  Preview:n,9...2<.1Rc4.7..z3.L.>..Z..,E...G.........z.h.W...2<.p..,...2.-......d...H~.p.....p....L...|=...4..4..)....4..8.!.[.m.k./m.........Qn.......-.....x}........L...w.......?....p.m...uUA..!].l.L.s.t?!..*5.h.......G..+4,q.\.9...K.Z..2..n%.*./,.L.....D+.-7.z7P3B...%..4..#...;.q..&G.^.HG\.....i.&.GJ|1t..9.._?.t..]@s.7.......DW..).cVN...).$..p...N.c.9.?f.^..u...2@Y.$~.5u.....`._Q."....G..g...oS.H:.......T.5n.O.X'X..m.......M..+,...=-....sS..v..........9....<.*..f.IX...?....{....O'.nc.P..:..w...C..j..".O.al...S.....,...s......O....7.|.O>$.m...u...b0.xd{.....v....Ic.a.2.>..y"......1..s. .D......m...4....P.!..M6..J@...."....3."<.tE.^...}.%'6...*.9...C.V.n.9)...H.l.8...l..........]\......UC..-Q&.'..i.n..f..5^..g..`{.......?..H....u<.#.,l..>M."...g'gM..93.x....:]...@.G...t.:...[R.T....f..n:...S..3T..l...v.x..:.S...........8?4....>dV.a....^9.6c.e.s5H.;'J4....-.{e......y.........zrw.C.~...6V....x.$...U.Hp'`eDL+.{....G.M.v~+Sm.?..RHe.g^K....... u...........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4062
                  Entropy (8bit):7.946858660434708
                  Encrypted:false
                  SSDEEP:
                  MD5:3C790CD7226F4636EDAD84F27DC089C6
                  SHA1:C22E3AFD2EE3FE85DCD03CEAD8CBB62CDC945D9D
                  SHA-256:5A5187F240704359E0796F60E4ED39EF204C7B71E83B0888E6EF57E214607B17
                  SHA-512:1759A255B6AF30968B0604875ECFC5D252B448B350191D40A968C8B94C9D52AD0FDB4B0CF53AE3294DBD71F57D9AF68984EEBB52B5190AD1DB183BA5B4966526
                  Malicious:false
                  Preview:t...l.FyA.K..;...v......P.\r"..Dt.J._Ur...{:...Jc}s..kc-.$..<.Jy...t>.......'._...a..3....@.7...5L..m&......'.v;.o..s.=<gD..m........,%.@..CO.ScR.@...R...icT...v.......$<.~I4.QT.Q..Xd>....e.YWJ^t..W.-.|.E6?O.3.B..\Q.....V.E.p?i.+u..5.C..3oB.O.^.Hx.y.Q.V.H ...=.X...l.\Z.....a.p..JT........Y..A.4!..^...>.]..n...x.Y...;_d'..*...Hk3.....u.1Y.Q..9..~..).?.o~|m..#W....H.`MDR..O.m.......2...p5.j.nJ.CBj+.l$#..C1.`.8.N...".....g...<8..M....(!e......yLp.U.CQ(..T9.3T...5.k...tKc..a..D0..>.c.&^.pfv..]M.;@+0"U.......-fO.s......R#.. >.]3.f.....Ki.N......p o!....!.".WD.?y,.UP..Xa..V. ..TG.....V.hG....m.....h..".....h..v.J)...^.B....D.-....Ly...|9]...Y%.v...;..f^(.!+<`....x.]...B...2........:.....L@.......Nu..%9y..=Bf.,.e.y|..m...............=......[...c........e.i.B....nl....#.q:.../.09[...|......}ETT...l...GV.BUS.-...1?%....5.3.(.gt=...$...I.A.x..'.....P...r.3.Ac.U.7..H2VSK8H.F5Bg7dhB.e..abs.....|.Tbl}hv.v..C.<;0...m.......h.I....GfK@.<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4062
                  Entropy (8bit):7.946858660434708
                  Encrypted:false
                  SSDEEP:
                  MD5:3C790CD7226F4636EDAD84F27DC089C6
                  SHA1:C22E3AFD2EE3FE85DCD03CEAD8CBB62CDC945D9D
                  SHA-256:5A5187F240704359E0796F60E4ED39EF204C7B71E83B0888E6EF57E214607B17
                  SHA-512:1759A255B6AF30968B0604875ECFC5D252B448B350191D40A968C8B94C9D52AD0FDB4B0CF53AE3294DBD71F57D9AF68984EEBB52B5190AD1DB183BA5B4966526
                  Malicious:false
                  Preview:t...l.FyA.K..;...v......P.\r"..Dt.J._Ur...{:...Jc}s..kc-.$..<.Jy...t>.......'._...a..3....@.7...5L..m&......'.v;.o..s.=<gD..m........,%.@..CO.ScR.@...R...icT...v.......$<.~I4.QT.Q..Xd>....e.YWJ^t..W.-.|.E6?O.3.B..\Q.....V.E.p?i.+u..5.C..3oB.O.^.Hx.y.Q.V.H ...=.X...l.\Z.....a.p..JT........Y..A.4!..^...>.]..n...x.Y...;_d'..*...Hk3.....u.1Y.Q..9..~..).?.o~|m..#W....H.`MDR..O.m.......2...p5.j.nJ.CBj+.l$#..C1.`.8.N...".....g...<8..M....(!e......yLp.U.CQ(..T9.3T...5.k...tKc..a..D0..>.c.&^.pfv..]M.;@+0"U.......-fO.s......R#.. >.]3.f.....Ki.N......p o!....!.".WD.?y,.UP..Xa..V. ..TG.....V.hG....m.....h..".....h..v.J)...^.B....D.-....Ly...|9]...Y%.v...;..f^(.!+<`....x.]...B...2........:.....L@.......Nu..%9y..=Bf.,.e.y|..m...............=......[...c........e.i.B....nl....#.q:.../.09[...|......}ETT...l...GV.BUS.-...1?%....5.3.(.gt=...$...I.A.x..'.....P...r.3.Ac.U.7..H2VSK8H.F5Bg7dhB.e..abs.....|.Tbl}hv.v..C.<;0...m.......h.I....GfK@.<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):4062
                  Entropy (8bit):7.946858660434708
                  Encrypted:false
                  SSDEEP:
                  MD5:3C790CD7226F4636EDAD84F27DC089C6
                  SHA1:C22E3AFD2EE3FE85DCD03CEAD8CBB62CDC945D9D
                  SHA-256:5A5187F240704359E0796F60E4ED39EF204C7B71E83B0888E6EF57E214607B17
                  SHA-512:1759A255B6AF30968B0604875ECFC5D252B448B350191D40A968C8B94C9D52AD0FDB4B0CF53AE3294DBD71F57D9AF68984EEBB52B5190AD1DB183BA5B4966526
                  Malicious:false
                  Preview:t...l.FyA.K..;...v......P.\r"..Dt.J._Ur...{:...Jc}s..kc-.$..<.Jy...t>.......'._...a..3....@.7...5L..m&......'.v;.o..s.=<gD..m........,%.@..CO.ScR.@...R...icT...v.......$<.~I4.QT.Q..Xd>....e.YWJ^t..W.-.|.E6?O.3.B..\Q.....V.E.p?i.+u..5.C..3oB.O.^.Hx.y.Q.V.H ...=.X...l.\Z.....a.p..JT........Y..A.4!..^...>.]..n...x.Y...;_d'..*...Hk3.....u.1Y.Q..9..~..).?.o~|m..#W....H.`MDR..O.m.......2...p5.j.nJ.CBj+.l$#..C1.`.8.N...".....g...<8..M....(!e......yLp.U.CQ(..T9.3T...5.k...tKc..a..D0..>.c.&^.pfv..]M.;@+0"U.......-fO.s......R#.. >.]3.f.....Ki.N......p o!....!.".WD.?y,.UP..Xa..V. ..TG.....V.hG....m.....h..".....h..v.J)...^.B....D.-....Ly...|9]...Y%.v...;..f^(.!+<`....x.]...B...2........:.....L@.......Nu..%9y..=Bf.,.e.y|..m...............=......[...c........e.i.B....nl....#.q:.../.09[...|......}ETT...l...GV.BUS.-...1?%....5.3.(.gt=...$...I.A.x..'.....P...r.3.Ac.U.7..H2VSK8H.F5Bg7dhB.e..abs.....|.Tbl}hv.v..C.<;0...m.......h.I....GfK@.<
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1092
                  Entropy (8bit):7.766989067339871
                  Encrypted:false
                  SSDEEP:
                  MD5:D94F9C6BF075BE0F3EB770BD439EC0C7
                  SHA1:C315D089B87624CF8E311278FBD3B93F0B7E4207
                  SHA-256:E24A4EEB2BB09B76AD7CB6F4AE4FDE7B89BDB740C0E6DA0E63B8E176E2089B45
                  SHA-512:EEE42878F00C77BE1F464DB20E0C46A68DE957512663641266ED380CF815FA8702275AD3DFA34A65ECEA10D7ADD5FC3B6A2DEC0D71997E7ACEDEEBB0AA59CCB3
                  Malicious:false
                  Preview:,#..m.X..6.Ep)...?...P.|o......R..34.U..%....E.........W.&R.....$Z..]O...]Q.15.^b.].o-.....|........&;h.........y....3`.y.*.EQ.:F.0ad...OF.Vr{e..B.(.)..[.....~.B.:*.f/.V....b..#......S......!.......&..q....f...@b.<).?.$.?...G.p\.8.. .J$......n..H-...@...9.;t..@.Zy......x.;.Z.*.;...*......v.n...2Y.~...G...~D-g$^JB.Y....j....@,s...U.:.<w%t.*iD....T...c....#8...-.70..g...c. .P7R..=B.v.!\.^.].-.1...z.|1.I._.E.HT>T....@.g..C........f.....!...K...Y.<...BB.....Q.ds\rIX..,......P..~.Hj...b.X.H:F......d.....9.T.L.'.}....g...f....fyw..;.`t.9..$gO....}uf...<zF....q.e..z.6.T1...pB..q.../..sb:MI~....@.../...N....e...,..2....kM..2D.R>...M.;a1Y....R.....'`........]8....P.5]O.q.hD.D.i..=..:5.i./_..1..Z9L../.....?.8-.b.~...{...l(MY.....,.-w.s.....H.....U.0.T.C.W...3.;._..%.{.DEw:..;J...!.........tr...h#,.-B.a...l.:`.U...".)...f....]u..'.v.(.S..W...H.`.v)...X.......0.."..>..N|.AU...W...^..../w..Xk.?...+.{.%.%.F.....'.<D7?.>n..._.B....b.t.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1092
                  Entropy (8bit):7.766989067339871
                  Encrypted:false
                  SSDEEP:
                  MD5:D94F9C6BF075BE0F3EB770BD439EC0C7
                  SHA1:C315D089B87624CF8E311278FBD3B93F0B7E4207
                  SHA-256:E24A4EEB2BB09B76AD7CB6F4AE4FDE7B89BDB740C0E6DA0E63B8E176E2089B45
                  SHA-512:EEE42878F00C77BE1F464DB20E0C46A68DE957512663641266ED380CF815FA8702275AD3DFA34A65ECEA10D7ADD5FC3B6A2DEC0D71997E7ACEDEEBB0AA59CCB3
                  Malicious:false
                  Preview:,#..m.X..6.Ep)...?...P.|o......R..34.U..%....E.........W.&R.....$Z..]O...]Q.15.^b.].o-.....|........&;h.........y....3`.y.*.EQ.:F.0ad...OF.Vr{e..B.(.)..[.....~.B.:*.f/.V....b..#......S......!.......&..q....f...@b.<).?.$.?...G.p\.8.. .J$......n..H-...@...9.;t..@.Zy......x.;.Z.*.;...*......v.n...2Y.~...G...~D-g$^JB.Y....j....@,s...U.:.<w%t.*iD....T...c....#8...-.70..g...c. .P7R..=B.v.!\.^.].-.1...z.|1.I._.E.HT>T....@.g..C........f.....!...K...Y.<...BB.....Q.ds\rIX..,......P..~.Hj...b.X.H:F......d.....9.T.L.'.}....g...f....fyw..;.`t.9..$gO....}uf...<zF....q.e..z.6.T1...pB..q.../..sb:MI~....@.../...N....e...,..2....kM..2D.R>...M.;a1Y....R.....'`........]8....P.5]O.q.hD.D.i..=..:5.i./_..1..Z9L../.....?.8-.b.~...{...l(MY.....,.-w.s.....H.....U.0.T.C.W...3.;._..%.{.DEw:..;J...!.........tr...h#,.-B.a...l.:`.U...".)...f....]u..'.v.(.S..W...H.`.v)...X.......0.."..>..N|.AU...W...^..../w..Xk.?...+.{.%.%.F.....'.<D7?.>n..._.B....b.t.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1092
                  Entropy (8bit):7.766989067339871
                  Encrypted:false
                  SSDEEP:
                  MD5:D94F9C6BF075BE0F3EB770BD439EC0C7
                  SHA1:C315D089B87624CF8E311278FBD3B93F0B7E4207
                  SHA-256:E24A4EEB2BB09B76AD7CB6F4AE4FDE7B89BDB740C0E6DA0E63B8E176E2089B45
                  SHA-512:EEE42878F00C77BE1F464DB20E0C46A68DE957512663641266ED380CF815FA8702275AD3DFA34A65ECEA10D7ADD5FC3B6A2DEC0D71997E7ACEDEEBB0AA59CCB3
                  Malicious:false
                  Preview:,#..m.X..6.Ep)...?...P.|o......R..34.U..%....E.........W.&R.....$Z..]O...]Q.15.^b.].o-.....|........&;h.........y....3`.y.*.EQ.:F.0ad...OF.Vr{e..B.(.)..[.....~.B.:*.f/.V....b..#......S......!.......&..q....f...@b.<).?.$.?...G.p\.8.. .J$......n..H-...@...9.;t..@.Zy......x.;.Z.*.;...*......v.n...2Y.~...G...~D-g$^JB.Y....j....@,s...U.:.<w%t.*iD....T...c....#8...-.70..g...c. .P7R..=B.v.!\.^.].-.1...z.|1.I._.E.HT>T....@.g..C........f.....!...K...Y.<...BB.....Q.ds\rIX..,......P..~.Hj...b.X.H:F......d.....9.T.L.'.}....g...f....fyw..;.`t.9..$gO....}uf...<zF....q.e..z.6.T1...pB..q.../..sb:MI~....@.../...N....e...,..2....kM..2D.R>...M.;a1Y....R.....'`........]8....P.5]O.q.hD.D.i..=..:5.i./_..1..Z9L../.....?.8-.b.~...{...l(MY.....,.-w.s.....H.....U.0.T.C.W...3.;._..%.{.DEw:..;J...!.........tr...h#,.-B.a...l.:`.U...".)...f....]u..'.v.(.S..W...H.`.v)...X.......0.."..>..N|.AU...W...^..../w..Xk.?...+.{.%.%.F.....'.<D7?.>n..._.B....b.t.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1190
                  Entropy (8bit):7.802132517044609
                  Encrypted:false
                  SSDEEP:
                  MD5:6433810AC181B885AB29108A5DC37280
                  SHA1:4B8DBE9953791E8FCD6D33B35126B5E4CC264812
                  SHA-256:6793CEC2B882140805E6873DEB8BABED6A354B93B491CD76CBD07550E2C226D0
                  SHA-512:C929DF6B6D31D88084B585C8531D5101656BF4F04356CF1F59DDFE8FD8664EE04055F17D4C750D026D70D47517DF45D6D01F80756660275269377E4A6A5444DE
                  Malicious:false
                  Preview:>..9."..VNG.U.l..c/?.....@>.^+...s...).+.HNI....z..h......n.?.4....i.C.V..y9$P.[..d.Zp..3.+..1..*.Gx...y.&iB<T]...e.W..C.D.G.....+...Z./..{..9......o.s.V....B.B.0.O.q.s...WS...........8]..o.)....X.Y.@.Y(*.cF.).>.E::.o.fI... W...e9.E...]X.k.....2.B#......FkE.x............Yw..@...q...K.0.iQw.r`.."z|.".z....=/.....O?....p.x.'Y).d....'c~*...../...$....x~.}e..P..T...^.C.......z;.....'K.02"!..j.:j..X}w.rEs.........hvK>.)...Ya..0....v=P..BJ....5lE..,....H..<.T.OX.....c.z...i..hx.....P...~....E.VD.......X.o.......F..m..Af...?..x......7#.'...._Hl 8.< ...Vi.......hs`.........Wl<~...>%K.8.+.>..S.m...}......x.0.....[V.F..N.r.*q...4......cEg.g.....h..>^<.{{....4N...R.e@.../M...Q....R........Oqe.[?..m.6..B"....=..:...`...KE..M{............|.hp..eC..=.(..@+...txz.2r....u..^.....UDC..)...7.....tQ.Hc..I._K...?.ne,%....;.OY..@.MfC.ac.....vX.W..bN.st.-`s...E.....sp..*..%.*..9...!._O.o..@1!._t."............,Zj.Q.2.M@\.\..2@.zV.....?v....)...3.3e.v..R-......0..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1190
                  Entropy (8bit):7.802132517044609
                  Encrypted:false
                  SSDEEP:
                  MD5:6433810AC181B885AB29108A5DC37280
                  SHA1:4B8DBE9953791E8FCD6D33B35126B5E4CC264812
                  SHA-256:6793CEC2B882140805E6873DEB8BABED6A354B93B491CD76CBD07550E2C226D0
                  SHA-512:C929DF6B6D31D88084B585C8531D5101656BF4F04356CF1F59DDFE8FD8664EE04055F17D4C750D026D70D47517DF45D6D01F80756660275269377E4A6A5444DE
                  Malicious:false
                  Preview:>..9."..VNG.U.l..c/?.....@>.^+...s...).+.HNI....z..h......n.?.4....i.C.V..y9$P.[..d.Zp..3.+..1..*.Gx...y.&iB<T]...e.W..C.D.G.....+...Z./..{..9......o.s.V....B.B.0.O.q.s...WS...........8]..o.)....X.Y.@.Y(*.cF.).>.E::.o.fI... W...e9.E...]X.k.....2.B#......FkE.x............Yw..@...q...K.0.iQw.r`.."z|.".z....=/.....O?....p.x.'Y).d....'c~*...../...$....x~.}e..P..T...^.C.......z;.....'K.02"!..j.:j..X}w.rEs.........hvK>.)...Ya..0....v=P..BJ....5lE..,....H..<.T.OX.....c.z...i..hx.....P...~....E.VD.......X.o.......F..m..Af...?..x......7#.'...._Hl 8.< ...Vi.......hs`.........Wl<~...>%K.8.+.>..S.m...}......x.0.....[V.F..N.r.*q...4......cEg.g.....h..>^<.{{....4N...R.e@.../M...Q....R........Oqe.[?..m.6..B"....=..:...`...KE..M{............|.hp..eC..=.(..@+...txz.2r....u..^.....UDC..)...7.....tQ.Hc..I._K...?.ne,%....;.OY..@.MfC.ac.....vX.W..bN.st.-`s...E.....sp..*..%.*..9...!._O.o..@1!._t."............,Zj.Q.2.M@\.\..2@.zV.....?v....)...3.3e.v..R-......0..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1190
                  Entropy (8bit):7.802132517044609
                  Encrypted:false
                  SSDEEP:
                  MD5:6433810AC181B885AB29108A5DC37280
                  SHA1:4B8DBE9953791E8FCD6D33B35126B5E4CC264812
                  SHA-256:6793CEC2B882140805E6873DEB8BABED6A354B93B491CD76CBD07550E2C226D0
                  SHA-512:C929DF6B6D31D88084B585C8531D5101656BF4F04356CF1F59DDFE8FD8664EE04055F17D4C750D026D70D47517DF45D6D01F80756660275269377E4A6A5444DE
                  Malicious:false
                  Preview:>..9."..VNG.U.l..c/?.....@>.^+...s...).+.HNI....z..h......n.?.4....i.C.V..y9$P.[..d.Zp..3.+..1..*.Gx...y.&iB<T]...e.W..C.D.G.....+...Z./..{..9......o.s.V....B.B.0.O.q.s...WS...........8]..o.)....X.Y.@.Y(*.cF.).>.E::.o.fI... W...e9.E...]X.k.....2.B#......FkE.x............Yw..@...q...K.0.iQw.r`.."z|.".z....=/.....O?....p.x.'Y).d....'c~*...../...$....x~.}e..P..T...^.C.......z;.....'K.02"!..j.:j..X}w.rEs.........hvK>.)...Ya..0....v=P..BJ....5lE..,....H..<.T.OX.....c.z...i..hx.....P...~....E.VD.......X.o.......F..m..Af...?..x......7#.'...._Hl 8.< ...Vi.......hs`.........Wl<~...>%K.8.+.>..S.m...}......x.0.....[V.F..N.r.*q...4......cEg.g.....h..>^<.{{....4N...R.e@.../M...Q....R........Oqe.[?..m.6..B"....=..:...`...KE..M{............|.hp..eC..=.(..@+...txz.2r....u..^.....UDC..)...7.....tQ.Hc..I._K...?.ne,%....;.OY..@.MfC.ac.....vX.W..bN.st.-`s...E.....sp..*..%.*..9...!._O.o..@1!._t."............,Zj.Q.2.M@\.\..2@.zV.....?v....)...3.3e.v..R-......0..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):589
                  Entropy (8bit):7.507596596854129
                  Encrypted:false
                  SSDEEP:
                  MD5:19239C7CA11462BBDAEFDF2D6BBAB49D
                  SHA1:42128AC225D5006F9026887DFBE76EC0DDAAB1D9
                  SHA-256:51177BA907A1C7FBF3F3B75C2E0CD4956EAFD3258B782658009072296FC96C46
                  SHA-512:15DB6B7145495DED458A2ABD19A2F7049DDC163B94254099E63E13F75166DD02C046968AF426FF7351D2C6A2730568312519DA96D56D8CC9F77EAB084F6E2F3D
                  Malicious:false
                  Preview:QV.`.[..|$..?.1.j.>..a:...;.@D...E....6.]..E...bP..A....>!..@.......m1.eN7..a...4.-.......m..i6...2.z....9.j..1L...i.w......u...n.......&+O(OMh"..#2....*...."g..b..F@k..H.Xh.h.gX..NG;.......C..y.b^.3.....Ev....r@....;...)m|1.q......4...U.H..QM.0...9.t...>}.........(..n...1..e..g;Ua..k.Y8......*.u.>....(.G.............iB6....e.3v.........v..1S...X....J..^.2...?.w...#.X}....Q.Vu..O.7..y'....7.3.<WA/.............2~.....Z$.!...&.2...7.iK.$p.-h5....98I...6....T.................z....,3p.6r...ZjB\[)N.2....v|08..OG........"ZH........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):589
                  Entropy (8bit):7.507596596854129
                  Encrypted:false
                  SSDEEP:
                  MD5:19239C7CA11462BBDAEFDF2D6BBAB49D
                  SHA1:42128AC225D5006F9026887DFBE76EC0DDAAB1D9
                  SHA-256:51177BA907A1C7FBF3F3B75C2E0CD4956EAFD3258B782658009072296FC96C46
                  SHA-512:15DB6B7145495DED458A2ABD19A2F7049DDC163B94254099E63E13F75166DD02C046968AF426FF7351D2C6A2730568312519DA96D56D8CC9F77EAB084F6E2F3D
                  Malicious:false
                  Preview:QV.`.[..|$..?.1.j.>..a:...;.@D...E....6.]..E...bP..A....>!..@.......m1.eN7..a...4.-.......m..i6...2.z....9.j..1L...i.w......u...n.......&+O(OMh"..#2....*...."g..b..F@k..H.Xh.h.gX..NG;.......C..y.b^.3.....Ev....r@....;...)m|1.q......4...U.H..QM.0...9.t...>}.........(..n...1..e..g;Ua..k.Y8......*.u.>....(.G.............iB6....e.3v.........v..1S...X....J..^.2...?.w...#.X}....Q.Vu..O.7..y'....7.3.<WA/.............2~.....Z$.!...&.2...7.iK.$p.-h5....98I...6....T.................z....,3p.6r...ZjB\[)N.2....v|08..OG........"ZH........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):589
                  Entropy (8bit):7.507596596854129
                  Encrypted:false
                  SSDEEP:
                  MD5:19239C7CA11462BBDAEFDF2D6BBAB49D
                  SHA1:42128AC225D5006F9026887DFBE76EC0DDAAB1D9
                  SHA-256:51177BA907A1C7FBF3F3B75C2E0CD4956EAFD3258B782658009072296FC96C46
                  SHA-512:15DB6B7145495DED458A2ABD19A2F7049DDC163B94254099E63E13F75166DD02C046968AF426FF7351D2C6A2730568312519DA96D56D8CC9F77EAB084F6E2F3D
                  Malicious:false
                  Preview:QV.`.[..|$..?.1.j.>..a:...;.@D...E....6.]..E...bP..A....>!..@.......m1.eN7..a...4.-.......m..i6...2.z....9.j..1L...i.w......u...n.......&+O(OMh"..#2....*...."g..b..F@k..H.Xh.h.gX..NG;.......C..y.b^.3.....Ev....r@....;...)m|1.q......4...U.H..QM.0...9.t...>}.........(..n...1..e..g;Ua..k.Y8......*.u.>....(.G.............iB6....e.3v.........v..1S...X....J..^.2...?.w...#.X}....Q.Vu..O.7..y'....7.3.<WA/.............2~.....Z$.!...&.2...7.iK.$p.-h5....98I...6....T.................z....,3p.6r...ZjB\[)N.2....v|08..OG........"ZH........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):264
                  Entropy (8bit):6.8647008415009125
                  Encrypted:false
                  SSDEEP:
                  MD5:02B5BF11B136E1A2AAEE61CF540EC30E
                  SHA1:AB57DCE230C9B14A9DEB920D9456FE649653FB3C
                  SHA-256:CFCC15534ACBCFA49470074634C901CEC689738662AE996C07E8869E701316F7
                  SHA-512:A3DD4821878FC330079F081518CD21A29AFEB8C542C4EB61FEC5B415A2BE02C945BBB2E44CD25CF28D594813B911A7D8795EDC2F969A28D37264F8384C05E3A1
                  Malicious:false
                  Preview:..2.?=t.....`....G.f.W....-.W"..!.K..N....x....K.N.b!.FPi.,..m.r)..9fu/...v. ...SWN.r...1...J1..7../.o..j.#....<.U~..;.\..|.I........F..3W^XU,4.X7...6....^.R.h.}h.......s.I.......l..k*..z..zl3...\.[_.5.f...c....&.r...x.R..........h...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):264
                  Entropy (8bit):6.8647008415009125
                  Encrypted:false
                  SSDEEP:
                  MD5:02B5BF11B136E1A2AAEE61CF540EC30E
                  SHA1:AB57DCE230C9B14A9DEB920D9456FE649653FB3C
                  SHA-256:CFCC15534ACBCFA49470074634C901CEC689738662AE996C07E8869E701316F7
                  SHA-512:A3DD4821878FC330079F081518CD21A29AFEB8C542C4EB61FEC5B415A2BE02C945BBB2E44CD25CF28D594813B911A7D8795EDC2F969A28D37264F8384C05E3A1
                  Malicious:false
                  Preview:..2.?=t.....`....G.f.W....-.W"..!.K..N....x....K.N.b!.FPi.,..m.r)..9fu/...v. ...SWN.r...1...J1..7../.o..j.#....<.U~..;.\..|.I........F..3W^XU,4.X7...6....^.R.h.}h.......s.I.......l..k*..z..zl3...\.[_.5.f...c....&.r...x.R..........h...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):264
                  Entropy (8bit):6.8647008415009125
                  Encrypted:false
                  SSDEEP:
                  MD5:02B5BF11B136E1A2AAEE61CF540EC30E
                  SHA1:AB57DCE230C9B14A9DEB920D9456FE649653FB3C
                  SHA-256:CFCC15534ACBCFA49470074634C901CEC689738662AE996C07E8869E701316F7
                  SHA-512:A3DD4821878FC330079F081518CD21A29AFEB8C542C4EB61FEC5B415A2BE02C945BBB2E44CD25CF28D594813B911A7D8795EDC2F969A28D37264F8384C05E3A1
                  Malicious:false
                  Preview:..2.?=t.....`....G.f.W....-.W"..!.K..N....x....K.N.b!.FPi.,..m.r)..9fu/...v. ...SWN.r...1...J1..7../.o..j.#....<.U~..;.\..|.I........F..3W^XU,4.X7...6....^.R.h.}h.......s.I.......l..k*..z..zl3...\.[_.5.f...c....&.r...x.R..........h...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):717
                  Entropy (8bit):7.599058250541575
                  Encrypted:false
                  SSDEEP:
                  MD5:1AC2D03AE9D4457CAFE934C50AA2FD6F
                  SHA1:4EB1C3EB264FF0AD0CBF6B1D0013ED6F2D7AA55F
                  SHA-256:5D99EE851798FD81D1B160BAED29B24AABC3CB2725C11DA329C35FA1EEFA6A62
                  SHA-512:BDAA602A818E382A1084947158C0BF00528BA2E5E7851C2ADB0CBD252A8528E230CC68BB508D90873F0AB5D57B19ABE49691F36F357EEB18AFF84B920E00B17E
                  Malicious:false
                  Preview:.i......Y........5.....>\[.F<M...+...&3...c*."Q.*...U)..@quW?....=.._V.-8..a...(......d$:.d...zQ..27.*...n.Y......$..x...y..m..^...f......6..lO....6...*.pX.1(....x..e..P^UT+.ZT.w....C...E..l.....iO...oH.I>20a.r..S..%;.$.....k,...p...-=....!.B.K...........*......F.O.K...i.f.P.(........~...F;.8.uIx{...k................-vITJ..&..1.....N...B......j.}...8.}....0..`.`l.....V+.,.......x%=.8..;b..[....;....T.E...{.._......PYC...qO.i.e.{~...T.`BH@.D.b...n....$%U...mE.l....B...o........v....e......`$B...<...-.....B...2.y.Q\.....\...u...1......./.3O.P.....B.+..U.|...m....(.k..-.........a4-b...yGBu.D.@..8BX...]1.&#..B.........b.....IoeM..........-...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):717
                  Entropy (8bit):7.599058250541575
                  Encrypted:false
                  SSDEEP:
                  MD5:1AC2D03AE9D4457CAFE934C50AA2FD6F
                  SHA1:4EB1C3EB264FF0AD0CBF6B1D0013ED6F2D7AA55F
                  SHA-256:5D99EE851798FD81D1B160BAED29B24AABC3CB2725C11DA329C35FA1EEFA6A62
                  SHA-512:BDAA602A818E382A1084947158C0BF00528BA2E5E7851C2ADB0CBD252A8528E230CC68BB508D90873F0AB5D57B19ABE49691F36F357EEB18AFF84B920E00B17E
                  Malicious:false
                  Preview:.i......Y........5.....>\[.F<M...+...&3...c*."Q.*...U)..@quW?....=.._V.-8..a...(......d$:.d...zQ..27.*...n.Y......$..x...y..m..^...f......6..lO....6...*.pX.1(....x..e..P^UT+.ZT.w....C...E..l.....iO...oH.I>20a.r..S..%;.$.....k,...p...-=....!.B.K...........*......F.O.K...i.f.P.(........~...F;.8.uIx{...k................-vITJ..&..1.....N...B......j.}...8.}....0..`.`l.....V+.,.......x%=.8..;b..[....;....T.E...{.._......PYC...qO.i.e.{~...T.`BH@.D.b...n....$%U...mE.l....B...o........v....e......`$B...<...-.....B...2.y.Q\.....\...u...1......./.3O.P.....B.+..U.|...m....(.k..-.........a4-b...yGBu.D.@..8BX...]1.&#..B.........b.....IoeM..........-...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):717
                  Entropy (8bit):7.599058250541575
                  Encrypted:false
                  SSDEEP:
                  MD5:1AC2D03AE9D4457CAFE934C50AA2FD6F
                  SHA1:4EB1C3EB264FF0AD0CBF6B1D0013ED6F2D7AA55F
                  SHA-256:5D99EE851798FD81D1B160BAED29B24AABC3CB2725C11DA329C35FA1EEFA6A62
                  SHA-512:BDAA602A818E382A1084947158C0BF00528BA2E5E7851C2ADB0CBD252A8528E230CC68BB508D90873F0AB5D57B19ABE49691F36F357EEB18AFF84B920E00B17E
                  Malicious:false
                  Preview:.i......Y........5.....>\[.F<M...+...&3...c*."Q.*...U)..@quW?....=.._V.-8..a...(......d$:.d...zQ..27.*...n.Y......$..x...y..m..^...f......6..lO....6...*.pX.1(....x..e..P^UT+.ZT.w....C...E..l.....iO...oH.I>20a.r..S..%;.$.....k,...p...-=....!.B.K...........*......F.O.K...i.f.P.(........~...F;.8.uIx{...k................-vITJ..&..1.....N...B......j.}...8.}....0..`.`l.....V+.,.......x%=.8..;b..[....;....T.E...{.._......PYC...qO.i.e.{~...T.`BH@.D.b...n....$%U...mE.l....B...o........v....e......`$B...<...-.....B...2.y.Q\.....\...u...1......./.3O.P.....B.+..U.|...m....(.k..-.........a4-b...yGBu.D.@..8BX...]1.&#..B.........b.....IoeM..........-...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.869365510247304
                  Encrypted:false
                  SSDEEP:
                  MD5:DAD559961BE465E98C48AED389B0C341
                  SHA1:04A896998C80FFE0AD3D64B673AB8363C3CB7D41
                  SHA-256:18AA3322B6E8E75D8BB99110C02DB5EF5A4DF5C00E335DB3BCE6E8D8D81CCEB9
                  SHA-512:90E8E87CEA14D76CE1B17F2291E66CC02CD746A4FE6D93CBE8D2EE8CFBCC88310B90A8F6B35C30B90680CEDACCABC72D83B90801C916ED317A795D65CB6A2ED0
                  Malicious:false
                  Preview:._.;.'.....N..../h.5e..g....!bJ/.Y..9 .....f.:..H-./...v.......yBh...q......v.Ui....v.y..z$..N... 7..1...9d....Q1]v...1q...7._(..-.8w..#M...i!3.*...Y.......Y.r...$.......?.....fK.R.=<.}.@Lj....E..."...(..L?eM.~z]r.2..$hh..Gs@7.H..W..1_...j...&..B.'.a.J.d..QqRt@.....O..CE..m...........5.Q..v.S.......;+;`^*...x..z.}.-....3.....:(f.B..US.M.=.r..).-.......k...(...lB? .}...;..P.d./+T_.%.v......z`...../)u..W..s....-V...t..mU...b.#....;j^.vy.....o..j.@...|...^K.....y.F*....0X....y3..c....g.......8.."....7b..H...]XH..id..+t(..qvZ..``Z0..q.Q.<N.....2....+...`.O.E...V]ac+..a&..~C.;.**.D...7.W..........u..............k[}....@R.W*A....5.]...S:c..=..@..yW.f..~........L..{..Q..I.19(.(.&3Gju..I.E.u.S.......c$Tu.+..Oc....~..i...v7.k.\..P...`.1..y.cvKAN.....r...}'....<.x3....apRn.UA.m.{..Ag.t.1D..F.V.p..?y....w..Y....,.`.M..SG.X.....X.Q....=7.@.1......p....Q.....B../......x.,..J...._.Q....u..&u...S..U.|..&.....#..?`......cJ..$.....i....O\?..,.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.869365510247304
                  Encrypted:false
                  SSDEEP:
                  MD5:DAD559961BE465E98C48AED389B0C341
                  SHA1:04A896998C80FFE0AD3D64B673AB8363C3CB7D41
                  SHA-256:18AA3322B6E8E75D8BB99110C02DB5EF5A4DF5C00E335DB3BCE6E8D8D81CCEB9
                  SHA-512:90E8E87CEA14D76CE1B17F2291E66CC02CD746A4FE6D93CBE8D2EE8CFBCC88310B90A8F6B35C30B90680CEDACCABC72D83B90801C916ED317A795D65CB6A2ED0
                  Malicious:false
                  Preview:._.;.'.....N..../h.5e..g....!bJ/.Y..9 .....f.:..H-./...v.......yBh...q......v.Ui....v.y..z$..N... 7..1...9d....Q1]v...1q...7._(..-.8w..#M...i!3.*...Y.......Y.r...$.......?.....fK.R.=<.}.@Lj....E..."...(..L?eM.~z]r.2..$hh..Gs@7.H..W..1_...j...&..B.'.a.J.d..QqRt@.....O..CE..m...........5.Q..v.S.......;+;`^*...x..z.}.-....3.....:(f.B..US.M.=.r..).-.......k...(...lB? .}...;..P.d./+T_.%.v......z`...../)u..W..s....-V...t..mU...b.#....;j^.vy.....o..j.@...|...^K.....y.F*....0X....y3..c....g.......8.."....7b..H...]XH..id..+t(..qvZ..``Z0..q.Q.<N.....2....+...`.O.E...V]ac+..a&..~C.;.**.D...7.W..........u..............k[}....@R.W*A....5.]...S:c..=..@..yW.f..~........L..{..Q..I.19(.(.&3Gju..I.E.u.S.......c$Tu.+..Oc....~..i...v7.k.\..P...`.1..y.cvKAN.....r...}'....<.x3....apRn.UA.m.{..Ag.t.1D..F.V.p..?y....w..Y....,.`.M..SG.X.....X.Q....=7.@.1......p....Q.....B../......x.,..J...._.Q....u..&u...S..U.|..&.....#..?`......cJ..$.....i....O\?..,.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.869365510247304
                  Encrypted:false
                  SSDEEP:
                  MD5:DAD559961BE465E98C48AED389B0C341
                  SHA1:04A896998C80FFE0AD3D64B673AB8363C3CB7D41
                  SHA-256:18AA3322B6E8E75D8BB99110C02DB5EF5A4DF5C00E335DB3BCE6E8D8D81CCEB9
                  SHA-512:90E8E87CEA14D76CE1B17F2291E66CC02CD746A4FE6D93CBE8D2EE8CFBCC88310B90A8F6B35C30B90680CEDACCABC72D83B90801C916ED317A795D65CB6A2ED0
                  Malicious:false
                  Preview:._.;.'.....N..../h.5e..g....!bJ/.Y..9 .....f.:..H-./...v.......yBh...q......v.Ui....v.y..z$..N... 7..1...9d....Q1]v...1q...7._(..-.8w..#M...i!3.*...Y.......Y.r...$.......?.....fK.R.=<.}.@Lj....E..."...(..L?eM.~z]r.2..$hh..Gs@7.H..W..1_...j...&..B.'.a.J.d..QqRt@.....O..CE..m...........5.Q..v.S.......;+;`^*...x..z.}.-....3.....:(f.B..US.M.=.r..).-.......k...(...lB? .}...;..P.d./+T_.%.v......z`...../)u..W..s....-V...t..mU...b.#....;j^.vy.....o..j.@...|...^K.....y.F*....0X....y3..c....g.......8.."....7b..H...]XH..id..+t(..qvZ..``Z0..q.Q.<N.....2....+...`.O.E...V]ac+..a&..~C.;.**.D...7.W..........u..............k[}....@R.W*A....5.]...S:c..=..@..yW.f..~........L..{..Q..I.19(.(.&3Gju..I.E.u.S.......c$Tu.+..Oc....~..i...v7.k.\..P...`.1..y.cvKAN.....r...}'....<.x3....apRn.UA.m.{..Ag.t.1D..F.V.p..?y....w..Y....,.`.M..SG.X.....X.Q....=7.@.1......p....Q.....B../......x.,..J...._.Q....u..&u...S..U.|..&.....#..?`......cJ..$.....i....O\?..,.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1474444
                  Entropy (8bit):7.9998782037076515
                  Encrypted:true
                  SSDEEP:
                  MD5:AE343C3C8F8C5B9FC65454D80E67934F
                  SHA1:6FBD8FF42FFC8E503ACE50147A24809AD444C1A4
                  SHA-256:6FF66049E68E087D9B00972565CE7E9B6E014AF9181CD5FFA8E96EB2A06ADB0B
                  SHA-512:E0C77C87D967571CF227693F6F6C05CE7F1460CA3D96DA87FFD66C1A2D58D30F909D65E3F422EF752B714D01F0A1BC86C57F67EA2FF660F542C7D382EB4AEE62
                  Malicious:true
                  Preview:...n...E.'.O....bp......^f....t.^..W.$./.y.?.....J.EoN.....n0b......q[~T...<R.t....Q.#..,?y.q.9...agO.E.5Uc,@...NBg..J..U..Q....\M%k..hm.7@i.r.j...v._...T.K.R..I..D...D...#....G.37EXD0...)'..]..sZ..........Rb?..o(X.......M@.~.G.....J......<.Uw...(.GJ..)...Y......0..7.u.)d.,[G.}y......BG.:gD~..`.v.i........{d.g.....t.].l.r^..a..w....h..aI.K0.i..,.bz..C^......q.iR.JO.3...KU7.........5..lUl.<..=.hR...'..........DL&..!w.}*...'...cB..]..'.Ju.GN.7)._...O...c..Xki...........C..O.MIsH.A8...q.Y..........z.#.D.<.Q........hQ..f..P.6~..R..M......@.#..ZPL..]..^H....sC...".nV......<.*.....7F3..9..5..1.=(......_..~...fW..M. .0......o8...?.....>....h{..k-1>.,n]}fV.-..d.+@.gn.[.t.uY!...Zp....$..J..n......</.G.}).....L(...j.WJl....O.Oz ......R...w......|.f.a..W (#P.5..0.....L..p...3.:+..|....\-|.!...S.....o....M.(#N..%k&.=..6.(..6.m...`.9.I......5d........;T..X(.#....._...<0..X........>)0{.3..yN5..a.Ma..I.][....y.)'.JnlpZu/x$..Y.os.13.t..$.-C>.*uFx|.\..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1474444
                  Entropy (8bit):7.9998782037076515
                  Encrypted:true
                  SSDEEP:
                  MD5:AE343C3C8F8C5B9FC65454D80E67934F
                  SHA1:6FBD8FF42FFC8E503ACE50147A24809AD444C1A4
                  SHA-256:6FF66049E68E087D9B00972565CE7E9B6E014AF9181CD5FFA8E96EB2A06ADB0B
                  SHA-512:E0C77C87D967571CF227693F6F6C05CE7F1460CA3D96DA87FFD66C1A2D58D30F909D65E3F422EF752B714D01F0A1BC86C57F67EA2FF660F542C7D382EB4AEE62
                  Malicious:true
                  Preview:...n...E.'.O....bp......^f....t.^..W.$./.y.?.....J.EoN.....n0b......q[~T...<R.t....Q.#..,?y.q.9...agO.E.5Uc,@...NBg..J..U..Q....\M%k..hm.7@i.r.j...v._...T.K.R..I..D...D...#....G.37EXD0...)'..]..sZ..........Rb?..o(X.......M@.~.G.....J......<.Uw...(.GJ..)...Y......0..7.u.)d.,[G.}y......BG.:gD~..`.v.i........{d.g.....t.].l.r^..a..w....h..aI.K0.i..,.bz..C^......q.iR.JO.3...KU7.........5..lUl.<..=.hR...'..........DL&..!w.}*...'...cB..]..'.Ju.GN.7)._...O...c..Xki...........C..O.MIsH.A8...q.Y..........z.#.D.<.Q........hQ..f..P.6~..R..M......@.#..ZPL..]..^H....sC...".nV......<.*.....7F3..9..5..1.=(......_..~...fW..M. .0......o8...?.....>....h{..k-1>.,n]}fV.-..d.+@.gn.[.t.uY!...Zp....$..J..n......</.G.}).....L(...j.WJl....O.Oz ......R...w......|.f.a..W (#P.5..0.....L..p...3.:+..|....\-|.!...S.....o....M.(#N..%k&.=..6.(..6.m...`.9.I......5d........;T..X(.#....._...<0..X........>)0{.3..yN5..a.Ma..I.][....y.)'.JnlpZu/x$..Y.os.13.t..$.-C>.*uFx|.\..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:OpenPGP Public Key
                  Category:dropped
                  Size (bytes):1474444
                  Entropy (8bit):7.9998782037076515
                  Encrypted:true
                  SSDEEP:
                  MD5:AE343C3C8F8C5B9FC65454D80E67934F
                  SHA1:6FBD8FF42FFC8E503ACE50147A24809AD444C1A4
                  SHA-256:6FF66049E68E087D9B00972565CE7E9B6E014AF9181CD5FFA8E96EB2A06ADB0B
                  SHA-512:E0C77C87D967571CF227693F6F6C05CE7F1460CA3D96DA87FFD66C1A2D58D30F909D65E3F422EF752B714D01F0A1BC86C57F67EA2FF660F542C7D382EB4AEE62
                  Malicious:true
                  Preview:...n...E.'.O....bp......^f....t.^..W.$./.y.?.....J.EoN.....n0b......q[~T...<R.t....Q.#..,?y.q.9...agO.E.5Uc,@...NBg..J..U..Q....\M%k..hm.7@i.r.j...v._...T.K.R..I..D...D...#....G.37EXD0...)'..]..sZ..........Rb?..o(X.......M@.~.G.....J......<.Uw...(.GJ..)...Y......0..7.u.)d.,[G.}y......BG.:gD~..`.v.i........{d.g.....t.].l.r^..a..w....h..aI.K0.i..,.bz..C^......q.iR.JO.3...KU7.........5..lUl.<..=.hR...'..........DL&..!w.}*...'...cB..]..'.Ju.GN.7)._...O...c..Xki...........C..O.MIsH.A8...q.Y..........z.#.D.<.Q........hQ..f..P.6~..R..M......@.#..ZPL..]..^H....sC...".nV......<.*.....7F3..9..5..1.=(......_..~...fW..M. .0......o8...?.....>....h{..k-1>.,n]}fV.-..d.+@.gn.[.t.uY!...Zp....$..J..n......</.G.}).....L(...j.WJl....O.Oz ......R...w......|.f.a..W (#P.5..0.....L..p...3.:+..|....\-|.!...S.....o....M.(#N..%k&.=..6.(..6.m...`.9.I......5d........;T..X(.#....._...<0..X........>)0{.3..yN5..a.Ma..I.][....y.)'.JnlpZu/x$..Y.os.13.t..$.-C>.*uFx|.\..
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.860437734467738
                  Encrypted:false
                  SSDEEP:
                  MD5:CE08F06475B5E44B9059D03E8D83D4DB
                  SHA1:06ED27EADC378A00671C446D269BFADE6A19D896
                  SHA-256:8A4304E08F6B4DD56BBA33B6CBB1E1F6F4E09E570D8F5C02128A1F01A5CBCDD8
                  SHA-512:47C37760B223C38657C7A183ED64981B761CFE3A532839780EA28D992564C45CB891020E247BEEC0BAAEFDD23E8537372D3BED4593C9407D430D3F7FFC484B76
                  Malicious:false
                  Preview:;...(.K).S.u...U.B.Ev!.a.S............?."\..08W7.7.p.2Ce....D.s.9wB...%...."....]...q..0..2$........H..nz......!....M.}..S.(2..........-!.89..Uh.W..5.tj..G..(.Q.h-.Q_1.........d..mT.>.x.[...[.`.S....c ..,.....|-..s..N..l\..I@."..B..c...[.CI....1N..Z%k....J..@........'...C....\{.=...z.@i..m8a!.'M. .....9. 7.A.!.T....k.......z...........,2....u.QS.N........i...2.........&o.._.6h.B#....rW..?....w.(+.`y.5.r.....K........l..S.cT,%....;y..G.}.l1.Dh:1,c.....1...FHk.b.y6...#...`..t..r...:...B..Ku.B..z+GM.Y.f....6...zPe..!....'r".NC..>..DH..5;.J..?.....I.I,..^m.......\DCD....ISj.K..A;.....=.+v...{.c.>.q3.`0.=..|k...z.......AP.c..F.O.W..!.qG."....FA..v\....w.....+...:0M..,;..0S&.G ..5.+_(.D..S.*].l........8...n.D.t..F,|C.........qR.......>...>.`ON.a,.:...x.......7T.%.o+.4...h2U..?....M...0X..n0.^.o.s..]....@...;.R..Ng...;...(.5....R..v~.G...W.e..2..Y.).......t.;......uV.^.rLp.7..78[.E...!.Y......&c...........MD........5...............[..-%.<...|.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.860437734467738
                  Encrypted:false
                  SSDEEP:
                  MD5:CE08F06475B5E44B9059D03E8D83D4DB
                  SHA1:06ED27EADC378A00671C446D269BFADE6A19D896
                  SHA-256:8A4304E08F6B4DD56BBA33B6CBB1E1F6F4E09E570D8F5C02128A1F01A5CBCDD8
                  SHA-512:47C37760B223C38657C7A183ED64981B761CFE3A532839780EA28D992564C45CB891020E247BEEC0BAAEFDD23E8537372D3BED4593C9407D430D3F7FFC484B76
                  Malicious:false
                  Preview:;...(.K).S.u...U.B.Ev!.a.S............?."\..08W7.7.p.2Ce....D.s.9wB...%...."....]...q..0..2$........H..nz......!....M.}..S.(2..........-!.89..Uh.W..5.tj..G..(.Q.h-.Q_1.........d..mT.>.x.[...[.`.S....c ..,.....|-..s..N..l\..I@."..B..c...[.CI....1N..Z%k....J..@........'...C....\{.=...z.@i..m8a!.'M. .....9. 7.A.!.T....k.......z...........,2....u.QS.N........i...2.........&o.._.6h.B#....rW..?....w.(+.`y.5.r.....K........l..S.cT,%....;y..G.}.l1.Dh:1,c.....1...FHk.b.y6...#...`..t..r...:...B..Ku.B..z+GM.Y.f....6...zPe..!....'r".NC..>..DH..5;.J..?.....I.I,..^m.......\DCD....ISj.K..A;.....=.+v...{.c.>.q3.`0.=..|k...z.......AP.c..F.O.W..!.qG."....FA..v\....w.....+...:0M..,;..0S&.G ..5.+_(.D..S.*].l........8...n.D.t..F,|C.........qR.......>...>.`ON.a,.:...x.......7T.%.o+.4...h2U..?....M...0X..n0.^.o.s..]....@...;.R..Ng...;...(.5....R..v~.G...W.e..2..Y.).......t.;......uV.^.rLp.7..78[.E...!.Y......&c...........MD........5...............[..-%.<...|.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.860437734467738
                  Encrypted:false
                  SSDEEP:
                  MD5:CE08F06475B5E44B9059D03E8D83D4DB
                  SHA1:06ED27EADC378A00671C446D269BFADE6A19D896
                  SHA-256:8A4304E08F6B4DD56BBA33B6CBB1E1F6F4E09E570D8F5C02128A1F01A5CBCDD8
                  SHA-512:47C37760B223C38657C7A183ED64981B761CFE3A532839780EA28D992564C45CB891020E247BEEC0BAAEFDD23E8537372D3BED4593C9407D430D3F7FFC484B76
                  Malicious:false
                  Preview:;...(.K).S.u...U.B.Ev!.a.S............?."\..08W7.7.p.2Ce....D.s.9wB...%...."....]...q..0..2$........H..nz......!....M.}..S.(2..........-!.89..Uh.W..5.tj..G..(.Q.h-.Q_1.........d..mT.>.x.[...[.`.S....c ..,.....|-..s..N..l\..I@."..B..c...[.CI....1N..Z%k....J..@........'...C....\{.=...z.@i..m8a!.'M. .....9. 7.A.!.T....k.......z...........,2....u.QS.N........i...2.........&o.._.6h.B#....rW..?....w.(+.`y.5.r.....K........l..S.cT,%....;y..G.}.l1.Dh:1,c.....1...FHk.b.y6...#...`..t..r...:...B..Ku.B..z+GM.Y.f....6...zPe..!....'r".NC..>..DH..5;.J..?.....I.I,..^m.......\DCD....ISj.K..A;.....=.+v...{.c.>.q3.`0.=..|k...z.......AP.c..F.O.W..!.qG."....FA..v\....w.....+...:0M..,;..0S&.G ..5.+_(.D..S.*].l........8...n.D.t..F,|C.........qR.......>...>.`ON.a,.:...x.......7T.%.o+.4...h2U..?....M...0X..n0.^.o.s..]....@...;.R..Ng...;...(.5....R..v~.G...W.e..2..Y.).......t.;......uV.^.rLp.7..78[.E...!.Y......&c...........MD........5...............[..-%.<...|.....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):389
                  Entropy (8bit):7.295045756482532
                  Encrypted:false
                  SSDEEP:
                  MD5:AE8C3E640D55993E13006922ABC5D5B5
                  SHA1:573FFA74578E5CE5A41360EA76FF2D42DE229E81
                  SHA-256:F33551192A0F2028AF2CC4AF30E8E285E57DB680E7DCCF77C2B42020FE6A081B
                  SHA-512:CF331A410F228879B61A296453E88D588A2B8D2EB1E3D1EAA1223AAFDA57881A66C429E6AB56D9D9F8DF1511751B6626BC243FC92B5A0171B7BE7B3F8C4DD4AB
                  Malicious:false
                  Preview:n.~...P...U..'......S..X.>N.3c.0JN^*65k.j.{>.}....&....Vm..Dw....6@ lU.9...Uk@.&_..9`.....s.....H..&(.n.6r$+.mE../.r?Op..Ib..^q.S...xa..2....2Y.t......i.F..L.|_\.{.....$VG.L..|>o..|m7DR..!(.....`1/KC...m}rtH..........O.e..?+.NW.{#B.H.<^.z.D.........dU.A.....y.e.*.G..........*Ik........F.._..*.0..q.f..s.........%..~...]&.g....)v.``.sd/............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):389
                  Entropy (8bit):7.295045756482532
                  Encrypted:false
                  SSDEEP:
                  MD5:AE8C3E640D55993E13006922ABC5D5B5
                  SHA1:573FFA74578E5CE5A41360EA76FF2D42DE229E81
                  SHA-256:F33551192A0F2028AF2CC4AF30E8E285E57DB680E7DCCF77C2B42020FE6A081B
                  SHA-512:CF331A410F228879B61A296453E88D588A2B8D2EB1E3D1EAA1223AAFDA57881A66C429E6AB56D9D9F8DF1511751B6626BC243FC92B5A0171B7BE7B3F8C4DD4AB
                  Malicious:false
                  Preview:n.~...P...U..'......S..X.>N.3c.0JN^*65k.j.{>.}....&....Vm..Dw....6@ lU.9...Uk@.&_..9`.....s.....H..&(.n.6r$+.mE../.r?Op..Ib..^q.S...xa..2....2Y.t......i.F..L.|_\.{.....$VG.L..|>o..|m7DR..!(.....`1/KC...m}rtH..........O.e..?+.NW.{#B.H.<^.z.D.........dU.A.....y.e.*.G..........*Ik........F.._..*.0..q.f..s.........%..~...]&.g....)v.``.sd/............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):389
                  Entropy (8bit):7.295045756482532
                  Encrypted:false
                  SSDEEP:
                  MD5:AE8C3E640D55993E13006922ABC5D5B5
                  SHA1:573FFA74578E5CE5A41360EA76FF2D42DE229E81
                  SHA-256:F33551192A0F2028AF2CC4AF30E8E285E57DB680E7DCCF77C2B42020FE6A081B
                  SHA-512:CF331A410F228879B61A296453E88D588A2B8D2EB1E3D1EAA1223AAFDA57881A66C429E6AB56D9D9F8DF1511751B6626BC243FC92B5A0171B7BE7B3F8C4DD4AB
                  Malicious:false
                  Preview:n.~...P...U..'......S..X.>N.3c.0JN^*65k.j.{>.}....&....Vm..Dw....6@ lU.9...Uk@.&_..9`.....s.....H..&(.n.6r$+.mE../.r?Op..Ib..^q.S...xa..2....2Y.t......i.F..L.|_\.{.....$VG.L..|>o..|m7DR..!(.....`1/KC...m}rtH..........O.e..?+.NW.{#B.H.<^.z.D.........dU.A.....y.e.*.G..........*Ik........F.._..*.0..q.f..s.........%..~...]&.g....)v.``.sd/............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):25142
                  Entropy (8bit):7.991780175255634
                  Encrypted:true
                  SSDEEP:
                  MD5:665BE6EE58B3F9A93BA7BBFC47B69480
                  SHA1:A525F0019D45E501624D761FA468803DCD8E1C60
                  SHA-256:FCAC819341E158BFC5A51FA7BBCEDCF784A62BFDE3A2856F12506C33DD3555CD
                  SHA-512:6DB3E8DE36147AB4DCE0ADE0E98674530E75B00640933572AE4F2D5973642ADB8B41655D7F3C2EC46159556BC37550B3DDF8D4B46341645B8028175A221237F2
                  Malicious:true
                  Preview:.L....|..@{.h^t......Y.!...V.cDj.~.s....,..3.oN..Q...ST...._..W..z.e.......W....:...j.>....X8..cz...P.#....y.......G..O2.R.VC..X.3.".6..S .Y.1.[_#....L.[......c."...d..V.1..L:..5.r~C......k..n..d#..n.r.ORO'P..X..dmM....g..w'...!R.|..*.......e~..b....v|.`.D..W..].-k(...U.I....L.5....c.....!.G.1%]...H.CN..5..MN..x..E.=W..3l.mJ..D...8....Y.P..Vc.!....;L....`LF..Z..u....N.P.Tch.s|..}H?.k..V/V..Ye..=A.e.Z..ni..3.._.N.X..I.#...S{lB...!........T....M.w..1/...N......gcO..>..?..|......PF...8...k....`.s.i.j.g&A<..12. N.w,...g.....L]x.........2.+....G,sfcJD.YY........VZ...S.+.^#J!.......(.^....XM....+.j..q...S.X...d....F...O.lth.Qu........l..m...B3..a.XQ.p....s".d.!....n....E..........z~.. ...~J...b.k7e.5.g..\..E......a....i.Ce..4.1...+u...K.}.R.H..lc3sb$<.K.Z\.n0.>.{.\%...g...w.R..).`.{K.$.>E.38X...N.~X.e..C.......F.+...5U1....*.....x..`4W.y.}...U..t.`.......\j.@z..F#7[/.*..L..5..Hv.m.....|..M....;?....`@_b..({x#.....=..4...u..[l7...g.........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):25142
                  Entropy (8bit):7.991780175255634
                  Encrypted:true
                  SSDEEP:
                  MD5:665BE6EE58B3F9A93BA7BBFC47B69480
                  SHA1:A525F0019D45E501624D761FA468803DCD8E1C60
                  SHA-256:FCAC819341E158BFC5A51FA7BBCEDCF784A62BFDE3A2856F12506C33DD3555CD
                  SHA-512:6DB3E8DE36147AB4DCE0ADE0E98674530E75B00640933572AE4F2D5973642ADB8B41655D7F3C2EC46159556BC37550B3DDF8D4B46341645B8028175A221237F2
                  Malicious:true
                  Preview:.L....|..@{.h^t......Y.!...V.cDj.~.s....,..3.oN..Q...ST...._..W..z.e.......W....:...j.>....X8..cz...P.#....y.......G..O2.R.VC..X.3.".6..S .Y.1.[_#....L.[......c."...d..V.1..L:..5.r~C......k..n..d#..n.r.ORO'P..X..dmM....g..w'...!R.|..*.......e~..b....v|.`.D..W..].-k(...U.I....L.5....c.....!.G.1%]...H.CN..5..MN..x..E.=W..3l.mJ..D...8....Y.P..Vc.!....;L....`LF..Z..u....N.P.Tch.s|..}H?.k..V/V..Ye..=A.e.Z..ni..3.._.N.X..I.#...S{lB...!........T....M.w..1/...N......gcO..>..?..|......PF...8...k....`.s.i.j.g&A<..12. N.w,...g.....L]x.........2.+....G,sfcJD.YY........VZ...S.+.^#J!.......(.^....XM....+.j..q...S.X...d....F...O.lth.Qu........l..m...B3..a.XQ.p....s".d.!....n....E..........z~.. ...~J...b.k7e.5.g..\..E......a....i.Ce..4.1...+u...K.}.R.H..lc3sb$<.K.Z\.n0.>.{.\%...g...w.R..).`.{K.$.>E.38X...N.~X.e..C.......F.+...5U1....*.....x..`4W.y.}...U..t.`.......\j.@z..F#7[/.*..L..5..Hv.m.....|..M....;?....`@_b..({x#.....=..4...u..[l7...g.........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):25142
                  Entropy (8bit):7.991780175255634
                  Encrypted:true
                  SSDEEP:
                  MD5:665BE6EE58B3F9A93BA7BBFC47B69480
                  SHA1:A525F0019D45E501624D761FA468803DCD8E1C60
                  SHA-256:FCAC819341E158BFC5A51FA7BBCEDCF784A62BFDE3A2856F12506C33DD3555CD
                  SHA-512:6DB3E8DE36147AB4DCE0ADE0E98674530E75B00640933572AE4F2D5973642ADB8B41655D7F3C2EC46159556BC37550B3DDF8D4B46341645B8028175A221237F2
                  Malicious:true
                  Preview:.L....|..@{.h^t......Y.!...V.cDj.~.s....,..3.oN..Q...ST...._..W..z.e.......W....:...j.>....X8..cz...P.#....y.......G..O2.R.VC..X.3.".6..S .Y.1.[_#....L.[......c."...d..V.1..L:..5.r~C......k..n..d#..n.r.ORO'P..X..dmM....g..w'...!R.|..*.......e~..b....v|.`.D..W..].-k(...U.I....L.5....c.....!.G.1%]...H.CN..5..MN..x..E.=W..3l.mJ..D...8....Y.P..Vc.!....;L....`LF..Z..u....N.P.Tch.s|..}H?.k..V/V..Ye..=A.e.Z..ni..3.._.N.X..I.#...S{lB...!........T....M.w..1/...N......gcO..>..?..|......PF...8...k....`.s.i.j.g&A<..12. N.w,...g.....L]x.........2.+....G,sfcJD.YY........VZ...S.+.^#J!.......(.^....XM....+.j..q...S.X...d....F...O.lth.Qu........l..m...B3..a.XQ.p....s".d.!....n....E..........z~.. ...~J...b.k7e.5.g..\..E......a....i.Ce..4.1...+u...K.}.R.H..lc3sb$<.K.Z\.n0.>.{.\%...g...w.R..).`.{K.$.>E.38X...N.~X.e..C.......F.+...5U1....*.....x..`4W.y.}...U..t.`.......\j.@z..F#7[/.*..L..5..Hv.m.....|..M....;?....`@_b..({x#.....=..4...u..[l7...g.........
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):622
                  Entropy (8bit):7.572909779619948
                  Encrypted:false
                  SSDEEP:
                  MD5:1D68618BD97D7D2B4F33ECC342E39BB1
                  SHA1:ED37F67E6C06767927FD47AFBA954D9C5724A708
                  SHA-256:B4382E27376E105968B02A2D56EECA0DDFDD0C735A7DEBF8C93B55BF64EEBB75
                  SHA-512:FC63E0C9F7D56895C0B8D395C8CE2373B71C8D399328EF593CC4919E1CC9C2379E651E0F63C513AFB23420E20CC29860450D69185780C403D8C13FE5522C6FAE
                  Malicious:false
                  Preview:j...t,.C..m}.d....h...`+.q.U..........X.............z..ka...j..4.w....&..dV"..;..A......5.-..Hx..f=..M..v.7...0.....*..6M...I}...8."fn.l(..53...$.b +....t.{,....i[.k..!.h...fF..+9........,N...9....02~..|/$..e0..z.Y.A..........[...DZ.b..e#..........w...x..@J........v.rQ.]...u.+v.{..n:.R%.c...]'..I.OH.%.".*...#s....L.....n&.............me....d...I"..'n).v..T...r.j.M..]..#.k.%r*s..].....L...vP..a.m......X...."...M..fy*._.../`........6L.8&n.....8iQ.t.S-...........Nl...)...n*Q.....Vt.z..$...Z+..[........p...x...l.D...=H./.....c..vF.~.S.......5tuh._._.M...F ........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):622
                  Entropy (8bit):7.572909779619948
                  Encrypted:false
                  SSDEEP:
                  MD5:1D68618BD97D7D2B4F33ECC342E39BB1
                  SHA1:ED37F67E6C06767927FD47AFBA954D9C5724A708
                  SHA-256:B4382E27376E105968B02A2D56EECA0DDFDD0C735A7DEBF8C93B55BF64EEBB75
                  SHA-512:FC63E0C9F7D56895C0B8D395C8CE2373B71C8D399328EF593CC4919E1CC9C2379E651E0F63C513AFB23420E20CC29860450D69185780C403D8C13FE5522C6FAE
                  Malicious:false
                  Preview:j...t,.C..m}.d....h...`+.q.U..........X.............z..ka...j..4.w....&..dV"..;..A......5.-..Hx..f=..M..v.7...0.....*..6M...I}...8."fn.l(..53...$.b +....t.{,....i[.k..!.h...fF..+9........,N...9....02~..|/$..e0..z.Y.A..........[...DZ.b..e#..........w...x..@J........v.rQ.]...u.+v.{..n:.R%.c...]'..I.OH.%.".*...#s....L.....n&.............me....d...I"..'n).v..T...r.j.M..]..#.k.%r*s..].....L...vP..a.m......X...."...M..fy*._.../`........6L.8&n.....8iQ.t.S-...........Nl...)...n*Q.....Vt.z..$...Z+..[........p...x...l.D...=H./.....c..vF.~.S.......5tuh._._.M...F ........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):622
                  Entropy (8bit):7.572909779619948
                  Encrypted:false
                  SSDEEP:
                  MD5:1D68618BD97D7D2B4F33ECC342E39BB1
                  SHA1:ED37F67E6C06767927FD47AFBA954D9C5724A708
                  SHA-256:B4382E27376E105968B02A2D56EECA0DDFDD0C735A7DEBF8C93B55BF64EEBB75
                  SHA-512:FC63E0C9F7D56895C0B8D395C8CE2373B71C8D399328EF593CC4919E1CC9C2379E651E0F63C513AFB23420E20CC29860450D69185780C403D8C13FE5522C6FAE
                  Malicious:false
                  Preview:j...t,.C..m}.d....h...`+.q.U..........X.............z..ka...j..4.w....&..dV"..;..A......5.-..Hx..f=..M..v.7...0.....*..6M...I}...8."fn.l(..53...$.b +....t.{,....i[.k..!.h...fF..+9........,N...9....02~..|/$..e0..z.Y.A..........[...DZ.b..e#..........w...x..@J........v.rQ.]...u.+v.{..n:.R%.c...]'..I.OH.%.".*...#s....L.....n&.............me....d...I"..'n).v..T...r.j.M..]..#.k.%r*s..].....L...vP..a.m......X...."...M..fy*._.../`........6L.8&n.....8iQ.t.S-...........Nl...)...n*Q.....Vt.z..$...Z+..[........p...x...l.D...=H./.....c..vF.~.S.......5tuh._._.M...F ........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):182
                  Entropy (8bit):6.343563044963777
                  Encrypted:false
                  SSDEEP:
                  MD5:41DB0AABD27515EC89AD294D6DB00180
                  SHA1:0A8E11D287864ED8A0DD21A9560DC5552F5CFA2F
                  SHA-256:E96A5A24AEC58B96E4697300850603BC3D7EEF98E03BB1D6FD27163FF8B6B727
                  SHA-512:947162C845058523475D4F760EE2012CFDC8E009ED228EC537921BAC183875D565BD068E633BDA6AF35E69BA83DC7D3691D87ADE6E59C4927D69C70363994FDB
                  Malicious:false
                  Preview:.2*..:(+..p..Na.;........Y..3.'..01._.TL.^..G/..\.....]Q.....&.I.YT....r..|,*..........g..<.X90........]O......7z.b)T~pe..]dNv....UW.r............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):182
                  Entropy (8bit):6.343563044963777
                  Encrypted:false
                  SSDEEP:
                  MD5:41DB0AABD27515EC89AD294D6DB00180
                  SHA1:0A8E11D287864ED8A0DD21A9560DC5552F5CFA2F
                  SHA-256:E96A5A24AEC58B96E4697300850603BC3D7EEF98E03BB1D6FD27163FF8B6B727
                  SHA-512:947162C845058523475D4F760EE2012CFDC8E009ED228EC537921BAC183875D565BD068E633BDA6AF35E69BA83DC7D3691D87ADE6E59C4927D69C70363994FDB
                  Malicious:false
                  Preview:.2*..:(+..p..Na.;........Y..3.'..01._.TL.^..G/..\.....]Q.....&.I.YT....r..|,*..........g..<.X90........]O......7z.b)T~pe..]dNv....UW.r............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):182
                  Entropy (8bit):6.343563044963777
                  Encrypted:false
                  SSDEEP:
                  MD5:41DB0AABD27515EC89AD294D6DB00180
                  SHA1:0A8E11D287864ED8A0DD21A9560DC5552F5CFA2F
                  SHA-256:E96A5A24AEC58B96E4697300850603BC3D7EEF98E03BB1D6FD27163FF8B6B727
                  SHA-512:947162C845058523475D4F760EE2012CFDC8E009ED228EC537921BAC183875D565BD068E633BDA6AF35E69BA83DC7D3691D87ADE6E59C4927D69C70363994FDB
                  Malicious:false
                  Preview:.2*..:(+..p..Na.;........Y..3.'..01._.TL.^..G/..\.....]Q.....&.I.YT....r..|,*..........g..<.X90........]O......7z.b)T~pe..]dNv....UW.r............................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32908898
                  Entropy (8bit):6.3088006704050414
                  Encrypted:false
                  SSDEEP:
                  MD5:15814B6AD987742E16C126AFEC429AA7
                  SHA1:3D4585B31BE29CD1508F7847DC43FCBA1E5AAEED
                  SHA-256:64E3C8E080F781F76402DE1901435693AE53107D7C0C11B522653A47432CD236
                  SHA-512:53C240CB64A80A96E5A773B4989F456032681DF90648CF19D151098532CE7C737FC557383BB3815AF0EA5EDA668F1A0F301A4727802FB8D2BD00CAB8A09EFFD8
                  Malicious:false
                  Preview: <a...K.y..K.=..ch=.q...^.....e...$..On~$P].vm7..<.Z..n.H..3....:B.s...Z0....7.)S..t...H..U....<.,. ...+..@.a....K.^.........=..K.=.|.VD>....5~..avT.. .L08}p..'&*...K...H.p....u.R.w..........Bk.m@...p......ar.B.t.&...0..i..._..u....w.....]...c.....kw.p.H:.........n.~I...CP.....+.H.?..'...3.G......g.|........[...q.....Z.R.l......Y..(I....u....p...Cn.`....?.0kF...*....hj5.......;.9[.`l..v..g..5-C..(@./A.c....z.2`..{.......A2BH..lE....N.n..O..F........q..t.^[@......5..h.h...;.....^.K.&DT..L.]T.Bdw..?8........../8z9pP..!.X~.c..........:...t....q?......j..R.I...)...Vjv..\+J.+.C...e...M.".0..!.N.ep......I.*./D.u;...}..-..LK.._n...*CLI\1y..N..o..\...E..h,.....l?........eR.y^b.-10..^......5.T.:..[.pA/.-..v.Vs/....w.#.....?..$.".4...g.T(.`..h.......c./...X#..Y..K..../T..}]F.Y.^..I..f}.1K...Mw.]NY.u.w))...O....^].....!.3N.P$.<>h.m.......4<.@Dox.....:D.XO...t.7...#..g........d[3{....S....U5:...W.M;9._.A.,.V...=.....eyTt.U8.\X..c.}...;c..=.Go[.4l
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32908898
                  Entropy (8bit):6.3088006704050414
                  Encrypted:false
                  SSDEEP:
                  MD5:15814B6AD987742E16C126AFEC429AA7
                  SHA1:3D4585B31BE29CD1508F7847DC43FCBA1E5AAEED
                  SHA-256:64E3C8E080F781F76402DE1901435693AE53107D7C0C11B522653A47432CD236
                  SHA-512:53C240CB64A80A96E5A773B4989F456032681DF90648CF19D151098532CE7C737FC557383BB3815AF0EA5EDA668F1A0F301A4727802FB8D2BD00CAB8A09EFFD8
                  Malicious:false
                  Preview: <a...K.y..K.=..ch=.q...^.....e...$..On~$P].vm7..<.Z..n.H..3....:B.s...Z0....7.)S..t...H..U....<.,. ...+..@.a....K.^.........=..K.=.|.VD>....5~..avT.. .L08}p..'&*...K...H.p....u.R.w..........Bk.m@...p......ar.B.t.&...0..i..._..u....w.....]...c.....kw.p.H:.........n.~I...CP.....+.H.?..'...3.G......g.|........[...q.....Z.R.l......Y..(I....u....p...Cn.`....?.0kF...*....hj5.......;.9[.`l..v..g..5-C..(@./A.c....z.2`..{.......A2BH..lE....N.n..O..F........q..t.^[@......5..h.h...;.....^.K.&DT..L.]T.Bdw..?8........../8z9pP..!.X~.c..........:...t....q?......j..R.I...)...Vjv..\+J.+.C...e...M.".0..!.N.ep......I.*./D.u;...}..-..LK.._n...*CLI\1y..N..o..\...E..h,.....l?........eR.y^b.-10..^......5.T.:..[.pA/.-..v.Vs/....w.#.....?..$.".4...g.T(.`..h.......c./...X#..Y..K..../T..}]F.Y.^..I..f}.1K...Mw.]NY.u.w))...O....^].....!.3N.P$.<>h.m.......4<.@Dox.....:D.XO...t.7...#..g........d[3{....S....U5:...W.M;9._.A.,.V...=.....eyTt.U8.\X..c.}...;c..=.Go[.4l
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):327
                  Entropy (8bit):7.035186833566379
                  Encrypted:false
                  SSDEEP:
                  MD5:027A670B81AE3AFE514BBD495FF94F0A
                  SHA1:D5D4C01CB5B85D581FEE5E502F72495BB5AE5078
                  SHA-256:F7E47E57C5C52EF9E102B1B522C2E1B5C506F4D1C5CF4FC137AC8E932E9D52AC
                  SHA-512:E2FDB8DD073C4E97D019A51CC66F35724960D57A4E13A27815FD71351B4C4C1C6409A61211A8F18369BC1BBB7ACD8DD0FB068B728CD140BA18935ACE1F6A88FE
                  Malicious:false
                  Preview:Z..W(.......U..b.OtT.O&T8.T..>......s.FW.'U..H.E.Tf.0.T.i%.F..~..]s..ng........_....8.w..6N=.7j.>Z....k7......ZK(;.M..P=...i..>=.........@..."A..k...B@.....!.....1!...a{.{.~..C. ...1.%.\.....1.. ..c>......s....up.z...............C;.....o.=.+.0.P..0....[..fDr...K.2.............1d..;........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):327
                  Entropy (8bit):7.035186833566379
                  Encrypted:false
                  SSDEEP:
                  MD5:027A670B81AE3AFE514BBD495FF94F0A
                  SHA1:D5D4C01CB5B85D581FEE5E502F72495BB5AE5078
                  SHA-256:F7E47E57C5C52EF9E102B1B522C2E1B5C506F4D1C5CF4FC137AC8E932E9D52AC
                  SHA-512:E2FDB8DD073C4E97D019A51CC66F35724960D57A4E13A27815FD71351B4C4C1C6409A61211A8F18369BC1BBB7ACD8DD0FB068B728CD140BA18935ACE1F6A88FE
                  Malicious:false
                  Preview:Z..W(.......U..b.OtT.O&T8.T..>......s.FW.'U..H.E.Tf.0.T.i%.F..~..]s..ng........_....8.w..6N=.7j.>Z....k7......ZK(;.M..P=...i..>=.........@..."A..k...B@.....!.....1!...a{.{.~..C. ...1.%.\.....1.. ..c>......s....up.z...............C;.....o.=.+.0.P..0....[..fDr...K.2.............1d..;........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):327
                  Entropy (8bit):7.035186833566379
                  Encrypted:false
                  SSDEEP:
                  MD5:027A670B81AE3AFE514BBD495FF94F0A
                  SHA1:D5D4C01CB5B85D581FEE5E502F72495BB5AE5078
                  SHA-256:F7E47E57C5C52EF9E102B1B522C2E1B5C506F4D1C5CF4FC137AC8E932E9D52AC
                  SHA-512:E2FDB8DD073C4E97D019A51CC66F35724960D57A4E13A27815FD71351B4C4C1C6409A61211A8F18369BC1BBB7ACD8DD0FB068B728CD140BA18935ACE1F6A88FE
                  Malicious:false
                  Preview:Z..W(.......U..b.OtT.O&T8.T..>......s.FW.'U..H.E.Tf.0.T.i%.F..~..]s..ng........_....8.w..6N=.7j.>Z....k7......ZK(;.M..P=...i..>=.........@..."A..k...B@.....!.....1!...a{.{.~..C. ...1.%.\.....1.. ..c>......s....up.z...............C;.....o.=.+.0.P..0....[..fDr...K.2.............1d..;........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.847912621626575
                  Encrypted:false
                  SSDEEP:
                  MD5:7F55AA5717887E2639B5FFA1566C4EB9
                  SHA1:0E1743BF9CC2F3BA8474A1C2E5D714E2322728C5
                  SHA-256:36A22493E2414CBE13DD18370FBF8FC8CE429537227C25C4EA9975606721B9E7
                  SHA-512:80F9A0EA2D3AA14FFCC04F5D656D916A046036A1A2DB10E9DAAB544D2A00539958F3EF756BF5CC06B2104E2FFC306374C01ED86BAEBA3171641A9EE006A8B6DE
                  Malicious:false
                  Preview:...tz.T3P|..!/Y...T.xb7.7..z .o.G.w....u#l.?b.y=G..I.....c3...U...Y.Tv..f.,pP.@h...%....I...K4.-...5JI...2.Z..O]..$!PY..Mr/.bD8;..z#..,....,>.:H.s:g........"..&.z..y-.`.....~.c..........G.bE$.L>K..~.|...X.v...X.7z..AXP.Y.*..{..0....f%.sK...Pz?..w?.m.?..#J.C..).h...(.n.....8j.d.)L.$....ij.7'e7N....F...U|.......t..5R....e..Aj.).....T-....5e..........u'y'..9.1..V...<.<A.\m.^...f.pA..n......j...+).J...U+..iM.E_.%.$S....k.#.,j..4W#..@<FW..f.@yZ~.....m...e.&.....g...(...J.._....'A8e[:.4.;.5!...~..W.l.pG.dA.qT...+ct.....<.....G.8...E.t@......&....h.....%L.Z..$.?...Hb..vb.}C......D...cy0...Gi[......+..M{.....]P.....O<...........s.&.E......'D...{..H......s.....%..[T.#.j...l.S..np}..s.@..-.[46....X.O..+..g>1T..~f...|.S...T..P1F.F.m......{Fy.{@..|k'_...`.....m.K...........B..r8_..y..t).$.?w.$b7.+...hR....qor.p.W.8].k!...FM!.1L...*.xJ.R.JteX..[..!..0.....p.....k.R.;...n........<r..Iy.9.!...c.G..p....z.ftD..K....S...#".P.)..%.Z.z.....!...J\u. ....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.847912621626575
                  Encrypted:false
                  SSDEEP:
                  MD5:7F55AA5717887E2639B5FFA1566C4EB9
                  SHA1:0E1743BF9CC2F3BA8474A1C2E5D714E2322728C5
                  SHA-256:36A22493E2414CBE13DD18370FBF8FC8CE429537227C25C4EA9975606721B9E7
                  SHA-512:80F9A0EA2D3AA14FFCC04F5D656D916A046036A1A2DB10E9DAAB544D2A00539958F3EF756BF5CC06B2104E2FFC306374C01ED86BAEBA3171641A9EE006A8B6DE
                  Malicious:false
                  Preview:...tz.T3P|..!/Y...T.xb7.7..z .o.G.w....u#l.?b.y=G..I.....c3...U...Y.Tv..f.,pP.@h...%....I...K4.-...5JI...2.Z..O]..$!PY..Mr/.bD8;..z#..,....,>.:H.s:g........"..&.z..y-.`.....~.c..........G.bE$.L>K..~.|...X.v...X.7z..AXP.Y.*..{..0....f%.sK...Pz?..w?.m.?..#J.C..).h...(.n.....8j.d.)L.$....ij.7'e7N....F...U|.......t..5R....e..Aj.).....T-....5e..........u'y'..9.1..V...<.<A.\m.^...f.pA..n......j...+).J...U+..iM.E_.%.$S....k.#.,j..4W#..@<FW..f.@yZ~.....m...e.&.....g...(...J.._....'A8e[:.4.;.5!...~..W.l.pG.dA.qT...+ct.....<.....G.8...E.t@......&....h.....%L.Z..$.?...Hb..vb.}C......D...cy0...Gi[......+..M{.....]P.....O<...........s.&.E......'D...{..H......s.....%..[T.#.j...l.S..np}..s.@..-.[46....X.O..+..g>1T..~f...|.S...T..P1F.F.m......{Fy.{@..|k'_...`.....m.K...........B..r8_..y..t).$.?w.$b7.+...hR....qor.p.W.8].k!...FM!.1L...*.xJ.R.JteX..[..!..0.....p.....k.R.;...n........<r..Iy.9.!...c.G..p....z.ftD..K....S...#".P.)..%.Z.z.....!...J\u. ....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.847912621626575
                  Encrypted:false
                  SSDEEP:
                  MD5:7F55AA5717887E2639B5FFA1566C4EB9
                  SHA1:0E1743BF9CC2F3BA8474A1C2E5D714E2322728C5
                  SHA-256:36A22493E2414CBE13DD18370FBF8FC8CE429537227C25C4EA9975606721B9E7
                  SHA-512:80F9A0EA2D3AA14FFCC04F5D656D916A046036A1A2DB10E9DAAB544D2A00539958F3EF756BF5CC06B2104E2FFC306374C01ED86BAEBA3171641A9EE006A8B6DE
                  Malicious:false
                  Preview:...tz.T3P|..!/Y...T.xb7.7..z .o.G.w....u#l.?b.y=G..I.....c3...U...Y.Tv..f.,pP.@h...%....I...K4.-...5JI...2.Z..O]..$!PY..Mr/.bD8;..z#..,....,>.:H.s:g........"..&.z..y-.`.....~.c..........G.bE$.L>K..~.|...X.v...X.7z..AXP.Y.*..{..0....f%.sK...Pz?..w?.m.?..#J.C..).h...(.n.....8j.d.)L.$....ij.7'e7N....F...U|.......t..5R....e..Aj.).....T-....5e..........u'y'..9.1..V...<.<A.\m.^...f.pA..n......j...+).J...U+..iM.E_.%.$S....k.#.,j..4W#..@<FW..f.@yZ~.....m...e.&.....g...(...J.._....'A8e[:.4.;.5!...~..W.l.pG.dA.qT...+ct.....<.....G.8...E.t@......&....h.....%L.Z..$.?...Hb..vb.}C......D...cy0...Gi[......+..M{.....]P.....O<...........s.&.E......'D...{..H......s.....%..[T.#.j...l.S..np}..s.@..-.[46....X.O..+..g>1T..~f...|.S...T..P1F.F.m......{Fy.{@..|k'_...`.....m.K...........B..r8_..y..t).$.?w.$b7.+...hR....qor.p.W.8].k!...FM!.1L...*.xJ.R.JteX..[..!..0.....p.....k.R.;...n........<r..Iy.9.!...c.G..p....z.ftD..K....S...#".P.)..%.Z.z.....!...J\u. ....
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):420
                  Entropy (8bit):7.322552794216834
                  Encrypted:false
                  SSDEEP:
                  MD5:537C5C6ABD6B496163DCB751E21751A8
                  SHA1:29DBF194289B9AC790DE86843F08ADF73CC02D9F
                  SHA-256:A204C12F7295ED198E352BBCB6A90588D6879D4ADCE66146D60E8FC069AE34D1
                  SHA-512:D185FB93DD56CBDFE18A309FE44B41CDFC1793697034BC407B11094B65056DCD6CE3A709157124ECBA4CD911C943A6EEBEEC2EE80CB94A79B205298E4B2E7E2C
                  Malicious:false
                  Preview:.K..p.....Q.E.A.<...<9q'`&...r.u....j..c3....B.'V.k.m...."{;M.6!y...M&1..o.t.b.s.".#x.`....f.LU.Kv..U..WL.u*.......pXWP....Co..":`2..cL%p...K..N......4.c...5A. qBe.4_^.._......{t. d.....F7.{h.U2.It..O....+Z.,..`.....T..n...xvpS.....m.Y...,MG Z8..S......67P.y....6]..|F..E.).,9H...A.V.l.....E.............b...........sl.[i.5.....T........U.L.n{.].E*....bb...eEE...B<.k........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):420
                  Entropy (8bit):7.322552794216834
                  Encrypted:false
                  SSDEEP:
                  MD5:537C5C6ABD6B496163DCB751E21751A8
                  SHA1:29DBF194289B9AC790DE86843F08ADF73CC02D9F
                  SHA-256:A204C12F7295ED198E352BBCB6A90588D6879D4ADCE66146D60E8FC069AE34D1
                  SHA-512:D185FB93DD56CBDFE18A309FE44B41CDFC1793697034BC407B11094B65056DCD6CE3A709157124ECBA4CD911C943A6EEBEEC2EE80CB94A79B205298E4B2E7E2C
                  Malicious:false
                  Preview:.K..p.....Q.E.A.<...<9q'`&...r.u....j..c3....B.'V.k.m...."{;M.6!y...M&1..o.t.b.s.".#x.`....f.LU.Kv..U..WL.u*.......pXWP....Co..":`2..cL%p...K..N......4.c...5A. qBe.4_^.._......{t. d.....F7.{h.U2.It..O....+Z.,..`.....T..n...xvpS.....m.Y...,MG Z8..S......67P.y....6]..|F..E.).,9H...A.V.l.....E.............b...........sl.[i.5.....T........U.L.n{.].E*....bb...eEE...B<.k........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):420
                  Entropy (8bit):7.322552794216834
                  Encrypted:false
                  SSDEEP:
                  MD5:537C5C6ABD6B496163DCB751E21751A8
                  SHA1:29DBF194289B9AC790DE86843F08ADF73CC02D9F
                  SHA-256:A204C12F7295ED198E352BBCB6A90588D6879D4ADCE66146D60E8FC069AE34D1
                  SHA-512:D185FB93DD56CBDFE18A309FE44B41CDFC1793697034BC407B11094B65056DCD6CE3A709157124ECBA4CD911C943A6EEBEEC2EE80CB94A79B205298E4B2E7E2C
                  Malicious:false
                  Preview:.K..p.....Q.E.A.<...<9q'`&...r.u....j..c3....B.'V.k.m...."{;M.6!y...M&1..o.t.b.s.".#x.`....f.LU.Kv..U..WL.u*.......pXWP....Co..":`2..cL%p...K..N......4.c...5A. qBe.4_^.._......{t. d.....F7.{h.U2.It..O....+Z.,..`.....T..n...xvpS.....m.Y...,MG Z8..S......67P.y....6]..|F..E.).,9H...A.V.l.....E.............b...........sl.[i.5.....T........U.L.n{.].E*....bb...eEE...B<.k........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2340
                  Entropy (8bit):7.89653743892706
                  Encrypted:false
                  SSDEEP:
                  MD5:5435F31519A1C6DDC19F304E56583674
                  SHA1:F12B674E0D5F9E74C3A75215AEDE5AD22AE0B9F4
                  SHA-256:637547D10E0DC2BA11276D8CE65714D24C1E924BD48CA3FEEF504440BADC1A7C
                  SHA-512:E51D8FC6C0939E752C99638333CD5D1D5244CFE0A92CD1B52B71082DA40B13709FA092871265ECC167842F24191D5976EA67D84E25893E982866E0D9ED6079B0
                  Malicious:false
                  Preview:>.p...bb......r.`];vXY2...J.&..k'.......?..MB.L.../...+o\...L>.........T....Xf.......wD..........X..,..Z..5...65..G/.{.|&zZ.l7,]...L*J..........th..!..<.J4(.... .63/.....a..6...0.+0..kih}C...[......J..........,.,.:,/..]..pLGT>......~.\k.X;..F..d..^..7D......py.;W..=.*.'H..du.d.T.....n..E...G0j..Dy..mA.g.i.F....(._:.0....E....~.5a..-`O.........a...c.w.'.n..:U....(F=..\...].ht.P=.h]......6..3k-.L.^.L<....D@T5tf/i>\B..?.w.....f.. .`.'..._...([..D....(+.I."..]0..].y.r.P..~..@e..f.=..o.#..C........._...N.qz.B...rUt..4.h[?=.#.....Ez^W.u..S.....8B...@.zB.7..^..q...6o.Ql...".....xH......MU_`.#..8br.H.BS.*..]Od.u....:a..*/&..iZ..m...8.......]#..w...Q.Z....d.....C./9$.@.....h...}........FV..q........ZL...R. .$._]....[k"`S...S..t.........H..n|^...Hb~.....c..z2#....Y....G..........L....>.....8.......lOg..)j.]b..)z..$.l%..Q..A.......m.AU2....I....."z0../..G.v...&..T..6.6.."a.PAP.k.*.RqAOZq..1Y.........gx~...PB.=...z.....D.@...t.S..Tt..W.W..J
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2340
                  Entropy (8bit):7.89653743892706
                  Encrypted:false
                  SSDEEP:
                  MD5:5435F31519A1C6DDC19F304E56583674
                  SHA1:F12B674E0D5F9E74C3A75215AEDE5AD22AE0B9F4
                  SHA-256:637547D10E0DC2BA11276D8CE65714D24C1E924BD48CA3FEEF504440BADC1A7C
                  SHA-512:E51D8FC6C0939E752C99638333CD5D1D5244CFE0A92CD1B52B71082DA40B13709FA092871265ECC167842F24191D5976EA67D84E25893E982866E0D9ED6079B0
                  Malicious:false
                  Preview:>.p...bb......r.`];vXY2...J.&..k'.......?..MB.L.../...+o\...L>.........T....Xf.......wD..........X..,..Z..5...65..G/.{.|&zZ.l7,]...L*J..........th..!..<.J4(.... .63/.....a..6...0.+0..kih}C...[......J..........,.,.:,/..]..pLGT>......~.\k.X;..F..d..^..7D......py.;W..=.*.'H..du.d.T.....n..E...G0j..Dy..mA.g.i.F....(._:.0....E....~.5a..-`O.........a...c.w.'.n..:U....(F=..\...].ht.P=.h]......6..3k-.L.^.L<....D@T5tf/i>\B..?.w.....f.. .`.'..._...([..D....(+.I."..]0..].y.r.P..~..@e..f.=..o.#..C........._...N.qz.B...rUt..4.h[?=.#.....Ez^W.u..S.....8B...@.zB.7..^..q...6o.Ql...".....xH......MU_`.#..8br.H.BS.*..]Od.u....:a..*/&..iZ..m...8.......]#..w...Q.Z....d.....C./9$.@.....h...}........FV..q........ZL...R. .$._]....[k"`S...S..t.........H..n|^...Hb~.....c..z2#....Y....G..........L....>.....8.......lOg..)j.]b..)z..$.l%..Q..A.......m.AU2....I....."z0../..G.v...&..T..6.6.."a.PAP.k.*.RqAOZq..1Y.........gx~...PB.=...z.....D.@...t.S..Tt..W.W..J
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2340
                  Entropy (8bit):7.89653743892706
                  Encrypted:false
                  SSDEEP:
                  MD5:5435F31519A1C6DDC19F304E56583674
                  SHA1:F12B674E0D5F9E74C3A75215AEDE5AD22AE0B9F4
                  SHA-256:637547D10E0DC2BA11276D8CE65714D24C1E924BD48CA3FEEF504440BADC1A7C
                  SHA-512:E51D8FC6C0939E752C99638333CD5D1D5244CFE0A92CD1B52B71082DA40B13709FA092871265ECC167842F24191D5976EA67D84E25893E982866E0D9ED6079B0
                  Malicious:false
                  Preview:>.p...bb......r.`];vXY2...J.&..k'.......?..MB.L.../...+o\...L>.........T....Xf.......wD..........X..,..Z..5...65..G/.{.|&zZ.l7,]...L*J..........th..!..<.J4(.... .63/.....a..6...0.+0..kih}C...[......J..........,.,.:,/..]..pLGT>......~.\k.X;..F..d..^..7D......py.;W..=.*.'H..du.d.T.....n..E...G0j..Dy..mA.g.i.F....(._:.0....E....~.5a..-`O.........a...c.w.'.n..:U....(F=..\...].ht.P=.h]......6..3k-.L.^.L<....D@T5tf/i>\B..?.w.....f.. .`.'..._...([..D....(+.I."..]0..].y.r.P..~..@e..f.=..o.#..C........._...N.qz.B...rUt..4.h[?=.#.....Ez^W.u..S.....8B...@.zB.7..^..q...6o.Ql...".....xH......MU_`.#..8br.H.BS.*..]Od.u....:a..*/&..iZ..m...8.......]#..w...Q.Z....d.....C./9$.@.....h...}........FV..q........ZL...R. .$._]....[k"`S...S..t.........H..n|^...Hb~.....c..z2#....Y....G..........L....>.....8.......lOg..)j.]b..)z..$.l%..Q..A.......m.AU2....I....."z0../..G.v...&..T..6.6.."a.PAP.k.*.RqAOZq..1Y.........gx~...PB.=...z.....D.@...t.S..Tt..W.W..J
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):719
                  Entropy (8bit):7.627997848882904
                  Encrypted:false
                  SSDEEP:
                  MD5:DBCE960CF8F23EB025A00F0A905C9C5E
                  SHA1:606BD8D8E8ACAE5C6B033BAC34758FFC7943035E
                  SHA-256:1BDF48F6A7DB6C7BFC65A3A1611DD3C0198A13085945044E0981C54C036FBB76
                  SHA-512:FE28490349C570167046D818F9BDB78AC414C51B51C41B26BB58645788343CC0A73D397263DF8C657DB303F735E26E16BC3746052577302A36CC24E0D20ACC04
                  Malicious:false
                  Preview:..<.+...`W...1......a..k...G.4.'..K..... B.*.v........]6........v..I......V..r....v.R...;>b0.J.?/?.*. O.W..i....&.A.Z..!...G\.wp7.{....!q.$....7i..P~+....@...6.'cr.}E1.S..}......5Eu.?l..4u.bG......s.......> .-M...Wgs.o....X..X......5.Ju.O..v).O?.....,....$r......B.'.Oq...}J m.......f........n,....=.fZ....0X1....%.l.wE.$..%8.M.c.{.._......|..t...x.an....so..!.'....sB......(h*...b"...e3)kS.....m.>SX..-.H...3}Z`.U..'.T:7..;p...Y....fB.:....dN[.:uDS....DZA......u.H."..$.......C...c...cd.#l.7...........u0...d)....R...W]....o.h..-........A..y..<|.ni.!......r.6....B.......*.....+*..a.....D/.......G..#..C.....S.aY.3Q~)i...|. .K.qi..m..QP..........y.m^D......../...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):719
                  Entropy (8bit):7.627997848882904
                  Encrypted:false
                  SSDEEP:
                  MD5:DBCE960CF8F23EB025A00F0A905C9C5E
                  SHA1:606BD8D8E8ACAE5C6B033BAC34758FFC7943035E
                  SHA-256:1BDF48F6A7DB6C7BFC65A3A1611DD3C0198A13085945044E0981C54C036FBB76
                  SHA-512:FE28490349C570167046D818F9BDB78AC414C51B51C41B26BB58645788343CC0A73D397263DF8C657DB303F735E26E16BC3746052577302A36CC24E0D20ACC04
                  Malicious:false
                  Preview:..<.+...`W...1......a..k...G.4.'..K..... B.*.v........]6........v..I......V..r....v.R...;>b0.J.?/?.*. O.W..i....&.A.Z..!...G\.wp7.{....!q.$....7i..P~+....@...6.'cr.}E1.S..}......5Eu.?l..4u.bG......s.......> .-M...Wgs.o....X..X......5.Ju.O..v).O?.....,....$r......B.'.Oq...}J m.......f........n,....=.fZ....0X1....%.l.wE.$..%8.M.c.{.._......|..t...x.an....so..!.'....sB......(h*...b"...e3)kS.....m.>SX..-.H...3}Z`.U..'.T:7..;p...Y....fB.:....dN[.:uDS....DZA......u.H."..$.......C...c...cd.#l.7...........u0...d)....R...W]....o.h..-........A..y..<|.ni.!......r.6....B.......*.....+*..a.....D/.......G..#..C.....S.aY.3Q~)i...|. .K.qi..m..QP..........y.m^D......../...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):719
                  Entropy (8bit):7.627997848882904
                  Encrypted:false
                  SSDEEP:
                  MD5:DBCE960CF8F23EB025A00F0A905C9C5E
                  SHA1:606BD8D8E8ACAE5C6B033BAC34758FFC7943035E
                  SHA-256:1BDF48F6A7DB6C7BFC65A3A1611DD3C0198A13085945044E0981C54C036FBB76
                  SHA-512:FE28490349C570167046D818F9BDB78AC414C51B51C41B26BB58645788343CC0A73D397263DF8C657DB303F735E26E16BC3746052577302A36CC24E0D20ACC04
                  Malicious:false
                  Preview:..<.+...`W...1......a..k...G.4.'..K..... B.*.v........]6........v..I......V..r....v.R...;>b0.J.?/?.*. O.W..i....&.A.Z..!...G\.wp7.{....!q.$....7i..P~+....@...6.'cr.}E1.S..}......5Eu.?l..4u.bG......s.......> .-M...Wgs.o....X..X......5.Ju.O..v).O?.....,....$r......B.'.Oq...}J m.......f........n,....=.fZ....0X1....%.l.wE.$..%8.M.c.{.._......|..t...x.an....so..!.'....sB......(h*...b"...e3)kS.....m.>SX..-.H...3}Z`.U..'.T:7..;p...Y....fB.:....dN[.:uDS....DZA......u.H."..$.......C...c...cd.#l.7...........u0...d)....R...W]....o.h..-........A..y..<|.ni.!......r.6....B.......*.....+*..a.....D/.......G..#..C.....S.aY.3Q~)i...|. .K.qi..m..QP..........y.m^D......../...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):176
                  Entropy (8bit):6.212779494366391
                  Encrypted:false
                  SSDEEP:
                  MD5:A173A1BC363246CC525FB5C9E7DC2C9B
                  SHA1:41313393EE3507724DD32C4602A8FC3BB9904A54
                  SHA-256:D3F0103515471C0AA70F0611B94E7143646C4859516F712A7948D5A44E8BE153
                  SHA-512:467FF570BCD6184F9AE04BC49C262BA46B4C0DCFC9518F13746E70D7D0950D66C8284DAA67F364C5F0BEC8AE04A390D0E495B99A308C4EDE0B08536AA8B14597
                  Malicious:false
                  Preview:.W(/x2..\.F.........WH..!...0..5..&,.Y..&6.":.9....}O.,.$*.b"d.gA..>.A....-.C...........<.c.p)E..$PdY.... )..t....I,}..h....C...E.pt.ULYr.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):176
                  Entropy (8bit):6.212779494366391
                  Encrypted:false
                  SSDEEP:
                  MD5:A173A1BC363246CC525FB5C9E7DC2C9B
                  SHA1:41313393EE3507724DD32C4602A8FC3BB9904A54
                  SHA-256:D3F0103515471C0AA70F0611B94E7143646C4859516F712A7948D5A44E8BE153
                  SHA-512:467FF570BCD6184F9AE04BC49C262BA46B4C0DCFC9518F13746E70D7D0950D66C8284DAA67F364C5F0BEC8AE04A390D0E495B99A308C4EDE0B08536AA8B14597
                  Malicious:false
                  Preview:.W(/x2..\.F.........WH..!...0..5..&,.Y..&6.":.9....}O.,.$*.b"d.gA..>.A....-.C...........<.c.p)E..$PdY.... )..t....I,}..h....C...E.pt.ULYr.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):176
                  Entropy (8bit):6.212779494366391
                  Encrypted:false
                  SSDEEP:
                  MD5:A173A1BC363246CC525FB5C9E7DC2C9B
                  SHA1:41313393EE3507724DD32C4602A8FC3BB9904A54
                  SHA-256:D3F0103515471C0AA70F0611B94E7143646C4859516F712A7948D5A44E8BE153
                  SHA-512:467FF570BCD6184F9AE04BC49C262BA46B4C0DCFC9518F13746E70D7D0950D66C8284DAA67F364C5F0BEC8AE04A390D0E495B99A308C4EDE0B08536AA8B14597
                  Malicious:false
                  Preview:.W(/x2..\.F.........WH..!...0..5..&,.Y..&6.":.9....}O.,.$*.b"d.gA..>.A....-.C...........<.c.p)E..$PdY.... )..t....I,}..h....C...E.pt.ULYr.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):514
                  Entropy (8bit):7.485077152332643
                  Encrypted:false
                  SSDEEP:
                  MD5:7770FD303A9094AF270628F488340240
                  SHA1:9A7B8712B477D3E05EAEDE8D9EDC0E9CC49C2F21
                  SHA-256:F07E3E3BE8A0CFB18169FF5FF817D4DC80EB87870E207C5E13AA0995BAC6F8CB
                  SHA-512:73ABD9CC0ED080BF18098E6F82A6AE436F7DACE367192AB2C763DFBF8D270527DD2AC8A8FE8F3A2AC13106749F1F3CC6C7B98F48158965370B36024DE195DD96
                  Malicious:false
                  Preview:D..-7.W..u.~...bA....3S...i..?...+F...........%...u.E.q^....BQ..........c1eKY\8K...?.{......d..u."..>.m=l...gmJ[~.$.FV...O...Rb..;D.#2.....1..Z.)#.+..L..O.5..._....e[]r..p<".U.f.T<..>k...cy....O..E.x...<..H...3..w<..4%...(.q$_(....eG./..\.>....f....1..z.].D.<.\.....5.y{@8..&.:..!...S.D._y8...]@..]k....#......hmL......^DtrN...u.......aBMfR.F.L...vy.....r....>.BW%.(..VwPg...S:_............Vu-..D4..mb.........|...u.H....l.M.....gA...p.h...$...o...%...+`....P.........b...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):514
                  Entropy (8bit):7.485077152332643
                  Encrypted:false
                  SSDEEP:
                  MD5:7770FD303A9094AF270628F488340240
                  SHA1:9A7B8712B477D3E05EAEDE8D9EDC0E9CC49C2F21
                  SHA-256:F07E3E3BE8A0CFB18169FF5FF817D4DC80EB87870E207C5E13AA0995BAC6F8CB
                  SHA-512:73ABD9CC0ED080BF18098E6F82A6AE436F7DACE367192AB2C763DFBF8D270527DD2AC8A8FE8F3A2AC13106749F1F3CC6C7B98F48158965370B36024DE195DD96
                  Malicious:false
                  Preview:D..-7.W..u.~...bA....3S...i..?...+F...........%...u.E.q^....BQ..........c1eKY\8K...?.{......d..u."..>.m=l...gmJ[~.$.FV...O...Rb..;D.#2.....1..Z.)#.+..L..O.5..._....e[]r..p<".U.f.T<..>k...cy....O..E.x...<..H...3..w<..4%...(.q$_(....eG./..\.>....f....1..z.].D.<.\.....5.y{@8..&.:..!...S.D._y8...]@..]k....#......hmL......^DtrN...u.......aBMfR.F.L...vy.....r....>.BW%.(..VwPg...S:_............Vu-..D4..mb.........|...u.H....l.M.....gA...p.h...$...o...%...+`....P.........b...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):514
                  Entropy (8bit):7.485077152332643
                  Encrypted:false
                  SSDEEP:
                  MD5:7770FD303A9094AF270628F488340240
                  SHA1:9A7B8712B477D3E05EAEDE8D9EDC0E9CC49C2F21
                  SHA-256:F07E3E3BE8A0CFB18169FF5FF817D4DC80EB87870E207C5E13AA0995BAC6F8CB
                  SHA-512:73ABD9CC0ED080BF18098E6F82A6AE436F7DACE367192AB2C763DFBF8D270527DD2AC8A8FE8F3A2AC13106749F1F3CC6C7B98F48158965370B36024DE195DD96
                  Malicious:false
                  Preview:D..-7.W..u.~...bA....3S...i..?...+F...........%...u.E.q^....BQ..........c1eKY\8K...?.{......d..u."..>.m=l...gmJ[~.$.FV...O...Rb..;D.#2.....1..Z.)#.+..L..O.5..._....e[]r..p<".U.f.T<..>k...cy....O..E.x...<..H...3..w<..4%...(.q$_(....eG./..\.>....f....1..z.].D.<.\.....5.y{@8..&.:..!...S.D._y8...]@..]k....#......hmL......^DtrN...u.......aBMfR.F.L...vy.....r....>.BW%.(..VwPg...S:_............Vu-..D4..mb.........|...u.H....l.M.....gA...p.h...$...o...%...+`....P.........b...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2178
                  Entropy (8bit):7.903977992709532
                  Encrypted:false
                  SSDEEP:
                  MD5:83C1B04B1FF3732300FFB89CD73174DC
                  SHA1:BF5A781ECDB8C07C4B7DDDB17970200EE9D39B26
                  SHA-256:ADC3BECB54FA880F7B35207C0EE6B227D44E340F8368F6B9D6729499AC6CB594
                  SHA-512:AB3EEB0039A60BAF02319F13DDB9C105D99A47BEE32C856BB890AD4F877CFFF713E5D305B1E78AF579CDEDE36C2CE9953E94C66F460C84DF8DFFC5DAF7F38044
                  Malicious:false
                  Preview:SYv..|.{...^.:..H#.."......ec....[O-..7...YJr.....`.g......vmt.0..X........;oM.-.S......%....&vbe.#.hs.2=.@..q.N...r....i..H...X...d......C..R...c..S...Q5.....s... .}sN%...Z.*k..?p...n.%.....C...&...l.....JS.......0....RVg._^=\!..8.f.....o....u..v7......-,...l#5.G..x...os.a0......D......n..E..];....\..k.J...`*...^..K$.w.. ....K.......b:Kb....B....BU.....s>R2...................2....}.e.......i.."..t8.k.J....}S.T8T.i.Q`.....E&...$[5.(....7....^.p.....:i....Wbe...&..P.O...........8^..NpT.R.GE3.@..."..mqe,.u:c.1E..=. x-..jB{.4...........7K.~&._....e.'../...,"..]m..(.6..^G.TwZ.V.......t......... P..}..X(.WU.YAX):.....j.*..5.......6V...T...8E.WZ....|.....6...p>(.q.B.uJ..c..N....T.....J?....._...d..........(j(.EMl.._..}.&........3..id>M..o.k...!d{.<...`.y$}.-..J5Szd.G.r.D.......V....~.5q..T.f....F..W~].u.|wh.Bu.b..U(%..a^.W..'..e...lE....x.$..L6..U...PO2...X...|.-....F<...i....+.x.......0.7.r0.9...UeUpG..*.....a..[).&.75.P..F8oh.Q.,...}
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2178
                  Entropy (8bit):7.903977992709532
                  Encrypted:false
                  SSDEEP:
                  MD5:83C1B04B1FF3732300FFB89CD73174DC
                  SHA1:BF5A781ECDB8C07C4B7DDDB17970200EE9D39B26
                  SHA-256:ADC3BECB54FA880F7B35207C0EE6B227D44E340F8368F6B9D6729499AC6CB594
                  SHA-512:AB3EEB0039A60BAF02319F13DDB9C105D99A47BEE32C856BB890AD4F877CFFF713E5D305B1E78AF579CDEDE36C2CE9953E94C66F460C84DF8DFFC5DAF7F38044
                  Malicious:false
                  Preview:SYv..|.{...^.:..H#.."......ec....[O-..7...YJr.....`.g......vmt.0..X........;oM.-.S......%....&vbe.#.hs.2=.@..q.N...r....i..H...X...d......C..R...c..S...Q5.....s... .}sN%...Z.*k..?p...n.%.....C...&...l.....JS.......0....RVg._^=\!..8.f.....o....u..v7......-,...l#5.G..x...os.a0......D......n..E..];....\..k.J...`*...^..K$.w.. ....K.......b:Kb....B....BU.....s>R2...................2....}.e.......i.."..t8.k.J....}S.T8T.i.Q`.....E&...$[5.(....7....^.p.....:i....Wbe...&..P.O...........8^..NpT.R.GE3.@..."..mqe,.u:c.1E..=. x-..jB{.4...........7K.~&._....e.'../...,"..]m..(.6..^G.TwZ.V.......t......... P..}..X(.WU.YAX):.....j.*..5.......6V...T...8E.WZ....|.....6...p>(.q.B.uJ..c..N....T.....J?....._...d..........(j(.EMl.._..}.&........3..id>M..o.k...!d{.<...`.y$}.-..J5Szd.G.r.D.......V....~.5q..T.f....F..W~].u.|wh.Bu.b..U(%..a^.W..'..e...lE....x.$..L6..U...PO2...X...|.-....F<...i....+.x.......0.7.r0.9...UeUpG..*.....a..[).&.75.P..F8oh.Q.,...}
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2178
                  Entropy (8bit):7.903977992709532
                  Encrypted:false
                  SSDEEP:
                  MD5:83C1B04B1FF3732300FFB89CD73174DC
                  SHA1:BF5A781ECDB8C07C4B7DDDB17970200EE9D39B26
                  SHA-256:ADC3BECB54FA880F7B35207C0EE6B227D44E340F8368F6B9D6729499AC6CB594
                  SHA-512:AB3EEB0039A60BAF02319F13DDB9C105D99A47BEE32C856BB890AD4F877CFFF713E5D305B1E78AF579CDEDE36C2CE9953E94C66F460C84DF8DFFC5DAF7F38044
                  Malicious:false
                  Preview:SYv..|.{...^.:..H#.."......ec....[O-..7...YJr.....`.g......vmt.0..X........;oM.-.S......%....&vbe.#.hs.2=.@..q.N...r....i..H...X...d......C..R...c..S...Q5.....s... .}sN%...Z.*k..?p...n.%.....C...&...l.....JS.......0....RVg._^=\!..8.f.....o....u..v7......-,...l#5.G..x...os.a0......D......n..E..];....\..k.J...`*...^..K$.w.. ....K.......b:Kb....B....BU.....s>R2...................2....}.e.......i.."..t8.k.J....}S.T8T.i.Q`.....E&...$[5.(....7....^.p.....:i....Wbe...&..P.O...........8^..NpT.R.GE3.@..."..mqe,.u:c.1E..=. x-..jB{.4...........7K.~&._....e.'../...,"..]m..(.6..^G.TwZ.V.......t......... P..}..X(.WU.YAX):.....j.*..5.......6V...T...8E.WZ....|.....6...p>(.q.B.uJ..c..N....T.....J?....._...d..........(j(.EMl.._..}.&........3..id>M..o.k...!d{.<...`.y$}.-..J5Szd.G.r.D.......V....~.5q..T.f....F..W~].u.|wh.Bu.b..U(%..a^.W..'..e...lE....x.$..L6..U...PO2...X...|.-....F<...i....+.x.......0.7.r0.9...UeUpG..*.....a..[).&.75.P..F8oh.Q.,...}
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):292
                  Entropy (8bit):6.868542360710211
                  Encrypted:false
                  SSDEEP:
                  MD5:07B40445DA95DE0B80D3DAF1DFB25F99
                  SHA1:D4D52002929C634B5D8335B478784E6185C4BC8E
                  SHA-256:E14D0F8DB3848C2AB145C650915AECCC834FEB1557203AD3145D1FDDCA1E4B28
                  SHA-512:795A61FF2EB2EAACC0F67F482076EC25135074C5A07EA4970A2D0E16F6653D08D6C41C01A62A9D097A140A73255641675605DEB87BF0279775D1A0B889AA16A8
                  Malicious:false
                  Preview:;.8..C`8..H..&V../F(..A.lBZ7Bp.J.=i.L~....+..0u..h.. ..;}K)-.0g..{...-.z.8.+..... Q..../.#b.......U...5E..gc..~.L..7...L.s.A$.o.U..u*..0.U......[.R...bJ%..d..{..d.e.....M.LO................x..).'.f..S\...>.d........&.X.....UT~..;|...0.%~).*h.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):292
                  Entropy (8bit):6.868542360710211
                  Encrypted:false
                  SSDEEP:
                  MD5:07B40445DA95DE0B80D3DAF1DFB25F99
                  SHA1:D4D52002929C634B5D8335B478784E6185C4BC8E
                  SHA-256:E14D0F8DB3848C2AB145C650915AECCC834FEB1557203AD3145D1FDDCA1E4B28
                  SHA-512:795A61FF2EB2EAACC0F67F482076EC25135074C5A07EA4970A2D0E16F6653D08D6C41C01A62A9D097A140A73255641675605DEB87BF0279775D1A0B889AA16A8
                  Malicious:false
                  Preview:;.8..C`8..H..&V../F(..A.lBZ7Bp.J.=i.L~....+..0u..h.. ..;}K)-.0g..{...-.z.8.+..... Q..../.#b.......U...5E..gc..~.L..7...L.s.A$.o.U..u*..0.U......[.R...bJ%..d..{..d.e.....M.LO................x..).'.f..S\...>.d........&.X.....UT~..;|...0.%~).*h.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):292
                  Entropy (8bit):6.868542360710211
                  Encrypted:false
                  SSDEEP:
                  MD5:07B40445DA95DE0B80D3DAF1DFB25F99
                  SHA1:D4D52002929C634B5D8335B478784E6185C4BC8E
                  SHA-256:E14D0F8DB3848C2AB145C650915AECCC834FEB1557203AD3145D1FDDCA1E4B28
                  SHA-512:795A61FF2EB2EAACC0F67F482076EC25135074C5A07EA4970A2D0E16F6653D08D6C41C01A62A9D097A140A73255641675605DEB87BF0279775D1A0B889AA16A8
                  Malicious:false
                  Preview:;.8..C`8..H..&V../F(..A.lBZ7Bp.J.=i.L~....+..0u..h.. ..;}K)-.0g..{...-.z.8.+..... Q..../.#b.......U...5E..gc..~.L..7...L.s.A$.o.U..u*..0.U......[.R...bJ%..d..{..d.e.....M.LO................x..).'.f..S\...>.d........&.X.....UT~..;|...0.%~).*h.........................@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1362
                  Entropy (8bit):7.831909567153469
                  Encrypted:false
                  SSDEEP:
                  MD5:ADFF184505E23B8FCFFE986B58FD7ABC
                  SHA1:00FC3FFCFD772410ECA2AE6255FD70E22D122973
                  SHA-256:9788E80ECA7EFA81CFD31D4BC6AF5DC5D7AE6D9D43F041271D7CFDA80A9CC42E
                  SHA-512:92110C3B0D46DAE1B916004E2B36FFB98B85F58B2CFA4C0188A68F789494CED2F37A1530DAEFADABD657D0C796219DCF4E05EBCDE747FBE6DFAA2CC0AE5295B8
                  Malicious:false
                  Preview:..5...I...u..&L2.[6w........)......cE...EZ...~..q.s..I...o..rHT.;I}..k....x..!.%.....0-z...tu..4.wD>....PTQ{'U......E?.b..W..w..e..Hj..w../_1R+.s.........\...9.=..L.s.....r..b...G.#._4....K.../........g..A...,.$N.".._.Q....z.&.<\{...aH.@........I[.G.Ra..f}..J....S.%u...#.....U.E.....ih~......,.E.Gt...1..u.['1...8.E.a:S......).l.&yS*...#F.~....T{."...g|..t.[...>......t....`..9;59i.......%..e.2.R....s..2b...[....0$....S..V.....|j.......@...../.]-..%...!..]..h.....A.&.j.S01l..%u..........(..QJ...z.....U. T....!X..........1..hq.D...i.8.n4-2..02^...>:\"..p.b....X....e...?Y..j....2..f7.x...u.....F..1..`.....UL.q.............Pt.Sg..n6...c.Fu.z.i.. sF]...-}J..l..R.@.e.+.Fy....(..[x/O.....0=.?R...E5...G;.5SC.n..?oA_..We.O8#mF.5),+..c...(...Z.}..f...Pp0..<0..C.Dgu..o`z.C.|A...g.Z.?.d^.......c..H.4......&.g.N...MV.v/... [..p`...@..~qA...q..".}.:]n./.m.)....D.0.(:d..^.jG.r.._..5 ..A.....@X.V .w..S-!2=Pn....q`OH..].Z..L.......=...h.GjX}(P.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1362
                  Entropy (8bit):7.831909567153469
                  Encrypted:false
                  SSDEEP:
                  MD5:ADFF184505E23B8FCFFE986B58FD7ABC
                  SHA1:00FC3FFCFD772410ECA2AE6255FD70E22D122973
                  SHA-256:9788E80ECA7EFA81CFD31D4BC6AF5DC5D7AE6D9D43F041271D7CFDA80A9CC42E
                  SHA-512:92110C3B0D46DAE1B916004E2B36FFB98B85F58B2CFA4C0188A68F789494CED2F37A1530DAEFADABD657D0C796219DCF4E05EBCDE747FBE6DFAA2CC0AE5295B8
                  Malicious:false
                  Preview:..5...I...u..&L2.[6w........)......cE...EZ...~..q.s..I...o..rHT.;I}..k....x..!.%.....0-z...tu..4.wD>....PTQ{'U......E?.b..W..w..e..Hj..w../_1R+.s.........\...9.=..L.s.....r..b...G.#._4....K.../........g..A...,.$N.".._.Q....z.&.<\{...aH.@........I[.G.Ra..f}..J....S.%u...#.....U.E.....ih~......,.E.Gt...1..u.['1...8.E.a:S......).l.&yS*...#F.~....T{."...g|..t.[...>......t....`..9;59i.......%..e.2.R....s..2b...[....0$....S..V.....|j.......@...../.]-..%...!..]..h.....A.&.j.S01l..%u..........(..QJ...z.....U. T....!X..........1..hq.D...i.8.n4-2..02^...>:\"..p.b....X....e...?Y..j....2..f7.x...u.....F..1..`.....UL.q.............Pt.Sg..n6...c.Fu.z.i.. sF]...-}J..l..R.@.e.+.Fy....(..[x/O.....0=.?R...E5...G;.5SC.n..?oA_..We.O8#mF.5),+..c...(...Z.}..f...Pp0..<0..C.Dgu..o`z.C.|A...g.Z.?.d^.......c..H.4......&.g.N...MV.v/... [..p`...@..~qA...q..".}.:]n./.m.)....D.0.(:d..^.jG.r.._..5 ..A.....@X.V .w..S-!2=Pn....q`OH..].Z..L.......=...h.GjX}(P.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1362
                  Entropy (8bit):7.831909567153469
                  Encrypted:false
                  SSDEEP:
                  MD5:ADFF184505E23B8FCFFE986B58FD7ABC
                  SHA1:00FC3FFCFD772410ECA2AE6255FD70E22D122973
                  SHA-256:9788E80ECA7EFA81CFD31D4BC6AF5DC5D7AE6D9D43F041271D7CFDA80A9CC42E
                  SHA-512:92110C3B0D46DAE1B916004E2B36FFB98B85F58B2CFA4C0188A68F789494CED2F37A1530DAEFADABD657D0C796219DCF4E05EBCDE747FBE6DFAA2CC0AE5295B8
                  Malicious:false
                  Preview:..5...I...u..&L2.[6w........)......cE...EZ...~..q.s..I...o..rHT.;I}..k....x..!.%.....0-z...tu..4.wD>....PTQ{'U......E?.b..W..w..e..Hj..w../_1R+.s.........\...9.=..L.s.....r..b...G.#._4....K.../........g..A...,.$N.".._.Q....z.&.<\{...aH.@........I[.G.Ra..f}..J....S.%u...#.....U.E.....ih~......,.E.Gt...1..u.['1...8.E.a:S......).l.&yS*...#F.~....T{."...g|..t.[...>......t....`..9;59i.......%..e.2.R....s..2b...[....0$....S..V.....|j.......@...../.]-..%...!..]..h.....A.&.j.S01l..%u..........(..QJ...z.....U. T....!X..........1..hq.D...i.8.n4-2..02^...>:\"..p.b....X....e...?Y..j....2..f7.x...u.....F..1..`.....UL.q.............Pt.Sg..n6...c.Fu.z.i.. sF]...-}J..l..R.@.e.+.Fy....(..[x/O.....0=.?R...E5...G;.5SC.n..?oA_..We.O8#mF.5),+..c...(...Z.}..f...Pp0..<0..C.Dgu..o`z.C.|A...g.Z.?.d^.......c..H.4......&.g.N...MV.v/... [..p`...@..~qA...q..".}.:]n./.m.)....D.0.(:d..^.jG.r.._..5 ..A.....@X.V .w..S-!2=Pn....q`OH..].Z..L.......=...h.GjX}(P.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.8576242921227735
                  Encrypted:false
                  SSDEEP:
                  MD5:20F5AE9AC1F4E63B9C8A178F95681B8A
                  SHA1:16EC32ECA06AC1E8A4C163EA36C69F7DA6AC4AFC
                  SHA-256:0E44FCDCFAEF243AF8847702953A336BCDE0846C7A456F8229D58D6F1465F174
                  SHA-512:1A83A1C5F2C82CF1559871EF41CCA199B181641B064D33CDBB548BA6D1CEDE84E7219813ABB88CF2ACE96B2A515C0C4323A2A6EB4C761C5A3CB6200244868129
                  Malicious:false
                  Preview:..?y6.BS7..iO'KD/n......W..9................1.]....Y[(u._....].U.Dv..,+.0NR.5..8;a=R..A..."-.U...{`..=.u....=6.......|d .Z.......Z^.]..@...k.3..fN..8.j....V...%sC...U..i.hU.W_../d.k.............Z.....\.P..Z.......?.`.'h0.-w.P..lG+k.=......Ys85...<.E|.T.M...../.~..Q.....r...aeQ...\.......&w.+h....S.....Ui.MG.S......@.2......G....4..{uIL..k..x[p^E.....:9...-...f.a.|.... .[8k...T.. eI.rS..........[A ..w.`.....e/.S....:...y...8...G....R|S..x.\..n.r.j..5.e`&.9..W$W...2D...Fs-5.n.QR.G.lZ9...W^.B.o.}...V.4.Y..Z...LN.C..{......oGO.=0#..^.G...6y.~..39=. &9.}.o..9."..|qP.~...D...o.u4..\.R.{.+....k.RbO..2.g).......).....b8..q....=.@..C. W...B..n.v...`e..'...M;%.........qe.<>..g.m:g.yo.7..z......x1..............A.".>...V..f.X..0b...r._..A....R...qkB......i..dK<.=4./.u..r......rm.C..].......X...p#....R....2".KL-.....Wt6.5)hK~."..~!..Z1|8.....D."...J.....=.=.O.[.H.Z.u....&...j._=.N....=.-.F.$d0...9j..k...$,...oS.4..j.7..!..............<r.q..O..It.]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.8576242921227735
                  Encrypted:false
                  SSDEEP:
                  MD5:20F5AE9AC1F4E63B9C8A178F95681B8A
                  SHA1:16EC32ECA06AC1E8A4C163EA36C69F7DA6AC4AFC
                  SHA-256:0E44FCDCFAEF243AF8847702953A336BCDE0846C7A456F8229D58D6F1465F174
                  SHA-512:1A83A1C5F2C82CF1559871EF41CCA199B181641B064D33CDBB548BA6D1CEDE84E7219813ABB88CF2ACE96B2A515C0C4323A2A6EB4C761C5A3CB6200244868129
                  Malicious:false
                  Preview:..?y6.BS7..iO'KD/n......W..9................1.]....Y[(u._....].U.Dv..,+.0NR.5..8;a=R..A..."-.U...{`..=.u....=6.......|d .Z.......Z^.]..@...k.3..fN..8.j....V...%sC...U..i.hU.W_../d.k.............Z.....\.P..Z.......?.`.'h0.-w.P..lG+k.=......Ys85...<.E|.T.M...../.~..Q.....r...aeQ...\.......&w.+h....S.....Ui.MG.S......@.2......G....4..{uIL..k..x[p^E.....:9...-...f.a.|.... .[8k...T.. eI.rS..........[A ..w.`.....e/.S....:...y...8...G....R|S..x.\..n.r.j..5.e`&.9..W$W...2D...Fs-5.n.QR.G.lZ9...W^.B.o.}...V.4.Y..Z...LN.C..{......oGO.=0#..^.G...6y.~..39=. &9.}.o..9."..|qP.~...D...o.u4..\.R.{.+....k.RbO..2.g).......).....b8..q....=.@..C. W...B..n.v...`e..'...M;%.........qe.<>..g.m:g.yo.7..z......x1..............A.".>...V..f.X..0b...r._..A....R...qkB......i..dK<.=4./.u..r......rm.C..].......X...p#....R....2".KL-.....Wt6.5)hK~."..~!..Z1|8.....D."...J.....=.=.O.[.H.Z.u....&...j._=.N....=.-.F.$d0...9j..k...$,...oS.4..j.7..!..............<r.q..O..It.]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1609
                  Entropy (8bit):7.8576242921227735
                  Encrypted:false
                  SSDEEP:
                  MD5:20F5AE9AC1F4E63B9C8A178F95681B8A
                  SHA1:16EC32ECA06AC1E8A4C163EA36C69F7DA6AC4AFC
                  SHA-256:0E44FCDCFAEF243AF8847702953A336BCDE0846C7A456F8229D58D6F1465F174
                  SHA-512:1A83A1C5F2C82CF1559871EF41CCA199B181641B064D33CDBB548BA6D1CEDE84E7219813ABB88CF2ACE96B2A515C0C4323A2A6EB4C761C5A3CB6200244868129
                  Malicious:false
                  Preview:..?y6.BS7..iO'KD/n......W..9................1.]....Y[(u._....].U.Dv..,+.0NR.5..8;a=R..A..."-.U...{`..=.u....=6.......|d .Z.......Z^.]..@...k.3..fN..8.j....V...%sC...U..i.hU.W_../d.k.............Z.....\.P..Z.......?.`.'h0.-w.P..lG+k.=......Ys85...<.E|.T.M...../.~..Q.....r...aeQ...\.......&w.+h....S.....Ui.MG.S......@.2......G....4..{uIL..k..x[p^E.....:9...-...f.a.|.... .[8k...T.. eI.rS..........[A ..w.`.....e/.S....:...y...8...G....R|S..x.\..n.r.j..5.e`&.9..W$W...2D...Fs-5.n.QR.G.lZ9...W^.B.o.}...V.4.Y..Z...LN.C..{......oGO.=0#..^.G...6y.~..39=. &9.}.o..9."..|qP.~...D...o.u4..\.R.{.+....k.RbO..2.g).......).....b8..q....=.@..C. W...B..n.v...`e..'...M;%.........qe.<>..g.m:g.yo.7..z......x1..............A.".>...V..f.X..0b...r._..A....R...qkB......i..dK<.=4./.u..r......rm.C..].......X...p#....R....2".KL-.....Wt6.5)hK~."..~!..Z1|8.....D."...J.....=.=.O.[.H.Z.u....&...j._=.N....=.-.F.$d0...9j..k...$,...oS.4..j.7..!..............<r.q..O..It.]
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):233
                  Entropy (8bit):6.573221115225378
                  Encrypted:false
                  SSDEEP:
                  MD5:E010597BB5BA89F9D5E6F9E93B42D7A6
                  SHA1:CE77334C1A6BF4E09CB41B5740788B68E49D85B2
                  SHA-256:EC30708B606429FA86C6F1E0CC32CE721168BB805165F4C8676E9EC4DDFD2201
                  SHA-512:F79225CAD64A63A7DE5450D717C2EE96166D1BDD68B78755664E637AD66D95BCC4964724775478456A2A06FAC37183777B9CEEF294D4FDA9ECE1B5C50D05847E
                  Malicious:false
                  Preview:.5.7.<.T..G$...B.$f........O.w...~.0v.?..\.....F:e..x........Z.W..........S.C.8.....|M.:.g...wKAEh.I.'..B...7.z.8X.KS...i...=..G^I.......UZ~q.5.?.........)Q....20..5..T....$<Ab\.C.F.X.0..........I...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):233
                  Entropy (8bit):6.573221115225378
                  Encrypted:false
                  SSDEEP:
                  MD5:E010597BB5BA89F9D5E6F9E93B42D7A6
                  SHA1:CE77334C1A6BF4E09CB41B5740788B68E49D85B2
                  SHA-256:EC30708B606429FA86C6F1E0CC32CE721168BB805165F4C8676E9EC4DDFD2201
                  SHA-512:F79225CAD64A63A7DE5450D717C2EE96166D1BDD68B78755664E637AD66D95BCC4964724775478456A2A06FAC37183777B9CEEF294D4FDA9ECE1B5C50D05847E
                  Malicious:false
                  Preview:.5.7.<.T..G$...B.$f........O.w...~.0v.?..\.....F:e..x........Z.W..........S.C.8.....|M.:.g...wKAEh.I.'..B...7.z.8X.KS...i...=..G^I.......UZ~q.5.?.........)Q....20..5..T....$<Ab\.C.F.X.0..........I...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):233
                  Entropy (8bit):6.573221115225378
                  Encrypted:false
                  SSDEEP:
                  MD5:E010597BB5BA89F9D5E6F9E93B42D7A6
                  SHA1:CE77334C1A6BF4E09CB41B5740788B68E49D85B2
                  SHA-256:EC30708B606429FA86C6F1E0CC32CE721168BB805165F4C8676E9EC4DDFD2201
                  SHA-512:F79225CAD64A63A7DE5450D717C2EE96166D1BDD68B78755664E637AD66D95BCC4964724775478456A2A06FAC37183777B9CEEF294D4FDA9ECE1B5C50D05847E
                  Malicious:false
                  Preview:.5.7.<.T..G$...B.$f........O.w...~.0v.?..\.....F:e..x........Z.W..........S.C.8.....|M.:.g...wKAEh.I.'..B...7.z.8X.KS...i...=..G^I.......UZ~q.5.?.........)Q....20..5..T....$<Ab\.C.F.X.0..........I...............@.......
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7284
                  Entropy (8bit):7.977664630534286
                  Encrypted:false
                  SSDEEP:
                  MD5:EE928585CB1B2ED5B941C7610F5C1BCA
                  SHA1:CE16F564E76BAFC3BB5B1A82619A2D0F4BEBF8E6
                  SHA-256:761F08E888CE8317AF70C8931615C468ABAA01EE9D81D3AFCDC55C17E1B460E0
                  SHA-512:A5D3C97F996D15062873FD71812810B9965AD0EF7CC70DA34E4463AF704D976486A17662F8E10A91DFFCE7BCAB882A5902FBA69779A3A500698C946470BF78AC
                  Malicious:false
                  Preview:O..t6......:../..6..R-.}k.....a.........d..}.......*.F.P...l.......21XI..8o=..B..B>..z..ln6...hZRg|o...>3.m..'.....c4.zz.r.z.....P5X...&evz..;.T.....w.{.N..l.F....!n.?.8x..LR"ql2...{.......|!LE..1.XJs .....!O?.CX.....1...:.......s.YL....r.5.Y..:~.q...W.*.wN.7~...b.._..q^...0...?+...B..y..b.....T<..." ./...E." ..][.e.]....G3...s..$......6Q..&....../-U.....;.1....v,]i..J.........B....-.w.G..I.....-^.............s.^.QTP..e.V<G.8/...w.CCA...,*.....@...i..0q..L..q(/y.~.......pyv..Og...`>.=w..].O.i6BMe.* .H...#x.R$?....c....Y....}...5l...5.<H...Ju..S.`....,S..=..m}...Q.i...'..f.>...dh.Y.d.xD.-~dT1..a.....=K.g..O..f>~...`..S.....LY...8..;.....c......$.....F(..7.y..X^..y..|.4.....N'.|..P...LK3)%..^.W.a..|R.3.V....Z..H.}...G..=......=..`.f...A~>....U.+.k.X...{....~?.;Q.u....tb...TTG..$.k...cP.[gP.\./..A0..v..7..a....c.&..V.X..Q../P..gYu.*.......&.i..x..cR.#.#wH.TP..B.'_.I...z[..h.^..V....1v.m)..OY..t...j,3.3..{U..gX....9.3...[$-.4iE.vz.s..=;N.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7284
                  Entropy (8bit):7.977664630534286
                  Encrypted:false
                  SSDEEP:
                  MD5:EE928585CB1B2ED5B941C7610F5C1BCA
                  SHA1:CE16F564E76BAFC3BB5B1A82619A2D0F4BEBF8E6
                  SHA-256:761F08E888CE8317AF70C8931615C468ABAA01EE9D81D3AFCDC55C17E1B460E0
                  SHA-512:A5D3C97F996D15062873FD71812810B9965AD0EF7CC70DA34E4463AF704D976486A17662F8E10A91DFFCE7BCAB882A5902FBA69779A3A500698C946470BF78AC
                  Malicious:false
                  Preview:O..t6......:../..6..R-.}k.....a.........d..}.......*.F.P...l.......21XI..8o=..B..B>..z..ln6...hZRg|o...>3.m..'.....c4.zz.r.z.....P5X...&evz..;.T.....w.{.N..l.F....!n.?.8x..LR"ql2...{.......|!LE..1.XJs .....!O?.CX.....1...:.......s.YL....r.5.Y..:~.q...W.*.wN.7~...b.._..q^...0...?+...B..y..b.....T<..." ./...E." ..][.e.]....G3...s..$......6Q..&....../-U.....;.1....v,]i..J.........B....-.w.G..I.....-^.............s.^.QTP..e.V<G.8/...w.CCA...,*.....@...i..0q..L..q(/y.~.......pyv..Og...`>.=w..].O.i6BMe.* .H...#x.R$?....c....Y....}...5l...5.<H...Ju..S.`....,S..=..m}...Q.i...'..f.>...dh.Y.d.xD.-~dT1..a.....=K.g..O..f>~...`..S.....LY...8..;.....c......$.....F(..7.y..X^..y..|.4.....N'.|..P...LK3)%..^.W.a..|R.3.V....Z..H.}...G..=......=..`.f...A~>....U.+.k.X...{....~?.;Q.u....tb...TTG..$.k...cP.[gP.\./..A0..v..7..a....c.&..V.X..Q../P..gYu.*.......&.i..x..cR.#.#wH.TP..B.'_.I...z[..h.^..V....1v.m)..OY..t...j,3.3..{U..gX....9.3...[$-.4iE.vz.s..=;N.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):7284
                  Entropy (8bit):7.977664630534286
                  Encrypted:false
                  SSDEEP:
                  MD5:EE928585CB1B2ED5B941C7610F5C1BCA
                  SHA1:CE16F564E76BAFC3BB5B1A82619A2D0F4BEBF8E6
                  SHA-256:761F08E888CE8317AF70C8931615C468ABAA01EE9D81D3AFCDC55C17E1B460E0
                  SHA-512:A5D3C97F996D15062873FD71812810B9965AD0EF7CC70DA34E4463AF704D976486A17662F8E10A91DFFCE7BCAB882A5902FBA69779A3A500698C946470BF78AC
                  Malicious:false
                  Preview:O..t6......:../..6..R-.}k.....a.........d..}.......*.F.P...l.......21XI..8o=..B..B>..z..ln6...hZRg|o...>3.m..'.....c4.zz.r.z.....P5X...&evz..;.T.....w.{.N..l.F....!n.?.8x..LR"ql2...{.......|!LE..1.XJs .....!O?.CX.....1...:.......s.YL....r.5.Y..:~.q...W.*.wN.7~...b.._..q^...0...?+...B..y..b.....T<..." ./...E." ..][.e.]....G3...s..$......6Q..&....../-U.....;.1....v,]i..J.........B....-.w.G..I.....-^.............s.^.QTP..e.V<G.8/...w.CCA...,*.....@...i..0q..L..q(/y.~.......pyv..Og...`>.=w..].O.i6BMe.* .H...#x.R$?....c....Y....}...5l...5.<H...Ju..S.`....,S..=..m}...Q.i...'..f.>...dh.Y.d.xD.-~dT1..a.....=K.g..O..f>~...`..S.....LY...8..;.....c......$.....F(..7.y..X^..y..|.4.....N'.|..P...LK3)%..^.W.a..|R.3.V....Z..H.}...G..=......=..`.f...A~>....U.+.k.X...{....~?.;Q.u....tb...TTG..$.k...cP.[gP.\./..A0..v..7..a....c.&..V.X..Q../P..gYu.*.......&.i..x..cR.#.#wH.TP..B.'_.I...z[..h.^..V....1v.m)..OY..t...j,3.3..{U..gX....9.3...[$-.4iE.vz.s..=;N.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2738
                  Entropy (8bit):7.926389636035081
                  Encrypted:false
                  SSDEEP:
                  MD5:66936AA256B010CC1ACBE3D4451E35E7
                  SHA1:9CAE4FB7D6A4C66C5F5B9E63C2C8C8F848C2D050
                  SHA-256:23CBBEACDFC1316FF42FD99AF8FA410880192B286DDD87632F7E321386156D0A
                  SHA-512:2F239BF83BE9B84F0DE89F515CAD9FE589E8A9ED37DAA6E80B29B67D356E3B70BBDC20A7C5C7C333F259A0845D6A871322D1A4ABED03E51B07E643EB0A94C38E
                  Malicious:false
                  Preview:.-.......Kv....W.u.k8.w.....a.?7.....uQK.W.....~..... .&|.S....o...........O?J.3.{..z.....d....f..."....$]...>...Oz.....Q.)..........c>.{.."...R0.6.3.9.y..".G4...2(..(.A......Nv...Q`.....A..~..>.E+.P...w..{...z../..y.%Z.......|oe...8.....7F.P..l.5...6..v..I...U.e.....S...Ik.......x`>..n.p....=.....3)..l.E......p.P.,=...'<H.Ca.x.......r/.;)>p...X=.z./;UE...e',8.......N..Y.8.[.......A.>.tp..Vro...?...l..7J.7.wx.`.e..(.?...P....d.....=y..6.6[z..%...^.k..7.T.<.n....j.pI..9.#|..9W..vzV.....~a+.#2.2.................|s.~'..O^..5..!.!qx.%Uhh.(#X;d......=5-u........E.....|Cg..ca....2.S.....2.'..L.P....^..[..d/u.-...AZB..[$Yb........]X......}..n.......8.E...lq.&...T.S...A.erN....\<$d..X..6].9}.w........RA.....O....m...]'8....`<.l....>P<.....l...^...VE.#.......1...o..Np...-.6..C..cl.^6K.|.........Y.+..Y..U.8I\...e.e......f..'.F.....=..-&\..@Xe}B.X....c4V.\.z...../.o.Y.......:.T..L.Y.`8...R.G....t.._ .U....R..R.)#...I."q.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2738
                  Entropy (8bit):7.926389636035081
                  Encrypted:false
                  SSDEEP:
                  MD5:66936AA256B010CC1ACBE3D4451E35E7
                  SHA1:9CAE4FB7D6A4C66C5F5B9E63C2C8C8F848C2D050
                  SHA-256:23CBBEACDFC1316FF42FD99AF8FA410880192B286DDD87632F7E321386156D0A
                  SHA-512:2F239BF83BE9B84F0DE89F515CAD9FE589E8A9ED37DAA6E80B29B67D356E3B70BBDC20A7C5C7C333F259A0845D6A871322D1A4ABED03E51B07E643EB0A94C38E
                  Malicious:false
                  Preview:.-.......Kv....W.u.k8.w.....a.?7.....uQK.W.....~..... .&|.S....o...........O?J.3.{..z.....d....f..."....$]...>...Oz.....Q.)..........c>.{.."...R0.6.3.9.y..".G4...2(..(.A......Nv...Q`.....A..~..>.E+.P...w..{...z../..y.%Z.......|oe...8.....7F.P..l.5...6..v..I...U.e.....S...Ik.......x`>..n.p....=.....3)..l.E......p.P.,=...'<H.Ca.x.......r/.;)>p...X=.z./;UE...e',8.......N..Y.8.[.......A.>.tp..Vro...?...l..7J.7.wx.`.e..(.?...P....d.....=y..6.6[z..%...^.k..7.T.<.n....j.pI..9.#|..9W..vzV.....~a+.#2.2.................|s.~'..O^..5..!.!qx.%Uhh.(#X;d......=5-u........E.....|Cg..ca....2.S.....2.'..L.P....^..[..d/u.-...AZB..[$Yb........]X......}..n.......8.E...lq.&...T.S...A.erN....\<$d..X..6].9}.w........RA.....O....m...]'8....`<.l....>P<.....l...^...VE.#.......1...o..Np...-.6..C..cl.^6K.|.........Y.+..Y..U.8I\...e.e......f..'.F.....=..-&\..@Xe}B.X....c4V.\.z...../.o.Y.......:.T..L.Y.`8...R.G....t.._ .U....R..R.)#...I."q.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):2738
                  Entropy (8bit):7.926389636035081
                  Encrypted:false
                  SSDEEP:
                  MD5:66936AA256B010CC1ACBE3D4451E35E7
                  SHA1:9CAE4FB7D6A4C66C5F5B9E63C2C8C8F848C2D050
                  SHA-256:23CBBEACDFC1316FF42FD99AF8FA410880192B286DDD87632F7E321386156D0A
                  SHA-512:2F239BF83BE9B84F0DE89F515CAD9FE589E8A9ED37DAA6E80B29B67D356E3B70BBDC20A7C5C7C333F259A0845D6A871322D1A4ABED03E51B07E643EB0A94C38E
                  Malicious:false
                  Preview:.-.......Kv....W.u.k8.w.....a.?7.....uQK.W.....~..... .&|.S....o...........O?J.3.{..z.....d....f..."....$]...>...Oz.....Q.)..........c>.{.."...R0.6.3.9.y..".G4...2(..(.A......Nv...Q`.....A..~..>.E+.P...w..{...z../..y.%Z.......|oe...8.....7F.P..l.5...6..v..I...U.e.....S...Ik.......x`>..n.p....=.....3)..l.E......p.P.,=...'<H.Ca.x.......r/.;)>p...X=.z./;UE...e',8.......N..Y.8.[.......A.>.tp..Vro...?...l..7J.7.wx.`.e..(.?...P....d.....=y..6.6[z..%...^.k..7.T.<.n....j.pI..9.#|..9W..vzV.....~a+.#2.2.................|s.~'..O^..5..!.!qx.%Uhh.(#X;d......=5-u........E.....|Cg..ca....2.S.....2.'..L.P....^..[..d/u.-...AZB..[$Yb........]X......}..n.......8.E...lq.&...T.S...A.erN....\<$d..X..6].9}.w........RA.....O....m...]'8....`<.l....>P<.....l...^...VE.#.......1...o..Np...-.6..C..cl.^6K.|.........Y.+..Y..U.8I\...e.e......f..'.F.....=..-&\..@Xe}B.X....c4V.\.z...../.o.Y.......:.T..L.Y.`8...R.G....t.._ .U....R..R.)#...I."q.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24419
                  Entropy (8bit):7.9916801065312555
                  Encrypted:true
                  SSDEEP:
                  MD5:5E3E81A21CFD11805CF8FC361265BA5F
                  SHA1:64B2649E24BB16C6263300B349F453665460E48E
                  SHA-256:E14F2339C313FC94D796FE6A3792A5F7B24D80771B7B873B0A8A57E0335AB26C
                  SHA-512:4DA570106655BF1D1AA92BDF369DEDDFE62CA7A6425B1B121580C90ABA3D3D872BB1E64B916CA276FA27D0A5E79993353F6B39D27BBD5A091F9F02D5F8AAF20C
                  Malicious:true
                  Preview:'..v..F..[c'.I'..,.......!&P......u._AX.#....@.;.PKWt.\..B\tF......u.i?.[...}.......I..Y5J.;.....6}.... .....k%#L.....Q.!].q....f...Z.F..(..X..c3{.]..r~.^... . N."...a.!.A..S.|5...H..nh.....7..........4&...P.:.Of..qz....IX-'}8..r.....~.[Z.x....uz..v..y..h.0.:....\!.)E....g.c..Q...S....p.1u.=T.g..IAMB......0.q...$.a..6.(...C.A39l..y...u[.....bB^...U..?./.-(.....OjA.....p...uS.yn..W,.....0}..{..2p/...0.Pm.2T..}......RP.}ol......c..n.x.V._..0.u...M.....SXQ$..R....`....~4.l.L.0.....m*...._....^W....t..ohYB....%.g...+q.X7...a:X..JI.|..*X.q/t..+.O...V.....F....!....sf.u...6..C..D...:.!5..&...jQ....x.f.!.o. d.w..|....%....ff..R..J.B.9...o..J`.@.m..\.<Y(rc....>..-[......#..~%...w..F5..m....E].|.....:k..Q....&..N..=.@...8......<&..)<.....k..t(b.#..i..t.(......Q.s.M.O.Ya.`.]K...Vv.?.."....}2oI7]G.Z}@u...-C.W...zP......6/..E......=A.........+....:mH.......Y..R]... ...y.I..Jc%>.....f.F[8.@.;@..s.........T.Ti'p.V......r...._.]A.V...~6.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24419
                  Entropy (8bit):7.9916801065312555
                  Encrypted:true
                  SSDEEP:
                  MD5:5E3E81A21CFD11805CF8FC361265BA5F
                  SHA1:64B2649E24BB16C6263300B349F453665460E48E
                  SHA-256:E14F2339C313FC94D796FE6A3792A5F7B24D80771B7B873B0A8A57E0335AB26C
                  SHA-512:4DA570106655BF1D1AA92BDF369DEDDFE62CA7A6425B1B121580C90ABA3D3D872BB1E64B916CA276FA27D0A5E79993353F6B39D27BBD5A091F9F02D5F8AAF20C
                  Malicious:true
                  Preview:'..v..F..[c'.I'..,.......!&P......u._AX.#....@.;.PKWt.\..B\tF......u.i?.[...}.......I..Y5J.;.....6}.... .....k%#L.....Q.!].q....f...Z.F..(..X..c3{.]..r~.^... . N."...a.!.A..S.|5...H..nh.....7..........4&...P.:.Of..qz....IX-'}8..r.....~.[Z.x....uz..v..y..h.0.:....\!.)E....g.c..Q...S....p.1u.=T.g..IAMB......0.q...$.a..6.(...C.A39l..y...u[.....bB^...U..?./.-(.....OjA.....p...uS.yn..W,.....0}..{..2p/...0.Pm.2T..}......RP.}ol......c..n.x.V._..0.u...M.....SXQ$..R....`....~4.l.L.0.....m*...._....^W....t..ohYB....%.g...+q.X7...a:X..JI.|..*X.q/t..+.O...V.....F....!....sf.u...6..C..D...:.!5..&...jQ....x.f.!.o. d.w..|....%....ff..R..J.B.9...o..J`.@.m..\.<Y(rc....>..-[......#..~%...w..F5..m....E].|.....:k..Q....&..N..=.@...8......<&..)<.....k..t(b.#..i..t.(......Q.s.M.O.Ya.`.]K...Vv.?.."....}2oI7]G.Z}@u...-C.W...zP......6/..E......=A.........+....:mH.......Y..R]... ...y.I..Jc%>.....f.F[8.@.;@..s.........T.Ti'p.V......r...._.]A.V...~6.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):24419
                  Entropy (8bit):7.9916801065312555
                  Encrypted:true
                  SSDEEP:
                  MD5:5E3E81A21CFD11805CF8FC361265BA5F
                  SHA1:64B2649E24BB16C6263300B349F453665460E48E
                  SHA-256:E14F2339C313FC94D796FE6A3792A5F7B24D80771B7B873B0A8A57E0335AB26C
                  SHA-512:4DA570106655BF1D1AA92BDF369DEDDFE62CA7A6425B1B121580C90ABA3D3D872BB1E64B916CA276FA27D0A5E79993353F6B39D27BBD5A091F9F02D5F8AAF20C
                  Malicious:true
                  Preview:'..v..F..[c'.I'..,.......!&P......u._AX.#....@.;.PKWt.\..B\tF......u.i?.[...}.......I..Y5J.;.....6}.... .....k%#L.....Q.!].q....f...Z.F..(..X..c3{.]..r~.^... . N."...a.!.A..S.|5...H..nh.....7..........4&...P.:.Of..qz....IX-'}8..r.....~.[Z.x....uz..v..y..h.0.:....\!.)E....g.c..Q...S....p.1u.=T.g..IAMB......0.q...$.a..6.(...C.A39l..y...u[.....bB^...U..?./.-(.....OjA.....p...uS.yn..W,.....0}..{..2p/...0.Pm.2T..}......RP.}ol......c..n.x.V._..0.u...M.....SXQ$..R....`....~4.l.L.0.....m*...._....^W....t..ohYB....%.g...+q.X7...a:X..JI.|..*X.q/t..+.O...V.....F....!....sf.u...6..C..D...:.!5..&...jQ....x.f.!.o. d.w..|....%....ff..R..J.B.9...o..J`.@.m..\.<Y(rc....>..-[......#..~%...w..F5..m....E].|.....:k..Q....&..N..=.@...8......<&..)<.....k..t(b.#..i..t.(......Q.s.M.O.Ya.`.]K...Vv.?.."....}2oI7]G.Z}@u...-C.W...zP......6/..E......=A.........+....:mH.......Y..R]... ...y.I..Jc%>.....f.F[8.@.;@..s.........T.Ti'p.V......r...._.]A.V...~6.
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:true
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Users\user\Desktop\win32.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):1819
                  Entropy (8bit):5.0931758448527855
                  Encrypted:false
                  SSDEEP:
                  MD5:1049F7F2AEEAAF9F7432298EB16CD32D
                  SHA1:41DC98FDE3633CB7F20FF58CD4C6978A36B84455
                  SHA-256:BB3CCEC3210CD2C96FB40CAC04C6353487AD16BDE1DB417787858D5593B5E80F
                  SHA-512:F8111CC16382CC95E18515968164D9016DD2EEFD0D0E9F3BCEBDC7D14B9CACC9BB4C9D5560382FD3BCA38A6EE65F3DD6AD08A02BA9C76A51E2996CFD779B2A30
                  Malicious:false
                  Preview:Your network has been chosen for Security Audit by EMBARGO Team.....We successfully infiltrated your network, downloaded all important and sensitive documents, files, databases, and encrypted your systems.....You must contact us before the deadline 2024-07-31 05:53:57 +0000 UTC, to decrypt your systems and prevent your sensitive information from disclosure on our blog:..http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/....Do not modify any files or file extensions. Your data maybe lost forever.....Instructions:..1. Download torbrowser: https://www.torproject.org/download/..2. Go to your registration link:..=================================..http://a3kvb22nuhfgaluy6uzufrjn3azzsu7tylszdbyne3kiextdmxz4nnyd.onion/#/73298b954035a575199ccc340f6fb7cf..=================================..3. Register an account then login....If you have problems with this instructions, you can contact us on TOX:..9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47...
                  Process:C:\Windows\SysWOW64\PING.EXE
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):365
                  Entropy (8bit):4.7468302356135865
                  Encrypted:false
                  SSDEEP:
                  MD5:26344623BCA6E5AA1E82FF713260945B
                  SHA1:5656E4D403FC725DDD7ACACA10AD1EEC6D67F1CD
                  SHA-256:2A3359748601AA4C7A27A814807B866A227E22B3E9923F07A51156CE855DE40D
                  SHA-512:278E4A04E78A1D98D6C86572B19FD02131AD89AA26CA71C7398DDC22721C2211E47124E5F0C0CEE27F92AEC38C7AED587A54A27DBA10C0D872DC808530DCC15A
                  Malicious:false
                  Preview:..Pinging 927537 [::1] with 32 bytes of data:..Reply from ::1: time<1ms ..Reply from ::1: time<1ms ..Reply from ::1: time<1ms ..Reply from ::1: time<1ms ..Reply from ::1: time<1ms ....Ping statistics for ::1:.. Packets: Sent = 5, Received = 5, Lost = 0 (0% loss),..Approximate round trip times in milli-seconds:.. Minimum = 0ms, Maximum = 0ms, Average = 0ms..
                  File type:PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
                  Entropy (8bit):6.520178122484576
                  TrID:
                  • Win32 Executable (generic) a (10002005/4) 99.96%
                  • Generic Win/DOS Executable (2004/3) 0.02%
                  • DOS Executable Generic (2002/1) 0.02%
                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                  File name:win32.exe
                  File size:6'241'792 bytes
                  MD5:5d55fb708834d5ccde15d36554ea63e8
                  SHA1:612ec1d41b2aa2518363b18381fd89c12315100f
                  SHA256:ebffc9ced2dba66db9aae02c7ccd2759a36c5167df5cd4adb151b20e7eab173c
                  SHA512:41aca4e3899158e02a74c4a661d6927ba4561aafb5572ec05098fff087ae73af6f822062c320a5c81b0c478227eaaf1c9bde20f3e58ed9c35303f30173d22950
                  SSDEEP:98304:W3UW0wJh+x0CQluvl1kRz/eqWgUX7eDxen:aWb0CQluvlaeqZUX7eD
                  TLSH:25565B0AF813A999D97F65B0606FE735DD35482D00039D33CFDA9E306A6E7112E8DA1E
                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....n.f...............(..F..:_...............F...@..........................._.....f `...@... ............................
                  Icon Hash:90cececece8e8eb0
                  Entrypoint:0x4014a0
                  Entrypoint Section:.text
                  Digitally signed:false
                  Imagebase:0x400000
                  Subsystem:windows gui
                  Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE, DEBUG_STRIPPED
                  DLL Characteristics:DYNAMIC_BASE, NX_COMPAT
                  Time Stamp:0x66916E02 [Fri Jul 12 17:55:14 2024 UTC]
                  TLS Callbacks:0x81c2c0, 0x869270, 0x869220
                  CLR (.Net) Version:
                  OS Version Major:4
                  OS Version Minor:0
                  File Version Major:4
                  File Version Minor:0
                  Subsystem Version Major:4
                  Subsystem Version Minor:0
                  Import Hash:c870ba25f44c51987b6d4037448b82e5
                  Instruction
                  mov dword ptr [009CA434h], 00000001h
                  jmp 00007F61291C6AD6h
                  nop
                  mov dword ptr [009CA434h], 00000000h
                  jmp 00007F61291C6AC6h
                  nop
                  sub esp, 1Ch
                  mov eax, dword ptr [esp+20h]
                  mov dword ptr [esp], eax
                  call 00007F612962EA46h
                  cmp eax, 01h
                  sbb eax, eax
                  add esp, 1Ch
                  ret
                  nop
                  nop
                  nop
                  nop
                  nop
                  nop
                  nop
                  nop
                  push ebp
                  mov ebp, esp
                  push edi
                  push esi
                  push ebx
                  sub esp, 1Ch
                  mov dword ptr [esp], 0086E000h
                  call dword ptr [009CB644h]
                  sub esp, 04h
                  test eax, eax
                  je 00007F61291C6E95h
                  mov ebx, eax
                  mov dword ptr [esp], 0086E000h
                  call dword ptr [009CB6A4h]
                  mov edi, dword ptr [009CB654h]
                  sub esp, 04h
                  mov dword ptr [009C9028h], eax
                  mov dword ptr [esp+04h], 0086E013h
                  mov dword ptr [esp], ebx
                  call edi
                  sub esp, 08h
                  mov esi, eax
                  mov dword ptr [esp+04h], 0086E029h
                  mov dword ptr [esp], ebx
                  call edi
                  sub esp, 08h
                  mov dword ptr [0086D004h], eax
                  test esi, esi
                  je 00007F61291C6E33h
                  mov dword ptr [esp+04h], 009C902Ch
                  mov dword ptr [esp], 0094A104h
                  call esi
                  mov dword ptr [esp], 00401580h
                  call 00007F61291C6D83h
                  lea esp, dword ptr [ebp-0Ch]
                  pop ebx
                  pop esi
                  NameVirtual AddressVirtual Size Is in Section
                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IMPORT0x5cb0000x2070.idata
                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x5d00000x2b2f4.reloc
                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                  IMAGE_DIRECTORY_ENTRY_TLS0x5492740x18.rdata
                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IAT0x5cb5540x428.idata
                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                  .text0x10000x46be3c0x46c0009da8ac190efbe3ebef17dbd87536f5bbunknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  .data0x46d0000x3c00x400d092f1c71744f4e4e330b9159e875d59False0.4814453125dBase III DBT, version number 0, next free block index 10, 1st item "\201]\217"3.891504091061547IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                  .rdata0x46e0000xdb5280xdb6003b1f855835f1b88f4354a3810b938789False0.355890535968661data5.904279833567703IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                  .eh_fram0x54a0000x7e5bc0x7e6000cb1c55d1c33e0be9c1db70692bb2b6fFalse0.25661860163204747data4.648135091723182IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                  .bss0x5c90000x14700x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                  .idata0x5cb0000x20700x2200d5f94baeeffb3e19bd60402ec8d2e014False0.3220358455882353data5.0142397737160245IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                  .CRT0x5ce0000x380x2004e652713eb50a884e6fe09387dc0dbc1False0.080078125data0.3413119142480582IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                  .tls0x5cf0000x80x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                  .reloc0x5d00000x2b2f40x2b400b6f97f1c19d91630b83e24baf9709f0aFalse0.5534343388728323data6.611541602622622IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                  DLLImport
                  kernel32.dllAcquireSRWLockExclusive, AcquireSRWLockShared, AddVectoredExceptionHandler, AttachConsole, CancelIo, CloseHandle, CompareStringOrdinal, CopyFileExW, CreateDirectoryW, CreateEventW, CreateFileMappingA, CreateFileW, CreateHardLinkW, CreateMutexA, CreateMutexW, CreateNamedPipeW, CreateProcessW, CreateSymbolicLinkW, CreateThread, CreateToolhelp32Snapshot, CreateWaitableTimerExW, DeleteFileW, DeleteProcThreadAttributeList, DeviceIoControl, DuplicateHandle, ExitProcess, FindClose, FindFirstFileW, FindFirstVolumeW, FindNextFileW, FindNextVolumeW, FindVolumeClose, FlushFileBuffers, FormatMessageW, FreeEnvironmentStringsW, FreeLibrary, GetCommandLineW, GetComputerNameExW, GetConsoleMode, GetConsoleScreenBufferInfo, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, GetDriveTypeW, GetEnvironmentStringsW, GetEnvironmentVariableW, GetExitCodeProcess, GetFileAttributesW, GetFileInformationByHandle, GetFileInformationByHandleEx, GetFileType, GetFinalPathNameByHandleW, GetFullPathNameW, GetLastError, GetLogicalDriveStringsW, GetLogicalDrives, GetLogicalProcessorInformation, GetModuleFileNameW, GetModuleHandleA, GetModuleHandleW, GetNativeSystemInfo, GetOverlappedResult, GetProcAddress, GetProcessHeap, GetProcessId, GetStartupInfoA, GetStdHandle, GetSystemDirectoryW, GetSystemInfo, GetSystemTimeAsFileTime, GetTempPathW, GetVolumePathNamesForVolumeNameW, GetWindowsDirectoryW, GlobalAlloc, GlobalFree, HeapAlloc, HeapFree, HeapReAlloc, InitOnceBeginInitialize, InitOnceComplete, InitializeProcThreadAttributeList, IsWow64Process, LoadLibraryA, LoadLibraryExA, MapViewOfFile, Module32FirstW, Module32NextW, MoveFileExW, MultiByteToWideChar, OpenProcess, Process32FirstW, Process32NextW, QueryPerformanceCounter, QueryPerformanceFrequency, ReadConsoleW, ReadFile, ReadFileEx, ReleaseMutex, ReleaseSRWLockExclusive, ReleaseSRWLockShared, RemoveDirectoryW, RtlCaptureContext, SetConsoleMode, SetConsoleTextAttribute, SetCurrentDirectoryW, SetEnvironmentVariableW, SetEvent, SetFileAttributesW, SetFileInformationByHandle, SetFilePointerEx, SetFileTime, SetHandleInformation, SetLastError, SetProcessShutdownParameters, SetThreadStackGuarantee, SetUnhandledExceptionFilter, SetVolumeMountPointW, SetWaitableTimer, Sleep, SleepConditionVariableSRW, SleepEx, SwitchToThread, SystemTimeToFileTime, SystemTimeToTzSpecificLocalTime, TerminateProcess, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, TryAcquireSRWLockExclusive, TzSpecificLocalTimeToSystemTime, UnmapViewOfFile, UpdateProcThreadAttribute, WaitForMultipleObjects, WaitForSingleObject, WaitForSingleObjectEx, WakeAllConditionVariable, WakeConditionVariable, WideCharToMultiByte, Wow64DisableWow64FsRedirection, Wow64RevertWow64FsRedirection, WriteConsoleW, WriteFileEx
                  mpr.dllWNetAddConnection2W, WNetCancelConnection2W, WNetCloseEnum, WNetEnumResourceW, WNetOpenEnumW
                  netapi32.dllNetApiBufferFree, NetShareEnum
                  ntdll.dllNtCreateFile, NtReadFile, NtWriteFile, RtlNtStatusToDosError
                  ole32.dllCoCreateGuid
                  oleaut32.dllGetErrorInfo, SetErrorInfo, SysAllocStringLen, SysFreeString, SysStringLen
                  rstrtmgr.dllRmEndSession, RmGetList, RmRegisterResources, RmShutdown, RmStartSession
                  shell32.dllSHEmptyRecycleBinW
                  userenv.dllGetUserProfileDirectoryW
                  ws2_32.dllWSACleanup, WSADuplicateSocketW, WSAGetLastError, WSARecv, WSASend, WSASocketW, WSAStartup, accept, bind, closesocket, connect, freeaddrinfo, getaddrinfo, getpeername, getsockname, getsockopt, ioctlsocket, listen, recv, recvfrom, select, send, sendto, setsockopt, shutdown
                  ADVAPI32.dllAdjustTokenPrivileges, AllocateAndInitializeSid, ChangeServiceConfigW, CloseServiceHandle, ControlService, EnumDependentServicesW, EnumServicesStatusExW, ImpersonateLoggedOnUser, LogonUserW, LookupPrivilegeValueW, OpenProcessToken, OpenSCManagerW, OpenServiceW, QueryServiceStatusEx, RevertToSelf, SetEntriesInAclW, SetNamedSecurityInfoW, SystemFunction036
                  bcrypt.dllBCryptGenRandom
                  KERNEL32.dllCreateSemaphoreW, DeleteCriticalSection, EnterCriticalSection, InitializeCriticalSection, LeaveCriticalSection, ReleaseSemaphore, VirtualProtect, VirtualQuery
                  msvcrt.dll__getmainargs, __initenv, __p__acmdln, __p__commode, __p__fmode, __set_app_type, __setusermatherr, _amsg_exit, _cexit, _commode, _fmode, _fpreset, _initterm, _iob, _onexit, abort, calloc, exit, fprintf, free, fwrite, malloc, memcmp, memcpy, memmove, memset, signal, strlen, strncmp, vfprintf, wcslen
                  No network behavior found

                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:06:10:05
                  Start date:24/10/2024
                  Path:C:\Users\user\Desktop\win32.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Users\user\Desktop\win32.exe"
                  Imagebase:0x860000
                  File size:6'241'792 bytes
                  MD5 hash:5D55FB708834D5CCDE15D36554EA63E8
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true

                  Target ID:1
                  Start time:06:10:05
                  Start date:24/10/2024
                  Path:C:\Windows\System32\cmd.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled no
                  Imagebase:0x7ff682c60000
                  File size:289'792 bytes
                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:2
                  Start time:06:10:05
                  Start date:24/10/2024
                  Path:C:\Windows\System32\conhost.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Imagebase:0x7ff7699e0000
                  File size:862'208 bytes
                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:3
                  Start time:06:10:05
                  Start date:24/10/2024
                  Path:C:\Windows\System32\bcdedit.exe
                  Wow64 process (32bit):false
                  Commandline:bcdedit /set {default} recoveryenabled no
                  Imagebase:0x7ff6fc4a0000
                  File size:491'864 bytes
                  MD5 hash:74F7B84B0A547592CA63A00A8C4AD583
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:moderate
                  Has exited:true

                  Target ID:16
                  Start time:06:12:09
                  Start date:24/10/2024
                  Path:C:\Windows\SysWOW64\cmd.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Windows\System32\cmd.exe" /q /c ping localhost -n 5 > nul & del C:\Users\user\Desktop\win32.exe
                  Imagebase:0x260000
                  File size:236'544 bytes
                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:17
                  Start time:06:12:09
                  Start date:24/10/2024
                  Path:C:\Windows\System32\conhost.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Imagebase:0x7ff7699e0000
                  File size:862'208 bytes
                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:18
                  Start time:06:12:09
                  Start date:24/10/2024
                  Path:C:\Windows\SysWOW64\PING.EXE
                  Wow64 process (32bit):true
                  Commandline:ping localhost -n 5
                  Imagebase:0x770000
                  File size:18'944 bytes
                  MD5 hash:B3624DD758CCECF93A1226CEF252CA12
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  No disassembly