IOC Report
http://t.cm.morganstanley.com/r/?id=h1b92d14%2C134cc33c%2C1356be32&p1=www.saiengroup.com%2Fteaz%2F648c482b60b3906833c9304bab170add%2FJBVNhz%2FYW15LmNoZW5AZG91YmxlbGluZS5jb20=

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (39257), with CRLF line terminators
downloaded
Chrome Cache Entry: 103
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
PNG image data, 16 x 25, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 106
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 448x448, components 3
downloaded
Chrome Cache Entry: 107
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 108
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 109
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 110
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 448x448, components 3
dropped
Chrome Cache Entry: 111
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 112
HTML document, ASCII text
dropped
Chrome Cache Entry: 113
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 114
GIF image data, version 89a, 22 x 22
downloaded
Chrome Cache Entry: 115
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 116
GIF image data, version 89a, 22 x 22
dropped
Chrome Cache Entry: 117
GIF image data, version 89a, 24 x 24
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 119
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 120
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 513
downloaded
Chrome Cache Entry: 121
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 122
PNG image data, 338 x 72, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 70
ASCII text, with very long lines (65329), with CRLF line terminators
downloaded
Chrome Cache Entry: 71
HTML document, Unicode text, UTF-8 text, with very long lines (941), with CRLF line terminators
dropped
Chrome Cache Entry: 72
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 73
HTML document, ASCII text, with very long lines (33188), with no line terminators
downloaded
Chrome Cache Entry: 74
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 75
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 76
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (61177)
downloaded
Chrome Cache Entry: 78
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 79
PNG image data, 17 x 25, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 80
HTML document, ASCII text
downloaded
Chrome Cache Entry: 81
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 82
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 83
HTML document, Unicode text, UTF-8 text, with very long lines (1237), with CRLF line terminators
downloaded
Chrome Cache Entry: 84
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 85
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 86
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 513
dropped
Chrome Cache Entry: 87
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 88
PNG image data, 338 x 72, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 89
PNG image data, 6 x 97, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 90
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 110554
downloaded
Chrome Cache Entry: 91
PNG image data, 17 x 25, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 92
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 93
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 94
PNG image data, 6 x 97, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 96
PNG image data, 16 x 25, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 97
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 98
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 99
JSON data
dropped
There are 44 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2480 --field-trial-handle=2392,i,11732126496717548433,17344427469454119980,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://t.cm.morganstanley.com/r/?id=h1b92d14%2C134cc33c%2C1356be32&p1=www.saiengroup.com%2Fteaz%2F648c482b60b3906833c9304bab170add%2FJBVNhz%2FYW15LmNoZW5AZG91YmxlbGluZS5jb20="

URLs

Name
IP
Malicious
http://t.cm.morganstanley.com/r/?id=h1b92d14%2C134cc33c%2C1356be32&p1=www.saiengroup.com%2Fteaz%2F648c482b60b3906833c9304bab170add%2FJBVNhz%2FYW15LmNoZW5AZG91YmxlbGluZS5jb20=
malicious
http://www.saiengroup.com/teaz/648c482b60b3906833c9304bab170add/JBVNhz/YW15LmNoZW5AZG91YmxlbGluZS5jb20=
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/87607523f9976753/1713399298199/25UtOJ-4PhOhACd
104.17.2.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/2lznf/0x4AAAAAAAQ_ajLYJ-oSKSIN/auto/normal
https://aadcdn.msauthimages.net/dbd5a2dd-j1fx1ggwwalily23vjiuezfn6ijsocdmg58vgda4fdc/logintenantbranding/0/illustration?ts=636716750610080569
152.195.19.97
https://activemxmore.com/main/
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.6.0/jquery.min.js
104.17.25.14
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=87607523f9976753
104.17.2.184
https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_8owwt4u-33ps0wawi7tmow2.css
152.199.4.44
https://passwordreset.microsoftonline.com/?ru=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhZLNa9MAAMWbdq1b0dlNET0IEzzIJG2-0xR2SJt-pFuStU0amoOlaZM0bZqkbdK0uYseB8LAgRcPojt6Ei8Kehi7uPP8DwRFPMiObnoeXh7v8d7t_ZLLRBom0lAa2owhaSh3HyMJHMNwFUSRLgFilAqBWVQjQLhHoecVQhLdzmQ9mXr8xL-3_yNTePN8bbO59fnFIbDR9zx3mstkgiBIO7pudrV01xllrI7dM21jhrwDgBMAOIjGNRuUGofRKYFmYZTCYQInYRQlYRhJt0QabslsqAw4TyizGG9CkCJagx25OuTCoseLUtgKhwuuXMQUWYK4cAgrMhcI4tDjRmzIFy72tcWO2B8JIudxTG3BDaSAZySEZ2r4afS6QPteH7kQZ2KG2q_oiu5MRm3XmXoHsf0oa2_LVLkyq3f8Rcjy42q1gpCmQMlwFxs7xZaUX_TC1rRdsn18Z9uFFFrtg9VCXfLl4XAATjhyx9iFbFKCkOliYbCo2K-apqzkLV0k59uUU1B5vcD2XAItBc1i1RBMexdCbdjrBzZfLpXzou808Www5STOmtfAkS_DeAlSF0h7e9jlVa_RbWBzmOk4vR4KVXlZ1gJK1gdsVt015tREwAl80pg3CmatrxqjsSVW8CZV4uyybMrZPO-5TYyzS2irgyjCjDXyltFG9VCv0_zApcJsvUkTSjB383gFZECD7jShRnAYu3PJvTPkbSxxbkaOfRwjHVezzd6GO3F009IuQ2KGZIS_qeKMtDRtWSdLwLelW8uJVOp2ZCPy4CYUyy0vJ1ORi3S2BLyMnxMXxlcTj-4q9OuVr59-j6nIcTzTLNgMjVMGKs_6XmgV8g8JXrJ0oYQTZTxDDOcNX-34vfmYcbbgHLyXAPYSiePEGsu0-aLYEGmeoesM0oZ-JoCnVyLvV_7L8OnVG8mkb7Ytp9uxtOn6P5Y_XoucrR59-fDs1d7R98of0&mkt=en-US&hosted=0&device_platform=Windows+10
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1520722112:1713395675:Fybv0RgAUcvA2wE1JKV-kLLtV_0tb7lZl_7TvhqJ-Rs/87607523f9976753/573412a78ad2aa1
104.17.2.184
https://bc1q3jc6cu9q5t33q8gpk7h47pw.com/api/v3/auth
193.222.96.117
http://www.saiengroup.com/favicon.ico
120.136.14.8
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg
152.199.4.44
https://challenges.cloudflare.com/turnstile/v0/g/54ea73d52131/api.js?onload=onloadTurnstileCallback
104.17.2.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/87607523f9976753/1713399298197/6da8eb24f5f53b8a754917a6951c01ddae1de06f17567f971365618217d1d9e9/yq_oSBvvu_XQiGh
104.17.2.184
https://activemxmore.com/main/src.js
198.98.54.45
https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback
104.17.2.184
https://account.live.com/resetpassword.aspx
unknown
https://activemxmore.com/favicon.ico
198.98.54.45
https://outlook.office.com/mail/favicon.ico
52.96.183.242
http://t.cm.morganstanley.com/r/?id=h1b92d14%2C134cc33c%2C1356be32&p1=www.saiengroup.com%2Fteaz%2F648c482b60b3906833c9304bab170add%2FJBVNhz%2FYW15LmNoZW5AZG91YmxlbGluZS5jb20=
44.236.226.13
https://activemxmore.com/main/main.php
198.98.54.45
https://activemxmore.com/?e=amy.chen@doubleline.com
198.98.54.45
There are 14 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bc1q3jc6cu9q5t33q8gpk7h47pw.com
193.222.96.117
cs1100.wpc.omegacdn.net
152.199.4.44
activemxmore.com
198.98.54.45
fp2e7a.wpc.phicdn.net
192.229.211.108
LYH-efz.ms-acdc.office.com
52.96.183.242
morganstanley-mid-prod2-alb-1529755948.us-west-2.elb.amazonaws.com
44.236.226.13
part-0013.t-0009.t-msedge.net
13.107.246.41
cdnjs.cloudflare.com
104.17.25.14
sni1gl.wpc.upsiloncdn.net
152.195.19.97
challenges.cloudflare.com
104.17.2.184
www.google.com
108.177.122.99
part-0012.t-0009.t-msedge.net
13.107.213.40
www.saiengroup.com
120.136.14.8
aadcdn.msauthimages.net
unknown
passwordreset.microsoftonline.com
unknown
outlook.office.com
unknown
aadcdn.msftauth.net
unknown
ajax.aspnetcdn.com
unknown
t.cm.morganstanley.com
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.41
part-0013.t-0009.t-msedge.net
United States
152.195.19.97
sni1gl.wpc.upsiloncdn.net
United States
192.168.2.4
unknown
unknown
44.236.226.13
morganstanley-mid-prod2-alb-1529755948.us-west-2.elb.amazonaws.com
United States
104.17.3.184
unknown
United States
52.96.173.162
unknown
United States
13.107.213.40
part-0012.t-0009.t-msedge.net
United States
120.136.14.8
www.saiengroup.com
Japan
52.96.183.242
LYH-efz.ms-acdc.office.com
United States
152.199.4.44
cs1100.wpc.omegacdn.net
United States
239.255.255.250
unknown
Reserved
198.98.54.45
activemxmore.com
United States
193.222.96.117
bc1q3jc6cu9q5t33q8gpk7h47pw.com
Germany
104.17.2.184
challenges.cloudflare.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States
108.177.122.99
www.google.com
United States
There are 6 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://activemxmore.com/main/main.php#Z0JW4xC8o5rmgQhMFZffZ8eNP94q2Js1KbXPIAX7FotWfKIVKYaJ6owWxBmAkOC5ZzUI9RPPgiLw3urNsCwz12vyER9YFL3ElYnuQdk7v6DzA4m3GTCIW7gAYqzEbDjwBG1rTlypsbY2gl6XeJFaQWLPmkuxXN4yu6ZosyOUKNW083YnMDyDAjtWDXuALz9gF8E7Hs1rgYso1qLO4jsEDVAgT5RFE0Vk9zrQ2shirKHtatheNKSqFtGzzyedy9xHJZyMsQ5TANmKgEZ3pSu4lbEUJT8h2GZMGxz8nE2YrpII3IMsAgxVscQb5Zt8FtUm1uuo8wmAV5jZN5snm0jPca1h9uqPYlbZPGoXcLy8QR7EXz2kzm9Mwa4GFuwDPIDEo1CBMbJD2Qi0qkl0HuMeFRUklrYb9BPyDs9qDS3GIlH9G29nxWBcNwx8Xwk78aFLCObgGfWpAEzhGIEdEgqsMXAKuVRC5xoIlAY2PVsqz1HfKmtpCTRpRs9mn1ZsynbUX9WN4peDrVTbinAUhsj8UtvhvuK3RVYP5VD9kRNLNHW54x0lZkuTNZbjtWnlSlbXgP7AGUmuCjzGQz1QTwKHwW00SomLJxIZnPA4KXymg827I4YBBIj7Fk7xItis11soQ3sA00Wg9ZoR4mtF4MMJ7ThQnAioBLMsOf3Og05pZtg4QJJUwwEEpWuNxNb8yYBndEctEiSEL8ICSrwoXb2n8xaFlmOUkphy3u1IMUmy34aVwGkuSnR0V2GgouaJTshXWjFId2gg7qbD7w70TZ1O1H4qbf95Hr2EKImXLCdS3pwaVDaPDbDETI44YeaFFckpVGmHjAzmZ5xVJIKmTo1N76R5k1LZe5oaLLR5lrrlxYghG1EApFnwLfC5hn5wsuGefyjB0LXyJePqft1F9pcUFO0Wc6tEAaTQIdsJYphID79TAayKALEfzFcLMFqnPkeyxGhv6yeKGnDgyc08XFowlAi8f
malicious
http://www.saiengroup.com/teaz/648c482b60b3906833c9304bab170add/JBVNhz/YW15LmNoZW5AZG91YmxlbGluZS5jb20=
https://activemxmore.com/main/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/2lznf/0x4AAAAAAAQ_ajLYJ-oSKSIN/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/2lznf/0x4AAAAAAAQ_ajLYJ-oSKSIN/auto/normal
https://activemxmore.com/main/main.php#Z0JW4xC8o5rmgQhMFZffZ8eNP94q2Js1KbXPIAX7FotWfKIVKYaJ6owWxBmAkOC5ZzUI9RPPgiLw3urNsCwz12vyER9YFL3ElYnuQdk7v6DzA4m3GTCIW7gAYqzEbDjwBG1rTlypsbY2gl6XeJFaQWLPmkuxXN4yu6ZosyOUKNW083YnMDyDAjtWDXuALz9gF8E7Hs1rgYso1qLO4jsEDVAgT5RFE0Vk9zrQ2shirKHtatheNKSqFtGzzyedy9xHJZyMsQ5TANmKgEZ3pSu4lbEUJT8h2GZMGxz8nE2YrpII3IMsAgxVscQb5Zt8FtUm1uuo8wmAV5jZN5snm0jPca1h9uqPYlbZPGoXcLy8QR7EXz2kzm9Mwa4GFuwDPIDEo1CBMbJD2Qi0qkl0HuMeFRUklrYb9BPyDs9qDS3GIlH9G29nxWBcNwx8Xwk78aFLCObgGfWpAEzhGIEdEgqsMXAKuVRC5xoIlAY2PVsqz1HfKmtpCTRpRs9mn1ZsynbUX9WN4peDrVTbinAUhsj8UtvhvuK3RVYP5VD9kRNLNHW54x0lZkuTNZbjtWnlSlbXgP7AGUmuCjzGQz1QTwKHwW00SomLJxIZnPA4KXymg827I4YBBIj7Fk7xItis11soQ3sA00Wg9ZoR4mtF4MMJ7ThQnAioBLMsOf3Og05pZtg4QJJUwwEEpWuNxNb8yYBndEctEiSEL8ICSrwoXb2n8xaFlmOUkphy3u1IMUmy34aVwGkuSnR0V2GgouaJTshXWjFId2gg7qbD7w70TZ1O1H4qbf95Hr2EKImXLCdS3pwaVDaPDbDETI44YeaFFckpVGmHjAzmZ5xVJIKmTo1N76R5k1LZe5oaLLR5lrrlxYghG1EApFnwLfC5hn5wsuGefyjB0LXyJePqft1F9pcUFO0Wc6tEAaTQIdsJYphID79TAayKALEfzFcLMFqnPkeyxGhv6yeKGnDgyc08XFowlAi8f
https://passwordreset.microsoftonline.com/?ru=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhZLNa9MAAMWbdq1b0dlNET0IEzzIJG2-0xR2SJt-pFuStU0amoOlaZM0bZqkbdK0uYseB8LAgRcPojt6Ei8Kehi7uPP8DwRFPMiObnoeXh7v8d7t_ZLLRBom0lAa2owhaSh3HyMJHMNwFUSRLgFilAqBWVQjQLhHoecVQhLdzmQ9mXr8xL-3_yNTePN8bbO59fnFIbDR9zx3mstkgiBIO7pudrV01xllrI7dM21jhrwDgBMAOIjGNRuUGofRKYFmYZTCYQInYRQlYRhJt0QabslsqAw4TyizGG9CkCJagx25OuTCoseLUtgKhwuuXMQUWYK4cAgrMhcI4tDjRmzIFy72tcWO2B8JIudxTG3BDaSAZySEZ2r4afS6QPteH7kQZ2KG2q_oiu5MRm3XmXoHsf0oa2_LVLkyq3f8Rcjy42q1gpCmQMlwFxs7xZaUX_TC1rRdsn18Z9uFFFrtg9VCXfLl4XAATjhyx9iFbFKCkOliYbCo2K-apqzkLV0k59uUU1B5vcD2XAItBc1i1RBMexdCbdjrBzZfLpXzou808Www5STOmtfAkS_DeAlSF0h7e9jlVa_RbWBzmOk4vR4KVXlZ1gJK1gdsVt015tREwAl80pg3CmatrxqjsSVW8CZV4uyybMrZPO-5TYyzS2irgyjCjDXyltFG9VCv0_zApcJsvUkTSjB383gFZECD7jShRnAYu3PJvTPkbSxxbkaOfRwjHVezzd6GO3F009IuQ2KGZIS_qeKMtDRtWSdLwLelW8uJVOp2ZCPy4CYUyy0vJ1ORi3S2BLyMnxMXxlcTj-4q9OuVr59-j6nIcTzTLNgMjVMGKs_6XmgV8g8JXrJ0oYQTZTxDDOcNX-34vfmYcbbgHLyXAPYSiePEGsu0-aLYEGmeo
https://passwordreset.microsoftonline.com/?ru=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhZLNa9MAAMWbdq1b0dlNET0IEzzIJG2-0xR2SJt-pFuStU0amoOlaZM0bZqkbdK0uYseB8LAgRcPojt6Ei8Kehi7uPP8DwRFPMiObnoeXh7v8d7t_ZLLRBom0lAa2owhaSh3HyMJHMNwFUSRLgFilAqBWVQjQLhHoecVQhLdzmQ9mXr8xL-3_yNTePN8bbO59fnFIbDR9zx3mstkgiBIO7pudrV01xllrI7dM21jhrwDgBMAOIjGNRuUGofRKYFmYZTCYQInYRQlYRhJt0QabslsqAw4TyizGG9CkCJagx25OuTCoseLUtgKhwuuXMQUWYK4cAgrMhcI4tDjRmzIFy72tcWO2B8JIudxTG3BDaSAZySEZ2r4afS6QPteH7kQZ2KG2q_oiu5MRm3XmXoHsf0oa2_LVLkyq3f8Rcjy42q1gpCmQMlwFxs7xZaUX_TC1rRdsn18Z9uFFFrtg9VCXfLl4XAATjhyx9iFbFKCkOliYbCo2K-apqzkLV0k59uUU1B5vcD2XAItBc1i1RBMexdCbdjrBzZfLpXzou808Www5STOmtfAkS_DeAlSF0h7e9jlVa_RbWBzmOk4vR4KVXlZ1gJK1gdsVt015tREwAl80pg3CmatrxqjsSVW8CZV4uyybMrZPO-5TYyzS2irgyjCjDXyltFG9VCv0_zApcJsvUkTSjB383gFZECD7jShRnAYu3PJvTPkbSxxbkaOfRwjHVezzd6GO3F009IuQ2KGZIS_qeKMtDRtWSdLwLelW8uJVOp2ZCPy4CYUyy0vJ1ORi3S2BLyMnxMXxlcTj-4q9OuVr59-j6nIcTzTLNgMjVMGKs_6XmgV8g8JXrJ0oYQTZTxDDOcNX-34vfmYcbbgHLyXAPYSiePEGsu0-aLYEGmeo